Description
HIPAA | 45 CFR 164.502(e), 164.504(e)
HIPAA AI-Specific BAA Addendum Template
Document ID: HEL-AI-BAA-001 • Version 1.3
The business associate contract requirements at 45 CFR 164.502(e) and 164.504(e) were written for standard data processing, not for AI vendors that may use client PHI to train, retrain, or improve models shared across their entire customer base. A signed BAA does not, by itself, prohibit that use. Without an AI-specific addendum, a covered entity has no contractual basis to stop a vendor from using its PHI for model training, no defined treatment of AI-generated output as PHI, and no audit right specific to how the vendor’s AI system actually handles data.
This addendum amends the underlying BAA with 13 sections addressing AI-specific risk: a restriction on using PHI to train or fine-tune any AI model without separate written authorization, combined with a de-identification requirement (45 CFR 164.514(a)-(b)) when training is authorized; treatment of AI-generated output as PHI to the same extent as the data used to generate it; data segregation requirements for multi-tenant AI systems; mandatory human oversight and validation of AI-generated content before clinical or payment reliance; notification obligations for material changes to AI processing, including model version, training data source, or sub-processor changes; audit rights and data practice review; data destruction and return of PHI upon termination; and subcontractor and AI sub-processor flow-down obligations. Breach and security incident reporting for AI systems is addressed with a cross-reference to the AI Incident Response Addendum (HEL-AI-INC-001), and a precedence section clarifies how this addendum interacts with the underlying agreement. Vendors typically complete the AI Vendor Security & Compliance Questionnaire (HEL-AI-VDQ-001) before this addendum is executed.
What Is Included
Model Training and Data Handling Restrictions
- Restriction on AI model training using PHI and prohibition on re-identification, tied to 45 CFR 164.504(e)(2)(i)
- Treatment of AI-generated output as PHI, and data segregation requirements for multi-tenant AI systems
- Required human oversight and validation of AI-generated content before clinical or payment use
Notice, Audit, and Termination Terms
- Notification requirements for material changes to AI processing, model version, or sub-processors
- Audit rights, AI data practice review, and recordkeeping obligations
- Data destruction and return of PHI upon contract termination
Subcontractors and Incident Reporting
- Subcontractor and AI sub-processor flow-down obligations
- Breach and security incident reporting requirements involving AI systems
- Multi-framework notice and precedence clause relative to the underlying agreement
Who This Is For
Covered entities and business associates contracting with any AI vendor, whether the AI system is proprietary to the vendor, licensed from a third party, or operated by a subcontractor. Healthcare attorneys, privacy officers, and contract managers use this addendum to amend existing BAAs before renewal or to attach to new vendor agreements involving generative AI, predictive analytics, or clinical decision support tools.
This addendum is not effective on its own. It must be executed alongside a valid underlying Business Associate Agreement and reviewed by counsel for the specific vendor relationship and jurisdiction.
Format: Microsoft Word (.docx), fully editable • Delivered as an instant digital download • Document ID: HEL-AI-BAA-001









Reviews
There are no reviews yet.