AI vendors that sign HIPAA Business Associate Agreements
AI vendors that publicly offer a HIPAA Business Associate Agreement, enabling lawful processing of Protected Health Information.
For healthcare buyers — providers, health plans, clearinghouses — a signed HIPAA Business Associate Agreement is a hard prerequisite for any AI vendor that may touch PHI. The vendors below publicly offer a BAA. That alone is necessary but not sufficient: the BAA must cover sub-processors (most AI vendors route through OpenAI, Anthropic, Google, or Mistral), specify breach reporting, and address PHI handling end-to-end. Ask for the BAA template before signing the master agreement.
Vendors with HIPAA BAA
Anthropic
Score 11.44 · low
Amazon (AWS)
Score 12.34 · low
Salesforce
Score 12.74 · low
Cohere
Score 13.79 · low
IBM
Score 14.11 · low
Microsoft
Score 14.68 · low
OpenAI
Score 18.36 · low
Google DeepMind
Score 18.85 · low
Oracle
Score 19.89 · low
Palo Alto Networks
Score 19.89 · low
Nuance (Microsoft)
Score 20.86 · moderate
Writer
Score 20.93 · moderate
Mosaic (Databricks)
Score 22.6 · moderate
SentinelOne
Score 22.96 · moderate
Snowflake
Score 24.36 · moderate
ServiceNow
Score 24.4 · moderate
Datadog
Score 24.41 · moderate
SambaNova
Score 24.5 · moderate
PolyAI
Score 24.72 · moderate
Palantir
Score 25.09 · moderate
Databricks
Score 25.4 · moderate
Slack
Score 26.47 · moderate
Vanta
Score 27.24 · moderate
Zoom
Score 27.35 · moderate
CoreWeave
Score 29.93 · moderate
Arize AI
Score 30.6 · moderate
Zendesk
Score 30.94 · moderate
Galileo
Score 30.97 · moderate
Twilio
Score 31.65 · moderate
Abridge
Score 32.09 · moderate
Monday.com
Score 32.24 · moderate
Regard
Score 33.19 · moderate
Hippocratic AI
Score 33.46 · moderate
Darktrace
Score 35.77 · moderate
Buyer checklist
- Confirm the BAA covers sub-processors (which upstream model APIs see your data).
- Verify that breach reporting timeline meets your covered entity's policy.
- Confirm the vendor will return or destroy PHI at termination.
- Check whether the BAA is included at all pricing tiers or only enterprise.
- Run a mock incident-response tabletop covering the vendor as a business associate.
Compliance is necessary, not sufficient. Holding HIPAA BAA is a meaningful baseline, but no certification covers AI-specific risk end-to-end. Layer this on top of vendor-specific diligence — sub-processor disclosure, training-data policy, model card transparency, dependency-chain mapping.