Business associate agreement (BAA)
A business associate agreement (BAA) is a contract required by HIPAA between a covered entity, such as a provider or health plan, and a vendor that creates, receives, maintains, or transmits protected health information on its behalf. It obligates the vendor to safeguard the PHI, limit its use, report breaches, and pass the same obligations to its subcontractors.
01why it matters for a business
Any vendor in the chain that touches PHI, including cloud hosts, transcription services, AI model providers, automation platforms, and the developer maintaining the system, is generally a business associate or a subcontractor of one. Without a BAA in place, sharing PHI with them is generally a HIPAA violation even if nothing goes wrong. For AI projects, this is often the first practical constraint on which tools can be used.
A BAA is necessary but not sufficient. It defines responsibilities; it does not make a system secure. It also covers specific services: a cloud provider's BAA typically lists eligible services, and a model provider's BAA may cover its API but not its consumer app. Read the scope, and map every component of an AI system to a BAA before PHI flows through it.
02what it looks like in practice
A behavioral health practice plans an AI intake assistant. Mapping the data flow reveals five components that will touch PHI: the web form host, the automation platform, the model provider, the database, and the email service sending confirmations. Four offer BAAs covering the services planned. The automation platform does not, so that step is redesigned to run inside the practice's own cloud environment, which is covered. Only then does development with real data begin.
03common mistakes
- Assuming a vendor is HIPAA compliant because its website says so. Ask for the BAA.
- Signing a BAA for one service and using a different, uncovered one.
- Forgetting subcontractors and developers with access to production data.
- Treating the BAA as the security plan. Safeguards still have to be built.
04related terms
- HIPAA and AIHIPAA and AI refers to how the US Health Insurance Portability and Accountability Act applies when AI systems create, receive, store, or transmit protected health information.
- Protected health information (PHI)Protected health information (PHI) is individually identifiable health information held or transmitted by a HIPAA covered entity or its business associate, in any form.
- SOC 2SOC 2 is an attestation report, defined by the American Institute of Certified Public Accountants (AICPA), in which an independent CPA firm examines a service organization's controls against the Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.
- API integrationAPI integration is connecting software systems through their application programming interfaces (APIs), the defined ways one program can request data from or send instructions to another.
05where insomnia club fits
Insomnia Club maps every component of an AI system that touches PHI before building, so vendor and BAA questions are answered during scoping instead of discovered after launch.
see AI implementation →tell us what keeps you up at night.
Scoped by the people who ship it. Priced before we start.
book a call drop your number