Security & Privacy
What is a BAA and when do we need one with an AI vendor?
A Business Associate Agreement — the HIPAA contract required when a third party handles Protected Health Information on your behalf. Any GenAI vendor processing PHI (clinical documentation, prior auth text, patient communications) needs a valid BAA before touching that data. Not all vendors will sign one; those that will typically only cover specific configurations.
More on Security & Privacy
Related on this site
Framework dimensions
Whitepapers
Browse the full FAQ for 164 answers, or start a free GenAI maturity assessment to see where your organisation stands.