Description
HIPAA, EU AI ACT | 45 CFR 164.308(b), 164.502(e), 164.504(e)
HIPAA AI Intake and Governance Review Request Form Template
Document ID: HEL-AI-INTAKE-001 • Version 1.9
A department that adopts an AI tool without routing it through governance review creates exactly the kind of undocumented risk a security risk analysis under 45 CFR 164.308(a)(1)(ii)(A) is supposed to catch. Once an AI system is already processing PHI in production, the organization is retrofitting compliance instead of building it in. AI that is a medical device is high-risk under EU AI Act Article 6(1) and Annex I, while standalone uses such as benefit eligibility and triage fall under Annex III, and clinically influential tools fall under FDA SaMD guidance. All of them require documented pre-deployment review, not a verbal sign-off. Without a standard intake form, every request gets evaluated differently, and the Governance Committee has no consistent basis for comparing risk across proposals.
This form is built in two parts. Part I is the intake request itself, covering requestor information, AI solution overview (model type, hosting model, model basis), intended use, a data and privacy assessment covering PHI data flows, business associate determination (45 CFR 164.308(b), 164.314(a)), vendor model training, and prompt and output retention, security and technical review, clinical and operational risk, legal and compliance and ethical considerations, implementation and monitoring plans, and a requestor certification. Part II is a structured AI Risk Scoring Matrix the Governance Committee applies to assign a risk level and route the request through the appropriate approval path. Appendices cover revision history, signatures, related documents, and a key terms and definitions glossary, giving the Committee a consistent, defensible record for every AI system considered for adoption. If OCR, an accrediting body, or a plaintiff’s attorney later asks how a specific AI system was evaluated before it touched PHI, the completed form is the audit record that answers the question.
What Is Included
Part I: Intake Request Form
- Requestor information, AI solution overview, and intended use sections
- Data and privacy assessment covering PHI data flows, business associate status (45 CFR 164.308(b), 164.314(a)), vendor model training, and data retention
- Security and technical review, and clinical and operational risk sections
- Legal, compliance, and ethical considerations, plus implementation and monitoring plan and requestor certification
Part II: AI Risk Scoring Matrix
- Scoring across privacy, clinical safety, security, legal, and ethical risk domains with four-tier classification (Low, Moderate, High, Critical)
- AI Governance Committee use-only review and disposition section
Reference Appendices
- Revision history, signatures, related documents, and key terms and definitions glossary
Who This Is For
AI Governance Committees and privacy or security officers who need a standard intake process before any new AI tool, pilot, or vendor solution reaches production. Department leads and IT teams proposing a new AI use case use Part I to submit a complete request; the Governance Committee uses Part II to score and classify the risk consistently across every proposal, whether it is a new implementation, a pilot, or an existing tool discovered already in use.
This form is designed to feed directly into the AI Governance Committee Charter’s (HEL-AI-CHARTER-001) intake and approval process and the risk tier classification established in the AI Governance Policy (HEL-AI-GOV-001). Vendor security certifications and product documentation requested in Section 9 (Attachments) are supplied using the AI Vendor Security & Compliance Questionnaire (HEL-AI-VDQ-001).
Format: Microsoft Word (.docx), fully editable • Delivered as an instant digital download • Document ID: HEL-AI-INTAKE-001









Reviews
There are no reviews yet.