HIPAA was written in 1996. There were no large language models (LLMs), RAG systems, or ambient AI scribes at the time. Yet HIPAA applies to these technologies today. Why? Because HIPAA is technology neutral. It regulates how protected health information (PHI) is used, disclosed, and protected, not which technology processes it.
AI, however, creates more places for PHI to move. An AI workflow can connect an EHR to an API, cloud environment, model provider, AI application, storage layer, and downstream vendors. Every connection expands the security boundary. That is why a BAA for HIPAA compliant AI matters.
A Business Associate Agreement (BAA) is the contract every vendor must sign before it creates, receives, maintains, or transmits PHI on your behalf. In an AI workflow, that can mean the application vendor, the model provider, the cloud host, and the subcontractors behind them.
This guide covers when an AI vendor needs a BAA, what the agreement does and does not cover, which clauses to redline, and a checklist to run before PHI reaches a model.
When does an AI Vendor Need a BAA for HIPAA compliant AI?
An AI vendor needs a BAA when it creates, receives, maintains, or transmits PHI on your behalf. What matters is what the vendor does with PHI, not whether the product calls itself an AI tool.
That can include:
- an AI model that reads clinical notes;
- an ambient scribe that records or stores patient conversations;
- an AI platform that retains prompts containing PHI; or
- a service that processes patient information as part of an AI workflow.
If the vendor acts as a business associate and no exception applies, you need a BAA.
When does an AI Vendor Not Need a BAA?
Here’s when AI vendors don’t need a BAA:
De-identified data: HIPAA no longer treats data as PHI once you properly de-identify it using Safe Harbor or Expert Determination under 45 CFR 164.514(b). A vendor that receives only de-identified data does not need a BAA for that data. The order matters, though. If you send PHI to a vendor so the vendor can de-identify it, you still need a BAA that allows the vendor to perform that work.
Conduit Services: HIPAA’s conduit exception applies to services that only transmit information and retain it temporarily, such as traditional delivery or transmission services. HHS says a cloud service that stores ePHI is not a conduit, even with encrypted data and no key. An AI service that processes prompts is not transmission-only.
No PHI Involved: If you use AI to draft policies, summarize public research, or work with information that contains no PHI, you do not need a BAA for that activity.
A vendor claiming no BAA is needed is making a technical claim. Verify it.
And I recommend a BAA should be in place before you disclose PHI to a business associate. A retroactive BAA does not repair the HIPAA violation your organization has committed by transmitting PHI to an AI vendor without a signed agreement.
What a BAA for HIPAA Compliant AI Covers in 2026
Under 45 CFR 164.504(e), a BAA binds the vendor to use PHI only as permitted, apply safeguards, report breaches, flow terms down to subcontractors, open records to HHS, and return or destroy PHI at termination.
That is the vendor’s half of shared responsibility in HIPAA AI. You still control how people and AI systems access PHI, which tools they use, what activity you log, and how you assess ongoing risk.
Safeguards on the covered service
Access control and minimum necessary
Breach reporting and subcontractor flow-down
Audit logging and monitoring
Return or destruction of PHI
Training, approved-tool policy, and risk analysis
HIPAA does not currently require annual technical certification from every business associate. The proposed Security Rule update would add stronger verification requirements for business associates, but the proposal is not yet final.
AI Vendors That Sign a BAA for HIPAA: 2026 Status
Once you know what an AI vendor BAA should contain, the next question is whether the product you plan to use actually offers one.
As of September 2026, the major AI vendors handle BAA coverage differently:
AI vendor / product
BAA availability
What you need to know
ChatGPT Free / Plus / Business
No
OpenAI does not list these plans among its HIPAA-eligible products. Do not use them to process PHI.
ChatGPT Enterprise
Yes, conditional
Coverage applies to ChatGPT Enterprise with Regulated Workspace, not Enterprise by default. Some features remain outside of BAA coverage.
ChatGPT for Healthcare
Yes
OpenAI offers a BAA, does not train its models on customer content, and provides healthcare-specific security and governance controls.
ChatGPT for Clinicians
Yes
OpenAI currently lists it as a HIPAA-eligible product under its BAA framework.
