SitecoreAI, HIPAA, and Healthcare: Building AI-Powered Digital Experiences Responsibly

Healthcare has always been one of the most challenging industries for digital experience platforms. Organizations need to deliver personalized, modern digital experiences while protecting some of the most sensitive data imaginable. With AI becoming a core part of digital experiences, the conversation has become even more nuanced.

Before diving in, I want to caveat everything by saying that HIPAA is a complex regulation, and ultimately your legal, privacy, and compliance teams need to determine what level of risk is acceptable for your organization. Every healthcare organization interprets regulations slightly differently based on its business, risk tolerance, and governance model.

That said, I've spent well over a decade helping healthcare organizations, including providers, payers, and life sciences companies, design and implement digital experience platforms under HIPAA requirements. Over the last few years, Sitecore's platform has evolved significantly, as has Microsoft's Azure ecosystem that underpins it. AI has also fundamentally changed how we think about digital experiences.

This article shares how I think about SitecoreAI, HIPAA, and AI-powered digital experiences today.

Defining Protected Health Information (PHI)

Whenever healthcare organizations evaluate a digital experience platform, the first question should never be, "Does it support HIPAA?"

The better question is:

"What protected health information will our solution collect, process, or store?"

HIPAA defines Protected Health Information (PHI) as individually identifiable health information that is transmitted or maintained in any form or medium.

That sounds straightforward until you begin looking at modern digital experiences.

A patient filling out an appointment request that includes medical information is obviously providing PHI.

But what about someone who:

  • Searches for an oncologist

  • Uses a Find a Doctor experience to locate a cardiologist

  • Browses pages about diabetes treatments

  • Chats with an AI assistant about knee replacement surgery

  • Uses AI-powered search to ask healthcare-related questions

  • Saves physicians or care locations for future appointments

Some of these scenarios clearly involve PHI. Others fall into a much grayer area.

The Department of Health and Human Services (HHS) has also made it clear that website tracking technologies deserve careful consideration. Information such as IP addresses, when combined with healthcare-related interactions, may become individually identifiable depending on how it is collected and used.

There are rarely simple yes-or-no answers.

Healthcare organizations need to understand not only what information they collect, but also how that information is stored, processed, combined with other data, and ultimately used.

There Is Still No Such Thing as HIPAA-Compliant Software

One misconception I still hear regularly is that organizations are looking for "HIPAA-compliant software."

That really isn't how HIPAA works.

HIPAA governs how organizations protect and manage health information. Software provides capabilities that help organizations implement compliant solutions, but software alone cannot make an organization compliant.

The same principle applies to AI.

Adding AI to a platform does not make it compliant.

Moving to SaaS does not make it compliant.

Signing a Business Associate Agreement (BAA) does not make it compliant.

Compliance comes from a combination of:

  • Technology

  • Security controls

  • Organizational policies

  • Workforce training

  • Governance

  • Operational processes

  • Ongoing monitoring

Technology is simply one piece of that larger puzzle.

SitecoreAI and the HIPAA Shared Responsibility Model

One of the biggest changes over the last few years is how Sitecore approaches healthcare.

Rather than thinking about HIPAA as something a software platform either supports or doesn't support, Sitecore now approaches healthcare through a shared responsibility model.

That's exactly how organizations should think about it.

Sitecore is responsible for securing and operating the services it provides. That includes the underlying cloud infrastructure, encryption, identity capabilities, platform security, operational controls, and the ongoing monitoring required to operate enterprise SaaS services securely.

Healthcare organizations remain responsible for what they build on top of that platform.

That includes decisions around:

  • What data is collected

  • Which users can access it

  • Identity and authentication

  • Consent management

  • Data retention

  • Workforce training

  • AI governance

  • Appropriate use of personalization

  • Monitoring and auditing

A secure platform provides the foundation, but compliance ultimately depends on how that platform is implemented and governed.

Business Associate Agreements Have Matured

When I originally wrote about this topic a few years ago, much of the discussion centered around which Sitecore SaaS products would support Business Associate Agreements. At the time, Sitecore was still expanding its healthcare strategy as it transitioned from traditional platform products to its SaaS portfolio.

Today, that conversation has matured considerably.

Sitecore now offers Business Associate Agreements for the SaaS services intended to process or manage protected health information. Those agreements establish Sitecore's responsibilities for safeguarding that data while clearly defining the customer's responsibilities for configuration, governance, access management, and appropriate use of the platform.

As Sitecore has continued evolving into what is now SitecoreAI, more services have moved onto Azure-managed infrastructure under a common operational and security model. For healthcare organizations, that creates a more consistent platform architecture and reduces much of the uncertainty that existed during the early years of Sitecore's SaaS transition.

That doesn't eliminate the need to evaluate every service used within your solution. Third-party integrations, AI services, search platforms, analytics tools, identity providers, and hosting environments should all be reviewed to ensure they align with your organization's compliance requirements and have the appropriate contractual agreements in place wherever protected health information is involved.

AI Changes the Conversation

The biggest change over the last two years isn't simply that Sitecore has matured its healthcare offerings.

It's that AI is becoming part of nearly every digital experience.

Healthcare organizations are rapidly adopting conversational search, AI assistants, intelligent content recommendations, semantic search, and agentic workflows.

Those capabilities introduce entirely new governance questions.

