An AI vendor BAA checklist confirms two things. The business associate agreement must contain what HIPAA requires. And it must cover the AI plan and features your staff will actually use. Ask about covered tiers and features, model training, retention, subprocessors, and how fast you'll hear about a breach.
Takeaways
HIPAA sets the floor
45 CFR 164.504(e) lists what every BAA must contain. Start there.
AI adds new questions
Model training, retention, model-provider subprocessors and excluded features aren't covered by the regulation's list.
Scope is where deals go wrong
OpenAI and Anthropic both exclude specific features even when a BAA is signed.
Get answers in writing
A sales call is not a contract. Put the answers in the BAA or an attached exhibit.
Why AI vendors need a closer look
A business associate is anyone who "creates, receives, maintains, or transmits PHI" on your behalf. Any AI tool that takes prompts or uploads with patient data qualifies. You need a signed BAA first.
But a signed BAA isn't the end of it. AI products ship features fast, and vendors cover them unevenly. A tool can be "HIPAA compliant" on one plan and not on the plan your staff bought. It can be covered for chat but not for a new agent feature. The checklist below catches those gaps.
What HIPAA requires in every BAA
Under 45 CFR 164.504(e)(2), a BAA must:
- Set the permitted uses and disclosures of PHI, and bar any others.
- Require appropriate safeguards and compliance with the Security Rule for electronic PHI.
- Require reporting of uses or disclosures the contract doesn't allow, including breaches of unsecured PHI and security incidents.
- Bind any subcontractors that handle PHI to the same restrictions.
- Support patients' rights to access, amend, and get an accounting of disclosures.
- Make the vendor's books and records available to HHS.
- Require return or destruction of PHI at termination, where feasible.
- Let you terminate if the vendor materially breaches the contract.
If any of these are missing, stop. The questions below assume they're present.
The 12 questions
- 1
1. Which plans and tiers does the BAA cover?
Get the exact plan names in writing. OpenAI states ChatGPT Free, Plus, Pro and Business are not eligible. Anthropic states Claude Team, Free, Pro and Max can't enable HIPAA. Confirm your contract is on a covered tier.
- 2
2. Which features are excluded, even under the BAA?
Ask for the list. OpenAI excludes features including improved memory, browser use in cloud work and cloud Codex. Anthropic excludes Cowork, Web Fetch, Computer Use, MCP connectors, Claude in Chrome and beta features. Microsoft excludes Copilot web search queries.
- 3
3. What settings must we turn on?
Some vendors require an admin action before the BAA applies. Anthropic says standard Enterprise plans have no BAA coverage until a Primary Owner enables HIPAA. OpenAI uses a Regulated Workspace setting for Enterprise and Edu. Document who turned it on and when.
- 4
4. Is our data used to train models?
Get a clear no in the contract, covering prompts, uploads and outputs. Ask whether that includes the vendor's own models and any third-party models it calls.
- 5
5. How long is our data retained, and where?
Ask for retention periods for prompts, files, outputs and logs, including safety or abuse-monitoring copies. A BAA doesn't require zero data retention. OpenAI's API, for example, allows PHI on BAA-eligible endpoints with Modified Retention. Know which you have.
- 6
6. Who are the subprocessors, including model providers?
Many AI tools send your data to an outside model provider and a cloud host. Each one that touches PHI must be bound to the same terms, per 164.504(e). Get the list and how you'll be told about changes.
- 7
7. Where is the data stored and processed?
Ask which countries and regions. Some organizations and payer contracts require US-only processing. Get it in the contract if it matters to you.
- 8
8. How fast will you notify us of a breach?
HIPAA's outer limit for a business associate is 60 calendar days after discovery, and 'without unreasonable delay.' That's too slow to act on. Negotiate a shorter window, and ask what details you'll get.
- 9
9. Is PHI access logged, and can we see the logs?
The Security Rule requires mechanisms that 'record and examine activity' in systems containing ePHI. Ask whether you can see who accessed what, including vendor staff, and how long logs are kept.
- 10
10. What independent audits do you have?
Ask for a current SOC 2 Type II report or HITRUST certification, and read the scope section. Confirm the AI product you're buying is in scope, not just the company's older products.
- 11
11. What happens to our data when we leave?
HIPAA requires return or destruction of PHI at termination where feasible. Ask how long it takes, whether backups and model-provider copies are included, and whether you get written certification.
- 12
12. Is the BAA standard or negotiable?
Click-through BAAs often can't be changed. Anthropic's self-serve Enterprise BAA, for example, is a click-to-accept form that can't be modified. If you need shorter breach notice or US-only storage, find out early.
A BAA on the free plan
Rivvi includes a HIPAA BAA for you and two colleagues. No card. No clock.
Terms worth knowing
- SOC 2 Type II: an independent auditor's report on whether a company's security controls worked over a review period of several months. A Type I report only checks design at a single point in time.
- HITRUST: a certifiable security framework widely used in healthcare that maps to HIPAA and other standards.
- Zero data retention: a setting where the vendor doesn't store prompts or outputs after processing. It's not required for a BAA, but it reduces exposure.
- Subprocessor: any outside company your vendor uses to handle your data, such as a cloud host or a model provider.
How to run the review
- Send the 12 questions in writing before any pilot.
- Map each answer to a clause in the BAA or an attached exhibit.
- Record the approved plan, settings and excluded features in your AI acceptable use policy.
- Recheck every 6 to 12 months. AI vendors change plans and feature scope often.
If staff are already using unapproved tools, start with shadow AI in healthcare. For plan-by-plan coverage, see how to use AI with patient data.
How Rivvi answers
Rivvi is a HIPAA-compliant AI workspace for healthcare teams. The short version of our answers: a HIPAA BAA is included on the free plan, and Rivvi is SOC 2 Type II. Patient data is not used to train third-party models, and PHI access is logged. The security page has the rest. Ask us the other questions too.
Start with a BAA in place
You and two colleagues, with a HIPAA BAA. No card. No clock.
Sources
- eCFR: 45 CFR 164.504 (business associate contracts)
- eCFR: 45 CFR 160.103 definitions
- eCFR: 45 CFR 164.410 business associate breach notification
- eCFR: 45 CFR 164.312 technical safeguards (audit controls)
- OpenAI: HIPAA Implementation and Configuration Guide (July 9, 2026)
- OpenAI: HIPAA eligible products and functionality
- OpenAI: ChatGPT Regulated Workspace
- OpenAI API: Your data
- Anthropic: Business Associate Agreements for commercial customers
- Anthropic: HIPAA-ready Enterprise plans
- Microsoft: Enterprise data protection in Copilot