Applies to any AI system touching Protected Health Information (PHI). Governs how the AI's inputs, outputs, and decision records must be retained + secured + disclosed. Six-year minimum on documentation of policies + AI-decision records tied to a covered function.
If an AI touched a decision that affected a patient's care, coverage, admission, discharge, prescription, priority, or scheduling, then the record of what the AI did (input, output, model version, timestamp) is subject to HIPAA retention.
Standard six-year minimum. State malpractice tail typically pushes this to 7-10 years for clinical AI. "The vendor keeps it" is not a defensible answer when the covered entity is the accountable party.
The counterparty-question rehearsal section in your Snapshot ("reproduce this AI-generated decision from Day 47 as a defensible record") demonstrates the retention discipline works. If it does not, the Snapshot says so plainly.
See counterparty-question rehearsal in the healthcare sample →
The rule is the framing. The reason you'd pay $499 to know is the follow-on cost of NOT having the retention discipline before a request lands.
Read: HIPAA retention -- what it saves you if a request lands →
Healthcare Legal Insurance Banking Pharma RIA / Wealth Education Housing Energy Federal
Independent-verifier determination on ONE of your AI systems + 3 fix-first items + counterparty-question rehearsal + signed declaration.
Buy $499