HIPAA LLM bundle with BAA
A
Adam Coon
Per the current FAQ (https://docs.hatz.ai/en/articles/16044622-does-hatz-support-hipaa-compliance-or-offer-a-baa), Hatz does not currently support HIPAA compliance or offer a BAA. Given Hatz's existing security posture — SOC 2 Type I/II, SOC 3, tenant isolation, and built-in Compliance & Audit Logs with a dedicated Compliance Manager role — this is the one remaining gap standing between Hatz and a genuine leapfrog opportunity in the healthcare market.
The market problem this solves: Several major LLM providers now offer BAAs, but each requires the customer to self-manage a single-provider environment correctly:
- Anthropic (Claude API) — BAA available via manual HIPAA activation in Org Settings; requires Zero Data Retention request for true no-storage handling. Note: this applies to the Claude API only — not Claude Enterprise's CoWork/Managed Agents features, which are explicitly excluded.
- Microsoft Azure OpenAI — BAA available automatically under Microsoft's standard volume-licensing terms; Modified Abuse Monitoring can be requested to eliminate the 30-day human-review retention window.
- Google Vertex AI (Gemini) — BAA available via self-serve acceptance in Google Cloud Console; applies to Vertex AI only, not consumer Gemini.
- AWS Bedrock — BAA available under AWS's standard HIPAA-eligible services program; covers hosted Anthropic/other foundation models on Bedrock.
Each of these is "affordable" and enterprise-grade individually, but none of them provide unified, tenant-level audit governance across models. A practice or MSP has to trust that every staff member, every session, and every device only ever touches the one BAA-covered account — with no built-in mechanism to prove that, or to catch it when someone doesn't. That's the actual compliance risk: not a flaw in any one provider's security, but the operational gap between "we have a BAA" and "we can prove, continuously, that only BAA-covered infrastructure ever touched PHI."
This is precisely where Hatz is already ahead: the Compliance & Audit Logs feature already tracks admin actions, invocations, and content visibility per tenant, with exportable records and a Compliance Manager role. That's most of the governance layer HIPAA-conscious organizations struggle to build on their own. The only missing piece is guaranteeing that PHI-tagged tenants can only ever route to BAA-covered infrastructure.
D
Dean Lause
Yea.. This is one thing I was going to look at for a client that I have but appears this will be a NO GO without the BAA
B
Baruch Blaustein
HIPAA compliant AI platforms aren't easy to find. Anthropic only offers this for enterprise plans and I'm being told it takes months to get Anthropic to sign a BAA.
If Hatz builds this into the platform, Hatz partners can easily corner the Healthcare vertical AI market. It's a great hook to win over new IT clients for all services. I'm hoping this can be released really fast!!!!!
N
Nick E
Baruch Blaustein YES!!!!