AI Vendor BAA Guide
Twenty-one vendor verdicts turn on one contract. Here is what it is, and how to get one.
What a Business Associate Agreement Is
A Business Associate Agreement is the written contract HIPAA requires before a covered entity discloses protected health information to a vendor that will create, receive, maintain, or transmit that information on its behalf. Without one, the disclosure itself is the violation. Not the breach that might follow it.
That is the whole reason every entry in our directory opens with the BAA answer instead of a feature list. A vendor with excellent security and no BAA is still a vendor you cannot lawfully hand PHI.
The requirement sits at 45 CFR 164.502(e) in the Privacy Rule and 45 CFR 164.308(b) in the Security Rule. The required contents are at 45 CFR 164.504(e).
What the Regulation Actually Requires
Three provisions do the work. Read together they say: get satisfactory assurances, put them in writing, and make the writing say specific things.
45 CFR 164.502(e)(1)(i) permits a covered entity to disclose PHI to a business associate only if it "obtains satisfactory assurance that the business associate will appropriately safeguard the information." 164.502(e)(2) then requires that those assurances be "documented through a written contract or other written agreement or arrangement with the business associate that meets the applicable requirements of § 164.504(e)."
45 CFR 164.308(b)(1) is the Security Rule counterpart, and it is narrower and more specific: a covered entity may permit a business associate "to create, receive, maintain, or transmit electronic protected health information on the covered entity's behalf only if the covered entity obtains satisfactory assurances, in accordance with § 164.314(a)." 164.308(b)(3) requires the same documentation in writing.
Every AI tool a health system evaluates is squarely in the ePHI case. Both provisions apply. One contract typically satisfies both.
45 CFR 164.504(e)(2) decides whether the paper you hold is worth anything. The contract must establish the permitted and required uses and disclosures of PHI, and it must require the business associate to:
- Not use or disclose the information beyond what the contract or law permits.
- Use appropriate safeguards and comply with the Security Rule where applicable.
- Report unauthorized uses, disclosures, and breaches.
- Ensure that subcontractors agree to the same restrictions.
- Make PHI available for individual access under 164.524.
- Make PHI available for amendment under 164.526.
- Provide an accounting of disclosures under 164.528.
- Make its records available to the Secretary for a compliance review.
- Return or destroy PHI at termination, or extend the protections if return is not feasible.
Item 4 is the one that gets hard when a vendor runs on somebody else's model.
| Citation | Rule | What it requires |
|---|---|---|
| 45 CFR 164.502(e) | Privacy Rule | Satisfactory assurances before disclosing PHI, documented in a written agreement |
| 45 CFR 164.308(b) | Security Rule | Same requirement, stated for electronic PHI, referencing 164.314(a) |
| 45 CFR 164.504(e)(2) | Privacy Rule | The nine provisions the contract must contain |
| 45 CFR 160.103 | Definitions | A subcontractor handling PHI is itself a business associate |
This is not legal advice, and your counsel makes the call for your organization.
What a BAA Covers and What It Does Not
Treating a signed BAA as a finish line is the expensive mistake. It is a permission, and a narrow one.
| A BAA does this | A BAA does not do this |
|---|---|
| Makes the disclosure of PHI to that vendor permissible under 164.502(e) | Make the tool safe. Safety is access control, screening, retention, and audit |
| Binds the vendor contractually to the nine provisions of 164.504(e)(2) | Authorize any use beyond what the contract itself establishes. 164.504(e)(2)(i) is a ceiling, not a floor |
| Allocates liability and creates breach-reporting duties | Cover a different plan, tier, or product from the one named. Nine of the twenty-one vendors in the directory table below are gated that way |
| Obliges the vendor to flow the same restrictions down to its subcontractors | Prove the vendor did it. That is your diligence, not the contract's |
| Applies to the services the agreement enumerates | Cover services outside the enumerated list, which on hyperscalers is most of them |
| Sits alongside the minimum necessary standard at 164.502(b) | Replace it. A BAA does not license sending more PHI than the task needs |
| Covers the sanctioned deployment your organization configured | Say anything at all about staff using personal accounts |
That last row turns a procurement question into a governance question, which is where this guide ends.
How a Hospital Obtains One
The path depends entirely on what kind of vendor you are dealing with. Four routes, four different procedures. All four verified 2026-08-05.
