← Blog

HIPAA Business Associate Agreements for AI Vendors: The Clauses That Matter When PHI Reaches an LLM

Parminder Singh
Parminder Singh··5 min read
Summarize with AI

A HIPAA BAA for an AI vendor needs more than a signature. This guide maps the clauses that govern PHI in an LLM request, training restrictions, subprocessor changes, incident notice, and deployer-side audit evidence.

Compliance & Regulationhipaacomplianceai-securityphibusiness-associate-agreementhealthcare
HIPAA Business Associate Agreements for AI Vendors: The Clauses That Actually Matter When PHI Reaches an LLM

A clinical assistant can send a SOAP note to an LLM in 400 milliseconds. The request may contain a diagnosis and medication list. It can also include the medical record number, clinician identity, and care-setting detail. A signed Business Associate Agreement determines the vendor's permitted handling of that protected health information. It also leaves the covered entity responsible for the safeguards around the request before it reaches the model endpoint.

The federal requirements in 45 CFR 164.504(e) set the BAA contract requirements. The HIPAA Security Rule separately requires safeguards across administrative, physical, technical, and organizational controls for electronic PHI. I want to make the distinction concrete, because an AI service tier and the application integration have to line up before PHI enters a model request.

TL;DR

Name the exact AI service in the BAA, record its training and retention terms, track its subprocessors, document the approved clinical purpose, and keep a separate request-level audit record in the covered entity's environment. That record must identify the person or agent behind the routed request so the covered entity can reconstruct the event during a complaint or OCR inquiry.

The service named in the BAA

The agreement should identify the exact AI service and account that may receive PHI. "AI services" is too broad for a contract that may sit beside consumer chat products. It can otherwise include development sandboxes, regional endpoints, and enterprise API offerings under the same vendor brand.

Record the model endpoint and cloud region. The same record should name the service tier and account owner. Add the permitted workflow plus review owner. A radiology-summary service and an internal engineering chatbot have different data flows even when both call the same provider. This inventory gives the privacy officer a fixed object to review when the provider changes a product term or launches a new feature.

The agreement also needs the required permitted-use language. Under 45 CFR 164.504(e), the business associate may use or disclose PHI only as the contract allows or as law requires. The provision also covers safeguards and reporting of impermissible uses or disclosures. It extends the relevant restrictions to subcontractors. The clause belongs beside the actual architecture diagram, not in a procurement folder that nobody opens after signature.

Training, retention, human review

The clause with the highest consequence names how the vendor handles prompts and outputs. It should also address derived telemetry. A healthcare organization needs written limits on model training and service improvement. It also needs clear human-review and retention terms for the exact HIPAA-eligible service tier it selected.

Ask the vendor to identify the contract section and product document that applies to the account. Save that version with the BAA. Product terms can change faster than a three-year vendor-review cycle, and a generic statement that "customer data is protected" leaves the material questions unanswered.

The operational record should answer five items:

  • What request content can the vendor retain after inference, and for how long?
  • Does the selected tier exclude PHI from model training and product improvement?
  • Which support or safety workflow can expose a prompt to a human, including abuse review?
  • What configuration controls the customer must enable to obtain the stated retention treatment?
  • Which event requires the vendor to notify the covered entity?

The BAA requirements in 45 CFR 164.504(e) provide the legal baseline. Vendor privacy language is evidence only when it is incorporated into the contractual and technical configuration for the deployed service.

Subprocessors and data-processing terms

An LLM provider may use cloud infrastructure and support vendors while processing a request. Security services and regional affiliates can also process request data. The BAA must require the provider to obtain satisfactory assurances from each subcontractor that handles PHI, as 45 CFR 164.504(e) requires. A separate data-processing addendum can add useful commitments on personal data and international transfers. It does not replace the HIPAA BAA for PHI.

Procurement should ask for the current subprocessor list and the notice period for a material change. It should also document the objection route and the process for an emergency replacement. A dated PDF in a vendor portal is poor evidence when an OCR investigation asks which organization processed a clinical prompt on 14 May 2026.

This is where a vendor-security review needs a real control test. Compare the approved subprocessor list with the service endpoint configured by the application, then retain the evidence with the annual BAA review. The AI vendor security questionnaire has questions for that review, including the fourth-party path that standard SaaS questionnaires often miss.

The audit trail the BAA cannot supply

45 CFR 164.312(b) requires mechanisms to record and examine activity in systems that contain or use electronic PHI. The covered entity owns that evidence for its own clinical application and its outbound AI request path.

Provider audit logs frequently identify an API credential or service account. They may omit the clinician and patient context. They can also omit data classification, policy decision, or the specific application workflow behind a request. A request-level record needs those fields if the organization expects to reconstruct a disclosure during an OCR inquiry. The AI audit log format guide explains the fields that turn an API event into an accountable decision record.

Prompt-level classification matters in the same way. "Clinical note summarization" describes a workflow but leaves out the data that crossed the boundary. The HIPAA PHI redaction guide covers the controls that reduce PHI exposure before a prompt reaches an approved model endpoint.

Disclosure accounting and state-law evidence

HIPAA's accounting-of-disclosures rule at 45 CFR 164.528 includes exceptions for treatment and payment. It also includes healthcare operations and certain business-associate activities. The exception does not erase the facts needed when a patient or regulator asks what was sent to a vendor for an authorized purpose.

Colorado's SB 26-189 adds another reason to keep the request record distinct from the vendor contract. A BAA governs the HIPAA relationship. State-law duties can require separate decisions. The organization's own policies can require further evidence.

DeepInspect

DeepInspect sits inline between authenticated clinical applications or agents and the LLM APIs they call. It can bind routed traffic to the originating identity and inspect the prompt against a policy. The resulting record can include data classification and policy outcome. It can also identify the selected model endpoint.

The request-level record complements the contractual safeguards established by a BAA. The contract controls the vendor relationship; the request record shows what the covered entity allowed through its own application path. Local execution and provider-side account administration remain separate controls. Vendor subprocessor contracting and endpoint configuration have their own owners.

Let's talk today.

Frequently asked questions

Does a signed BAA make an AI deployment HIPAA compliant?

A BAA gives the covered entity the required assurances from its business associate. The organization still has to operate the Security Rule safeguards in its own environment, including access control and audit controls. Authentication and transmission security also remain its responsibility.

Which clauses matter most in a HIPAA BAA for an AI vendor?

Review the permitted service and purpose. Then document the training and retention treatment. Record security safeguards, incident reporting, subprocessor assurances, termination handling, and the vendor's duty to make records available where HIPAA requires them. Tie every clause to the selected service tier and account configuration.

Can an AI vendor use PHI to train its models?

The answer depends on the exact service tier and contract terms. The selected account settings can also change the answer. BAA terms and supporting product documents should state the training treatment plainly, identify the applicable version, and define the change-notice process.

Does a vendor audit log satisfy the HIPAA audit-control requirement?

Vendor logs can support an investigation, but the covered entity needs its own record of the user or agent and permitted purpose. It also needs the data classification, application route, model endpoint, and policy decision for each routed request.