AI Vendor Evaluation for US Healthtech: The Compliance Checklist

TL;DR
- US healthtech AI vendors must operate under HIPAA, and increasingly under ONC HTI-1, FedRAMP, or CJIS depending on use case. These are sector-specific requirements, not a single blanket standard like GDPR.
- Before starting a technical evaluation, confirm the vendor can sign a BAA, provide current ISO 27001/SOC 2 reports, disclose PHI processing locations, and share their subprocessor list.
- BAA terms vary widely across vendors. Breach notification timelines, subprocessor change notice, liability caps, and data use restrictions differ enough to affect your risk exposure.
- Vendors who prepare compliance documentation in advance (BAA, subprocessor list, security architecture, audit reports) shorten procurement timelines significantly.
What US healthcare software teams need to verify before starting a technical evaluation
There is a point in every US healthtech vendor evaluation where the technical conversation stops and the compliance conversation begins. The question is whether you hit that wall before or after you have invested weeks of engineering time.
This guide covers what US healthcare software teams at health systems, digital health companies, and EHR vendors need to verify about an AI vendor before beginning technical evaluation.
The regulatory landscape you are operating in
Building AI-enabled software for US healthcare means operating under a distinct set of federal requirements. Unlike EU markets, where GDPR applies broadly, the US framework is sector-specific.
HIPAA: the non-negotiable baseline
The Health Insurance Portability and Accountability Act governs the handling of Protected Health Information (PHI). If your product creates, receives, maintains, or transmits PHI on behalf of a HIPAA Covered Entity or Business Associate, HIPAA applies.
For AI vendors processing clinical audio or text, this means two things: your vendor must be able to sign a Business Associate Agreement (BAA) or a Subcontractor Business Associate Agreement (Sub-BAA) and they must demonstrate that their infrastructure meets the HIPAA Security Rule requirements for technical, administrative, and physical safeguards.
Corti has completed a HIPAA risk assessment and holds a HIPAA risk assessment attestation, supporting its ability to meet relevant HIPAA security and compliance expectations.
A vendor without a HIPAA compliant BAA cannot be used in any clinical workflow involving PHI.
ONC HTI-1: the emerging AI transparency rule
The Office of the National Coordinator's HTI-1 Final Rule introduces mandatory transparency requirements for AI and predictive algorithms used in certified health IT. It requires vendors to document 31 source attributes for each Decision Support Intervention, covering training data, intended use, performance metrics, fairness monitoring, and risk management. For builders integrating AI into certified EHR products, this is a compliance obligation, not optional. Corti's approach to AI governance under ISO 42001 directly supports HTI-1 documentation requirements.
FedRAMP: for government-adjacent use cases
If your product serves federal agencies, the VA, DoD health systems, or federally funded programmes, FedRAMP (Federal Risk and Authorization Management Program) authorization becomes relevant. FedRAMP Moderate is required for cloud services handling moderate-sensitivity federal data. Corti achieved FedRAMP Moderate compliance already in 2022.
CJIS: for law enforcement adjacent workflows
If your product is used by any law enforcement adjacent healthcare setting emergency communications, prison health, forensic mental health CJIS compliance may apply. CJIS governs the handling of Criminal Justice Information. Corti maintains CJIS-aligned/external assessment documentation for relevant public safety workflows, including products without direct access to criminal records.
ISO 27001 and SOC 2: enterprise-grade security assurance
Beyond US healthcare-specific requirements, enterprise buyers will also expect evidence of mature information security controls. ISO/IEC 27001 provides an internationally recognised framework for managing information security risks through a certified Information Security Management System (ISMS). SOC 2 further demonstrates that security, availability, confidentiality, and related trust controls are not only designed appropriately, but operate effectively over time.
Corti maintains both ISO 27001 and SOC 2 attestation reports providing customers with independent assurance that Corti’s security governance, operational controls, and risk management practices meet enterprise and healthcare-sector expectations.
The pre-technical checklist
Before your engineering team starts a technical evaluation, the following should be confirmed. Each represents a question your compliance team will ask and a failed answer stops your procurement process.
Questions your Security team will ask
- How does the vendor handle data encryption at rest and in transit?
- What is the vendor's vulnerability management process?
- What audit logging is available? Can your security team access access logs for PHI?
- What is the vendor's incident response plan? Has it been tested?
- Is the vendor on a continuous compliance monitoring platform?
How BAA terms actually differ between vendors
Not all BAAs are equal. The standard obligation is HIPAA compliance, but the terms that matter in practice vary significantly across vendors.
Breach notification timeline
HIPAA requires breach notification without unreasonable delay and no later than 60 calendar days after discovery. In practice, vendors do not negotiate this at all. Corti’s standard BAA requires notice of any non-compliant use or disclosure of PHI, Security Incident, or actual or suspected Breach without unreasonable delay, and no later than five days after discovery. Some general AI vendors may default closer to the HIPAA maximum; in a clinical breach scenario, 60 days is a long time.
Subprocessor change notice
How much notice does your vendor give before adding a new subprocessor? And do you have the right to object? Corti's DPA provides 30-day notice and customer objection rights as standard. This matters when your customer contracts with a health system contain audit rights over your supply chain.
Liability and indemnification
Does the vendor accept liability for breaches caused by its own systems? Review this clause carefully. Some general AI vendors cap liability at a multiple of fees paid; the health data context warrants a closer look at whether that cap is adequate for the risk profile of your product. Corti’s BAA includes indemnity for injury or damages arising from noncompliance, Security Incidents, or Breaches attributable to Corti’s negligence.
Data use restrictions
Does the vendor use your clinical data to train or improve its models? Corti does not use customer data to train models without explicit consent. This should be a standard clause in any clinical AI legal agreement.
Getting to a signed agreement faster
The vendors who close enterprise health system deals fastest are those who make the compliance review frictionless. That means arriving at the legal review with documentation already assembled: BAA, subprocessor list, ISO 27001, SOC 2 and security architecture overview.
For Corti customers, the compliance pack is a standard part of onboarding. The goal is not just to pass your security review but to make the review straightforward enough that you meet your procurement timeline.
The category of healthcare AI that can actually be deployed is defined not by what models can do technically, but by what infrastructure can survive clinical and regulatory scrutiny. Building on Corti means that scrutiny is already largely addressed before your customer asks the question.
Start your compliance evaluation with confidence. Access Corti's Trust Center https://trust.corti.ai/. For compliance documentation, BAA requests, or Security questions, contact privacy@corti.ai.
Build faster. Ship safer. Scale smarter.
Get started with healthcare-native APIs built to power real clinical workflows.