Route 1: The Direct API Vendor
You are contracting with the model provider itself. The BAA attaches to specific products and specific plans, and the plan you are on often decides the answer before anyone talks to sales.
Anthropic. The BAA covers Claude Enterprise and the first-party API. Consumer plans (Free, Pro, Max) are excluded, and so is Team. For Enterprise, the organization's Primary Owner accepts the BAA directly while activating HIPAA compliance in organization settings under "Data and privacy." For the first-party API, the Primary Owner signs the BAA and then contacts Anthropic sales to have it enabled. The agreement covers only the single organization that accepted it, and Anthropic's documentation names features it excludes, including Workbench, Claude Console, Claude Cowork, and features in beta. (Anthropic Privacy Center, "Business Associate Agreements (BAA) for Commercial Customers," read 2026-08-05.)
OpenAI. Request by emailing baa@openai.com with your company details and use case. OpenAI reviews each request case by case and states an enterprise agreement is not required to sign a BAA for the API platform. (OpenAI Help Center, "How can I get a Business Associate Agreement (BAA) with OpenAI for the API Services?", read via search index 2026-08-05; the article returned a 403 to direct fetch.)
The executable step: identify your plan first, then the product, then request. Asking sales for a BAA while your team runs on a consumer tier produces a slow no.
Route 2: The Hyperscaler
The BAA is standardized, self-service, and near-instant. The covered-products list is the actual work.
AWS. Sign in to AWS Artifact in the AWS Management Console to review, accept, and manage the BAA. AWS then states you "should only process, store, and transmit protected health information (PHI) in the HIPAA-eligible services defined in the Business Associate Addendum." Amazon Bedrock is on the HIPAA Eligible Services list, with named model exclusions. Amazon SageMaker AI is on it with named feature exclusions.
Google Cloud. Go to the IAM and Admin privacy page in the Cloud Console, select a project, click "Review and Accept" under the Google Cloud Platform HIPAA Business Associate Addendum, then "I Accept." You only need to opt in from one project in the account. Coverage is a named product list of roughly a hundred products, and Google states it "is updated as new products become available to the HIPAA program."
Microsoft. You do not have to request it. Microsoft states its HIPAA Business Associate Agreement "is available through the Microsoft Online Services Data Protection Addendum by default to all customers who are covered entities or business associates under HIPAA." Scope is the in-scope cloud services list, which currently names Microsoft 365 Copilot and Microsoft 365 Copilot Chat under Office 365 Commercial and GCC.
The executable step: accept the BAA, then match your exact workload to a named covered product before any PHI moves, and disable everything else. Google Vertex AI is the live example: Google Cloud signs a self-serve BAA, but "Vertex AI" by that name was not on the covered-products list when we checked. Vertex AI Workbench instances were. A signed BAA and an uncovered product is the same exposure as no BAA at all.
Route 3: The Consumer App
Usually there is no path, and the honest answer is a product-line answer rather than a procurement one. Check the vendor's own HIPAA or compliance page for a named tier. If your tier is not named, no amount of asking support changes the terms of service.
Ask in writing anyway. A dated written "no" from the vendor is an audit artifact, and it is worth more in a review than an absence of evidence. It is also what closes the loop on the case where a third-party aggregator says a BAA exists and the vendor's own documentation does not, which is exactly the Plaud case below.
The executable step: email the vendor, name the tier you actually run, ask whether a BAA is available on it, and file the reply either way.
Route 4: The Reseller or Wrapper Product
The product is a healthcare-branded interface over somebody else's model. You sign with the wrapper. The wrapper has its own chain behind it, and that chain is your problem too.
Four questions, in writing, before signature:
- Which model providers process our data, by name?
- Do you hold a signed BAA with each of them?
- Are they named as subprocessors in your published terms?
- Will you provide the subcontractor chain in writing on request, and notify us when it changes?
BastionGPT is the clean version of this category: its own security documentation states that all of its plans automatically incorporate a BAA, with no enterprise-tier gate and no request process (read 2026-08-05). CompliantChatGPT includes a standard BAA on all four of its tiers, and its privacy policy states that customer content is not used to train any model, "whether our own or any third party's" (read 2026-08-05). Our entry also notes that the same privacy policy does not name the model providers as subprocessors. Both facts are true at once, and question 3 above exists because of it.
The Subcontractor Chain
A wrapper product's BAA is necessary and not sufficient, and the chain behind the wrapper is the reason.
