If you run a physio clinic in Leeds or a home care agency in Norfolk and you've just typed "HIPAA compliance and AI" into Google, I have some awkward news. HIPAA is not your law, and the vendor who told you their tool is "HIPAA compliant" has told you almost nothing about whether it's safe to use in Britain.

Here's the short version. HIPAA is an American statute that applies to American healthcare organisations and the companies that work for them. In the UK, health data is governed by UK GDPR, the Data Protection Act 2018, the common law duty of confidentiality, and, if you touch NHS data or are registered with the Care Quality Commission, the NHS Data Security and Protection Toolkit. You can absolutely automate a health-adjacent business with AI, but the questions you need to ask are different from the ones a HIPAA checklist would give you, and most of them are about contracts, settings, and human review rather than clever software.

I've spent the last few years helping small UK businesses work out which bits of their admin to hand to software. The health-adjacent ones are the most rewarding and the most nerve wracking, because the upside is real and the downside is a letter from the Information Commissioner's Office. What follows is what I actually tell them.

Why HIPAA Keeps Turning Up In British Search Results

HIPAA stands for the Health Insurance Portability and Accountability Act, a US federal law from 1996 that sets privacy and security rules for what Americans call protected health information. Most AI tools are built in America, so their marketing pages are covered in HIPAA badges, and British owners reasonably assume that's the standard they need to meet. It isn't.

According to the cross border explainer published by Accountable, HIPAA rarely applies to a UK provider unless you're handling American patient data on behalf of a US covered entity, at which point HIPAA obligations layer on top of UK law rather than replacing it. If you're a UK aesthetics clinic with UK clients, that scenario simply doesn't arise. GDPR Local makes the same point: HIPAA does not directly apply here, and the NHS runs its own security regime.

There's one useful thing a HIPAA badge does tell you. A vendor willing to sign a HIPAA business associate agreement has usually built the basic security plumbing, such as encryption, access logs and audit trails. It is not evidence they'll sign a UK GDPR compliant data processing agreement, keep your data in the UK or EU, or refrain from training their models on your clients' consultation notes.

What Actually Governs Health Data In Britain

The foundation is UK GDPR, supported by the Data Protection Act 2018. Under those rules, anything revealing a person's physical or mental health is "special category data", which means processing it is prohibited by default unless you can point to a specific condition that permits it. As the ICO's special category data guidance explains, you need both a lawful basis under Article 6 and a separate Article 9 condition, and the ICO notes this guidance is currently under review because of changes made by the Data (Use and Access) Act.

That Act matters more than most small business owners realise. On 5 February 2026 it replaced the old Article 22 restrictions on automated decision making with new Articles 22A to 22D, which relax the rules for ordinary personal data but deliberately keep the stricter regime for special category data such as health. In plain terms, you have more freedom to let software make decisions about a customer's marketing preferences, and no new freedom to let it make decisions about their health without a human in the loop.

Then there's a layer people forget: the common law duty of confidentiality, which sits alongside data protection law and predates it. If a client tells your massage therapist about a back injury, that's confidential regardless of whether it's ever typed into a computer.

The regulator for all of this is the ICO, and it has real teeth. Under the DPA 2018 fining guidance, the higher maximum penalty is £17.5 million or 4 percent of worldwide annual turnover, whichever is greater, and breaches involving special category data sit in that higher tier. Nobody is fining a six person clinic seventeen million pounds, but the ICO can and does issue reprimands, enforcement notices and smaller fines, and the reputational cost of a published reprimand is brutal in a trust based business.

There's also a small administrative obligation that catches people out. Almost every business processing personal data must pay the ICO's annual data protection fee. Since February 2025 that's £52 for micro organisations and £78 for small and medium ones, with a £5 discount for direct debit. Not paying it can attract a penalty of up to £4,350, which is an expensive way to save fifty quid.

