Healthcare AI vendors that currently do not meet VNDRIQ's minimum approval requirements. Review key considerations and governance concerns before any deployment decision.
VNDRIQ strongly advises against deploying Not Approved vendors in any workflows involving Protected Health Information. Organizations that proceed must document the decision, obtain compliance and legal counsel approval, and implement compensating controls.
Common Issues
No Business Associate Agreement available
AI model training on PHI without opt-out
Insufficient HIPAA compliance documentation
Critical security certification gaps
Opaque subprocessor data sharing practices
No breach notification procedures documented
Consumer-grade security in enterprise healthcare context
Undisclosed data retention practices
History of regulatory violations or reported breaches
5 vendors found
Google Analytics 4
Analytics
Google Analytics — no BAA available, not recommended for healthcare deployments with PHI
HubSpot Healthcare
Marketing Automation
HubSpot CRM and marketing — no BAA available, not recommended for PHI marketing workflows
Klaviyo
Marketing Automation
Email and SMS marketing platform — no BAA available, not recommended for healthcare PHI campaigns
Mailchimp
Email & Secure Messaging
Email marketing platform — no BAA available, not recommended for healthcare PHI email
Meta Pixel (Healthcare)
Analytics
Meta tracking pixel — no BAA, critical PHI exposure risk, strongly not recommended for healthcare sites
Re-evaluation
When VNDRIQ Re-evaluates Not Approved Vendors
Not Approved vendors are subject to re-evaluation when they publish material improvements to their compliance posture or when VNDRIQ identifies new information warranting review.
Triggers for Re-evaluation
New or updated BAA published
Security certification obtained or renewed
AI training policy updated with PHI exclusion
Independent compliance audit published
Organizational request with supporting documentation
What Organizations Should Do
Do not deploy in PHI workflows without compliance and legal counsel review
Document formal decision if proceeding against guidance
Implement compensating controls and enhanced monitoring
Request VNDRIQ re-evaluation if vendor has updated posture
Consider approved alternatives in the same category
Common Questions
Informational Use Disclaimer
VNDRIQ vendor assessments are based on publicly available information and do not constitute legal, compliance, or purchasing advice. Assessments reflect VNDRIQ's independent analysis at time of last review. Always verify directly with vendors and consult your legal and compliance counsel before making deployment decisions.
VNDRIQ Intelligence Platform