45 CFR 160.103 defines a business associate to include "a subcontractor that creates, receives, maintains, or transmits protected health information on behalf of the business associate." A subcontractor is "a person to whom a business associate delegates a function, activity, or service." Microsoft states the same thing about itself in its own compliance documentation: "when a business associate subcontracts with a cloud service provider to create, receive, maintain, or transmit PHI, the cloud service provider also becomes a business associate."
So the chain has paper at every link. 45 CFR 164.502(e)(1)(ii) requires the business associate to obtain satisfactory assurances from its subcontractor. 45 CFR 164.308(b)(2) says the same for ePHI.
Both rules then add one more provision: the covered entity is not required to obtain those assurances directly. 164.502(e)(1)(i) says plainly that "a covered entity is not required to obtain such satisfactory assurances from a business associate that is a subcontractor."
That cuts both ways. You do not sign paper with your vendor's model provider, and you do have to confirm your vendor did.
One Product, Four Links in the Chain
A hospital licenses a clinical documentation product. The product is built on Claude. The vendor runs Claude through Amazon Bedrock rather than Anthropic's first-party API.
- Link 1. The hospital is the covered entity. It signs a BAA with the documentation vendor. This is the only contract the hospital signs.
- Link 2. The documentation vendor is a business associate. Because it routes PHI to Bedrock, AWS is its subcontractor, and 164.502(e)(1)(ii) obliges the vendor to obtain satisfactory assurances from AWS. AWS provides them through the BAA accepted in AWS Artifact.
- Link 3. The Bedrock route puts Anthropic's model inside AWS's covered service rather than under a separate Anthropic agreement. Amazon Bedrock is on the AWS HIPAA Eligible Services list, with named model exclusions, so the vendor has to confirm the specific model it calls is not one of the excluded ones.
- Link 4. Had the vendor used Anthropic's first-party API instead, the chain would run to Anthropic directly, and the vendor would need Anthropic's own BAA on a HIPAA-ready organization, not just an API key.
So the hospital's practical work is to ask the vendor which of those two routes it uses, and to get the answer in writing.
Our Claude entry documents this multi-route structure in detail, because Claude is the model where the routes genuinely diverge: consumer plans covered by nothing, Team excluded, Enterprise covered once the HIPAA setting is on, the first-party API covered once sales enables it, and the cloud-provider routes covered by the cloud provider's agreement instead.
Same model. Five different answers. The route decides the verdict.
What Is Not a BAA
None of the following permits a covered entity to disclose PHI to a vendor: a SOC 2 Type II report, a HITRUST CSF certification, ISO 27001, ISO/IEC 42001, a compliance-automation "HIPAA Validation Report" of the kind Drata and Vanta produce, or a GDPR Data Processing Agreement.
Every one of them describes how carefully a vendor handles data. A BAA is what makes handing them PHI lawful. Different instruments, different jobs.
Microsoft makes the underlying point about itself, in its own words: "There's currently no certification standard that the Department of Health and Human Services approves to demonstrate compliance with HIPAA or the HITECH Act by a business associate." No certificate exists that HHS blesses. That is why the contract is the artifact.
The live case in our own directory is Plaud. Its compliance documentation, read 2026-08-05, enumerates ISO/IEC 27001:2022, ISO/IEC 27701:2019, GDPR, SOC 2 Type II, a HIPAA Validation Report, and EN 18031, and adds a Data Processing Agreement on the Team plan. A Business Associate Agreement is not among them. A vendor that holds a BAA says BAA, because it is the first artifact healthcare buyers ask for.
The full argument lives elsewhere. SOC 2 against HIPAA is SOC 2 and HIPAA for AI platforms. HITRUST, the ISO standards, the Validation Report, and the DPA get their own treatment at /ai-governance/hipaa-attestation-vs-baa/.
