Not Approved

Not Approved Healthcare AI Vendors

Healthcare AI vendors that currently do not meet VNDRIQ's minimum approval requirements. Review key considerations and governance concerns before any deployment decision.

VNDRIQ strongly advises against deploying Not Approved vendors in any workflows involving Protected Health Information. Organizations that proceed must document the decision, obtain compliance and legal counsel approval, and implement compensating controls.

Common Issues

Governance Concerns Leading to Not Approved

No Business Associate Agreement available

AI model training on PHI without opt-out

Insufficient HIPAA compliance documentation

Critical security certification gaps

Opaque subprocessor data sharing practices

No breach notification procedures documented

Consumer-grade security in enterprise healthcare context

Undisclosed data retention practices

History of regulatory violations or reported breaches

Re-evaluation

Re-evaluation Policy

When VNDRIQ Re-evaluates Not Approved Vendors

Not Approved vendors are subject to re-evaluation when they publish material improvements to their compliance posture or when VNDRIQ identifies new information warranting review.

Triggers for Re-evaluation

  • New or updated BAA published

  • Security certification obtained or renewed

  • AI training policy updated with PHI exclusion

  • Independent compliance audit published

  • Organizational request with supporting documentation

What Organizations Should Do

  • Do not deploy in PHI workflows without compliance and legal counsel review

  • Document formal decision if proceeding against guidance

  • Implement compensating controls and enhanced monitoring

  • Request VNDRIQ re-evaluation if vendor has updated posture

  • Consider approved alternatives in the same category

Common Questions

Frequently Asked Questions

Informational Use Disclaimer

VNDRIQ vendor assessments are based on publicly available information and do not constitute legal, compliance, or purchasing advice. Assessments reflect VNDRIQ's independent analysis at time of last review. Always verify directly with vendors and consult your legal and compliance counsel before making deployment decisions.