Massive Bio has made its inaugural strategic investment in Rivvi. Read the announcement

← Glossary

Definition · Allowed AI at work

Zero data retention (ZDR)

Zero data retention (ZDR) is an arrangement where an AI model provider does not store customer prompts or outputs after returning a response. Customers request it to limit how long sensitive data sits with the provider. ZDR is a contract and configuration setting. It is not a HIPAA requirement and does not replace a BAA.

What zero data retention is

By default, many AI model providers keep API inputs and outputs for a limited window, often for abuse and safety monitoring. Zero data retention removes that storage, so prompts and responses are not written to logs after the request finishes. Providers typically grant ZDR to approved accounts, and some features that need stored data do not work with it.

ZDR and HIPAA are separate questions, and the rules vary by provider and product. As of 2026, OpenAI's API BAA does not require ZDR. Eligibility depends on Modified Retention settings, and BAA-eligible endpoints can process PHI even if data is retained. Anthropic, by contrast, covers Claude Code under its BAA only with ZDR enabled on qualified accounts.

ZDR is also different from training. A provider can retain data without training on it, or train on data it keeps briefly. When evaluating a healthcare AI vendor, ask which model providers it uses, what retention applies, and whether BAAs flow down the chain. Rivvi signs a BAA, and patient data is not used to train third-party models.

Questions

Zero data retention, answered

Does HIPAA require zero data retention?
No. HIPAA requires that PHI be protected with safeguards and handled under a BAA, not that it be deleted immediately. A vendor may retain PHI as long as the BAA permits it and the data is secured. ZDR reduces exposure, but it is a choice, not a legal requirement.
Is zero data retention the same as not training on data?
No. Retention is about whether the provider stores your prompts and outputs. Training is about whether that data is used to improve models. A provider can keep data for 30 days for abuse checks and never train on it. Ask about both, separately.
Does OpenAI require ZDR for a BAA?
Not for its API, as of 2026. OpenAI's data controls documentation says BAA eligibility depends on Modified Retention, and BAA-eligible endpoints can be used for PHI even if data is retained. Some features, such as web search, are not HIPAA eligible. Check the current terms before relying on any configuration.
What should I ask an AI vendor about data retention?
Ask which model providers process your data and how long each retains prompts and outputs. Ask whether a BAA covers every subcontractor that touches PHI. Ask whether your data trains any model, and how you can delete it. Get the answers in the contract, not just a sales email.

Try it on your own data today.

Free to start. Most teams are using it the same day.