BAA Status Across the AI Tool Directory
Every row is drawn from AuthenTech AI's own vendor entry, each of which cites the vendor's primary documentation. Verification dates are the date we read that documentation, not the date we published. BAA terms and covered-product lists change without notice. Confirm against the vendor's current terms and get the answer in writing before any PHI moves.
| Vendor | BAA offered | On which tier | Trains on inputs | Verified |
|---|---|---|---|---|
| Adobe Acrobat AI Assistant | No | None. Absent from Adobe's HIPAA-Ready Services list, which covers Acrobat Sign only | No, per Adobe. Moot given the exclusion | 2026-07-20 |
| BastionGPT | Yes | Every paid plan, automatic. No tier gate, no request process | No | 2026-08-05 |
| Blueprint | Yes | All plans, automatic in Terms of Service, countersignable copy available | No | 2026-07-12 |
| ChatGPT (OpenAI) | Yes, on some routes | Enterprise, Edu, ChatGPT for Healthcare, ChatGPT for Clinicians (individual), and the API. Free, Plus and Pro are not covered; Team and self-serve Business are excluded | Varies by tier. Yes by default on Free/Plus/Pro; no on the covered routes | July 2026 (month only) |
| Claude (Anthropic) | Yes, on some routes | Enterprise with HIPAA activated, the first-party API once enabled, or via AWS Bedrock or Google Cloud under the cloud provider's BAA. Free, Pro, Max and Team are not covered | No on the commercial routes | No date stated on the entry |
| CompliantChatGPT | Yes | All four tiers from Starter up | No | 2026-08-05 |
| Microsoft Copilot | Yes, with conditions | Paid tenant-integrated Microsoft 365 Copilot and Copilot Chat with enterprise data protection. BAA arrives by default via the Data Protection Addendum. Free consumer Copilot is not covered | No on the tenant routes | July 2026 (month only) |
| Doximity GPT | Yes, with conditions | Member-level BAA attached automatically at registration for verified clinicians. Organization-level coverage is a separate arrangement | Not stated by the vendor. Unverified | 2026-07-12 |
| Fireflies.ai | Yes, with conditions | Enterprise only, and Private Storage must also be enabled. Both switches, not one | No by default | 2026-07-12 |
| Freed | Yes | All plans including the trial, automatic via Terms of Use | On de-identified notes. Vendor states PHI is never used for AI training. No documented opt-out | 2026-07-12 |
| Gemini (Google) | Yes, on some routes | Managed Workspace domain (Gemini app, Gemini Mac App, Gemini in Workspace are on Google's HIPAA Included Functionality list; Gemini in Chrome is excluded) and named Google Cloud generative products. Personal accounts are not covered | Varies by route. Consumer activity can be used to improve services; no on Workspace and Cloud | July 2026 (month only) |
| Google Vertex AI | Yes, with conditions | Google Cloud signs a self-serve BAA, but coverage is product-enumerated and "Vertex AI" by that name was not on the covered list. Vertex AI Workbench instances and the renamed Gemini Enterprise products were | No, contractual restriction | 2026-07-12 |
| Hathr.AI | Yes | Advertises 24-hour BAAs. Plan applicability is not stated on the page we reviewed. Confirm in writing | No | 2026-08-05 |
| Heidi Health | Yes, with conditions | Vendor executes BAAs when handling PHI as a business associate. No vendor page states which tier includes it | No | 2026-07-12 |
| Krisp | Yes, with conditions | Enterprise tier of the AI Meeting Assistant, 100-seat minimum, by email request | No on meeting content. Model improvement is consent-based | 2026-07-12 |
| Nabla | Yes | All plans. The BAA is a mandatory appendix to the Terms of Service | No identifiable PHI. Terms of Service section 8.1 reserves use of fully de-identified data | 2026-07-12 |
| Otter.ai | Yes, with conditions | Enterprise only, via sales | Yes by default below Enterprise. Off for Enterprise workspaces | 2026-07-12 |
| Plaud | No published BAA | None. Compliance documentation enumerates ISO 27001, ISO 27701, GDPR, SOC 2 Type II, a HIPAA Validation Report and EN 18031, plus a Team-plan DPA. No BAA | No by default, opt-in only | 2026-08-05 |
| Read AI | Yes, with conditions | Enterprise+ annual only, five-license minimum, SAML SSO and domain capture enabled, BAA executed through support | Off by default. Model contribution is opt-in | 2026-07-12 |
