Business Associate Agreement (BAA)· Healthcare privacy and procurement
Business Associate Agreement — The Only Document That Makes a Chatbot Vendor Answerable for Patient Data, and Why It Sits Above Every Self-Serve Tier We Could Document
Quick answer: A Business Associate Agreement is the contract that has to exist before a covered entity hands patient data to a vendor. Three things on this page matter more than the definition. The first is that there is no such thing as a HIPAA certificate that transfers a duty to your vendor, and the regulator says so in its own words about Security Rule certifications: HHS "does not endorse or otherwise recognize private organizations' 'certifications' regarding the Security Rule," and such certifications "do not absolve covered entities of their legal obligations under the Security Rule." A vendor page that reads HIPAA compliant is a claim; the BAA is the instrument. The second is that the regulator has stopped treating chatbots as a grey area. OCR's own published list of business associate examples includes a "Third-party vendor Artificial Intelligence (AI) chatbot on a provider's patient portal that provides services involving the patient's PHI such as symptom assessment, medical reminders, and appointment scheduling." The third is an audit of our own coverage, and it is the part no law firm can write: across the fifteen platform reviews we have published, fourteen mention HIPAA, exactly one names a BAA on a named tier in a vendor document, and in every case where a BAA is actually located that way, the tier carrying it is custom-priced.
The claim and the contract are different objects
Two sentences look alike on a vendor page and are not alike at all.
We are HIPAA compliant describes a state the vendor asserts about itself. Nobody issues it, no federal registry records it, and no auditor's signature is attached to the phrase by law. HHS is direct about this in the narrower case of the Security Rule: there is "no standard or implementation specification that requires a covered entity to 'certify' compliance," and while an external organization may perform an evaluation, "HHS does not endorse or otherwise recognize private organizations' 'certifications' regarding the Security Rule, and such certifications do not absolve covered entities of their legal obligations under the Security Rule." That FAQ is scoped to the Security Rule rather than to HIPAA at large, and we are quoting it as what it is. The point it settles is enough on its own: a badge purchased from a compliance vendor does not move a legal duty from you to anyone.
We will sign a BAA describes a contract. The Privacy Rule permits a covered entity to disclose PHI to a business associate only where it obtains "satisfactory assurances, in the form of a contract or other written arrangement," that the data will be appropriately safeguarded, at 45 CFR 164.502(e)(1)(i). The contents of that contract are specified at 45 CFR 164.504(e). The Security Rule adds its own BAA requirements at 45 CFR 164.308(b), with the term obliging the business associate to report security incidents to you sitting at 45 CFR 164.314(a)(2)(i)(C). Signed, the document creates obligations that a court and a regulator can both reach.
The practical consequence for a buyer is one exchange rather than three separate ones. Not are you HIPAA compliant, which invites a marketing answer, but will you sign a BAA, on which tier, and can I see the template before I pay you.
OCR names chatbots explicitly
The older version of this argument turned on whether a messaging tool was a "conduit," like the postal service, and so outside the business associate definition entirely. That route is closed for essentially anything a chatbot does with message content. OCR limits the conduit exception to entities that "only provide transmission services for PHI (whether in electronic or paper form), including any temporary storage of PHI," and states plainly that entities "that access PHI on a regular or frequent basis to perform a service on behalf of a covered entity are not conduits." A bot that reads a message to classify it has accessed the PHI.
OCR's Business Associates guidance, last reviewed on its own page on 30 July 2026, goes further and lists among its examples of business associates a "Third-party vendor Artificial Intelligence (AI) chatbot on a provider's patient portal that provides services involving the patient's PHI such as symptom assessment, medical reminders, and appointment scheduling." Medical reminders are in that list. So is appointment scheduling. Neither is a diagnosis, and a lot of clinic-side chatbot buying assumes that staying away from clinical content keeps you outside HIPAA as well. On the regulator's own example list, it does not.
One thing worth knowing about the other side of the contract. Since the HITECH Act and OCR's 2013 final rule, business associates are directly liable to OCR, but only for an enumerated set of ten items. Impermissible uses and disclosures are on that list. So are failure to comply with the Security Rule, failure to notify you of a breach, and failure to put BAAs in place with their own subcontractors. Much of the Privacy Rule is not on it. For everything outside those ten, the vendor's obligation to you exists because the BAA says so, which is another way of saying that the quality of the document is not a formality.
