HIPAA
HIPAA (Health Insurance Portability and Accountability Act) is the US law governing the privacy and security of protected health information (PHI) — strict requirements that apply to any AI system touching healthcare data.
HIPAA requires: a Business Associate Agreement (BAA) with every vendor handling PHI, encryption in transit and at rest, role-based access, audit logs, breach notification, and a slew of administrative safeguards. AI vendors selling to healthcare must be HIPAA-ready end-to-end — including their model providers, vector stores, and observability tools.
Example
A medical practice using AI Support must verify the AI vendor signs a BAA, that PHI never leaves the BAA-covered region, and that all model providers downstream are also under BAA.
How OpenLabor uses it
OpenLabor offers HIPAA-eligible deployments with BAA, BAA-covered model routing, and PHI-safe redaction.
Are major LLM providers HIPAA-eligible?
Anthropic and OpenAI offer HIPAA-eligible tiers via signed BAAs. Open-weight self-hosted models are eligible because you control the deployment.
Related: baa, encryption-at-rest, audit-trail, pii-redaction.
AI Labor Glossary