
A third of medical groups have built their own AI tools, and the HIPAA work comes with them
About 34 percent of medical groups have built their own tools with AI. Check HIPAA, code ownership and insurance before yours goes live.
About a third of medical groups have used AI to build their own software, and many of those homegrown tools sit in the parts of the practice that handle patient data: scheduling, prior authorization, denials and patient-facing workflows.
A Sept. 22 MGMA Stat poll of 228 medical group leaders found 34 percent have built an app or workflow tool in-house using AI, according to
The approach, often called "vibe coding," lets someone describe what they want in plain language and have a generative AI tool write the code. It puts working software within reach of physicians and administrators who have never written a line of it.
Respondents described building tools for scheduling, prior authorization and denial work, internal dashboards, inventory management, call handling, recalls and staff tracking. Some projects moved closer to protected health information, including charting support, biologic-ordering workflows, coding and audit guidance, and patient-facing tools.
The 10 percent who weren't sure may be the more telling number. MGMA noted that leaders may not have full visibility into what staff are building or testing inside their own organizations. Formal oversight is still catching up: a
Put the tool in the risk analysis
MGMA recommends sorting any homegrown project by what it can see and what it can do. A vacation-request tracker that never touches patient information should not clear the same approval process as a tool that reads the chart, writes back into the EHR or drafts clinical content.
Any homegrown tool that handles electronic protected health information belongs in the practice's HIPAA security risk analysis. Under
The development process counts too. MGMA warns that patient records pasted into a coding assistant to debug a display problem are still PHI, and a consumer AI account should not be assumed to come with a business associate agreement.
Settle who owns it
A side project built by one employee on a Friday afternoon can become something the whole practice depends on within months. MGMA advises practices to put in writing who owns the source code, who holds the passwords and API keys, who approves changes and who fixes the tool if the builder leaves. That matters most when the builder is a physician-owner or a contractor, because ownership of code "is not automatic, and it is a bad thing to litigate later," MGMA wrote.
If the tool stores information that becomes part of the medical record, retention rules follow it. MGMA's example: if the builder leaves in 2028 and the tool is retired in 2029, the practice still needs to produce a legible, authenticated 2027 chart in 2035.
Coverage is the other open question. MGMA recommends asking the practice's insurance broker before go-live whether cyber and professional liability policies would respond to a breach or patient-harm claim involving software the practice built itself.
Buying doesn't remove the risk
Practices that buy AI tools instead of building them face a similar gap. In a recent
For practices ready to experiment, MGMA suggests starting on the lower-risk rungs, prototyping with synthetic or de-identified data, giving new tools read-only access first and keeping the old process running until the new one proves itself. The bar may rise: HHS has proposed tougher HIPAA Security Rule requirements, including stronger encryption, multifactor authentication and security testing, though the changes are not yet final.
Related to this article