OpenAI API
Yes, conditional
Your organization needs a BAA and an account provisioned with Modified Retention. Only HIPAA-eligible endpoints and configurations should handle PHI.
Google Workspace with Gemini
Yes, for included functionality
Google currently includes the Gemini app and Gemini in Workspace under its HIPAA BAA. Gemini in Chrome is excluded.
Microsoft Copilot / Copilot Chat
Yes, conditional
Microsoft supports HIPAA compliance for properly configured implementations. Web search queries sit outside the DPA and BAA.
Azure OpenAI Service
Yes, conditional
Microsoft provides BAA coverage through its Data Protection Addendum for in-scope services. Verify the exact service, deployment, and modality before processing PHI.
Anthropic Claude API
Yes, conditional
Anthropic may provide a BAA for qualifying HIPAA-eligible services such as its first-party API. Claude Free, Pro, Max, and general Claude for Work are not covered.
Otter.ai
Yes, Enterprise only
Otter currently makes HIPAA support, and its BAA process available on the Enterprise plan, not the Business plan.
The key point is that BAA coverage follows the specific service, not the vendor name.
As you can see, Anthropic’s BAA covers its first-party API and Enterprise organizations where a Primary Owner has activated HIPAA settings and accepted the agreement. A standard Enterprise plan is not covered until then. OpenAI lists a short set of HIPAA-eligible products, including ChatGPT for Healthcare, ChatGPT for Enterprise with Regulated Workspace, and the API with Modified Retention.
Within covered tiers, OpenAI excludes cloud browser use, event-triggered scheduled tasks, Codex in the cloud, and improved memory. Anthropic excludes third-party data flows through connectors, MCP, and Claude in Chrome, plus Cowork and beta features. Administrators can switch these on, and then the risk is theirs. Coverage can also depend on when you accepted your BAA.
Vendor terms change frequently, so review the latest documentation before approving any AI use involving PHI.
Your BAA may not cover the AI features your team uses. KLEAP reviews your AI stack, flags the gaps, and shows you where PHI could leave your environment. [Get an AI vendor BAA review]
Book a slot with us:
[Get an AI vendor BAA review →]
8 AI Vendor BAA Clauses to Redline Before You Sign
A standard BAA was not written for AI. Redline these eight clauses, and put every answer in the contract, not in a marketing FAQ.
- Training and Secondary Use: HIPAA lets a BAA permit a vendor to use PHI for its own "proper management and administration." Narrow that carve-out so it cannot cover model training. Prohibit using your prompts, outputs, or files as AI training data unless you approve in writing. Vendor documentation can change without notice. Contract terms bind.
- De-Identification Rights: Strike any blanket right to de-identify PHI. HHS says a vendor may de-identify only as the BAA authorizes. Bar re-identification, and bar training on de-identified data.
- Subprocessors and Chain of Liability: Require a named list of AI subprocessors, covering the model provider, cloud host, vector database, and logging tools. Demand advance notice of changes signed downstream BAAs, and vendor liability for every link
- Retention and Zero Data Retention:Ask for retention periods by data type, model, and feature. Zero data retention may not reach every model. Since June 2026, Anthropic's Covered Models require 30-day retention and are unavailable under ZDR unless Anthropic authorizes it.
- Prompt and Abuse Monitoring Logs: Abuse-monitoring logs can hold prompts and responses. OpenAI retains them up to 30 days by default. Require the BAA to cover them, cap their retention, and restrict human review of flagged content.
- Return or Destruction: The rule requires return or destruction of PHI at termination, where feasible. Extend that to embeddings, vector indexes, fine-tuned models, caches, and backups, with written certification and a deadline.
- Breach Notice SLA: HIPAA allows up to 60 days from discovery. You can set a far shorter contractual clock, such as 72 hours, and define security incidents to include attempted access.
- Audit and Log Export: HHS says HIPAA does not require cloud providers to allow customer audits. The contract must. Require audit rights, SOC 2 report access, and log export to your SIEM, including vendor staff access.
