Provision record
OpenAI · OpenAI Enterprise Privacy · View original document ↗

BAA available for HIPAA compliance via API

High severity Medium confidence Explicit document language Common · 298 of 352 platforms

Key Facts · in the document’s own words

Can OpenAI sign Business Associate Agreements?
“We are able to sign Business Associate Agreements (BAA) in support of customers' compliance with the Health Insurance Portability and Accountability Act (HIPAA).”
Version CA-V-005281, captured July 26, 2026 · live source ↗
Our reading, not the document’s words
OpenAI is able to sign Business Associate Agreements in support of customers' compliance with HIPAA.
Stay ahead of the changes
Track OpenAI and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
ⓘ

This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The availability of a BAA is a prerequisite for customers operating under HIPAA to lawfully use a service provider handling protected health information.

⚠

Interpretive note: The excerpt states OpenAI 'is able to' sign a BAA but does not specify conditions, eligibility criteria, or whether signing is guaranteed on request. The claim reflects the stated capability without inferring an unconditional obligation.

Recent Activity

This document changed recently

Medium Jul 18, 2026

The updated terms state that workspace admins 'can control' data retention rather than directly controlling it. This conditional phrasing may suggest that retention control is optional or contingent rather than a guaranteed capability. Enterprise customers relying on admin-driven data retention policies should clarify with OpenAI whether this change affects their ability to set specific retention timelines for workspace data.

View change record →
High May 28, 2026

The updated terms shift governance of conversation access and retention from end users to workspace administrators. Under the revised policy, workspace admins can now view, access, export, and delete any end user conversations within their workspace and control how long workspace data is retained. Additionally, OpenAI now reserves the right to retain deleted or unsaved conversations beyond the standard 30-day deletion window if retention is reasonably necessary to protect its services or any third party from harm, beyond prior language that limited retention extensions to legal requirements. Within an enterprise account, end users no longer have unilateral control over conversation visibility or deletion of their own conversations.

View change record →

Consumer impact (what this means for users)

If you are subject to HIPAA, you may request a Business Associate Agreement from OpenAI.

How other platforms handle this

Minecraft Medium

You make it clear that you (not us) are responsible for anything that happens during your event

Shopify Medium

If you use these services, you need to respect how the supply chain works and what terms are asked of you.

Midjourney Medium

Your consent to this Privacy Policy followed by Your submission of such information represents Your agreement to that transfer.

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
We are able to sign Business Associate Agreements (BAA) in support of customers' compliance with the Health Insurance Portability and Accountability Act (HIPAA).

Excerpt from OpenAI's Enterprise Privacy

Provision details

Document information
Document
OpenAI Enterprise Privacy
Entity
OpenAI
Tracking information
First captured by ConductAtlas
May 12, 2026
Text quoted from version
CA-V-005281, captured July 26, 2026
Record ID
CA-P-062746
Document ID
CA-D-000825
Evidence Provenance
Source URL
Wayback Machine
Extracted-text SHA-256 (version CA-V-005281)
0c25699bc3c20c13ead95ab1bc1fc06c9552397328b9ef2365fddd4c635e98ef
Analysis generated
July 9, 2026 04:24 UTC
Methodology
Evidence
✓ Excerpt found verbatim in version CA-V-005281 (checked Oct. 5, 2026)
Citation Record
Entity: OpenAI
Document: OpenAI Enterprise Privacy
Record ID: CA-P-062746
Version: CA-V-005281
Captured: 2026-07-26 00:06:29 UTC
SHA-256: 0c25699bc3c20c13…
URL: https://conductatlas.com/platform/openai/openai-enterprise-privacy/provision/CA-P-062746/baa-available-for-hipaa-compliance-via-api/
Accessed: Oct. 8, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does OpenAI's BAA available for HIPAA compliance via API clause do?

The availability of a BAA is a prerequisite for customers operating under HIPAA to lawfully use a service provider handling protected health information.

How does this clause affect you?

If you are subject to HIPAA, you may request a Business Associate Agreement from OpenAI.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 298 platforms. See the full comparison.

Is ConductAtlas affiliated with OpenAI?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.