Who Counts As Health-Adjacent

You don't need to be a GP practice for any of this to bite. In my work, health-adjacent usually means one of the following: physiotherapists, osteopaths and chiropractors; dental practices; aesthetics and skin clinics; opticians; community pharmacies; domiciliary care agencies and small care homes; private counsellors and therapists; nutritionists and personal trainers who collect health questionnaires; and the medical secretaries, virtual assistants and billing firms who work for any of them.

Some of those groups have extra rules. If your organisation handles NHS patient data, uses NHSmail or delivers services under an NHS contract, you must complete the Data Security and Protection Toolkit, known as the DSPT, which is an annual self assessment against the National Data Guardian's ten data security standards. According to the 2025 to 2026 DSPT guide from GRC Solutions, failing to complete it can cost you NHSmail access, delay contract renewals and expose you to contract penalties.

For adult social care, the Hertfordshire Care Providers Association reports that changes under the Health and Care Act 2022 and the Data (Use and Access) Act 2025 have made the annual DSPT legally mandatory for CQC registered adult social care providers, and that CQC inspectors now ask for it under the well led quality statements. The 2025 to 2026 deadline was 30 June 2026 and version 9 for 2026 to 2027 is already published, so if you're a care provider reading this, that toolkit is your compliance backbone, and any AI tool you add has to be defensible within it.

The Three Mistakes I See Most Often

The first is pasting client information into a free consumer chatbot. I've watched a clinic receptionist drop a full referral letter into free ChatGPT to "tidy the wording". OpenAI's own help pages confirm that on Free, Plus and Pro plans in a personal workspace, data sharing for model training is switched on by default and you have to go to Settings, then Data Controls, and turn off "Improve the model for everyone". On ChatGPT Business, Enterprise and the API, inputs and outputs are not used for training by default. That single difference is the whole argument for paying for a business tier.

The second is recording consultations without a plan. AI scribes, which listen to a consultation and draft the notes, are wonderful and I recommend them below, but I've seen practitioners switch one on with no privacy notice, no consent conversation, no idea where the audio is stored and no review step before the note goes in the record. Each of those is a separate problem under UK GDPR, and together they're a mess.

The third is the boring one: automation that sends the wrong thing to the wrong person. Beyond Encryption's analysis of ICO incident reporting found that misdirected email remains one of the most common incident types UK organisations disclose, with health featuring prominently in the sector split. When you automate appointment reminders, follow ups and results letters, you scale whatever error rate you already had. Build the recipient check into the workflow before you build the speed.

What The Tools Actually Cost In Pounds

For general AI assistance, ChatGPT Business is the sensible entry point. AI Build Group, a UK OpenAI channel partner, checked OpenAI's UK checkout on 18 September 2026 and found Standard seats at £15 per user per month billed annually or £18 billed monthly, excluding VAT, with a two seat minimum. For a five person practice that's £900 a year on the annual plan, and you get the no training default plus admin controls over who's in the workspace.

Microsoft 365 Copilot is harder to price with confidence. Guides published in 2026 by Compare the Cloud, Syntax, Cloudswitched and Copilot 365 quote UK figures anywhere from £16.10 to £30 per user per month for the add on, and Microsoft restructured its Microsoft 365 licensing on 1 July 2026, when Business Standard rose to £10.80 per user per month according to Nerdster's breakdown. Treat every Copilot figure you read, including these, as something to verify on Microsoft's UK pricing page the week you buy. One detail worth knowing from ExpertSure's Copilot review: Microsoft added Anthropic models as a subprocessor in January 2026, and those are excluded from the EU and UK Data Boundary commitments, so if UK data residency matters to you, ask Microsoft which models your tenant uses.

Google Workspace is the cheaper bundle. Compare the Cloud's May 2026 comparison put Business Standard with Gemini at £11.80 per user per month with AI included in every seat, which for a ten person team came to £1,416 a year against £3,060 for Microsoft with Copilot at full price.

For AI scribes specifically, Heidi Health is the name most UK clinicians know. It has a free tier with unlimited transcription on standard templates and ten advanced actions a month, and Heidi's help centre says pricing is regional and billed in local currency. The Online GP's comparison piece puts the UK paid tier at around £50 per user per month, while US reviewers such as Vero and Twofold report the equivalent Clinician plan at $150 a month after a February 2026 restructure, so the UK price is a genuine bargain by comparison. Where a tool only bills in US dollars, the pound figures I give are approximate conversions and will move with the exchange rate.

