“We signed the BAA, so we’re covered.”
I’ve heard that sentence end more healthcare AI conversations than any other, and I’d like it to stop ending them, because it confuses a contract with a system.
Credit where due: the business associate agreement matters. HHS guidance permits covered entities and business associates to use cloud services for electronic protected health information when the required agreement is in place and HIPAA duties are otherwise met. Permitted uses, safeguards, reporting obligations, subcontractor terms, return or destruction at exit. Real obligations, really allocated.
Here’s what the signature didn’t do. It didn’t decide where ePHI is stored or how it moves. It didn’t verify an identity, scope an access grant, protect a backup, or test a recovery. It didn’t determine which data this workflow needs at minimum, what gets logged, or what happens in the first hour of an incident. Contracts allocate duties. They can’t configure services, and nobody’s risk analysis gets shorter because procurement went smoothly.
The confusion compounds when the BAA becomes a permission slip. A signed agreement gets treated as proof the service is safe for any clinical or administrative use, when the workflow, the data set, the user role, the integration, and the retention period were never examined.
My counterargument is a map. For each proposed workflow, trace the information from source to output. Name every system and person able to see it. Identify the minimum data the task requires, the human review point, the retention rule, the deletion path, and the downtime behavior. Then read the agreement beside that map and check they describe the same reality.
Local inference earns a paragraph here because it genuinely changes the exposure pattern: data that never leaves institutional infrastructure skips the routine transfer to an outside inference provider, and fewer parties hold sensitive material. I build those systems. I still won’t claim the box creates compliance. An on-site server with broad accounts, weak logging, and untested backups is just a shorter path to the same bad afternoon.
So the next time an AI vendor leads with the BAA, take it, thank them, and ask for the second conversation: data path, access model, incident boundary, exit procedure. That’s the one where the deployment gets real.