A business associate agreement moves liability. Self-hosting removes the disclosure entirely β the difference matters more than most procurement checklists assume
On ibl.ai you own all the code and the data, run it model-agnostic across any LLM, and pay with no per-seat pricing β so you can deploy anywhere, from your own cloud to a fully air-gapped network.
Last updated:
A business associate agreement is the standard answer to HIPAA and AI. Sign it, and the vendor becomes a business associate bound to safeguard protected health information, report breaches, and accept liability for its own failures.
It is a real control and it is not nothing. But a BAA does not stop PHI from leaving your network. It governs what happens to that data after it arrives on someone else's infrastructure.
Self-hosting changes the question. If inference runs inside your perimeter, there is no disclosure to a business associate, because there is no business associate β the same way running a report in your own EHR is not a disclosure.
This page compares the two honestly: what a BAA genuinely covers, where the residual risk sits, and which clinical workloads justify keeping PHI on hardware you own.
by ibl.ai on your infrastructure
PHI never leaves your perimeterby OpenAI, Microsoft, Google, AWS
Contractual coverage for cloud processing| Criteria | Self-Hosted AI | Vendor BAA |
|---|---|---|
| Does PHI Leave Your Network | No. Prompts containing PHI are processed by models running inside your own perimeter. | Yes. The BAA governs the disclosure; it does not prevent it. |
| Breach Surface | Limited to your own environment, which you already secure and audit for the EHR. | Extends to the vendor's infrastructure, subprocessors, and their incident response. |
| Subprocessor Exposure | None. There is no downstream chain because nothing is transmitted. | Cloud AI vendors use subprocessors; the BAA passes obligations down but widens the surface. |
| Retention and Training Use | Retention is whatever your policy says, because the logs are on your systems. | Enterprise terms typically exclude training use and bound retention β verify it in writing per product tier. |
| Criteria | Self-Hosted AI | Vendor BAA |
|---|---|---|
| Ease of Getting to Compliant | Requires infrastructure, deployment, and your own security review of the platform. | Sign the agreement, enable the eligible service tier, and you have a defensible position quickly. |
| Audit Evidence | Complete request-level logs in systems you own, correlatable with your existing access audits. | Vendor attestations plus your own access logs, with some layers behind the vendor's boundary. |
| Coverage Across Every Feature | The whole deployment is inside your perimeter; there is no eligible-versus-ineligible surface. | BAAs typically cover specific products and tiers β adjacent features may fall outside scope. |
| Fit for Research and Secondary Use | De-identification, cohort work, and secondary analysis stay entirely under your IRB and controls. | Secondary use is often the hardest thing to reconcile with a vendor's standard terms. |
| Criteria | Self-Hosted AI | Vendor BAA |
|---|---|---|
| Integration with Epic, Oracle Health, and athenahealth | Same-network integration over APIs and MCP, with no PHI egress on every retrieval. | Possible, but each retrieval that includes PHI is another disclosure crossing the boundary. |
| Cost at Health-System Scale | Flat license plus owned compute, so extending access to every clinician is not a budget event. | Per-seat licensing across thousands of clinicians and staff scales with headcount, not use. |
| Continuity and Downtime Exposure | Runs inside your data center and keeps working during a vendor or region outage. | Clinical workflows inherit the vendor's availability and its incident timelines. |
| Speed to First Clinical Pilot | Deployment and validation take weeks, or days with engineers who do it for you. | A covered tier and a signed agreement can put a pilot in front of clinicians immediately. |
Self-hosting makes the question moot: with no transmission there is no disclosure, no business associate, and no reliance on another organization's safeguards.
A BAA is an allocation of duty and liability. It obliges the vendor to safeguard PHI and report breaches. It does not, and cannot, prevent PHI from being transmitted and processed elsewhere.
A BAA makes cloud AI defensible. It does not make it private. Whether that distinction matters depends on the sensitivity of the workload.
In a self-hosted deployment every feature sits inside the same perimeter, so there is no map of which capabilities are covered and which are not.
Vendor BAAs attach to named products and tiers. Teams routinely assume an organization-wide agreement covers every adjacent feature, and it usually does not.
If you rely on a BAA, enumerate exactly which services are in scope and enforce that boundary technically, not just in policy.
Self-hosting carries real cost: infrastructure, model serving, and a security review your team must perform rather than inherit.
For workloads that touch no PHI at all β policy drafting, scheduling logistics, general staff productivity β a covered cloud service is faster and entirely reasonable.
Segment by data class. Keep PHI-bearing clinical work inside the perimeter and let non-PHI work use whatever is convenient.
These workloads are PHI-saturated by nature, and self-hosting removes the disclosure rather than papering over it with an agreement.
Where no protected information is involved, a covered cloud service is faster to deploy and the residual risk is minimal.
Secondary use is the hardest case to reconcile with standard vendor terms, and keeping it in-house keeps it under your IRB and your controls.
Per-seat licensing across thousands of clinical staff scales with headcount rather than usage, and a flat self-hosted license removes that multiplier.
Timeline: Six to twelve weeks including security review and clinical validation
Timeline: Days to a few weeks
ibl.ai is the agentic AI platform where you own all the code and the data. You self-host the entire stack inside your own perimeter, run it model-agnostic across any LLM and switch anytime, and pay by usage with no per-seat pricing β so you can deploy anywhere: your cloud, on-premise, GovCloud, or fully air-gapped.
ibl.ai lets a health system stop negotiating the disclosure and remove it. The platform is self-hosted, so prompts containing protected health information are processed by models running inside your own network, logged in systems you already audit. Agentic OS integrates with Epic, Oracle Health, and athenahealth over internal endpoints, runs guardrails and PII redaction before a model ever sees a record, and operates fully air-gapped where there is no outbound connectivity. You own all the code and the data, and the flat license means extending AI to every clinician is not a per-seat budget decision.
Full source code under a perpetual license, running on your infrastructure. Not API access to someone else's platform β the stack itself is yours.
Run any LLM β Claude, GPT, Gemini, Llama, Command, or your own fine-tune β and switch providers without rewriting the platform.
Usage-based billing against a budget cap you set. Cost tracks what your organization actually uses, not how many people you employ.
Your cloud, your VPC, on-premise, GovCloud, or a fully air-gapped network with no outbound connectivity.
1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.
ibl.ai is family-owned and operated from New York, NY β a U.S.-headquartered, domestically-owned long-term partner, not a vendor that sells licenses and moves on.
See how ibl.ai deploys AI agents you own and controlβon your infrastructure, integrated with your systems.