Binding law — in force
AI tools Vermont mental health professionals use must be HIPAA-compliant (Vermont H.816)
Under 18 V.S.A. § 7115(d), the AI tools a Vermont mental health professional may use in providing mental health services are tools that comply with HIPAA (Pub. L. 104-191); FDA-authorized digital therapeutics and software as a medical device are included when prescribed or recommended by a mental health professional. Detect session notes, transcripts or other client records sent to a model API with no business-associate, HIPAA-eligible endpoint or de-identification safeguard.
Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.4
- Lane
- Binding law — in force In force: applies since 17 Jun 2026
- Official source
- 18 V.S.A. § 7115(d) · captured 3 Oct 2026 · anchor hash (SHA-256)
44ec86c51990…· 5 more anchors in the data release - Verification
- Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
- Data release
- Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
- Legal review
- Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
- Audit standard
- Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
- Health fields renamed to generic identifiers
- Model calls wrapped in an internal client
- Vendor coverage (a business associate agreement, a HIPAA-eligible endpoint) is often recorded outside the repository; the finding asks for it, it does not establish that none exists.
Who it applies to
- Duty falls on: individual professional
- Sectors: healthcare
- Vermont mental health professionals as 18 V.S.A. § 7115(a)(2) defines them: individuals licensed, certified or rostered to provide mental health services as physicians, psychiatric APRNs, psychologists, peer support providers and peer recovery support specialists, social workers, alcohol and drug abuse counselors, clinical mental health counselors, marriage and family therapists, psychoanalysts, applied behavior analysts, nonlicensed or noncertified psychotherapists and noncertified psychoanalysts, and any other professional who provides mental health services, for the AI tools they use with client information. What makes an AI tool 'compliant with' HIPAA when the professional is not a covered entity (for example a rostered psychotherapist who does not bill electronically) is a legal question. In force since 2026-06-17.
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Send identifiable health data only to AI endpoints registered with a signed BAA or processing agreement and retention and training off; otherwise de-identify first.
A single client factory for model, embedding and transcription calls that handle health information: it looks the endpoint up in a vendor register and refuses to return a client unless the register shows the required contract (business associate agreement, or a processing agreement barring further disclosure) and the endpoint is the covered deployment with data retention and training use turned off. Call sites that cannot meet that de-identify or redact the record before building the prompt, or check a recorded patient authorization for that use. Keep the vendor register in the repository so reviewers can match each AI endpoint to its legal basis, and never route health data into marketing or other non-care generation.
Where it goes: 6 API calls and integrations, 3 config and feature flags, 7 prompt construction, 12 repository artifacts.
Example (Python + OpenAI SDK (Azure OpenAI)), before:
client = OpenAI()
resp = client.chat.completions.create(model='gpt-4o', messages=[
{'role': 'user', 'content': f'Summarize: {patient.clinical_note}'}])After:
VENDORS = load_yaml('vendors/ai_vendors.yaml') # baa_signed, zero_data_retention per endpoint
def phi_client(name: str) -> tuple[AzureOpenAI, str]:
v = VENDORS[name]
if not (v['baa_signed'] and v['zero_data_retention']):
raise PermissionError(f'{name} is not cleared for PHI')
client = AzureOpenAI(azure_endpoint=v['endpoint'], api_key=os.environ['AZURE_OPENAI_KEY'],
api_version=v['api_version'])
return client, v['deployment']
client, deployment = phi_client('azure-openai-hipaa')
resp = client.chat.completions.create(model=deployment, messages=[
{'role': 'user', 'content': f'Summarize: {patient.clinical_note}'}])Control: Health information sent to an external AI vendor without the contractual or legal basis the law requires. The same guard addresses 8 items with binding law in 7 jurisdictions. Engineering guidance, not legal advice.
Rule id vt-h816.hipaa-covered-ai-tools · review status: primary source derived