A Business Associate Agreement (BAA) is a contract required under the US HIPAA law between a covered entity — such as a healthcare provider — and a vendor acting on its behalf that will handle protected health information (PHI) on its behalf. The BAA makes that vendor legally accountable for safeguarding the data, and without one in place, sharing PHI with the vendor is itself a HIPAA violation.
The pieces: PHI, covered entity, business associate
Protected health information (PHI) is individually identifiable health information held or transmitted by a covered entity or business associate — diagnoses, treatment notes, identifiers. Note the scope: HIPAA protects PHI in those hands, not health data at large. The same symptom typed into a fitness app or a search box is not PHI. A covered entity is a health plan, a healthcare clearinghouse, or a healthcare provider that conducts certain transactions electronically — which is why not every clinician is one, and why coaches, wellness apps and most therapists outside insurance billing generally are not. A business associate is a person or organisation that creates, receives, maintains or transmits PHI in performing a function or service on behalf of a covered entity — a transcription service, a cloud host, an AI tool — and a business associate's own subcontractors are business associates too. Where that relationship exists, HIPAA requires written assurances, in practice a signed BAA, before PHI flows. Not every disclosure of PHI needs one: treatment disclosures between providers and several other regulatory exceptions do not.
Why this matters for AI
Standard consumer AI products — a free or personal ChatGPT, Claude, or Gemini account — do not sign a BAA. So pasting session notes or patient details into one means PHI has gone to a vendor with no BAA in place, outside HIPAA's requirements. Some providers will sign BAAs for eligible enterprise or API customers under specific terms, but that is a separate, contracted arrangement — not what you get from the everyday consumer app. The practical implications for clinicians are covered in is ChatGPT HIPAA compliant? a guide for therapists and coaches.
Where Secret Chat AI stands (honestly)
Secret Chat AI is a privacy-focused gateway, not a HIPAA compliance solution, and it does not sign a BAA. It reduces exposure — local-only history, anonymized email-only sessions, no training on your prompts — but reducing exposure is not the same as HIPAA compliance. If you are handling PHI, treat a BAA and your own compliance program as the requirement, and remove identifying details before sending anything to any cloud AI. Honesty here is the point: we tell you what we do and do not cover.
Frequently Asked Questions
- Is ChatGPT HIPAA compliant?
Not in its consumer form. OpenAI does not sign a BAA for free or personal ChatGPT plans, so sending protected health information to a consumer ChatGPT account falls outside HIPAA's requirements.
- Does Secret Chat AI sign a BAA?
No. Secret Chat AI is a privacy-focused gateway, not a HIPAA compliance solution, and does not sign a BAA. It lowers data exposure but should not be relied on as a compliance control for protected health information.
- Who needs a BAA?
Any HIPAA covered entity (or business associate) that lets an outside vendor handle protected health information on its behalf. The BAA must be in place before the PHI is shared, not after.
Related terms: Training Opt-Out · Zero-Retention API · all glossary terms