Update Your Business Associate Agreement for AI

security privacy data
Lisa Ritter, CPA, CFE, CITP, Partner

A Business Associate Agreement (BAA) is a contract between a HIPAA (Health Insurance Portability and Accountability Act) covered entity and a third party that performs services involving Protected Health Information (PHI).  The BAA outlines how PHI can be used by a third party, what safeguards must be in place, and what is required in the event of a breach.

PHI includes the following:

  • Names
  • Addresses
  • Birth Dates
  • Social Security Numbers
  • Medical Records
  • Health Insurance Information and
  • Other Data that Can be Used to Identify a Patient.

PHI must be protected when it is transmitted or maintained in any form.

Failing to have a BAA in place or exposing PHI can lead to penalties. Penalties for exposing PHI are structured into four tiers, based on the level of culpability and whether the violations were corrected in a timely manner. Fines range from a minimum of $141 per violation to a maximum of $2,134,831 per violation.

The current business climate introduces new risks and responsibilities due to Artificial Intelligence (AI) becoming widely available. AI may be used by third parties to deliver services but may also be used to train or improve AI models.   Your BAA should clearly define what data can be used and for what purpose.

Consider the following when drafting and updating your BAA:

  • Define AI use cases clearly.
  • Prohibit secondary use of PHI for AI training unless explicitly authorized.
  • Mandate security protocols for AI systems, including encryption and access controls.
  • Require subcontractor compliance if the AI vendor uses third – party services.
  • Include transparency clauses for decision making, especially in clinical contexts

As artificial intelligence reshapes every industry, the responsibility to protect patient data becomes critical. By proactively addressing AI in BAA’s, organizations can ensure that the privacy of PHI is maintained.

Connect With Us

Stay Connected!

Sign up to receive information on the latest government and non-profit industry insights, firm news, and upcoming events & seminars.

Jump to Page

Maher Duessel Cookie Preference Center

Your Privacy

When you visit our website, we use cookies on your browser to collect information. The information collected might relate to you, your preferences, or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. For more information about how we use Cookies, please see our Privacy Policy.

Strictly Necessary Cookies

Always Active

Necessary cookies enable core functionality such as security, network management, and accessibility. You may disable these by changing your browser settings, but this may affect how the website functions.

Functional Cookies

Always Active

Some functions of the site require remembering user choices, for example your cookie preference, or keyword search highlighting. These do not store any personal information.

Form Submissions

Always Active

When submitting your data, for example on a contact form or event registration, a cookie might be used to monitor the state of your submission across pages.

Performance / Analytical Cookies

Analytical cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.

Powered by Firmseek