| Retell AI | Yes | All plans, self-serve signing, no fee | Yes by default per the privacy policy. Negotiate a no-training term in the DPA | 2026-07-12 |
| Zoom AI Companion | Yes, with conditions | Paid plans (Pro, Business, Business Plus, Enterprise). Free is not covered | No, categorically: audio, video, chat, screen share, attachments | 2026-07-12 |
Adobe Acrobat AI Assistant
None. Absent from Adobe's HIPAA-Ready Services list, which covers Acrobat Sign only
Read article →BastionGPT
Every paid plan, automatic. No tier gate, no request process
Read article →Blueprint
All plans, automatic in Terms of Service, countersignable copy available
Read article →ChatGPT (OpenAI)
Enterprise, Edu, ChatGPT for Healthcare, ChatGPT for Clinicians (individual), and the API. Free, Plus and Pro are not covered; Team and self-serve Business are excluded
Read article →Claude (Anthropic)
Enterprise with HIPAA activated, the first-party API once enabled, or via AWS Bedrock or Google Cloud under the cloud provider's BAA. Free, Pro, Max and Team are not covered
Read article →CompliantChatGPT
All four tiers from Starter up
Read article →Microsoft Copilot
Paid tenant-integrated Microsoft 365 Copilot and Copilot Chat with enterprise data protection. BAA arrives by default via the Data Protection Addendum. Free consumer Copilot is not covered
Read article →Doximity GPT
Member-level BAA attached automatically at registration for verified clinicians. Organization-level coverage is a separate arrangement
Read article →Fireflies.ai
Enterprise only, and Private Storage must also be enabled. Both switches, not one
Read article →Freed
All plans including the trial, automatic via Terms of Use
Read article →Gemini (Google)
Managed Workspace domain (Gemini app, Gemini Mac App, Gemini in Workspace are on Google's HIPAA Included Functionality list; Gemini in Chrome is excluded) and named Google Cloud generative products. Personal accounts are not covered
Read article →Google Vertex AI
Google Cloud signs a self-serve BAA, but coverage is product-enumerated and "Vertex AI" by that name was not on the covered list. Vertex AI Workbench instances and the renamed Gemini Enterprise products were
Read article →Hathr.AI
Advertises 24-hour BAAs. Plan applicability is not stated on the page we reviewed. Confirm in writing
Read article →Heidi Health
Vendor executes BAAs when handling PHI as a business associate. No vendor page states which tier includes it
Read article →Krisp
Enterprise tier of the AI Meeting Assistant, 100-seat minimum, by email request
Read article →Nabla
All plans. The BAA is a mandatory appendix to the Terms of Service
Read article →Otter.ai
Enterprise only, via sales
Read article →Plaud
None. Compliance documentation enumerates ISO 27001, ISO 27701, GDPR, SOC 2 Type II, a HIPAA Validation Report and EN 18031, plus a Team-plan DPA. No BAA
Read article →Read AI
Enterprise+ annual only, five-license minimum, SAML SSO and domain capture enabled, BAA executed through support
Read article →Retell AI
All plans, self-serve signing, no fee
Read article →Zoom AI Companion
Paid plans (Pro, Business, Business Plus, Enterprise). Free is not covered
Read article →Three patterns run through the table.
Six of the twenty-one offer a BAA on every plan. Nine gate it behind a specific tier, seat minimum, or configuration switch. "Vendor X is HIPAA compliant" is not a fact about vendor X. It is a fact about a plan.
A BAA and a training policy are separate questions. Retell AI signs a BAA on every plan at no fee, and its privacy policy grants itself the right to train on customer data by default. Both are true. One contract does not answer the other question, which is why our directory tracks them in separate columns and why your review should too.
Configuration can void the paper. Fireflies needs Private Storage on alongside the Enterprise BAA. Read AI needs SAML SSO and domain capture. Anthropic's Enterprise coverage needs the HIPAA setting activated by the Primary Owner. In each case an organization can hold a valid signed BAA and still be outside its scope because a toggle is off.
The full verdicts, sources, and dates for every row live in the AI Tool HIPAA Compliance Directory.
