<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>HASP Blog</title>
    <link>https://usehasp.com/blog</link>
    <description>Guides on compliant AI, regulated workflows, HIPAA, and building the tools regulated teams actually need.</description>
    <language>en-us</language>
    <lastBuildDate>Fri, 22 May 2026 00:00:00 GMT</lastBuildDate>
    <managingEditor>hello@usehasp.com (HASP Team)</managingEditor>
    <webMaster>hello@usehasp.com (HASP)</webMaster>
    <image>
      <url>https://usehasp.com/og-image.jpg</url>
      <title>HASP Blog</title>
      <link>https://usehasp.com/blog</link>
      <width>144</width>
      <height>76</height>
    </image>
    <atom:link href="https://usehasp.com/blog/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>HIPAA Security Rule and AI: What § 164.308 Requires of Vendors</title>
      <link>https://usehasp.com/blog/hipaa-security-rule-for-ai-vendors</link>
      <guid isPermaLink="true">https://usehasp.com/blog/hipaa-security-rule-for-ai-vendors</guid>
      <description>When you put AI into a HIPAA workflow, the AI vendor becomes a business associate. Here is how to evaluate that vendor through the lens of § 164.308.</description>
      <pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate>
      <author>hello@usehasp.com (HASP Team)</author>
      <category>HIPAA security rule AI</category><category>45 CFR 164.308</category><category>administrative safeguards AI</category><category>HIPAA security rule administrative safeguards</category><category>AI business associate HIPAA</category><category>HIPAA security rule update</category>
    </item>
    <item>
      <title>Real HIPAA Violations From AI: What Regulators Have Penalized</title>
      <link>https://usehasp.com/blog/hipaa-violations-from-ai</link>
      <guid isPermaLink="true">https://usehasp.com/blog/hipaa-violations-from-ai</guid>
      <description>OCR has not yet fined anyone for an AI tool by name. That is a lag, not an all-clear. Here is what regulators have penalized that maps directly onto how AI fails.</description>
      <pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate>
      <author>hello@usehasp.com (HASP Team)</author>
      <category>HIPAA AI violation</category><category>HIPAA AI enforcement</category><category>OCR HIPAA AI fine</category><category>AI HIPAA violation example</category><category>HIPAA risk analysis AI</category><category>impermissible disclosure AI vendor</category><category>HIPAA compliant AI</category>
    </item>
    <item>
      <title>How to Evaluate HIPAA AI Vendors: A 20-Point Checklist</title>
      <link>https://usehasp.com/blog/how-to-evaluate-hipaa-ai-vendors</link>
      <guid isPermaLink="true">https://usehasp.com/blog/how-to-evaluate-hipaa-ai-vendors</guid>
      <description>A 20-point checklist for evaluating HIPAA AI vendors — BAA scope, the inference path, PHI handling, audit integrity, and the vendor&apos;s own posture.</description>
      <pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate>
      <author>hello@usehasp.com (HASP Team)</author>
      <category>HIPAA AI vendor checklist</category><category>evaluate HIPAA AI vendor</category><category>HIPAA compliant AI vendor</category><category>AI vendor security questionnaire HIPAA</category><category>HIPAA AI due diligence</category><category>BAA AI vendor questions</category>
    </item>
    <item>
      <title>Is ChatGPT HIPAA-Compliant? An Honest Answer for 2026</title>
      <link>https://usehasp.com/blog/is-chatgpt-hipaa-compliant</link>
      <guid isPermaLink="true">https://usehasp.com/blog/is-chatgpt-hipaa-compliant</guid>
      <description>It depends on which ChatGPT, and the default answer is no. Here&apos;s what OpenAI&apos;s BAA actually covers in 2026 — and what a regulated team still has to build around it.</description>
      <pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate>
      <author>hello@usehasp.com (HASP Team)</author>
      <category>is ChatGPT HIPAA compliant</category><category>ChatGPT HIPAA BAA</category><category>OpenAI HIPAA compliant</category><category>ChatGPT Enterprise HIPAA</category><category>ChatGPT PHI healthcare</category><category>HIPAA compliant AI chat</category>
    </item>
    <item>
      <title>Is Claude HIPAA-Compliant? What Anthropic&apos;s BAA Actually Covers</title>
      <link>https://usehasp.com/blog/is-claude-hipaa-compliant</link>
      <guid isPermaLink="true">https://usehasp.com/blog/is-claude-hipaa-compliant</guid>
      <description>Anthropic will sign a BAA for some Claude products and not others. Here&apos;s what that BAA covers, what it leaves to you, and how to tell the difference.</description>
      <pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate>
      <author>hello@usehasp.com (HASP Team)</author>
      <category>is Claude HIPAA compliant</category><category>Anthropic BAA</category><category>Claude HIPAA</category><category>Claude business associate agreement</category><category>Anthropic HIPAA compliance</category><category>HIPAA compliant AI</category>
    </item>
    <item>
      <title>PHI Scanning vs. Redaction: What Actually Protects Data</title>
      <link>https://usehasp.com/blog/phi-scanning-vs-redaction</link>
      <guid isPermaLink="true">https://usehasp.com/blog/phi-scanning-vs-redaction</guid>
