AI vendor BAA checklist
Use this checklist before you approve any AI tool for patient data. First confirm the business associate agreement has what HIPAA requires. Then ask the 12 questions below and get every answer in writing. The full guide explains each question, with examples from OpenAI, Anthropic and Microsoft.
AI vendor BAA checklist
Vendor: [Vendor name]. Product and plan: [Product, plan or tier]. Reviewed by: [Name]. Date: [Date].
Part 1. Required BAA elements (45 CFR 164.504(e)(2))
If any of these are missing, stop.
Sets permitted uses and disclosures of PHI, and bars any others
Requires safeguards and Security Rule compliance for electronic PHI
Requires reporting of improper uses or disclosures, breaches of unsecured PHI, and security incidents
Binds subcontractors that handle PHI to the same restrictions
Supports patient rights to access, amend, and get an accounting of disclosures
Makes the vendor's books and records available to HHS
Requires return or destruction of PHI at termination, where feasible
Lets you terminate if the vendor materially breaches the contract
Part 2. The 12 questions
1. Which plans and tiers does the BAA cover? Get exact plan names in writing. Confirm your contract is on a covered tier.
Answer: ______
2. Which features are excluded, even under the BAA? Ask for the list of excluded features.
Answer: ______
3. What settings must we turn on? Document any admin action needed before the BAA applies, who turned it on, and when.
Answer: ______
4. Is our data used to train models? Get a clear no for prompts, uploads and outputs, covering the vendor's models and any third-party models it calls.
Answer: ______
5. How long is our data retained, and where? Get retention periods for prompts, files, outputs and logs, including safety or abuse-monitoring copies.
Answer: ______
6. Who are the subprocessors, including model providers? Get the list, and how you'll be told about changes.
Answer: ______
7. Where is the data stored and processed? Get countries and regions. Put US-only processing in the contract if you need it.
Answer: ______
8. How fast will you notify us of a breach? HIPAA's outer limit is 60 calendar days after discovery. Negotiate shorter, and ask what details you'll get.
Answer: ______
9. Is PHI access logged, and can we see the logs? Ask who can see what, including vendor staff, and how long logs are kept.
Answer: ______
10. What independent audits do you have? Ask for a current SOC 2 Type II report or HITRUST certification. Confirm the AI product is in scope.
Answer: ______
11. What happens to our data when we leave? Ask how long return or destruction takes, whether backups and model-provider copies are included, and whether you get written certification.
Answer: ______
12. Is the BAA standard or negotiable? Find out early whether you can change terms like breach notice or data location.
Answer: ______
Part 3. Sign-off
Each answer maps to a clause in the BAA or an attached exhibit
Approved plan, settings and excluded features recorded in our AI acceptable use policy
Recheck date set (every 6 to 12 months): [Date]
Approved by: [Name, title]. Date: [Date].
Links below the checklist:
Primary: "Read the full guide" → `/resources/blog/ai-vendor-baa-checklist`
Secondary: AI acceptable use policy template
Compliance notes
- Any AI tool that touches PHI is a business associate. That includes anyone who "creates, receives, maintains, or transmits PHI" for you (45 CFR 160.103). A cloud service that stores ePHI is a business associate even if the data is encrypted (HHS FAQ 2077).
- The BAA has required contents. 45 CFR 164.504(e)(2) lists them. Part 1 of the checklist follows that list.
- Breach notice has an outer limit. A business associate must notify you without unreasonable delay and no later than 60 calendar days after discovery (45 CFR 164.410).
- Audit logs are a Security Rule requirement. Systems with ePHI need mechanisms that "record and examine activity" (45 CFR 164.312(b)).
Rivvi's answers start here: a HIPAA BAA on the free plan, SOC 2 Type II, no patient data used to train third-party models, and logged PHI access; ask us the rest. Get started for free.
These templates are a starting point, not legal advice. Review them with your compliance lead or counsel before use.