# HIPAA BAA vs Self-Hosted AI

> Source: https://ibl.ai/resources/comparisons/hipaa-baa-vs-self-hosted-ai
> Last updated: 2026-08-17


*A business associate agreement moves liability. Self-hosting removes the disclosure entirely — the difference matters more than most procurement checklists assume*

**On ibl.ai you own all the code and the data, run it model-agnostic across any LLM, and pay with no per-seat pricing — so you can deploy anywhere, from your own cloud to a fully air-gapped network.**

## What's the difference between Self-Hosted AI and Vendor BAA?

A business associate agreement is the standard answer to HIPAA and AI. Sign it, and the vendor becomes a business associate bound to safeguard protected health information, report breaches, and accept liability for its own failures.

It is a real control and it is not nothing. But a BAA does not stop PHI from leaving your network. It governs what happens to that data after it arrives on someone else's infrastructure.

Self-hosting changes the question. If inference runs inside your perimeter, there is no disclosure to a business associate, because there is no business associate — the same way running a report in your own EHR is not a disclosure.

This page compares the two honestly: what a BAA genuinely covers, where the residual risk sits, and which clinical workloads justify keeping PHI on hardware you own.

## Feature Comparison

### What Actually Happens to PHI

| Criteria | Self-Hosted AI | Vendor BAA |
|----------|--------------------|--------------------|
| Does PHI Leave Your Network | No. Prompts containing PHI are processed by models running inside your own perimeter. | Yes. The BAA governs the disclosure; it does not prevent it. |
| Breach Surface | Limited to your own environment, which you already secure and audit for the EHR. | Extends to the vendor's infrastructure, subprocessors, and their incident response. |
| Subprocessor Exposure | None. There is no downstream chain because nothing is transmitted. | Cloud AI vendors use subprocessors; the BAA passes obligations down but widens the surface. |
| Retention and Training Use | Retention is whatever your policy says, because the logs are on your systems. | Enterprise terms typically exclude training use and bound retention — verify it in writing per product tier. |

### Compliance Posture

| Criteria | Self-Hosted AI | Vendor BAA |
|----------|--------------------|--------------------|
| Ease of Getting to Compliant | Requires infrastructure, deployment, and your own security review of the platform. | Sign the agreement, enable the eligible service tier, and you have a defensible position quickly. |
| Audit Evidence | Complete request-level logs in systems you own, correlatable with your existing access audits. | Vendor attestations plus your own access logs, with some layers behind the vendor's boundary. |
| Coverage Across Every Feature | The whole deployment is inside your perimeter; there is no eligible-versus-ineligible surface. | BAAs typically cover specific products and tiers — adjacent features may fall outside scope. |
| Fit for Research and Secondary Use | De-identification, cohort work, and secondary analysis stay entirely under your IRB and controls. | Secondary use is often the hardest thing to reconcile with a vendor's standard terms. |

### Operational Reality

| Criteria | Self-Hosted AI | Vendor BAA |
|----------|--------------------|--------------------|
| Integration with Epic, Oracle Health, and athenahealth | Same-network integration over APIs and MCP, with no PHI egress on every retrieval. | Possible, but each retrieval that includes PHI is another disclosure crossing the boundary. |
| Cost at Health-System Scale | Flat license plus owned compute, so extending access to every clinician is not a budget event. | Per-seat licensing across thousands of clinicians and staff scales with headcount, not use. |
| Continuity and Downtime Exposure | Runs inside your data center and keeps working during a vendor or region outage. | Clinical workflows inherit the vendor's availability and its incident timelines. |
| Speed to First Clinical Pilot | Deployment and validation take weeks, or days with engineers who do it for you. | A covered tier and a signed agreement can put a pilot in front of clinicians immediately. |

## Detailed Analysis

### What a BAA Does and Does Not Do

**Self-Hosted AI:** Self-hosting makes the question moot: with no transmission there is no disclosure, no business associate, and no reliance on another organization's safeguards.

**Vendor BAA:** A BAA is an allocation of duty and liability. It obliges the vendor to safeguard PHI and report breaches. It does not, and cannot, prevent PHI from being transmitted and processed elsewhere.

