Governance · 5 minute read
AI and HIPAA Business Associate Agreements: What Must Be in Place
An AI vendor that creates, receives, or transmits protected health information on a covered entity's behalf is a business associate and must sign a business associate agreement before PHI reaches it, including model providers processing PHI. The agreement covers permitted uses, safeguards, breach notification, subcontractor flow-down, and return or destruction, and the covered entity must verify the service tier's terms.
Healthcare organizations adopting AI face a question that consumer AI tools were not designed to answer: who is responsible for protected health information once it reaches a model? The answer is that any vendor or model provider that receives PHI on the organization's behalf is a business associate, and a business associate agreement must exist before the first record flows, with configuration and safeguards that match it. This guide covers when a BAA is required, what it must cover, and the mistakes that create violations, drawing on FISTA Solutions' AI enablement practice. The safety context is in the AI safety in healthcare operations whitepaper and the hospital setting in ai in hospitals. This article is general guidance, not legal advice; organizations should confirm obligations with counsel and privacy officers.
Which AI vendors are business associates?
| Vendor type | Touches PHI when | BAA required |
|---|---|---|
| Model providers via API | Prompts or documents containing PHI are sent | Yes, on a tier that offers one |
| AI application vendors | The application processes patient records | Yes |
| Transcription and documentation tools | Clinical conversations or notes are processed | Yes |
| Infrastructure hosting AI components | PHI is stored or processed on it | Yes, typically already in place |
| Analytics on de-identified data | Data meets the de-identification standard | No, if standard is met |
Provider selection with BAA availability in mind is in how to choose an llm provider.
What must the BAA cover?
Permitted and required uses and disclosures of PHI; a prohibition on other uses, including training or improving models; appropriate administrative, physical, and technical safeguards; reporting of breaches and security incidents within defined timelines; flow-down of the same obligations to subcontractors that touch PHI, including any model providers behind an application vendor; support for individual rights where the vendor holds records; return or destruction of PHI at termination; and compliance with applicable rules. Vendor review practice is in ai third party risk management.
Why does the service tier and configuration matter?
Providers offer BAAs on specific tiers, often enterprise or healthcare offerings, with settings that disable training on inputs, limit retention, and support audit logging. A BAA signed for one tier does not cover usage through another, and a covered tier used with retention or training settings that contradict the BAA is a gap. Verify the tier, the settings, and the region before PHI flows, and monitor that they remain in place. Questionnaire practice is in the ai vendor security questionnaire.
What safeguards must the covered entity still apply?
The BAA governs the vendor; the covered entity's own program governs its AI components: risk analysis including AI-specific threats, minimum necessary PHI in prompts and retrieval, access controls so assistants read only what the user may, encryption of indexes and logs, activity logging with redaction, workforce training, and incident procedures. A compliant vendor behind a leaky application is still a breach. Access design is in ai access control and leakage controls in ai data leakage prevention.
How does de-identification fit?
Data de-identified to the applicable standard is not PHI, and many analytics, model development, and evaluation uses can proceed on it without a BAA. De-identification must actually meet the standard, and re-identification risk in AI contexts, where models can infer identity from combinations, should be assessed. Do not treat removal of obvious identifiers as de-identification. Privacy assessment practice is in the ai privacy impact assessment checklist.
What happens when a vendor has an incident?
The BAA's reporting obligations trigger; the covered entity assesses whether PHI was compromised, which requires knowing what PHI was sent and retained, which requires lineage and logs; notification obligations follow the assessment. AI incidents such as leakage through outputs or logs are within scope. Practice is in ai incident disclosure and trail design in how to build an ai audit trail.
What records should be kept?
The inventory of AI vendors and the PHI each receives; executed BAAs and the tier each covers; configuration evidence for training, retention, and logging settings; risk analyses; access and activity logs; workforce training records; and incident records. Record practice is in ai record keeping requirements.
What mistakes create violations?
Clinicians using consumer AI tools with patient information; BAAs assumed because the vendor's website says compliant; the wrong tier or settings in use; application vendors without flow-down to their model providers; PHI in logs the entity controls; and de-identification that does not meet the standard. Each is common and each is avoidable with inventory, contracts, and configuration checks.
What does compliant practice look like?
A telehealth provider deploying a documentation assistant inventories PHI flows, selects a model provider tier with a BAA, verifies training and retention settings, signs the BAA before any PHI is processed, applies minimum necessary and access controls in its application, encrypts and redacts logs, trains clinicians, and documents the risk analysis. Configuration is re-verified quarterly and after provider changes. The setting is in ai in telehealth.
How FISTA Solutions helps with HIPAA and AI
FISTA Solutions builds healthcare AI systems with minimum necessary data flows, permission-aware retrieval, encrypted and redacted logging, and audit trails, and helps clients select BAA-covered tiers, verify configuration, and extend risk analyses to AI. The AI enablement practice leads privacy-by-design, AI agents ship with the safeguards, and forward deployed engineers embed with client compliance and clinical informatics teams. The record behind the approach is 150+ projects with 99.9% uptime.
To put AI on PHI with the agreements and safeguards in place, message FISTA on WhatsApp, or read the AI safety in healthcare operations whitepaper for the wider safety program.
Share-ready article cover
Download the generated social format.
Clear answers
Questions raised by this field note.
Straightforward guidance for evaluating scope, fit, and the next step.
01Is an LLM provider a business associate?
If it receives, maintains, or transmits protected health information on behalf of a covered entity or business associate, yes, and a BAA is required before PHI is sent. Providers offer BAAs on specific enterprise or healthcare tiers; standard and consumer tiers typically do not qualify.
02What must the BAA cover?
Permitted and required uses and disclosures, prohibition on other uses including training, appropriate safeguards, reporting of breaches and security incidents, flow-down to subcontractors that touch PHI, individual rights support where applicable, return or destruction at termination, and compliance with applicable rules.
03Does the BAA alone make an AI system compliant?
No. The covered entity must still apply the security rule's safeguards to its own AI components, minimize PHI sent, configure the vendor service per the BAA, control access, log activity, and conduct risk analysis. The BAA governs the vendor; the entity's program governs the rest.
04Can de-identified data avoid the need for a BAA?
Data de-identified to the applicable standard is not PHI, so sending it does not require a BAA. De-identification must meet the standard, and re-identification risk in AI contexts should be assessed. Many analytics and model development uses can work this way.
05What configuration must match the BAA?
Data retention and logging settings, training and improvement opt-outs, region and residency where relevant, access controls on the vendor console, and audit logging. A BAA signed for a service used with the wrong settings is a gap.
Continue exploring
Related capabilities
Start with the hard problem
Need the outcome owned, not merely analyzed?
Tell us where delivery is constrained. We’ll map the fastest credible path from intent to verified production.