Skip to main content

HIPAA AI-Specific BAA Addendum

$67.00

A standard HIPAA business associate agreement satisfies 45 CFR 164.502(e) and 164.504(e) but says nothing about a vendor training its AI models on your PHI. This HIPAA AI-Specific BAA Addendum template amends any existing BAA with AI-specific terms: a training restriction on PHI, treatment of AI-generated output as PHI, multi-tenant data segregation, human oversight of AI-generated content, material-change notice, audit rights, data destruction on termination, and subcontractor obligations. Aimed at covered entities and business associates using any vendor whose AI system creates, receives, maintains, or transmits PHI.

Category:

Description

HIPAA  |  45 CFR 164.502(e), 164.504(e)

HIPAA AI-Specific BAA Addendum Template

Document ID: HEL-AI-BAA-001  •  Version 1.3

The business associate contract requirements at 45 CFR 164.502(e) and 164.504(e) were written for standard data processing, not for AI vendors that may use client PHI to train, retrain, or improve models shared across their entire customer base. A signed BAA does not, by itself, prohibit that use. Without an AI-specific addendum, a covered entity has no contractual basis to stop a vendor from using its PHI for model training, no defined treatment of AI-generated output as PHI, and no audit right specific to how the vendor’s AI system actually handles data.

This addendum amends the underlying BAA with 13 sections addressing AI-specific risk: a restriction on using PHI to train or fine-tune any AI model without separate written authorization, combined with a de-identification requirement (45 CFR 164.514(a)-(b)) when training is authorized; treatment of AI-generated output as PHI to the same extent as the data used to generate it; data segregation requirements for multi-tenant AI systems; mandatory human oversight and validation of AI-generated content before clinical or payment reliance; notification obligations for material changes to AI processing, including model version, training data source, or sub-processor changes; audit rights and data practice review; data destruction and return of PHI upon termination; and subcontractor and AI sub-processor flow-down obligations. Breach and security incident reporting for AI systems is addressed with a cross-reference to the AI Incident Response Addendum (HEL-AI-INC-001), and a precedence section clarifies how this addendum interacts with the underlying agreement. Vendors typically complete the AI Vendor Security & Compliance Questionnaire (HEL-AI-VDQ-001) before this addendum is executed.

What Is Included

Model Training and Data Handling Restrictions

  • Restriction on AI model training using PHI and prohibition on re-identification, tied to 45 CFR 164.504(e)(2)(i)
  • Treatment of AI-generated output as PHI, and data segregation requirements for multi-tenant AI systems
  • Required human oversight and validation of AI-generated content before clinical or payment use

Notice, Audit, and Termination Terms

  • Notification requirements for material changes to AI processing, model version, or sub-processors
  • Audit rights, AI data practice review, and recordkeeping obligations
  • Data destruction and return of PHI upon contract termination

Subcontractors and Incident Reporting

  • Subcontractor and AI sub-processor flow-down obligations
  • Breach and security incident reporting requirements involving AI systems
  • Multi-framework notice and precedence clause relative to the underlying agreement

Who This Is For

Covered entities and business associates contracting with any AI vendor, whether the AI system is proprietary to the vendor, licensed from a third party, or operated by a subcontractor. Healthcare attorneys, privacy officers, and contract managers use this addendum to amend existing BAAs before renewal or to attach to new vendor agreements involving generative AI, predictive analytics, or clinical decision support tools.

This addendum is not effective on its own. It must be executed alongside a valid underlying Business Associate Agreement and reviewed by counsel for the specific vendor relationship and jurisdiction.

Format: Microsoft Word (.docx), fully editable  •  Delivered as an instant digital download  •  Document ID: HEL-AI-BAA-001

Reviews

There are no reviews yet.

Be the first to review “HIPAA AI-Specific BAA Addendum”

Your email address will not be published. Required fields are marked *