Vendor BAA Matrix

Which AI vendors will sign a BAA and under what terms. This is re-verified quarterly.

VendorBAA?Plan requiredNotes
OpenAIYesEnterprise / API Zero Data RetentionAPI ZDR required for PHI use; Enterprise contracts include DPA.
Anthropic (via AWS Bedrock)YesAWS Bedrock + AWS BAAWork through Bedrock for enterprise-grade BAAs and controls.
Google (Gemini in Workspace)YesWorkspace Business+ w/ BAAGemini in Workspace covered under the Workspace BAA when enabled.
Microsoft (M365 Copilot)YesM365 E3/E5 + Microsoft BAACopilot in M365 is covered when tenant has an active BAA and proper settings.
Notion AILimitedEnterprise + BAAOnly workspace-scoped data; check export/retention settings.
PerplexityNoConsumer product; do not use with PHI.

Audit checklist

When negotiating a BAA, confirm: data retention, subprocessor list, access controls, encryption at rest/in transit, logging, and incident notification SLA.