HIPAA BAA
Contract that lets U.S. healthcare entities send Protected Health Information to vendors.
A Business Associate Agreement is a contract that lets a U.S. healthcare entity send Protected Health Information (PHI) to a vendor under HIPAA. Without a signed BAA, sending PHI to an LLM API is a HIPAA violation. Most major LLM providers offer one for enterprise customers.