A signed business associate agreement with a tech giant does not mean your patient data is safe from AI training models.
Healthcare providers are rushing to sign Business Associate Agreements (BAAs) with tech giants like Google and Microsoft. They believe these contracts act as a legal shield for deploying generative AI. They are wrong.
A standard BAA establishes legal accountability under HIPAA, but it is not a blanket security policy. The critical gap lies in how these agreements handle data usage. Many standard contracts lack explicit prohibitions against using protected health information (PHI) to train AI models.
The Training Loophole
If a vendor uses patient data to refine its algorithms, a standard BAA might not stop them. Healthcare organizations often assume that “HIPAA-compliant” means their data remains entirely private and static. It does not.
Without custom clauses, patient data can quietly feed the very models providers are paying to use. This creates a massive compliance risk. It also opens the door to shadow AI, where employees input sensitive data into unmonitored tools.
The Action Plan
Organizations must look beyond the standard contract. Security teams need to actively monitor specific AI configurations. They must demand explicit contractual bans on using PHI for model training.
A signature on a BAA is just the starting line, not the finish. Healthcare leaders must realize that compliance is an active operational task, not a legal checkbox.
