Key Takeaways
- ·HIPAA limits a business associate to the uses its contract permits, and that contract may not permit a use your organization couldn't make itself (45 CFR 164.502(a)(3) and 164.504(e)(2)(i)). The open questions sit in the exceptions and in how the contract defines its terms.
- ·Properly de-identified data is outside the HIPAA Privacy Rule. A vendor may de-identify your PHI only to the extent your BAA authorizes it, so that one clause deserves more attention than any other when model training is the concern.
- ·The Joint Commission and CHAI guidance recommends defining permitted uses, prohibiting re-identification, and reserving audit rights in data use agreements. Take those terms to your attorney before you sign or renew.
The short answer
Not by itself. Under the Privacy Rule, a business associate may use PHI only as its contract permits, and the contract may not authorize a use that would violate the rule if your own organization did it. That is a real limit on what a vendor can do with identifiable patient data. The exposure comes from three places a BAA can leave open: a right to de-identify your data, broad wording about what the vendor's services include, and terms in the master agreement that claim to control over the BAA. Whether your contracts close those gaps is a question for your attorney. Making sure someone asks is a governance job.
What HIPAA Settles and What It Leaves Open
HIPAA calls for a written agreement when a vendor creates, receives, maintains, or transmits protected health information on your behalf (45 CFR 164.502(e)). The rule was written with billing companies and data warehouses in mind, well before vendors trained models on customer data. As of September 2026, we aren't aware of HHS guidance that speaks directly to AI model training under a BAA.
The text that does exist is stricter than many executives assume. A business associate may use or disclose PHI "only as permitted or required by its business associate contract" or as required by law (164.502(a)(3)). The contract, in turn, "may not authorize the business associate to use or further disclose the information in a manner that would violate the requirements of this subpart, if done by the covered entity" (164.504(e)(2)(i)). The rule names two exceptions: the vendor's own "proper management and administration," and "data aggregation services relating to the health care operations of the covered entity."
So the useful question for a governance committee is narrower than "do we have a BAA." It is what the BAA and the documents around it say about de-identification, about the scope of the vendor's services, and about which document wins when they conflict.
Three Contract Terms to Find Before You Sign
These are the places to look, and the questions to bring to counsel, when the concern is patient data ending up in a vendor's training set.
The right to de-identify
Once data meets the HIPAA de-identification standard, the Privacy Rule no longer applies to it (164.502(d)(2)). HHS guidance adds the part that matters for contracts: "A covered entity may use a business associate to de-identify PHI on its behalf only to the extent such activity is authorized by their business associate agreement" (HHS de-identification guidance). If your BAA grants the vendor a right to de-identify your data and use the result, that clause is the one to read most closely. The Joint Commission and CHAI guidance notes that de-identified data "may be used to train, tune, or test AI tools" and says organizations "should still apply strong protections and contractual guardrails."
How the contract defines the vendor's services
Some agreements describe the services to include improving the vendor's products. Whether that wording reaches model training on your patients' data, and whether HIPAA would allow it if it did, are questions for your attorney. The governance task is to find the definition and put it in front of them.
Which document controls
Master agreements usually say which document governs when terms conflict. Some BAAs state that the BAA controls for anything involving PHI, and some master agreements claim the reverse. Under the rule quoted above, a contract can't authorize a use of PHI that HIPAA prohibits, but you want counsel to settle the order of precedence before any dispute arises. The CHAI Third Party Management playbook also points out that a platform's AI data processing terms "often differ materially from the general terms of service and may be updated independently of the underlying agreement."
When a Vendor Won't Sign a BAA
If a vendor will handle PHI on your behalf, HIPAA calls for the written agreement before you share the data. The obligation to have one in place falls on your organization. A vendor that declines to sign is telling you one of two things: it believes its product never touches PHI, which your privacy officer and counsel should test against how the product really works, or it shouldn't be receiving PHI from you. A lower price in exchange for broader data rights belongs in the same conversation, in front of the governance committee and counsel, before anyone signs.
Where the Liability Sits
Business associates are directly liable under HIPAA for their own violations, including impermissible uses and disclosures of PHI (HHS OCR, Direct Liability of Business Associates). What HIPAA doesn't decide is who bears the cost between you and the vendor when something goes wrong. The indemnification, limitation of liability, and insurance terms in the master agreement decide that, and those terms are negotiated.
If a vendor won't agree to limits on secondary use of visit transcripts or other patient data, write that down in your governance record and take it to the committee before signing. A documented decision made with that information is easier to explain to a board than a contract nobody read closely.
What to Bring to Counsel
We aren't attorneys and this isn't drafting advice. These are the items we suggest a governance committee gather and hand to counsel, drawn from the Joint Commission and CHAI guidance and the CHAI governance playbooks.
