Healthcare AI Governance

    Does Our Vendor's BAA Actually Prevent Them From Using Our Patient Data to Train Their AI Models?

    Probably not. A signed BAA sets a floor, not a ceiling, and most AI vendor contracts are structured to preserve far more data use rights than healthcare leaders realize.

    Last updated: · By Teresa Younkin & Jim Younkin, Mosaic Life Tech

    Key Takeaways

    • ·A HIPAA BAA sets a minimum threshold, not a complete prohibition. Many AI vendors retain broad data use rights in their master service agreements that the BAA doesn't override.
    • ·Vendors frequently claim that de-identified data falls outside HIPAA scope and use that carve-out to justify using your patient data for model training.
    • ·Negotiating explicit contractual language, audit rights, and a refusal to accept unfavorable supersession clauses is the only reliable protection.

    The short answer

    No. A BAA alone does not reliably prevent an AI vendor from using your patient data to train their models. HIPAA permits data use as allowed by the agreement, which means vendors can negotiate broad rights into the main service contract that the BAA doesn't touch. Many do exactly that. The BAA provides legal structure, not substantive protection, unless you've negotiated specific language that closes the gaps.

    Why the BAA Isn't Enough on Its Own

    HIPAA requires a BAA when a vendor touches protected health information on your behalf. That requirement was designed for a world of billing vendors and data warehouses. It wasn't designed for AI systems that train on data at scale, and the statutory framework hasn't caught up.

    The core problem is structural. HIPAA allows covered entities and business associates to use PHI "as permitted by the agreement." That phrase gives vendors significant room to negotiate broad data use rights directly into the master service agreement while leaving the BAA largely untouched. The BAA gets signed, the legal box gets checked, and the actual data use rights live somewhere else in the contract stack.

    CHIME and other health IT organizations have flagged this gap, recommending that HIPAA BAA requirements be enhanced to include clearer, enforceable definitions that explicitly address model training. Those enhancements haven't arrived yet.

    Three Structural Tactics Vendors Use

    Understanding how vendors structure these arrangements helps you know what to look for when reviewing contracts.

    Supersession clauses in the master agreement

    The master service agreement includes language stating it supersedes all other documents regarding data use. The BAA is attached as an exhibit. The exhibit doesn't override the master. You signed both, but one controls.

    De-identification carve-outs

    Vendors claim that once data is de-identified, it falls outside HIPAA scope entirely. They then use that de-identified data freely for model training. The problem is that de-identification standards under HIPAA are context-dependent and don't map cleanly onto modern AI systems, where re-identification risk is real and increasingly well-documented. What counts as de-identified under one framework may not adequately protect your patients under another.

    Discount-for-data arrangements

    Some vendors offer products at steep discounts in exchange for broader data use rights, including model training. The economic logic is straightforward from their side. The governance risk to you is that the arrangement typically involves forgoing the BAA or accepting terms that grant expansive rights. Some vendors refuse to sign BAAs at all and position this as standard practice.

    The Default Position Is Liability Transfer to You

    Ambient AI vendors in particular have made liability transfer a default contracting posture. The BAA structure places the majority of responsibility on the healthcare organization, not the vendor. If the vendor uses your data in ways that create patient harm or regulatory exposure, your organization is holding more of that liability than most healthcare executives realize.

    Providers who have raised concerns about secondary data use, including whether visit transcripts or ruled-out diagnoses will appear in training data, often encounter vendors who won't agree to restrictive terms. That refusal is information. It tells you where the vendor's business model sits and whether your interests are structurally aligned.

    What Actually Works

    Reliable protection comes from explicit contractual language, not from the existence of a BAA. Here's what to look for and negotiate.

    ·

    Read the master service agreement alongside the BAA

    Look specifically for supersession language. If the MSA says it controls over all attachments or exhibits regarding data use, the BAA may be largely decorative.

    ·

    Require explicit training data prohibition

    The contract should state specifically that patient data, including de-identified or aggregated derivatives, may not be used for AI model training without your separate written consent.

    ·

    Define de-identification in the contract

    Don't accept a vendor's reference to HIPAA Safe Harbor or Expert Determination without specifics. Ask what standard they use, who performs the assessment, and what they define as de-identified data for purposes of secondary use.

    ·

    Build in audit rights

    The right to verify data use isn't just a negotiating point. It's evidence of governance. A vendor that refuses audit rights is telling you something about how they intend to use your data.