Best for: ChatGPT Business suits admin heavy small teams that want drafting, summarising and a paper trail. Google Workspace with Gemini suits businesses already living in Gmail and Docs who want the cheapest defensible option. Heidi suits any clinician who writes consultation notes and can commit to reviewing every one. Copilot suits practices already paying for Microsoft 365 Business Standard or Premium who value staying inside Outlook and Word more than they value a predictable bill.

The July 2026 Ruling That Changed AI Scribes

This is the most important recent development for anyone in a clinical setting, and it happened a few weeks ago. In April 2025, NHS England published guidance that effectively treated every ambient scribing product that summarised a consultation as a medical device, which meant registration with the Medicines and Healthcare products Regulatory Agency, the MHRA, and a lot of confused suppliers and practices.

On 29 July 2026 the MHRA overruled that position. According to the MHRA's own announcement on GOV.UK, ambient voice technology products that are intended solely to transcribe, summarise clinical conversations, draft letters or suggest clinical codes for a clinician to review are not regulated as medical devices under the current framework. NHS England adopted the guidance the same day and revised its own document to remove its earlier interpretation.

Two caveats. As Bristows' analysis notes, the guidance only interprets the law applicable in Great Britain; Northern Ireland remains under the EU Medical Devices Regulation. And the exemption depends on intended purpose, so the moment a scribe starts making diagnostic suggestions or clinical recommendations, it's back in medical device territory. If a vendor's sales deck brags about "clinical insights", ask them in writing whether the product is registered with the MHRA and, if not, why not.

The evidence on time saved is also thinner than the adverts suggest. A BMJ commentary published in 2026 points out that the research base for ambient voice technology is still emerging and often relies on weak study designs. My own observation is that scribes save time for people who were slow typists and add time for people who now spend it correcting the draft. Trial one for a fortnight on your real caseload before you commit a team to it.

The One Document I Make Every Client Write

That document is a data protection impact assessment, or DPIA. It's a structured write up of what you plan to do with personal data, why, what could go wrong for the people involved, and what you'll do to reduce that risk. Under Article 35 of UK GDPR it's mandatory where processing is likely to result in high risk, and the ICO's list of operations requiring one includes large scale processing of special category data and innovative use of new technology.

The ICO's guidance on when a DPIA is needed is explicit that, absent a mandatory trigger, you as controller are responsible for assessing whether your processing is likely to be high risk. In my experience, health data plus a new AI tool is enough to justify doing one every time, and the ICO's AI and data protection guidance now includes a dedicated chapter on what to consider in a DPIA for AI. If you decide not to write one, write down why you decided that, because a documented decision is defensible and a shrug is not.

A good small business DPIA for an AI tool fits on three pages. Describe the tool and the data it touches. Name the lawful basis and the Article 9 condition. Record where the data is stored and whether it leaves the UK. List the risks: model training on your data, audio retained longer than needed, hallucinated content entering a record, a staff member using a personal account. Then write one mitigation per risk, with a name next to it. That's it, and it takes an afternoon.

Contracts, Processors, And What The Advanced Fine Teaches

Every AI vendor you use with client data is a processor, and UK GDPR requires a written contract with each one. In practice that means a data processing agreement, which most reputable providers publish online and let you accept as part of sign up. Read the clauses on sub processors, international transfers, retention and deletion, and whether they'll notify you promptly of a breach so you can meet your own 72 hour reporting window to the ICO.

The reason I'm so insistent about this is a fine from March 2025. The ICO fined Advanced Computer Software Group £3.07 million after a 2022 ransomware attack on its health and care subsidiary that exposed the personal data of 79,404 people, including details of how to get into the homes of 890 people receiving care. The attackers got in through a customer account without multi-factor authentication, and as the ICO's enforcement notice records, the regulator found gaps in MFA coverage, vulnerability scanning and patching. The initial proposed penalty was £6.09 million, reduced for cooperation.

