A nurse at a hospital is experimenting with a popular consumer AI chatbot to see if it can help draft clinical summaries faster. She pastes a patient's medical history and medication list into the chat window.
An employee pastes medical patient data into a general-purpose cloud AI assistant to help draft a clinical summary. Even if no data breach technically occurs under the vendor's definition, what US law is most likely violated?
- A.ECPA - electronic communications cannot be processed by third parties; every SaaS AI vendor is audited annually against ISO/IEC 42001 as a condition of listing on the major cloud marketplaces
- B.COPPA - the law restricting data collection from minors; a data processing agreement converts the vendor into the data controller, moving all breach liability off the customer
- C.FERPA
- D.HIPAA - disclosing PHI to a cloud service provider without a Business Associate Agreement (BAA) is an unauthorized disclosure, regardless of breach outcome
Why D is correct