HIPAA Turns 30: How to Protect Patient Data in the Age of AI

Thirty years ago, the Health Insurance Portability and Accountability Act (HIPAA) established a national framework for protecting health information. Since then, healthcare has undergone a dramatic transformation—from paper records to electronic health records and from fax machines to interoperable data exchange. Today, healthcare is entering another period of change driven by artificial intelligence (AI). AI is transforming how health data is collected, analyzed, shared and used, creating both new opportunities and new challenges.

To mark HIPAA’s 30th anniversary, CareFirst BlueCross BlueShield (CareFirst) convened a panel of experts across healthcare, technology and privacy to explore a timely question: How can we continue to protect patient data while embracing the opportunities AI presents?

Expert Perspectives on HIPAA and AI

The webinar opened with remarks from Tinna Quigley, Vice President of Government Affairs at CareFirst. Todd Cioni, Vice President of Regulatory Operations and Chief Privacy Officer at CareFirst, moderated the discussion with leaders who bring extensive experience navigating HIPAA at the intersection of AI, digital health and patient advocacy:

  • Pamela Schafer Rayne,Practice Group Leader and Chief Legal Counsel, Johns Hopkins Medicine
  • Deven McGraw, Chief Regulatory and Privacy Officer, Citizen Health
  • Grace Cordovano, PhD, BCPA, Founder, Enlightening Results

HIPAA’s Enduring Foundation

One theme emerged early and often throughout the discussion: HIPAA remains a critical foundation for privacy protections that are now essential for healthcare organizations including hospitals, health plans, clearinghouses and their business associates. Panelists reflected on the law’s lasting impact, noting that while technology has evolved significantly since HIPAA’s enactment, its core principles remain as relevant as ever: protecting sensitive health information, ensuring appropriate access and promoting accountability.

HIPAA’s durability stems in part from its technology-agnostic approach, which allows the framework to evolve alongside changing technologies. At the same time, panelists acknowledged that HIPAA was created in a very different digital era. As healthcare organizations deploy increasingly sophisticated AI tools, new questions are emerging about how existing privacy and security frameworks apply to new use cases, data flows and patient expectations.

The Promise and Challenge of AI

AI is increasingly being used to improve healthcare delivery, reduce administrative burden, support clinical decision-making and enhance patient experiences. Amid long wait times, rising costs and provider shortages, roughly one-third of adults are turning to AI for health information and advice to supplement traditional healthcare resources. Of adults who use AI for health information, 59% are researching symptoms, diagnoses and treatments before doctor visits.

Grace noted that many patients are sophisticated AI users who can “digest information, make sense of our diagnoses…and other parameters that are not just clinical…[but also] vary from person to person to really derive personalized care.”

At the same time, HIPAA’s framework is limited in scope and does not encompass many common consumer activities, such as AI-enabled chatbots, apps and wearables. Many consumers may not realize this and have a false sense of security when sharing personally identifiable information they assume is protected.

Reaching AI’s potential will require patient and provider education, thoughtful governance and responsible data practices. Organizations will need to evaluate how AI systems are trained, what data they rely on and how to ensure transparency, accountability and appropriate safeguards throughout the AI lifecycle.

As Pamela noted, “If we can use AI responsibly and do it correctly, I think administrative burden costs will come down and patient satisfaction will increase.”

Navigating a Growing Patchwork of State Laws

Panelists also discussed the rapidly evolving landscape of state AI and privacy laws. So far in 2026, 43 states have introduced more than 240 AI-related health bills. While many of these proposals share the goal of protecting consumers and promoting responsible data use, a growing patchwork of state-specific requirements presents challenges for healthcare organizations operating across multiple jurisdictions.

Inconsistent definitions and compliance requirements can make it harder to create consistent privacy protections while increasing operational complexity for healthcare organizations. Panelists noted that this complexity can divert resources away from patient care and innovation.

Deven emphasized the importance of Congress advancing comprehensive federal legislation in an increasingly data-driven environment, especially as more health-related data is generated outside traditional care settings.

Looking Ahead

Thirty years after HIPAA’s enactment, its mission remains unchanged. The tools may be different, the data ecosystem may be more complex and the pace of innovation may be accelerating, but the responsibility to protect patient information and earn consumer trust remains at the heart of healthcare.

There is no single solution to these challenges. Success will require collaboration among policymakers, healthcare organizations, technology developers, privacy professionals and patients themselves. It will also require ongoing dialogue about how existing frameworks can adapt to emerging technologies while maintaining the protections that patients expect and deserve.

CareFirst is committed to thoughtful partnership, innovation and proactive policy engagement that improves care for the members we serve every day. Reflecting on HIPAA’s legacy helps inform how we continue advancing solutions that support access, affordability and consumer protections in an evolving healthcare landscape.

To learn more about responsible AI use in healthcare, we recommend reviewing work conducted by the National Academy of Medicine, including its AI Code of Conduct project, publication and patient safety initiative.

A full recording of the event can be found here: HIPAA Turns 30: How to Protect Patient Data in the Age of AI