A redlined BAA governs the vendor’s side of the boundary. The risks on your side come next. If your team is still defining where AI can and cannot handle PHI, this guide to the HIPAA compliant use of AI in healthcare covers the broader controls around data use, access, and governance.
What a BAA Cannot Stop: Security Risks in HIPAA Compliant AI Workflows
Does a signed BAA stop a data leak? No. It assigns liability. It does not control who pastes PHI into a prompt, what an agent can reach, or where logs land. Map each risk to a control and a Security Rule safeguard.
Risk
Control
HIPAA safeguard
PHI in logs
Log scrubbing, SIEM ownership
§164.312(b)
Over-permissioned RAG
Scoped retrieval, minimum necessary
§164.312(a), §164.502(b)
Shadow AI and PHI in LLM Prompts
Shadow AI is the HIPAA gap a BAA cannot see. A 2026 Wolters Kluwer Health survey found nearly 20% of surveyed healthcare workers admit using unauthorized AI tools. Faster workflows were the top reason. A prompt from a personal account sits outside your BAA. Blocking alone pushes use out of sight. Give staff a sanctioned tool that is good enough, enforce SSO, and use browser DLP or prompt-layer redaction to hold PHI to the minimum necessary.
Connectors, AI Agents, and PHI in Logs
Prompt injection in healthcare AI grows with access. OWASP’s 2026 LLM Top 10 keeps prompt injection first and lifts excessive agency to third. Filtering reduces the risk but does not remove it. So, limit what a manipulated model can reach. Imprivata’s September 2026 survey found 28% of healthcare organizations already run agentic AI in production. Anthropic excludes third-party data flows through connectors from its BAA, and OpenAI says a connector’s availability does not make the connected service covered. Require human approval for any action that moves PHI outside your tenant.
Logs and vector stores can hold PHI too. Retrieval must respect each user’s own permissions, because one over-privileged retrieval identity lets any user pull any patient’s record. Scrub logs, and stream audit logs to your SIEM.
Therefore, test the paths, not the paper. Attempt PHI exfiltration through each sanctioned and unsanctioned AI path before go-live.
Making Your BAA for HIPAA Compliant AI Work in Practice
A BAA assigns liability. It doesn’t prove PHI can’t leave through a browser extension or an over-permissioned connector, so test each sanctioned and unsanctioned AI path before go-live. This is the scoped testing KLEAP runs for healthcare teams.
Want a second set of eyes before PHI goes live? At KLEAP, we work with healthcare security teams on pen testing and compliance, with a concierge approach. We can review your AI vendor intake and test the paths a BAA cannot cover. Talk to KLEAP about an AI vendor security review.
Frequently Asked Question
Does AI need a BAA under HIPAA?
Yes, if the AI vendor creates, receives, maintains, or transmits PHI on your behalf. If no PHI reaches the AI service, you generally do not need a BAA for that use case.
Does ChatGPT sign a BAA, and which HIPAA compliant AI tools do?
Yes, OpenAI offers BAAs for specific eligible products and configurations, not for every ChatGPT plan. Anthropic and Google also offer BAA coverage for certain services, while some features remain excluded, such as Gemini in Chrome.
Does a business associate agreement for AI make a workflow HIPAA compliant?
No. A business associate agreement for AI covers the vendor’s HIPAA obligations, but your organization still owns access control, minimum necessary, audit logging, monitoring, and risk analysis.
Does SOC 2 replace BAA?
No. SOC 2 shows that a vendor has tested certain security controls, while a BAA is the HIPAA-required contract for handling PHI. OCR does not certify software as HIPAA compliant, so SOC 2 should support your vendor assessment, not replace the BAA.
Can an AI vendor use PHI as AI training data?
Not unless the use is permitted under HIPAA, and your agreement allows it. Your BAA should clearly state whether the vendor can use PHI for model training, product improvement, or any secondary purpose.
How does Shadow AI create HIPAA risk?
Shadow AI creates HIPAA risk when employees send PHI to unapproved AI tools that sit outside your BAA coverage. Reduce that risk with SSO, approved-tool policies, browser or endpoint controls, DLP, and staff training.