Notice who was fined. Not the care agencies, the supplier. But those agencies still lost access to their records, still had to tell their clients, and still had to explain to CQC why their operation ground to a halt. GDPR Course's tally puts the ICO's 2025 monetary penalties at six notices worth more than £20 million, the regulator's biggest year by value since 2020, so the direction of travel is not towards leniency.

Three concrete lessons for a small business. Turn on multi-factor authentication for every account that can see client data, including the AI tools. Ask each vendor where the data physically sits, and if it's in the United States, ask what transfer mechanism they rely on, such as the UK extension to the EU US Data Privacy Framework or standard contractual clauses. And keep a one page register of every tool, what data it holds, and who the named contact is, because when something goes wrong, the first question the ICO asks is what you knew.

A Workflow I'd Actually Put In A Clinic

Here's the setup I've used with a four practitioner physio and sports injury clinic, with details changed.

Intake stays human. The form the patient completes is a standard secure web form on a UK hosted booking system, and no AI touches it. The health questionnaire is special category data from the moment it's submitted, so it goes straight into the practice management system with role based access and nothing else.

Consultation notes use an AI scribe on the practitioner's own device, with a printed notice in reception and a one sentence verbal check at the start of each session: "I use a note taking tool that listens to our conversation and drafts my notes, which I then check. Are you comfortable with that?" A no is recorded and honoured. Audio is set to delete once the note is generated, and the practitioner reads the full draft before it's saved. That review step is not optional; the NEJM AI trial cited by The Online GP found errors in every category reviewed across the scribes tested.

Admin uses ChatGPT Business with the workspace configured so nobody can use a personal account for work. Staff draft appointment reminder templates, rewrite policies and summarise supplier emails there. The rule on the wall is simple: no names, no dates of birth, no clinical details go into the assistant, ever, because the templates don't need them. Personalisation happens inside the practice management system by mail merge, not inside the AI.

Reminders and follow ups run on the practice management system's own automation, with two guardrails. The recipient field is locked to the patient record, so nothing can be sent to a free typed address, and any message that references a clinical outcome requires a practitioner to approve it before it goes. It's slower than full automation by about ninety seconds a message, which is the price of not becoming the next misdirected email statistic.

Everything is written in a DPIA of about four pages, reviewed once a year and after any tool change. Total software cost for the four practitioners and one administrator: roughly £75 a month for the ChatGPT Business seats, the scribe on Heidi's free tier for two practitioners and the paid tier for two, and whatever they were already paying for their booking platform.

When The Honest Answer Is Don't

Some situations shouldn't be automated yet, and I'd rather lose the work than pretend otherwise.

If you can't get a data processing agreement from a vendor, don't use them with client data, however good the product. If the tool won't let you turn off model training, or the answer to "where is my data stored" is a shrug, walk away. If your team is three people and you haven't done the basics, such as MFA, a current privacy notice and the ICO fee, do those first; an AI tool on top of a wobbly foundation just gives the wobble more reach.

Care providers in the middle of a DSPT submission should finish it before adding anything new, because every tool you add is another line of evidence you'll need to produce. And if what you really want is someone to answer the phone warmly, take a booking and notice when a regular sounds worried, that's a person, not a workflow. Health-adjacent businesses are where the case for hiring over automating is strongest.

Something You Can Do This Week

Pick the one AI tool your team is already using, officially or not, and check three things. Is the account a business tier with model training switched off, or a personal one? Is there a signed or accepted data processing agreement, and can you find it? And has anyone written down, even in a paragraph, what data goes in and what happens to it?

If all three are yes, you're ahead of most of the sector and your next job is a proper DPIA. If any are no, fix that one thing before Friday. AI compliance for health-adjacent businesses in the UK isn't about HIPAA badges or American penalty figures. It's about UK GDPR, the ICO and, for many of you, the DSPT, and it's mostly about doing small, boring things properly before you do clever things quickly.