What to Keep on File for an Audit
A BAA that nobody can produce during a review is functionally a BAA you do not have. The Security Rule requires documentation to be retained "for 6 years from the date of its creation or the date when it last was in effect, whichever is later" (45 CFR 164.316(b)(2)(i)). The Privacy Rule sets the same six-year period at 164.530(j)(2).
| Keep | Why |
|---|---|
| The countersigned BAA, both signatures, dated | The agreement itself. Unsigned drafts are common and are not agreements |
| The plan or tier the agreement attaches to, plus proof of what you actually run | Coverage lapses quietly when the deployment drifts from the plan the agreement names |
| The covered-services or eligible-products list as it read on the signature date | Hyperscaler lists change. You need the version that governed your deployment |
| Screenshots or export of the required configuration in its enabled state | Where coverage depends on a toggle, the toggle is part of the evidence |
| The vendor's written answer on subcontractors and model providers | Your 164.504(e)(2)(ii) flow-down diligence, evidenced |
| Dated written refusals from vendors that declined a BAA | Turns an absence of evidence into evidence of a decision |
| Termination records and the return-or-destruction confirmation | Required by 164.504(e)(2)(ii) |
| The date and source of each verification, including who checked and where | Makes the file re-auditable rather than re-researchable |
One habit worth building: record the URL and the read date every time you verify a vendor claim. It is the difference between a compliance file and a folder of PDFs.
The Part a BAA Does Not Solve
A BAA covers a deployment your organization chose, configured, and can name. It says nothing about the nurse manager who pasted a discharge summary into a personal chatbot account on her phone, because that account is not your deployment and the vendor never agreed to anything with you.
That is shadow AI, and it is a different control problem entirely. Contracts govern sanctioned paths. They have no reach into unsanctioned ones.
Which is why the vendor question and the workforce question have to be worked at the same time. Signing paper with three vendors while staff use eleven tools produces a compliant deployment and an uncontrolled surface. For how the two halves fit together, and what OCR expects of each, see HIPAA and AI compliance.
AI Vendor BAAs: Common Questions
Do we need a BAA with an AI vendor if we never send PHI?
No. The requirement at 45 CFR 164.502(e) attaches to disclosure of protected health information. If PHI genuinely never reaches the tool, the provision is not triggered. The practical difficulty is proving it, because PHI reaches AI tools through paraphrase and metadata far more often than through pasted records. See what counts as PHI in an AI context.
The vendor says it is "HIPAA compliant." Is that enough?
No. HHS approves no certification standard for HIPAA compliance, a point Microsoft states plainly in its own compliance documentation. "HIPAA compliant" in vendor marketing usually means the vendor has security controls. The regulation asks for a contract. Ask for the BAA by name and read which products and plans it covers.
Does a signed BAA cover every feature of the product?
Not necessarily. 45 CFR 164.504(e)(2)(i) requires the contract to establish the permitted uses and disclosures, which makes the enumerated scope a ceiling. Hyperscalers publish explicit covered-product lists, and Anthropic's BAA documentation names features it excludes. Match your actual workload to the named scope.
Our vendor is built on someone else's model. Do we need a BAA with that model provider?
No, and 45 CFR 164.502(e)(1)(i) says so directly: a covered entity is not required to obtain satisfactory assurances from a business associate that is a subcontractor. Your contract is with your vendor. Your vendor is obliged under 164.502(e)(1)(ii) and 164.308(b)(2) to have its own paper with the model provider. Your job is to verify it did, in writing.
Is a SOC 2 report or a HIPAA Validation Report a substitute?
No. Neither is a contract, neither allocates liability, and neither permits disclosure of PHI. See SOC 2 and HIPAA for AI platforms.
A vendor's own compliance page does not mention a BAA, but a third-party article says one is available. Which is right?
Treat the vendor's own current documentation as the source and the third-party claim as unverified until you hold a countersigned copy. Vendors that hold a BAA name it, because it is the first artifact healthcare buyers ask for. Our Plaud entry documents exactly this disagreement.
How often should we re-verify?
Covered-product lists, plan structures, and training policies change without announcement. Re-verify at renewal, when the vendor changes plan tiers or ships a major feature, and when a new team asks to use the tool for a new purpose. Record the date every time.
Is this legal advice?
No. This is not legal advice, and your counsel makes the call for your organization.
Related Resources
AI Tool HIPAA Compliance Directory
Every "is X HIPAA compliant" verdict in one sourced, dated directory
Read article →PHI and AI
What counts as protected health information when it reaches an AI tool
Read article →SOC 2 and HIPAA for AI Platforms
Why no volume of SOC 2 controls produces a signed BAA
Read article →HIPAA and AI Compliance
How HIPAA applies to AI tools and what OCR expects in 2026
Read article →The Contract Is Half the Control
A BAA makes one vendor's path lawful. A policy is what tells three thousand people which paths exist. Generate a healthcare-ready AI acceptable use policy in minutes, then use this guide to verify the tools it permits.