The full contract stack, read together
The master agreement, the BAA, any data processing or AI addendum, and the terms of service they reference. Ask which one controls for PHI.
Permitted uses, stated specifically
The Joint Commission and CHAI guidance suggests agreements "prohibit the use of data for purposes other than those explicitly stated in the agreement" and consider rights around "model outputs, local performance data, and monetization of data." Ask whether model training is addressed by name.
De-identification
Whether the vendor may de-identify your data at all, which HIPAA method it uses, who performs the work, what it may do with the result, and whether re-identification is prohibited. The guidance recommends an explicit prohibition.
Audit rights
The guidance recommends reserving the right to audit third-party vendors against the agreement. Ask what you could verify in practice and how.
Written confirmation on training
For AI features already switched on inside existing platforms, the CHAI Third Party Management playbook suggests requesting written confirmation that your organization's content is not used to train shared models, and asking about deletion or opt-out where available. It also describes adding an AI addendum to the BAA.
State law
State health privacy and AI laws can be stricter than HIPAA and several changed in 2026. Ask counsel which apply to your organization and your patients.
Frequently Asked Questions
Common questions from healthcare executives reviewing AI vendor contracts.
If we have a BAA, are we covered for AI vendors?
A BAA is one thing HIPAA calls for when a vendor handles PHI on your behalf. It doesn't tell you what the rest of the contract permits, and it doesn't reach data that has been properly de-identified. Whether your arrangement complies with HIPAA is a legal question for your attorney. Whether leadership knows what each vendor may do with patient data is a governance question, and you can answer it by finding the contract terms described above.
What does 'de-identified data' mean in AI vendor contracts?
HIPAA recognizes two methods (45 CFR 164.514). Safe Harbor removes 18 categories of identifiers and also requires that the organization have no actual knowledge the remaining information could identify a person. Expert Determination relies on a qualified expert who determines, and documents, that the risk of identification is very small. Data that meets either standard is no longer covered by the Privacy Rule. Both methods date from the original rule, before today's large-scale data linkage and machine learning techniques, which is one reason the Joint Commission and CHAI guidance recommends contractual guardrails and a prohibition on re-identification even for de-identified data. Ask what the vendor means by the term, which method it uses, and what it may do with the result.
Can a vendor refuse to sign a BAA and still work with us?
Not if it will handle PHI on your behalf. HIPAA calls for the written agreement before you share the data, and the duty to have one in place falls on your organization. A vendor may say its product never touches PHI. Have your privacy officer and counsel test that claim against how the product really works before anyone relies on it.
What should we ask counsel to look for on model training?
Whether the contract addresses AI model training by name. Whether the vendor has any right to de-identify your data and what it may do with the result. How the contract defines the vendor's services and whether product improvement is included. Which document controls when the master agreement and the BAA conflict. Whether re-identification is prohibited and whether you have audit rights. Phrases like 'shall not use data for any purpose other than providing the services' depend entirely on how 'services' is defined, so that definition belongs on the list.
What should we do if our current vendor contracts don't have these protections?
Start with an inventory of which vendors touch patient data and which agreements govern each one. The CHAI Third Party Management playbook describes a retroactive review for AI features that were switched on before a governance program existed: find them, rank them by risk, re-read the AI data terms, assign an owner, document the result, and use the contract's change-notification and renewal points to ask for better terms. Where you find a term you didn't expect, bring in counsel to assess your options. Keep a record of the review, because the record is part of your governance posture.
Who is liable if a vendor uses our patient data in violation of the BAA?
That depends on the facts and the contract, and it's a question for your attorney. Two general points are useful for a governance committee. Business associates are directly liable under HIPAA for their own impermissible uses and disclosures. And between you and the vendor, the indemnification, limitation of liability, and insurance terms in the master agreement decide who bears the cost, which is why those terms deserve the committee's attention before signing.
Sources
- 45 CFR 164.502(a)(3), (d) and (e), Uses and disclosures of protected health information: General rules. eCFR, accessed September 18, 2026.
- 45 CFR 164.504(e), Business associate contracts. eCFR, accessed September 18, 2026.
- 45 CFR 164.514(a)-(b), De-identification of protected health information. eCFR, accessed September 18, 2026.
- U.S. Department of Health and Human Services, Office for Civil Rights. Guidance Regarding Methods for De-identification of Protected Health Information in Accordance with the HIPAA Privacy Rule. Content last reviewed February 3, 2025.
- U.S. Department of Health and Human Services, Office for Civil Rights. Direct Liability of Business Associates. Content last reviewed July 16, 2021.
- The Joint Commission and the Coalition for Health AI. The Responsible Use of AI in Healthcare (RUAIH), Section 3, Data Security and Data Use Protections. September 17, 2025. (PDF)
- Coalition for Health AI. AI Governance Playbook, Subdomain 4.4: Third Party Management. Released May 27, 2026.