      <description>Scanning finds PHI in a prompt. Redaction removes it. They are not the same thing, and redaction is not the safe default most teams assume it is.</description>
      <pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate>
      <author>hello@usehasp.com (HASP Team)</author>
      <category>PHI scanning AI</category><category>PHI redaction</category><category>de-identification AI</category><category>PHI detection healthcare AI</category><category>HIPAA Safe Harbor de-identification</category><category>redact PHI before AI</category>
    </item>
    <item>
      <title>Prior Authorization and AI: What Works, What Doesn&apos;t</title>
      <link>https://usehasp.com/blog/prior-authorization-and-ai-what-works-what-doesnt</link>
      <guid isPermaLink="true">https://usehasp.com/blog/prior-authorization-and-ai-what-works-what-doesnt</guid>
      <description>AI can cut prior authorization work significantly - but only if the deployment handles PHI correctly and leaves the right decisions to humans. A practical breakdown.</description>
      <pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate>
      <author>hello@usehasp.com (HASP Team)</author>
      <category>AI prior authorization</category><category>prior auth automation</category><category>HIPAA AI healthcare</category><category>clinical documentation AI</category><category>AI for healthcare workflows</category><category>prior authorization software</category><category>healthcare AI compliance</category>
    </item>
    <item>
      <title>Built on every model. Never locked to one.</title>
      <link>https://usehasp.com/blog/built-on-every-model-never-locked-to-one</link>
      <guid isPermaLink="true">https://usehasp.com/blog/built-on-every-model-never-locked-to-one</guid>
      <description>Single-provider AI deployments are a resilience problem, a pricing problem, and a model-quality problem. Multi-provider deployments are a compliance problem — unless someone else owns the BAA. Here&apos;s the case for model-agnostic regulated AI.</description>
      <pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate>
      <author>hello@usehasp.com (HASP Team)</author>
      <category>multi provider AI</category><category>AI provider fallback</category><category>model agnostic AI</category><category>Claude vs GPT BAA</category><category>AI provider outage</category><category>Anthropic OpenAI BAA</category><category>AI vendor lock in HIPAA</category>
    </item>
    <item>
      <title>What Makes an Audit Trail Hold Up in an Investigation</title>
      <link>https://usehasp.com/blog/the-audit-trail-your-compliance-officer-wants</link>
      <guid isPermaLink="true">https://usehasp.com/blog/the-audit-trail-your-compliance-officer-wants</guid>
      <description>Application logs and compliance audit trails are different things. Here&apos;s what a real audit trail looks like for AI systems handling regulated data - and why the gap between the two matters.</description>
      <pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate>
      <author>hello@usehasp.com (HASP Team)</author>
      <category>AI audit trail</category><category>HIPAA audit controls</category><category>compliant AI audit log</category><category>AI compliance logging</category><category>tamper-evident audit trail</category><category>regulated AI</category><category>AI governance healthcare</category>
    </item>
    <item>
      <title>What a HIPAA BAA Actually Covers When You Use AI</title>
      <link>https://usehasp.com/blog/what-a-hipaa-baa-actually-covers-with-ai</link>
      <guid isPermaLink="true">https://usehasp.com/blog/what-a-hipaa-baa-actually-covers-with-ai</guid>
      <description>Most AI vendors will sign a BAA. That doesn&apos;t mean the BAA covers what you think it does. Here&apos;s what to check before you call your AI deployment compliant.</description>
      <pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate>
      <author>hello@usehasp.com (HASP Team)</author>
      <category>HIPAA BAA AI</category><category>business associate agreement AI</category><category>HIPAA compliant AI</category><category>AI vendor BAA</category><category>PHI in AI</category><category>HIPAA AI compliance</category><category>sign BAA AI tool</category>
    </item>
    <item>
      <title>Why Regulated Teams Can&apos;t Just Use ChatGPT</title>
      <link>https://usehasp.com/blog/why-regulated-teams-cant-just-use-chatgpt</link>
      <guid isPermaLink="true">https://usehasp.com/blog/why-regulated-teams-cant-just-use-chatgpt</guid>
      <description>ChatGPT is a useful tool. It is not a compliant one. Here&apos;s the specific gap between what general-purpose AI offers and what healthcare, legal, and financial services teams actually need.</description>
      <pubDate>Mon, 27 Apr 2026 00:00:00 GMT</pubDate>
      <author>hello@usehasp.com (HASP Team)</author>
      <category>HIPAA ChatGPT alternative</category><category>ChatGPT HIPAA compliant</category><category>regulated AI platform</category><category>compliant AI for healthcare</category><category>AI for legal teams HIPAA</category><category>enterprise AI compliance</category><category>HIPAA AI chatbot</category>
    </item>
  </channel>
</rss>