Your EHR Vendor Signed a BAA. The AI Tools Your Staff Use Did Not.


Ask your EHR vendor for a Business Associate Agreement and one arrives within a day. Ask your billing clearinghouse and they have a template ready. Now ask for a BAA covering the AI tools your staff already use to rewrite patient letters and summarize notes. For most of them there is nothing to send you. Not because the vendors are being difficult. Because the version your team is using does not come with one.
That gap is the entire subject of this article. It is not theoretical, it is not coming, and for most practices it is already open.
HIPAA already has an answer for this
There is a common assumption that regulators have not caught up with AI. On this specific question they have.
The Department of Health and Human Services maintains guidance on who counts as a Business Associate. In the version updated on July 30, 2026, the list of examples includes a third-party AI chatbot that handles protected health information on a provider's behalf. HHS is direct about it: a vendor whose tool touches PHI for you is a Business Associate, and a Business Associate needs a signed agreement before that data moves.
So the question is not whether HIPAA applies to AI tools. It does, through machinery that predates them by two decades. The Privacy Rule brought business associate agreements in 2003, the Security Rule added safeguard requirements in 2005, and the 2013 HITECH Omnibus Rule made business associates directly liable themselves. The question is narrower and much more uncomfortable: which AI tools in your practice have a BAA behind them, and which do not.
The tier trap
Here is what makes this hard for a practice to reason about. Every major AI vendor will sign a BAA, and every major AI vendor refuses to sign one for the account your staff are most likely using.
OpenAI does not offer a BAA for ChatGPT Free, Plus, Pro, or Business. Their own documentation states it plainly. A BAA is available for sales-managed ChatGPT Enterprise and Edu accounts, for the API, where no enterprise agreement is required, and through a separate in-product BAA flow for eligible individual clinicians using ChatGPT for Clinicians.
Anthropic excludes Free, Pro, Max, and Team from BAA coverage entirely. Coverage requires an Enterprise plan with HIPAA compliance activated, or the API on a HIPAA-ready organization.
Google puts its BAA inside paid Workspace, where an administrator has to review and accept it before PHI touches covered services. Once that is done, specific Gemini features sit on the covered list, and Google names them: help me write, smart replies, the side panel. A personal Google account has no path to any of this.
Microsoft names Microsoft 365 Copilot and Copilot Chat in its published list of HIPAA in-scope services for commercial Microsoft 365. The consumer Copilot at copilot.microsoft.com does not appear on that list.
Read that list again and notice the pattern. In every case the free or personal tier is the one with no agreement. That is also the tier a busy person reaches for at 7pm when a prior authorization letter needs rewriting.
Paying for the business tier is not the finish line
The second surprise catches practices that did the right thing.
Signing up for a business plan and executing a BAA does not place a protective wrapper around everything the vendor makes. Coverage is defined surface by surface.
Anthropic is a useful example because they publish the carve-outs. On an Enterprise plan with HIPAA compliance turned on, ordinary chat is covered. Their browser extension, their connectors to outside systems, and most beta features are explicitly available to use but explicitly not covered by the BAA.
Microsoft's agreement covers the platform, not how you configured it. Copilot surfaces whatever the signed-in user already has permission to open. If a shared drive is broader than it should be, Copilot will find what is in it, and the BAA has nothing to say about that.
The practical translation for an administrator: "we are on the business plan" answers less than it sounds like it does.
What your staff are actually doing
None of this would matter much if nobody used these tools. They do.
In a December 2025 Wolters Kluwer Health survey of 518 healthcare professionals, half providers and half administrators, 17 percent admitted using unauthorized AI tools at work, and 40 percent had encountered an unauthorized AI tool somewhere in their organization. The reason users gave most was not curiosity. Among providers it was a faster workflow, cited by 45 percent, and among administrators more than half said the same.
Two details in that data deserve attention from anyone running a practice.
The first is that more experienced clinicians were more likely to use unsanctioned tools than newer ones, not less. Among providers with under five years of experience, only 14 percent had used one. This is not a training-the-youngsters problem.
The second is what "unauthorized" tends to look like in practice: a personal account on a personal login, often a transcription or note-summarizing tool, used on a practice device. No purchase order, no IT ticket, no BAA, no record.
One more number from the same survey explains why policy alone has not fixed this: only 29 percent of providers said they were even aware of their organization's main AI policies.
So is it a breach?
Not automatically. But the burden runs against you.
Under the Breach Notification Rule, an impermissible disclosure of unsecured PHI is presumed to be a breach requiring notification, unless the practice documents a risk assessment showing a low probability that the information was compromised. That assessment weighs four factors: the nature and extent of the PHI, who received it, whether it was actually acquired or viewed, and what mitigation occurred.
