AI GlossaryHSafety and controversy
HIPAA Business Associate Agreement
A legal contract in U.S. healthcare law that hospitals sign with outside vendors who handle patient information
In plain words
A HIPAA Business Associate Agreement is a legal promise a hospital gets in writing from any outside company that will handle patient information, before handing that information over.
It's similar to how a landlord gets a moving company to sign a contract saying "we'll be liable if anything is lost or damaged" before letting them handle the belongings. When a hospital wants to send sensitive information like medical records or test results to an outside vendor — a cloud service or an AI chatbot, for example — it requires that vendor to sign a document pledging to protect the information to the same standard the hospital itself must meet. That document spells out specifics: how the data will be encrypted, who can access it, and how quickly a breach must be reported if one happens.
Under U.S. law, without this agreement in place, a hospital cannot share patient information with an outside service at all. So before any service can connect an AI chatbot to a hospital's electronic health record system, this kind of agreement has to already be established between the hospital and the AI company.
See also
Stories using this term
- ChatGPT links up with Epic EHR and nine medical data sourcesAI · 2026.09.02
- Gilbert+Tobin automates legal operations with 87% ChatGPT active-use rateAI · 2026.09.02
- Database tab added to ChatGPT Sites, lets you view accumulated data inside ChatGPTAI · 2026.08.19
- OpenAI keeps zero data retention for API, adds automated safety checks with no human reviewAI · 2026.08.20
- ChatGPT sites now handled by Codex instead of Git and CI, adds team invitesAI · 2026.08.21
- ChatGPT Work: internal demos show meeting briefs to strategy decksAI · 2026.08.19
