Binding law — in force
Protected health information may go to an AI vendor only under a business associate contract (HIPAA)
Under 45 CFR 164.502(e) a covered entity may let a business associate create, receive, maintain, or transmit protected health information on its behalf only after obtaining satisfactory assurance, documented in a written contract that meets 164.504(e), that the business associate will safeguard it; a business associate needs the same from its subcontractors. 164.504(e)(2) lists what the contract must say, including permitted uses, no further disclosure, safeguards, breach reporting, flow-down to subcontractors, and return or destruction at termination. An AI model, transcription, or embedding vendor that processes PHI for a covered entity or business associate fits the pattern the definition of business associate describes (160.103). Detect PHI flowing to a model API with no sign of a business associate agreement, a covered endpoint, or de-identification.
Who it applies to
- Duty falls on: deployer, processor
- Sectors: healthcare, insurance
- HIPAA covered entities (health plans, health care clearinghouses, and health care providers that conduct covered transactions) and their business associates, when an AI vendor creates, receives, maintains, or transmits protected health information on their behalf. Whether a given model provider is a business associate (and not, for example, a treatment provider) is a legal determination. Privacy standards applied from 2003-04-14 (164.534); the current business associate provisions from the 2013 Omnibus Rule, compliance date 2013-09-23.
- Not covered:
- Disclosures by a covered entity to a health care provider concerning the treatment of the individual (45 CFR 160.103, 'business associate' (4)(i))
- Health information de-identified under 164.514(a) is not individually identifiable health information, so it is not PHI (160.103, 164.514(a))
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Send identifiable health data only to AI endpoints registered with a signed BAA or processing agreement and retention and training off; otherwise de-identify first.
A single client factory for model, embedding and transcription calls that handle health information: it looks the endpoint up in a vendor register and refuses to return a client unless the register shows the required contract (business associate agreement, or a processing agreement barring further disclosure) and the endpoint is the covered deployment with data retention and training use turned off. Call sites that cannot meet that de-identify or redact the record before building the prompt, or check a recorded patient authorization for that use. Keep the vendor register in the repository so reviewers can match each AI endpoint to its legal basis, and never route health data into marketing or other non-care generation.
Where it goes: 6 API calls and integrations, 3 config and feature flags, 7 prompt construction, 12 repository artifacts.
What this provision adds:
- The written contract on the register covers permitted uses, no further disclosure, safeguards, breach reporting, flow-down to subcontractors, and return or destruction of PHI at termination.
- A business associate that passes PHI to an AI vendor needs the same written assurance from that vendor as its subcontractor.
Example (Python + OpenAI SDK (Azure OpenAI)), before:
client = OpenAI()
resp = client.chat.completions.create(model='gpt-4o', messages=[
{'role': 'user', 'content': f'Summarize: {patient.clinical_note}'}])After:
VENDORS = load_yaml('vendors/ai_vendors.yaml') # baa_signed, zero_data_retention per endpoint
def phi_client(name: str) -> tuple[AzureOpenAI, str]:
v = VENDORS[name]
if not (v['baa_signed'] and v['zero_data_retention']):
raise PermissionError(f'{name} is not cleared for PHI')
client = AzureOpenAI(azure_endpoint=v['endpoint'], api_key=os.environ['AZURE_OPENAI_KEY'],
api_version=v['api_version'])
return client, v['deployment']
client, deployment = phi_client('azure-openai-hipaa')
resp = client.chat.completions.create(model=deployment, messages=[
{'role': 'user', 'content': f'Summarize: {patient.clinical_note}'}])Control: Health information sent to an external AI vendor without the contractual or legal basis the law requires. The same guard addresses 2 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.
Rule id us-hipaa-privacy.ai-vendor-business-associate-contract · review status: primary source derived