HIPAA Business Associate Agreements for AI Vendors: The Clauses That Actually Matter When PHI Reaches an LLM
A signed BAA does not, on its own, make an AI deployment HIPAA-compliant. The BAA covers the vendor relationship; the deployer still owns the safeguards under 45 CFR 164.308, 164.312, and 164.316. This walks through the clauses that matter when PHI flows into an LLM, the training-on-PHI question every BAA now has to address, and the audit-trail requirements HIPAA imposes on the deployer regardless of what the vendor logs.
Read post →