In a recent Paubox Customer gathering of healthcare IT professionals, experts discussed AI clinical scribe tools. Attendees exchanged notes on options such as Doximity, Freed AI, Heidi, and Doxyme as potential applications for day-to-day documentation. The point of the discussion was not that these tools work. It was about who is covered legally when they do.
According to the recap of the gathering, the group’s compliance checklist was focused on three things, namely state two-party consent laws, whether a tool discloses recording before a session starts, and “BAA [business associate agreement] coverage (individual vs. organizational).” These terms are practical vendor and account management descriptions, not categories that are formally defined by HIPAA. It still holds true to healthcare organizations that the latter (organizational BAAs) is the difference between a tool your organization can justify in an audit and one that quietly creates a liability nobody signed up for.
The problem that lies between AI adoption and BAA coverage
Numbers help to see the scale of the problem. And a study on the legal and regulatory risks of generative AI in emergency medicine found that a large majority of physicians already use AI tools in clinical practice, while institutional safeguards have not kept pace. The same research states “a key measure of institutional protection remains woefully low,” noting the small number of health systems with BAAs in place for the third-party AI tools their staff is already using.
The gap in adoption is ahead of contracts, and that is where the individual vs. organizational BAA question does its damage. A clinician is not waiting for procurement to complete the vetting of the tool. They open an account, normally a personal account, and start using it. When it all goes wrong, typically no one investigates what name is on the account, or even whether that account falls under a BAA.
AI scribes make the pattern come alive. A review of the risks these tools bring to clinical practice found that they are now used in about 30% of physician practices, and documentation time is reduced by 20% to 30%. It ties back to the panel discussion where when a capability spreads that fast, the contract question tends to come up after the tool is already in daily use, not before.
Individual BAA vs. organizational BAA
An individual BAA typically means one person, or one account, is covered by an agreement, often at that person's initiative. An organizational BAA means the covered entity itself is the signing party, with centralized administration, i.e., provisioning and deprovisioning access, applying uniform configuration settings, and logging activity across every user under that agreement.
A detailed comparison from Paubox found that most major AI providers will sign a BAA, but the terms depend heavily on which tier of service is in use. Anthropic requires the account owner to sign the agreement and separately request that protected health information (PHI) handling be enabled; on Claude for Work, HIPAA coverage is available only on the Enterprise plan, not on Free, Pro, or Max. OpenAI's API platform will sign a BAA for ChatGPT for Healthcare and ChatGPT for Clinicians, while Enterprise requires a Regulated Workspace; ChatGPT Business does not qualify. Google's standalone Gemini API through AI Studio has no BAA option at all; the same underlying capability is available with a BAA only through Vertex AI.
The main differences
- An individual BAA covers one clinician or one account; an organizational BAA covers the healthcare organization and its authorized users.
- The individual signs the individual BAA; an authorized representative signs the organizational BAA.
- The individual normally manages their own account; the organization centrally manages user access and security settings.
- An individual account usually has limited organization-wide monitoring; an organizational account may provide centralized audit logs and activity monitoring.
- An individual BAA does not automatically authorize someone to use their employer’s PHI; an organizational BAA allows the organization to approve how staff use the tool with PHI.
Why shadow AI is a risk
The individual vs. organizational matter is also a way for shadow AI to take hold. Shadow AI refers to staff using AI tools that IT and compliance have never reviewed or approved, often because the tool is convenient, free, or already familiar from personal use.
Paubox’s research into this behavior found that 85% of healthcare IT leaders suspected staff was using unauthorized AI tools, but only 26% had actual visibility into that use. More than two-thirds had already identified rogue AI somewhere in their organization. More and more, individual employees are bringing in AI tools faster than organizations are contracting for them, and a portion of the workforce does not know a contract is even necessary. Each of those individual, unreviewed accounts is a potential entry point for PHI to leave the organization’s control without encryption guarantees, without an audit trail, and without a BAA in the back of it.
Who gets held accountable
The earlier referenced study outlines the framework for accountability, with hospitals, clinics, and health systems as the designated covered entities that carry primary responsibility for vetting third-party vendors and executing BAAs. When a provider uses an AI tool without a valid BAA and PHI is disclosed, it is typically the institution that faces regulatory exposure, potentially including fines and corrective action plans.
Individual clinicians are less likely to face direct civil penalties under HIPAA itself, but they remain accountable to their employer. It can mean retraining, formal warnings, suspension, or termination, consequences that are real even when they don't come from a federal regulator.
See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)
FAQs
Can an AI vendor use PHI to train its models after signing a BAA?
Only if that use is permitted by the agreement and HIPAA. A business associate generally cannot use PHI for its own independent purposes merely because it has access to the information.
Are AI generated notes and summaries considered PHI?
They can be if an output contains information about an identifiable patient and is created or received by a covered entity or business associate, it will generally remain PHI.
Can an organization test an AI tool without a BAA?
Yes, if the test uses synthetic information or data that has been properly de-identified before reaching the vendor.