**Verdict:** A BAA makes cloud AI defensible. It does not make it private. Whether that distinction matters depends on the sensitivity of the workload.

### The Scope Trap

**Self-Hosted AI:** In a self-hosted deployment every feature sits inside the same perimeter, so there is no map of which capabilities are covered and which are not.

**Vendor BAA:** Vendor BAAs attach to named products and tiers. Teams routinely assume an organization-wide agreement covers every adjacent feature, and it usually does not.

**Verdict:** If you rely on a BAA, enumerate exactly which services are in scope and enforce that boundary technically, not just in policy.

### Where Self-Hosting Is Not Worth It

**Self-Hosted AI:** Self-hosting carries real cost: infrastructure, model serving, and a security review your team must perform rather than inherit.

**Vendor BAA:** For workloads that touch no PHI at all — policy drafting, scheduling logistics, general staff productivity — a covered cloud service is faster and entirely reasonable.

**Verdict:** Segment by data class. Keep PHI-bearing clinical work inside the perimeter and let non-PHI work use whatever is convenient.

## FAQ

**Q: Does a signed BAA make an AI tool HIPAA compliant?**

It makes the arrangement defensible, not private. A BAA obliges the vendor to safeguard PHI, restrict use, and report breaches. PHI still leaves your network and is processed on the vendor's infrastructure, which remains a disclosure you must document in your risk analysis.

**Q: Is ChatGPT, Copilot, or Gemini HIPAA compliant?**

Each offers enterprise tiers where a BAA can be executed for specific covered services. Compliance depends on using an eligible tier under a signed agreement and keeping PHI out of features outside its scope — the boundary is per product, not per vendor.

**Q: Why would a health system self-host AI instead of signing a BAA?**

To eliminate the disclosure rather than govern it. Self-hosted inference means PHI never leaves the network, there is no subprocessor chain, no covered-versus-uncovered feature map, and no dependence on another organization's incident response.

**Q: Can self-hosted AI actually match cloud AI quality for clinical work?**

For documentation, summarization, coding support, retrieval over clinical guidance, and patient-communication drafting, open-weight models running locally perform well. The remaining gap is narrowest exactly where healthcare workloads concentrate.

**Q: Do we have to choose one approach for everything?**

No, and most systems should not. Segment by data class: PHI-bearing clinical workloads stay inside the perimeter, while non-PHI administrative work can use a covered cloud service. That requires a platform that can run in both places.

**Q: How does ibl.ai fit in?**

ibl.ai runs inside your clinical network — on-premise or air-gapped — so PHI never leaves your perimeter and no BAA is needed for the platform itself. You own all the code and the data, run any model, and can deploy on any cloud, on-premise, or air-gapped.


## Where does ibl.ai fit alongside Self-Hosted AI and Vendor BAA?

**ibl.ai is the agentic AI platform where you own all the code and the data. You self-host the entire stack inside your own perimeter, run it model-agnostic across any LLM and switch anytime, and pay by usage with no per-seat pricing — so you can deploy anywhere: your cloud, on-premise, GovCloud, or fully air-gapped.**

ibl.ai lets a health system stop negotiating the disclosure and remove it. The platform is self-hosted, so prompts containing protected health information are processed by models running inside your own network, logged in systems you already audit.

Agentic OS integrates with Epic, Oracle Health, and athenahealth over internal endpoints, runs guardrails and PII redaction before a model ever sees a record, and operates fully air-gapped where there is no outbound connectivity. You own all the code and the data, and the flat license means extending AI to every clinician is not a per-seat budget decision.

- **You own all the code and the data.** Full source code under a perpetual license, running on your infrastructure. Not API access to someone else's platform — the stack itself is yours.
- **Model-agnostic.** Run any LLM — Claude, GPT, Gemini, Llama, Command, or your own fine-tune — and switch providers without rewriting the platform.
- **No per-seat pricing.** Usage-based billing against a budget cap you set. Cost tracks what your organization actually uses, not how many people you employ.
- **Deploy anywhere.** Your cloud, your VPC, on-premise, GovCloud, or a fully air-gapped network with no outbound connectivity.

1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

ibl.ai is family-owned and operated from New York, NY — a U.S.-headquartered, domestically-owned long-term partner, not a vendor that sells licenses and moves on.
