Both OpenAI and Anthropic offer a business associate agreement, but only for their enterprise and API-based offerings, not for the free consumer chat products most people use by default. OpenAI makes a BAA available to qualifying API and ChatGPT Enterprise customers once specific data controls, such as disabling training on inputs, are confirmed, and Anthropic offers a BAA for eligible Claude API and enterprise customers, including deployments through cloud marketplaces such as AWS Bedrock or Google Cloud's Vertex AI, which carry their own separate BAA terms with the cloud provider. In every case, the BAA has to be requested and executed before any protected health information is sent, since simply having an enterprise account does not automatically create a signed agreement. Even with a BAA in place, the covered entity remains responsible for its own technical safeguards, access controls, and audit logging around how the model is used. Organizations that want to avoid depending on any vendor's BAA terms at all typically move to a self-hosted, open-weight model running entirely on their own infrastructure. As of 2026, exact BAA terms and eligibility should be verified directly with the provider before relying on them. Nanobase AI, based in Silicon Valley, confirms BAA coverage and configures the surrounding safeguards for healthcare clients using either provider.

Both providers offer a BAA, but eligibility is the real question

OpenAI and Anthropic each make a business associate agreement available, which surprises some teams who assume BAAs are reserved for legacy healthcare IT vendors rather than AI labs. The more useful question is not whether a BAA exists in principle, but which specific product tier qualifies and what conditions the company has to meet to actually get one signed. Assuming a BAA is available just because the vendor's name appears on a healthcare AI vendor list, without confirming the specific product and account type, is the most common way this goes wrong.

Comparing the two providers

AspectOpenAIAnthropic
Eligible productsChatGPT Enterprise, API accounts meeting requirementsClaude API and enterprise accounts, including via AWS Bedrock and Google Cloud Vertex AI
Consumer/free tier eligibleNoNo
Training on inputsMust be disabled as a condition of the BAADisabled by default for API and commercial offerings
Cloud marketplace availabilityAvailable through Azure OpenAI Service under Microsoft's BAA terms in some configurationsAvailable through AWS Bedrock and Google Cloud, inheriting the marketplace's own BAA where applicable
Process to obtainRequires reaching out through OpenAI's enterprise sales or support channelRequires a qualifying enterprise or API agreement with Anthropic

Both companies structure this the same way conceptually: the BAA rides on top of a qualifying commercial relationship, not on top of the model itself. Neither provider signs a BAA for its free consumer product under any circumstances, which makes the account type the deciding factor, not the vendor's brand.

Why cloud marketplace deployment changes the picture

Deploying Claude through AWS Bedrock or Google Cloud Vertex AI, or GPT models through Azure OpenAI Service, can bring the BAA question under the cloud provider's existing HIPAA program rather than requiring a separate direct agreement with the model vendor. This is often the fastest path for a healthcare organization that already has a HIPAA-covered relationship with AWS, Google Cloud, or Microsoft Azure, since it extends an existing BAA relationship rather than negotiating a new one from scratch. The tradeoff is that the exact scope of coverage depends on the specific marketplace terms, which should be confirmed rather than assumed to automatically extend to every AI service offered on that cloud. An existing cloud BAA is a real shortcut, but it only covers the specific services named in that agreement, not every AI feature the cloud provider later ships.

Steps to confirm BAA coverage before processing PHI

  1. Identify the exact product and account type intended for use, since eligibility differs meaningfully between a personal API key and an enterprise agreement.
  2. Contact the vendor, or the cloud marketplace if deploying through Bedrock, Vertex AI, or Azure, to confirm current BAA availability and request the agreement.
  3. Confirm the BAA explicitly covers the specific service being used, such as the chat completions API versus a newer product like an agent or assistants API, since coverage does not always extend automatically to every new feature a vendor ships.
  4. Verify training-on-inputs is disabled as part of the account configuration, independent of the BAA's existence.

A signed BAA that does not cover the specific product feature in use provides no protection for that feature, which makes step three the one most often skipped.

This is general information, not legal advice, and current BAA terms and eligibility should be confirmed directly with the vendor or cloud provider before processing any PHI.

Frequently asked questions

Does a BAA guarantee HIPAA compliance on its own?

No. The BAA satisfies the contractual requirement that a business associate agrees to handle PHI appropriately, but the covered entity still needs its own technical and administrative safeguards, such as access controls, encryption, and audit logging, covered in our broader guide to HIPAA compliant LLM use.

Can a small clinic or startup get a BAA from OpenAI or Anthropic?

Generally yes, through the API rather than needing a full enterprise sales relationship, though the exact process and any minimum commitment should be confirmed directly with the vendor, since terms and thresholds change over time.

Do open-weight models avoid the BAA question entirely?

Yes, for the inference step specifically. Running an open-weight model on infrastructure the organization controls, or on a cloud provider with which it already has a BAA, removes the need for a separate agreement with a model API vendor.

What happens if PHI was sent to a provider without a BAA in place?

This is treated as a HIPAA violation and, depending on scale and cause, may trigger breach notification obligations. Organizations that discover this should engage their privacy officer and, where applicable, legal counsel promptly rather than treating it as a technical cleanup task alone.

How Nanobase AI helps

Nanobase AI helps healthcare organizations confirm BAA coverage across LLM providers and cloud marketplaces, and builds the surrounding safeguards HIPAA requires beyond the agreement itself. Where cross-provider BAA complexity is not worth the operational overhead, we also deploy private, on-premise models as part of our AI security and compliance services.

Ready to discuss your project? Contact Nanobase AI or email hello@bumu.tech.