Now apply those four factors to a paragraph of patient detail typed into a consumer AI tool. The information was specific. The recipient is a company with no contractual restriction on its use of your data. It is on their servers. You cannot pull it back.
That is a difficult set of facts to write your way out of. Most compliance counsel treat it as reportable.
Genevieve Kanter, a senior fellow at the USC Schaeffer Center, has put the mechanism more bluntly than a vendor should: once information is entered into a public AI tool it sits on that company's servers, that company is not covered, and technically that is a data breach. She notes it holds even when the user has opted out of model training.
What it costs
Civil monetary penalties were adjusted for inflation on January 28, 2026. The current tiers run from $145 per violation at the low end to $73,011 per violation, with an annual cap of $2,190,294. Willful neglect left uncorrected starts at $73,011 per violation. To be complete: OCR has applied lower annual caps to the lower culpability tiers under a 2019 enforcement discretion notice, but the figures above are the official adjusted amounts on the books.
Separately, IBM's 2026 Cost of a Data Breach report puts the average healthcare breach at $6.64 million. That figure is down about ten percent from last year, and healthcare remains the costliest industry for the thirteenth consecutive year.
One figure from the same IBM report is worth quoting carefully, because it is frequently reported without its context. Across all industries studied, not healthcare alone, employee use of unapproved AI tools was involved in 43 percent of security incidents in 2026, up from 20 percent the year before. It more than doubled in a single year. Breaches involving shadow AI averaged $5.39 million, only about a third of organizations had a formal approval process for deploying AI tools, and one in five of those shadow AI breaches ended in a regulatory fine.
The honest part
There is no published enforcement action, resolution agreement, or civil penalty from the Office for Civil Rights that specifically punishes a practice for staff pasting PHI into a consumer AI tool. Not one, as of August 2026.
We are not going to pretend otherwise, and you should be skeptical of any vendor who implies the fines are already landing.
What has been happening is adjacent and instructive. OCR's Risk Analysis Initiative had produced twelve enforcement actions as of March 2026, and they all turn on the same failure: the organization could not show an accurate, thorough risk analysis of where electronic PHI actually lives and moves. An AI tool nobody inventoried is, by definition, missing from that analysis.
Worth noting too: the proposed HIPAA Security Rule update published in January 2025 has not been finalized. The 2013 rule remains in force. Anyone telling you that new AI-specific requirements are already law is ahead of the facts.
Where a practice actually starts
Not with a policy. With a list.
Almost every practice we speak with wants to jump to writing an AI policy, and almost none can answer the question the policy depends on: which AI tools are running right now, on which machines, signed into which accounts. A policy written without that list governs an imaginary practice.
The sequence that works is the reverse:
Find out what is in use. Every AI application, browser extension, and connected agent across your machines, and critically, whether each one is signed into a practice account or a personal one. That last distinction is the whole BAA question made visible.
Sort it. Some of what turns up will be genuinely useful work that deserves a sanctioned, covered path. Some of it will be a personal account handling patient information, and that stops.
Then write the rules, naming specific tools rather than categories. "No confidential data in public AI tools" is unenforceable because nobody knows which tools count. "Use this one, on your practice login, never that one" is a rule a busy person can follow at 7pm.
Then keep looking. New tools appear weekly, and an inventory taken once is a snapshot of a Tuesday.
Where we fit, and where we do not
We are a managed security provider, not a HIPAA consultancy. We do not perform your risk analysis, write your policies, or certify your compliance, and you should be wary of any security vendor who says they will. That work belongs with your compliance resource or your counsel.
What we run is the layer those documents assume exists. Our Managed AI Security service starts with a free Shadow AI Discovery: a light install, about a week of quiet observation, then a report of every AI tool, extension, and agent in use across your machines, including which are running on personal accounts, risk ranked in plain English. Nothing changes for your staff while it runs, and the report is yours whatever you decide to do next.
From there we enforce what you decide, on the tools you approve, and keep watching as new ones appear.
None of it guarantees compliance, and no honest vendor would say otherwise. It supports the safeguards your HIPAA program is already required to maintain, and it answers the one question a risk analysis cannot answer without it.
More on how this looks for practices specifically: cybersecurity for healthcare practices.
One question to take to your next staff meeting
Ask your team, with genuine amnesty and no consequences attached, which AI tools they are using to get through the day and which account they are signed into.
The answers tend to be more interesting than anyone expects. And it is a far better way to find out than reading it in a notification letter.
If you run a small or medium practice in Washington DC, Northern Virginia, or Maryland and want a plain-English read on where you stand, book a free 15-minute call.
Comments