Skip to main content

HIPAA AI Intake and Governance Review Request Form

$57.00

Every AI system that touches PHI needs a documented HIPAA intake review before deployment, not after an incident forces the question. The HIPAA AI Intake and Governance Review Request Form is a two-part HIPAA form template covering solution overview, intended use, a privacy assessment (including business associate determination under 45 CFR 164.308(b), 164.314(a)), security review, clinical and operational risk, and legal and ethical considerations, then applies an AI Risk Scoring Matrix the Governance Committee uses to assign a risk level. It creates the documented record needed to approve, condition, or reject any AI use case. Made for AI Governance Committees, IT and security teams, and department requestors.

Category:

Description

HIPAA, EU AI ACT  |  45 CFR 164.308(b), 164.502(e), 164.504(e)

HIPAA AI Intake and Governance Review Request Form Template

Document ID: HEL-AI-INTAKE-001  •  Version 1.9

A department that adopts an AI tool without routing it through governance review creates exactly the kind of undocumented risk a security risk analysis under 45 CFR 164.308(a)(1)(ii)(A) is supposed to catch. Once an AI system is already processing PHI in production, the organization is retrofitting compliance instead of building it in. AI that is a medical device is high-risk under EU AI Act Article 6(1) and Annex I, while standalone uses such as benefit eligibility and triage fall under Annex III, and clinically influential tools fall under FDA SaMD guidance. All of them require documented pre-deployment review, not a verbal sign-off. Without a standard intake form, every request gets evaluated differently, and the Governance Committee has no consistent basis for comparing risk across proposals.

This form is built in two parts. Part I is the intake request itself, covering requestor information, AI solution overview (model type, hosting model, model basis), intended use, a data and privacy assessment covering PHI data flows, business associate determination (45 CFR 164.308(b), 164.314(a)), vendor model training, and prompt and output retention, security and technical review, clinical and operational risk, legal and compliance and ethical considerations, implementation and monitoring plans, and a requestor certification. Part II is a structured AI Risk Scoring Matrix the Governance Committee applies to assign a risk level and route the request through the appropriate approval path. Appendices cover revision history, signatures, related documents, and a key terms and definitions glossary, giving the Committee a consistent, defensible record for every AI system considered for adoption. If OCR, an accrediting body, or a plaintiff’s attorney later asks how a specific AI system was evaluated before it touched PHI, the completed form is the audit record that answers the question.

What Is Included

Part I: Intake Request Form

  • Requestor information, AI solution overview, and intended use sections
  • Data and privacy assessment covering PHI data flows, business associate status (45 CFR 164.308(b), 164.314(a)), vendor model training, and data retention
  • Security and technical review, and clinical and operational risk sections
  • Legal, compliance, and ethical considerations, plus implementation and monitoring plan and requestor certification

Part II: AI Risk Scoring Matrix

  • Scoring across privacy, clinical safety, security, legal, and ethical risk domains with four-tier classification (Low, Moderate, High, Critical)
  • AI Governance Committee use-only review and disposition section

Reference Appendices

  • Revision history, signatures, related documents, and key terms and definitions glossary

Who This Is For

AI Governance Committees and privacy or security officers who need a standard intake process before any new AI tool, pilot, or vendor solution reaches production. Department leads and IT teams proposing a new AI use case use Part I to submit a complete request; the Governance Committee uses Part II to score and classify the risk consistently across every proposal, whether it is a new implementation, a pilot, or an existing tool discovered already in use.

This form is designed to feed directly into the AI Governance Committee Charter’s (HEL-AI-CHARTER-001) intake and approval process and the risk tier classification established in the AI Governance Policy (HEL-AI-GOV-001). Vendor security certifications and product documentation requested in Section 9 (Attachments) are supplied using the AI Vendor Security & Compliance Questionnaire (HEL-AI-VDQ-001).

Format: Microsoft Word (.docx), fully editable  •  Delivered as an instant digital download  •  Document ID: HEL-AI-INTAKE-001

Reviews

There are no reviews yet.

Be the first to review “HIPAA AI Intake and Governance Review Request Form”

Your email address will not be published. Required fields are marked *