    ·

    Treat refusal to negotiate as a red flag

    Vendors who won't discuss these terms are vendors who have made a deliberate decision about how they use data. That's your governance signal.

    Frequently Asked Questions

    Common questions from healthcare executives reviewing AI vendor contracts.

    If we have a BAA, are we HIPAA compliant for AI vendors?

    Having a BAA in place satisfies one of HIPAA's requirements for working with business associates, but it doesn't mean your data use arrangements are safe or that your organization is protected against broader governance risks. HIPAA compliance and vendor governance are related but not the same thing. A BAA can be fully HIPAA-compliant and still allow the vendor to use your patient data in ways your board would find alarming.

    What does 'de-identified data' mean in AI vendor contracts?

    HIPAA defines de-identification through two methods: Safe Harbor (removing 18 specific identifiers) and Expert Determination (statistical verification that re-identification risk is very small). Vendors often rely on one of these definitions to argue that data used for model training falls outside HIPAA scope. The problem is that these standards were developed before modern re-identification techniques existed. In AI contexts, de-identification is increasingly considered a risk spectrum, not a binary. Your contract should address what the vendor actually means by the term and what they're permitted to do with data that meets their definition.

    Can vendors really refuse to sign a BAA and still work with us?

    Yes, some do. A vendor that refuses to sign a BAA and still wants access to PHI is either claiming their product doesn't touch PHI (which you should evaluate carefully given how AI systems actually work) or asking you to accept a risk posture that your organization should weigh deliberately. In either case, that position is worth surfacing to your legal counsel and compliance team before proceeding.

    What contract language actually prevents training data use?

    Effective language is explicit, covers both PHI and de-identified derivatives, applies to aggregated data as well as individual records, requires written consent for any training use, and includes audit rights. Phrases like 'shall not use data for any purpose other than providing the contracted services' are a starting point, but many vendors interpret 'contracted services' broadly to include model improvement. The language needs to specifically name AI model training as a prohibited use.

    What should we do if our current vendor contracts don't have these protections?

    Start with a contract review that maps your existing AI vendor agreements against these categories. When contracts come up for renewal, renegotiate. If you discover a current contract has unfavorable terms you didn't anticipate, loop in legal counsel to assess your exposure and your options. This is also worth documenting as part of your AI governance posture, because the process of identifying and addressing the gap is itself evidence of governance.

    Who is liable if a vendor uses our patient data in violation of the BAA?

    Liability depends on the specific contract language, what was violated, and how the harm occurred. Under HIPAA, business associates can be held directly liable for their own violations. But healthcare organizations frequently find themselves sharing liability, particularly when the contract structure transferred responsibility to them or when oversight mechanisms weren't in place. The default contracting posture of many AI vendors is designed to maximize their flexibility and limit their liability. You're negotiating against that default every time you sign.

    Sources

    • CHIME (College of Healthcare Information Management Executives), recommendations on HIPAA BAA enhancement for AI data use.
    • U.S. Department of Health and Human Services, HIPAA Privacy Rule, 45 CFR Parts 160 and 164.
    • The Doctors Company, statements on malpractice coverage and AI vendor liability posture.
    • Health system governance forums and legal counsel advisories on ambient AI vendor contracting practices, 2024-2026.

    About the Authors

    Teresa Younkin

    Teresa Younkin, MSHI

    CEO & Co-Founder, Mosaic Life Tech

    20+ years leading AI, data governance, and interoperability initiatives across provider, payer, and federal health IT environments, including HL7 Da Vinci standards work and ONC programs.

    Jim Younkin

    Jim Younkin, MBA, FACHDM

    CTO & Co-Founder, Mosaic Life Tech

    30+ years across federal health IT programs, enterprise interoperability, and AI governance, including directing federal AI initiatives for ONC/ASTP and co-founding Pennsylvania's first regional HIE serving 4M+ patients.

    Mosaic Life Tech helps healthcare executives build board-visible AI governance posture aligned with Joint Commission and CHAI guidance. We don't sell AI tools or implementation services. Our work is advisory, and our interest is in helping organizations govern well before expectations harden into standards.

    Concerned about how your AI vendors are using patient data?

    We help healthcare executives understand what their AI vendor contracts actually say, and what governance posture looks like when the contracts don't say enough.

    Start a Conversation