For example:

  • Should AI assistants have access to PHI?

  • Should prompts be stored?

  • How long should conversations be retained?

  • Which AI models process patient interactions?

  • Should AI-generated responses be reviewed by clinicians?

  • How do you prevent hallucinations in healthcare scenarios?

  • What audit trail exists for AI-generated recommendations?

These are not simply technology questions.

They're governance questions.

Organizations should think about AI governance as an extension of their HIPAA governance, not as a separate initiative.

Building a Modern SitecoreAI Healthcare Architecture

One reason SitecoreAI fits well within modern healthcare architectures is that it embraces composability.

Rather than placing every capability into a single platform, organizations can combine specialized services while maintaining clear security boundaries.

A modern healthcare experience might combine:

  • SitecoreAI for content management and experience delivery

  • Sitecore Search for semantic discovery

  • Sitecore CDP and Personalize for audience management and personalization

  • Azure AI services and Azure OpenAI for conversational experiences and intelligent workflows

  • Epic, Cerner, or FHIR APIs for clinical integrations

  • Microsoft Entra ID or another enterprise identity provider for authentication

Each service plays a specific role while remaining governed through appropriate identity, security, encryption, and operational controls.

This modular architecture also makes it easier to isolate where PHI exists, reducing unnecessary exposure across the broader digital ecosystem.

Search, Personalization, and AI in Healthcare

One area that deserves particular attention is search.

Search platforms increasingly rely on AI to understand intent instead of simply matching keywords.

Healthcare organizations should evaluate whether search indexes contain PHI, how search logs are retained, and whether AI-powered search experiences expose sensitive information.

The same applies to personalization.

Modern personalization goes far beyond page targeting. It increasingly combines behavioral signals, first-party profiles, AI models, and customer context to deliver individualized experiences.

The technology is incredibly powerful.

But healthcare organizations should always begin with a simple principle:

Only collect the information you truly need, and only use it for purposes your patients reasonably expect.

The same philosophy should apply to AI agents. Just because an agent can access a system or answer a question doesn't necessarily mean it should. Limiting access to the minimum information required not only reduces compliance risk but also leads to more trustworthy AI experiences.

Implementation Considerations

Technology alone won't determine whether your solution satisfies your organization's compliance requirements.

Successful implementations should incorporate governance from the very beginning.

Some of the areas I encourage organizations to review include:

  • Identity and role-based access controls

  • Encryption of sensitive data at rest and in transit

  • API security

  • Consent management

  • AI governance policies

  • Audit logging and monitoring

  • Data retention policies

  • Prompt and conversation logging

  • Human review processes for AI-generated responses

  • Third-party integrations

  • Vendor Business Associate Agreements

  • Incident response planning

Security should never be bolted on after implementation.

It should be designed into the architecture from day one.

Hosting SitecoreAI on Vercel, Netlify, or Azure

One area that often gets overlooked in healthcare discussions is the front-end hosting platform.

In a modern SitecoreAI implementation, Sitecore manages your content and authoring experience, but the website your visitors interact with is typically hosted separately. For many organizations, that means platforms like Vercel or Netlify, although some choose to host their applications directly in Azure or AWS.

This distinction matters because the front-end application is responsible for serving every page, processing requests, and often interacting with services such as personalization, search, analytics, AI assistants, and backend APIs. Depending on how your application is designed, it may temporarily process or transmit information that could be considered Protected Health Information.

For healthcare organizations, the hosting platform should be evaluated just like any other vendor in the solution. Questions to consider include:

  • Does the hosting provider offer a Business Associate Agreement (BAA)?

  • Where is application data processed and logged?

  • What telemetry and request logs are retained?

  • Are server-side functions processing PHI?

  • How are secrets, API keys, and environment variables secured?

  • What controls exist for access logging, monitoring, and incident response?

Both Vercel and Netlify have significantly expanded their enterprise security offerings over the past few years and support healthcare customers through Business Associate Agreements for qualifying enterprise environments. Organizations should work directly with their hosting provider to understand what services are covered and whether their implementation meets internal compliance requirements.

In some cases, organizations may decide that hosting directly within Azure App Service or another Azure-native hosting model better aligns with their existing governance strategy. There is no universally correct answer. The important consideration is evaluating the entire delivery architecture, not just the content management system.

Ultimately, SitecoreAI, your hosting platform, AI services, search platform, analytics tools, and integrations all form part of a single healthcare solution. Each component should be evaluated for how it handles Protected Health Information and whether appropriate contractual agreements and operational controls are in place.

Final Thoughts

Healthcare organizations no longer need to ask whether modern SaaS digital experience platforms can support HIPAA-sensitive workloads.

The better question is how to architect those experiences responsibly.

SitecoreAI provides a strong technical foundation through Azure, secure SaaS services, Business Associate Agreements for supported healthcare workloads, encryption, identity capabilities, audit controls, and a mature shared responsibility model. Combined with appropriate governance, architecture, and operational processes, healthcare organizations can confidently deliver AI-powered digital experiences while protecting patient trust.

As AI becomes more deeply integrated into digital experiences, the organizations that succeed won't simply be those with the most advanced technology. They'll be the ones that combine innovation with disciplined governance, ensuring every new capability strengthens both the patient experience and the trust patients place in them.

Frequently Asked Questions

Next
Next

Susan’s Hero