What our own reviews actually record
We publish fifteen platform reviews. Fourteen of them use the word HIPAA somewhere; the exception is the Typebot review, which never does, though it names Botpress's "Enterprise BAA" in its alternatives section, about a competitor rather than about Typebot. Counting mentions is easy and tells you nothing. What matters is whether a review locates a BAA, by name, on a named tier, in a vendor document. On that test the fourteen collapse to one.
| What the review records | Platforms | Kind of evidence |
|---|---|---|
| A BAA named on a named tier, in a vendor pricing document | Botpress | Vendor-documented, tier-located |
| HIPAA on a named tier, with the word BAA supplied by us | Chatbase, Tars, Intercom | Vendor-documented tier, BAA inferred |
| A vendor HIPAA claim with no BAA path and no tier | Botpenguin | Vendor-claimed |
| An explicit negative or an absence on the vendor's own pages | Manychat, Tidio, Chatfuel, Wati, SendPulse, AiSensy, Landbot, Voiceflow, Blip | Documented absence |
| No HIPAA mention; a BAA named only for a competitor | Typebot | Silent on its own posture |
The single entry in the first row is worth reading closely. Botpress's per-tier security and compliance matrix carries a row reading "BAA (HIPAA Business Associate Agreement)" with a mark against Enterprise and nothing against Free, Plus or Team. That is a vendor document using the word.
The second row is where the distinction earns its keep. Chatbase gates HIPAA eligibility to Enterprise, and the tiers below it are explicitly outside; but the vendor's own language is "HIPAA-eligible," and the only place that review ties the word BAA to Chatbase is a comparison table we wrote; its other uses of the acronym all describe Botpress. Tars records "HIPAA / ISO / SOC 2 Compliance" as an Enterprise item on its pricing page and ships a HIPAA-compliant webhook as a first-class tool in the builder, which is a stronger signal than a badge. But the word BAA in that review is ours. Intercom states HIPAA on all three tiers, and our own compliance table says the BAA is "likely in Expert tier" and tells the reader to verify. Likely is not a finding, and Intercom is also the one case where the tier in question is published, at $132 per seat per month.
The tier pattern is the finding, and it is worth stating with the sample size visible. Four platforms put HIPAA on a named tier from a vendor document. In three of them, Botpress, Chatbase and Tars, that tier is the custom-priced one. Intercom is the fourth and the exception: its HIPAA statement covers published per-seat tiers from $29 upward, and what is missing there is not the price but the contract, which our own review can only call likely. Beneath the custom tiers sit published prices you can pay today with no vendor-written BAA attached: Botpress Plus at $189 a month monthly-billed, Chatbase Pro at $500 and Tars Premium at $499, and cheaper tiers below those still at Chatbase Hobby $40. No published tier anywhere in the set carries a vendor-written BAA.
So the real cost of the BAA is not a price step from one published figure to another. It is a step out of self-serve entirely: into a sales cycle, an annual commitment and a minimum you cannot see from the pricing page. Budget the calendar time, not just the money. Three platforms is not a market, and this is the pattern our own corpus supports rather than a claim about every vendor selling chatbots.
Where BAAs go wrong in practice
Signed, then routed around. The BAA covers the platform. Six weeks later somebody wires an automation that copies transcripts into a spreadsheet, a scheduling tool and an analytics product, none of which has signed anything. Every downstream service that touches the data needs its own contract, and OCR treats subcontractor BAAs as a direct-liability item for your vendor.
A model provider nobody counted. If the chatbot passes message text to a third-party model, that provider is in the path. Ask which one, under whose contract, and whether your data can reach it at all on your tier. Our LLM security entry covers the surface this opens.
PHI arriving where it was not invited. You built a website bot for shipping questions and a patient typed a diagnosis into it. Free-text fields collect what people put in them. The entity extraction entry explains why the fields you defined are not the only data you now hold.
A contract with no retention clause behind it. A BAA governs use and disclosure. It does not, by itself, tell you when the transcripts disappear. That is a separate decision, and our data retention policy entry sets out why the number has to come from you.
Assuming HIPAA is the only rule. If you are not a covered entity or a business associate, HIPAA may not reach you. Other things still can. The FTC's Health Breach Notification Rule was amended in 2024 to make its application to health apps and connected devices explicit. Washington's My Health My Data Act carries a private right of action. Not being covered is not the same as being unregulated.
Related terms
- Data retention policy — the companion decision a BAA does not make for you.
- LLM security — the risk surface once a model provider sits in the path.
- Session context — the live conversation state, the first place PHI lands.
- Entity extraction — why free text holds more categories of data than you defined.
- Chatbot knowledge base — the content side, which should never hold patient records.
- Human handoff — the moment the transcript reaches a second system and a second contract.
FAQ
What is a Business Associate Agreement?
