BAA for HIPAA Compliant AI in Healthcare

Hospitals are adopting AI faster than compliance can track. Apps like ambient scribes, diagnostic tools, and scheduling bots all touch PHI and are hence business associates. In such a scenario, BAA for HIPAA compliant AI is a must-have. And yet, just having a BAA won’t suffice anymore. In this blog, we talk about what provisions to have that make a BAA meaningful.

HIPAA was written in 1996. There were no large language models (LLMs), RAG systems, or ambient AI scribes at the time. Yet HIPAA applies to these technologies today. Why? Because HIPAA is technology neutral. It regulates how protected health information (PHI) is used, disclosed, and protected, not which technology processes it.  

 AI, however, creates more places for PHI to move. An AI workflow can connect an EHR to an API, cloud environment, model provider, AI application, storage layer, and downstream vendors. Every connection expands the security boundary. That is why a BAA for HIPAA compliant AI matters.  

A Business Associate Agreement (BAA) is the contract every vendor must sign before it creates, receives, maintains, or transmits PHI on your behalf. In an AI workflow, that can mean the application vendor, the model provider, the cloud host, and the subcontractors behind them.  

This guide covers when an AI vendor needs a BAA, what the agreement does and does not cover, which clauses to redline, and a checklist to run before PHI reaches a model. 

When does an AI Vendor Need a BAA for HIPAA compliant AI?

An AI vendor needs a BAA when it creates, receives, maintains, or transmits PHI on your behalf. What matters is what the vendor does with PHI, not whether the product calls itself an AI tool. 

That can include: 

  • an AI model that reads clinical notes;  
  • an ambient scribe that records or stores patient conversations;  
  • an AI platform that retains prompts containing PHI; or  
  • a service that processes patient information as part of an AI workflow. 

If the vendor acts as a business associate and no exception applies, you need a BAA. 

When does an AI Vendor Not Need a BAA?

Here’s when AI vendors don’t need a BAA: 

De-identified data: HIPAA no longer treats data as PHI once you properly de-identify it using Safe Harbor or Expert Determination under 45 CFR 164.514(b). A vendor that receives only de-identified data does not need a BAA for that data. The order matters, though. If you send PHI to a vendor so the vendor can de-identify it, you still need a BAA that allows the vendor to perform that work. 

Conduit Services: HIPAA’s conduit exception applies to services that only transmit information and retain it temporarily, such as traditional delivery or transmission services. HHS says a cloud service that stores ePHI is not a conduit, even with encrypted data and no key. An AI service that processes prompts is not transmission-only. 

No PHI Involved: If you use AI to draft policies, summarize public research, or work with information that contains no PHI, you do not need a BAA for that activity. 

A vendor claiming no BAA is needed is making a technical claim. Verify it. 

And I recommend a BAA should be in place before you disclose PHI to a business associate. A retroactive BAA does not repair the HIPAA violation your organization has committed by transmitting PHI to an AI vendor without a signed agreement. 

What a BAA for HIPAA Compliant AI Covers in 2026

Under 45 CFR 164.504(e), a BAA binds the vendor to use PHI only as permitted, apply safeguards, report breaches, flow terms down to subcontractors, open records to HHS, and return or destroy PHI at termination. 

That is the vendor’s half of shared responsibility in HIPAA AI. You still control how people and AI systems access PHI, which tools they use, what activity you log, and how you assess ongoing risk. 

The vendor owns 
You own 

Safeguards on the covered service 

Access control and minimum necessary 

Breach reporting and subcontractor flow-down 

Audit logging and monitoring 

Return or destruction of PHI 

Training, approved-tool policy, and risk analysis 

HIPAA does not currently require annual technical certification from every business associate. The proposed Security Rule update would add stronger verification requirements for business associates, but the proposal is not yet final. 

AI Vendors That Sign a BAA for HIPAA: 2026 Status

Once you know what an AI vendor BAA should contain, the next question is whether the product you plan to use actually offers one. 

As of September 2026, the major AI vendors handle BAA coverage differently: 

AI vendor / product 

BAA availability 

What you need to know 

ChatGPT Free / Plus / Business 

No 

OpenAI does not list these plans among its HIPAA-eligible products. Do not use them to process PHI.  

ChatGPT Enterprise 

Yes, conditional 

Coverage applies to ChatGPT Enterprise with Regulated Workspace, not Enterprise by default. Some features remain outside of BAA coverage.  

ChatGPT for Healthcare 

Yes 

OpenAI offers a BAA, does not train its models on customer content, and provides healthcare-specific security and governance controls.  

ChatGPT for Clinicians 

Yes 

OpenAI currently lists it as a HIPAA-eligible product under its BAA framework.  

OpenAI API 

Yes, conditional 

Your organization needs a BAA and an account provisioned with Modified Retention. Only HIPAA-eligible endpoints and configurations should handle PHI.  

Google Workspace with Gemini 

Yes, for included functionality 

Google currently includes the Gemini app and Gemini in Workspace under its HIPAA BAA. Gemini in Chrome is excluded.  

Microsoft Copilot / Copilot Chat 

Yes, conditional 

Microsoft supports HIPAA compliance for properly configured implementations. Web search queries sit outside the DPA and BAA.  

Azure OpenAI Service 

Yes, conditional 

Microsoft provides BAA coverage through its Data Protection Addendum for in-scope services. Verify the exact service, deployment, and modality before processing PHI.  

Anthropic Claude API 

Yes, conditional 

Anthropic may provide a BAA for qualifying HIPAA-eligible services such as its first-party API. Claude Free, Pro, Max, and general Claude for Work are not covered.  

