← Back to blog

June 30, 2026 · 3 min read

The real difference between a BAA and a privacy policy

The real difference between a BAA and a privacy policy
On this page

ChatGPT Doctors

Spend less time finishing notes

Turn the visit into a structured draft you can review and copy to your EHR.

Try it for free

No credit card required

Two different kinds of documents

Every website has a privacy policy. It's a unilateral statement: here's what we collect, here's what we do with it, here's how to opt out. You can't negotiate it, and if the company changes its mind, it just updates the page.

What a BAA actually commits to

A Business Associate Agreement is a different kind of document entirely. It's a signed contract required under HIPAA whenever a vendor handles protected health information on a covered entity's behalf. It spells out obligations, breach notification timelines, and liability, and both sides are bound by it.

Why the gap matters

If a tool you're using with patient data doesn't offer a BAA, that's not a minor gap. It usually means the vendor never built the product to handle PHI in the first place, and a privacy policy alone isn't going to cover you if something goes wrong.

The practical test

The practical test is simple: ask whether a BAA is available, and whether it's standard or something you have to escalate to a sales team to get. That answer tells you a lot about how seriously PHI was considered during design.

See how ChatGPT Doctors handles this in your own workflow.

Try it for free