It is the written contract a HIPAA covered entity must have with any vendor that creates, receives, maintains or transmits protected health information on its behalf. The Privacy Rule permits the disclosure only where the covered entity first obtains "satisfactory assurances, in the form of a contract or other written arrangement" that the data will be safeguarded, at 45 CFR 164.502(e)(1)(i). The required contents are specified at 45 CFR 164.504(e): what the vendor may and may not do with the data, a bar on further use or disclosure beyond the contract or the law, and, where the vendor carries out your Privacy Rule obligations, a commitment to meet those requirements in doing so. The Security Rule adds BAA requirements at 45 CFR 164.308(b), with the security-incident reporting term at 45 CFR 164.314(a)(2)(i)(C); breach notification to the covered entity is a separate obligation at 45 CFR 164.410.
Is a chatbot vendor a business associate?
If it handles PHI on behalf of a covered entity, yes, and OCR's own guidance now says so with a chatbot example: a "Third-party vendor Artificial Intelligence (AI) chatbot on a provider's patient portal that provides services involving the patient's PHI such as symptom assessment, medical reminders, and appointment scheduling." The conduit exception does not rescue it, because OCR limits that exception to entities providing transmission only and states that entities accessing PHI regularly to perform a service are not conduits. A bot that reads a message in order to route it has accessed the data.
Does HIPAA compliant on a vendor's website mean they will sign a BAA?
No, and the two claims are not related by anything except marketing. There is no federal HIPAA certification, and HHS says of Security Rule certifications specifically that it "does not endorse or otherwise recognize private organizations' 'certifications' regarding the Security Rule" and that they "do not absolve covered entities of their legal obligations under the Security Rule." The only question worth asking in a procurement call is whether the vendor will sign a BAA, on which tier, and whether you can read the template first.
Which chatbot platforms sign a BAA?
Ask the vendor, because the answer moves and because our own corpus shows how thin the public record is. Of our fifteen published reviews, one names a BAA on a named tier in a vendor document: Botpress, whose pricing matrix marks it Enterprise-only. Chatbase gates HIPAA eligibility to Enterprise but never uses the word BAA in its own material. Tars places HIPAA at Enterprise and ships a HIPAA-compliant webhook, though the word BAA there is again ours. Intercom states HIPAA across tiers and our review flags BAA availability as unverified. Manychat's review records the clearest negative: it does not sign BAAs. Everything else in the set records an absence or nothing at all.
Does a BAA cost extra?
In our reviewed set the question has the wrong shape, because a BAA is never a line item on a published price. In three of the four platforms where a HIPAA tier could be located at all, it sits on the tier above the last published one, and that tier is custom-priced. The fourth, Intercom, states HIPAA on published per-seat tiers from $29 upward, but our own review records the BAA itself as unverified rather than present. Beneath the custom tiers, and carrying no vendor-written BAA, are published prices including Botpress Plus at $189 a month monthly-billed, Tars Premium at $499, Chatbase Pro at $500 and Chatbase Hobby at $40. Plan for a sales cycle and an annual commitment rather than a checkout.
Do I need a BAA if my bot only books appointments?
Probably, if you are a covered entity or working on behalf of one. Appointment scheduling and medical reminders both appear on OCR's own example list of chatbot activities that make a vendor a business associate. The fact that a bot never discusses a condition does not put it outside the definition, because the appointment itself is information about an individual's health care. If your bot genuinely never receives identifiable health information, the analysis is different, but that is a claim to test against a real transcript sample rather than a design intention.
What happens if we skip it?
Disclosing PHI to a vendor without the required contract is itself a problem for you under 45 CFR 164.502(e), independent of whether anything is ever breached. The vendor carries its own exposure too: since the HITECH Act and OCR's 2013 final rule, business associates are directly liable to OCR for an enumerated set of ten items, including impermissible uses and disclosures, Security Rule compliance and breach notification. What the penalties would be in a given case is a question for counsel and not for a review site.
We are not a healthcare provider. Does any of this reach us?
Possibly not through HIPAA, and possibly through something else. HIPAA runs to covered entities, their business associates and those associates' subcontractors. A wellness app, a supplement retailer or a symptom-checker built for consumers may sit outside all three and still fall inside the FTC's Health Breach Notification Rule, amended in 2024 to make its application to health apps and connected devices explicit, or inside a state statute such as Washington's My Health My Data Act, which carries a private right of action. Our healthcare chatbot guide works through which of these reaches whom.