Otter.ai 

Yes, Enterprise only 

Otter currently makes HIPAA support, and its BAA process available on the Enterprise plan, not the Business plan. 

The key point is that BAA coverage follows the specific service, not the vendor name.  

As you can see, Anthropic’s BAA covers its first-party API and Enterprise organizations where a Primary Owner has activated HIPAA settings and accepted the agreement. A standard Enterprise plan is not covered until then. OpenAI lists a short set of HIPAA-eligible products, including ChatGPT for Healthcare, ChatGPT for Enterprise with Regulated Workspace, and the API with Modified Retention.  

Within covered tiers, OpenAI excludes cloud browser use, event-triggered scheduled tasks, Codex in the cloud, and improved memory. Anthropic excludes third-party data flows through connectors, MCP, and Claude in Chrome, plus Cowork and beta features. Administrators can switch these on, and then the risk is theirs. Coverage can also depend on when you accepted your BAA. 

Vendor terms change frequently, so review the latest documentation before approving any AI use involving PHI. 

Your BAA may not cover the AI features your team uses. KLEAP reviews your AI stack, flags the gaps, and shows you where PHI could leave your environment.  [Get an AI vendor BAA review] 

Book a slot with us: 

 [Get an AI vendor BAA review →] 

8 AI Vendor BAA Clauses to Redline Before You Sign

A standard BAA was not written for AI. Redline these eight clauses, and put every answer in the contract, not in a marketing FAQ. 

A redlined BAA governs the vendor’s side of the boundary. The risks on your side come next. If your team is still defining where AI can and cannot handle PHI, this guide to the HIPAA compliant use of AI in healthcare covers the broader controls around data use, access, and governance. 

What a BAA Cannot Stop: Security Risks in HIPAA Compliant AI Workflows

Does a signed BAA stop a data leak? No. It assigns liability. It does not control who pastes PHI into a prompt, what an agent can reach, or where logs land. Map each risk to a control and a Security Rule safeguard. 

Risk 

Control 

HIPAA safeguard 

Shadow AI 

Sanctioned tool, SSO enforcement, browser DLP 

Agent and connector exfiltration 

Least privilege, egress allow-lists 

PHI in logs 

Log scrubbing, SIEM ownership 

§164.312(b) 

Over-permissioned RAG 

Scoped retrieval, minimum necessary 

§164.312(a), §164.502(b) 

Vendor staff access 

Access logging, contract audit rights 

Shadow AI and PHI in LLM Prompts

Shadow AI is the HIPAA gap a BAA cannot see. A 2026 Wolters Kluwer Health survey found nearly 20% of surveyed healthcare workers admit using unauthorized AI tools. Faster workflows were the top reason. A prompt from a personal account sits outside your BAA. Blocking alone pushes use out of sight. Give staff a sanctioned tool that is good enough, enforce SSO, and use browser DLP or prompt-layer redaction to hold PHI to the minimum necessary. 

Connectors, AI Agents, and PHI in Logs

Prompt injection in healthcare AI grows with access. OWASP’s 2026 LLM Top 10 keeps prompt injection first and lifts excessive agency to third. Filtering reduces the risk but does not remove it. So, limit what a manipulated model can reach. Imprivata’s September 2026 survey found 28% of healthcare organizations already run agentic AI in production. Anthropic excludes third-party data flows through connectors from its BAA, and OpenAI says a connector’s availability does not make the connected service covered. Require human approval for any action that moves PHI outside your tenant. 

Logs and vector stores can hold PHI too. Retrieval must respect each user’s own permissions, because one over-privileged retrieval identity lets any user pull any patient’s record. Scrub logs, and stream audit logs to your SIEM. 

Therefore, test the paths, not the paper. Attempt PHI exfiltration through each sanctioned and unsanctioned AI path before go-live. 

Making Your BAA for HIPAA Compliant AI Work in Practice

A BAA assigns liability. It doesn’t prove PHI can’t leave through a browser extension or an over-permissioned connector, so test each sanctioned and unsanctioned AI path before go-live. This is the scoped testing KLEAP runs for healthcare teams. 

Want a second set of eyes before PHI goes live? At KLEAP, we work with healthcare security teams on pen testing and compliance, with a concierge approach. We can review your AI vendor intake and test the paths a BAA cannot cover. Talk to KLEAP about an AI vendor security review. 

Frequently Asked Question

Yes, if the AI vendor creates, receives, maintains, or transmits PHI on your behalf. If no PHI reaches the AI service, you generally do not need a BAA for that use case. 

Yes, OpenAI offers BAAs for specific eligible products and configurations, not for every ChatGPT plan. Anthropic and Google also offer BAA coverage for certain services, while some features remain excluded, such as Gemini in Chrome. 

No. A business associate agreement for AI covers the vendor’s HIPAA obligations, but your organization still owns access control, minimum necessary, audit logging, monitoring, and risk analysis. 

No. SOC 2 shows that a vendor has tested certain security controls, while a BAA is the HIPAA-required contract for handling PHI. OCR does not certify software as HIPAA compliant, so SOC 2 should support your vendor assessment, not replace the BAA. 

Not unless the use is permitted under HIPAA, and your agreement allows it. Your BAA should clearly state whether the vendor can use PHI for model training, product improvement, or any secondary purpose. 

Shadow AI creates HIPAA risk when employees send PHI to unapproved AI tools that sit outside your BAA coverage. Reduce that risk with SSO, approved-tool policies, browser or endpoint controls, DLP, and staff training. 

Share

Table of Contents