Sources
- U.S. Department of Health and Human Services, Office for Civil Rights, "Business Associates" guidance, read 24 August 2026; the page records "Content last reviewed July 30, 2026". Relied on for: the definition and examples of a business associate, including the AI chatbot example quoted in full in the second section and the FAQ; the statement that a covered entity may disclose PHI to a business associate where it obtains "satisfactory assurances, in the form of a contract or other written arrangement"; the summary of the elements required at 45 CFR 164.504(e); the Security Rule BAA requirements at 45 CFR 164.308(b) and the incident-reporting term at 45 CFR 164.314(a)(2); the subcontractor BAA requirement; and the conduit exception language, including that entities accessing PHI "on a regular or frequent basis to perform a service" are not conduits. We quote the page as OCR's guidance and do not assert when the AI chatbot example was added to it. hhs.gov
- OCR FAQ #2003, "Are we required to 'certify' our organization's compliance with the standards of the Security Rule?" (HHS page carrying "Content last reviewed July 26, 2013"), read 24 August 2026. Source of both certification quotations, which are printed here with their full clauses rather than truncated. Scope note, because it changes the strength of the claim: this FAQ is written about the Security Rule, not about HIPAA as a whole, and we have said so at every point it is quoted, including in the card summary. It establishes that HHS does not recognize private certifications and that they do not absolve legal obligations under that Rule; it is not a statement that the word "compliant" on a vendor page is meaningless. hhs.gov
- OCR, "Direct Liability of Business Associates" fact sheet, read 24 August 2026, for the enumerated list of ten items for which business associates are directly liable to OCR under the HITECH Act and the 2013 final rule (78 FR 5566), and for the accompanying statement that OCR's enforcement authority over business associates is limited to those items. The four we name in the body are, in the order the body names them, items 5, 3, 4 and 9 of that list. hhs.gov
- 45 CFR parts 160 and 164, consulted for the provisions cited above, plus 160.103 for the underlying definitions of covered entity, business associate and protected health information. Cited by number in the body: 164.502(e)(1)(i) (the disclosure condition), 164.504(e) (required contract elements), 164.308(b) (Security Rule BAA requirements), 164.314(a)(2)(i)(C) (the security-incident reporting term) and 164.410 (breach notification to the covered entity, which is the Breach Notification Rule and not the Security Rule). Cited as regulation text, not as advice about its application. ecfr.gov
- Chatbotscape review corpus, searched 24 August 2026 and published so the counts reproduce. Denominator:
ls sample-reviews/*-review.md | wc -lreturns 15. Mentions:grep -rliE "hipaa" sample-reviews/*-review.mdreturns 14 paths, all excepttypebot-review.md. Three searches were run, and the table is the union of all three, because no single one of them produces it.grep -rliE "business associate" sample-reviews/*-review.mdreturns 7 paths;grep -rlE "\bBAA\b" sample-reviews/*-review.mdreturns 11. Neither is a subset of the other. Six files use the acronym and never spell the term out (AiSensy, Chatbase, Intercom, Landbot, SendPulse, Typebot), two spell it out and never use the acronym (Manychat, Wati), and five do both. The union of the two narrow searches is 13, so the remaining two rows in the table, Blip and Botpenguin, rest on the broadhipaasearch alone. Publishing only the phrase search would have been a method that does not reproduce the published table, which is the same class of error as the counting mistakes recorded on /glossary/data-retention-policy, and the arithmetic here was itself wrong in an earlier draft of this entry before the sets were computed rather than subtracted. Following that entry's rule, every matched file was then read end to end and every hit quoted before classification rather than being classified from the grep line. That step produced the five-row split, caught the Chatbase and Tidio defects noted in the body, and demoted Chatbase out of the first row. Five of the seven "business associate" matches mention BAAs only to say the vendor does not offer one. Tier and price figures are quoted as our reviews recorded them at their own verification dates and are monthly-billed rates throughout, per our pricing methodology; they were not re-verified against vendor pricing pages for this entry, pricing moves, and a figure that decides a purchase should be checked on the vendor's own page. None of the compliance findings in the underlying reviews was established in a hands-on session. - U.S. Federal Trade Commission, Health Breach Notification Rule as amended in 2024, and Washington State's My Health My Data Act, referenced only for the narrow proposition that entities outside HIPAA can still carry health-data duties. Both are named rather than summarized here; the companion guide at /academy/healthcare-chatbot-guide handles them, and neither is the subject of this entry.
- Ahrefs Keywords Explorer, US overview and volume-by-country, queried 24 August 2026 — the demand, difficulty, CPC and country-split figures in this entry's keyword note, including the checks behind declining 'protected health information', 'hipaa compliant ai', 'medical chatbot' and 'chatbot for doctors'.
- Chatbotscape evaluation methodology. /methodology (continuously updated).