Flowers
How it works Features Privacy Pricing For students Blog Contact
Download
How it works Features Privacy Pricing For students Blog Contact Download

← All posts

Do you need a BAA for an AI note tool?

July 19, 2026 · ComplianceHIPAA

Business Associate Agreements are one of those HIPAA topics that everyone nods along to and very few people can actually explain. Here's the practical version, aimed at deciding whether you need one from a piece of software.

This is not legal advice. It's an explanation of how the rule is structured. Your own obligations depend on your situation, and confirming them is a conversation with counsel, not a blog post.

What a BAA is for

If you're a covered entity — most therapists in private practice are — HIPAA lets you share protected health information with outside parties who do work on your behalf. The BAA is the contract that makes that lawful. It obliges the other party to safeguard the PHI, restricts what they can do with it, and requires them to tell you if something goes wrong.

The requirement lives at 45 CFR 164.502(e) and 164.504(e). The definition that actually determines whether you need one is at 45 CFR 160.103.

The test

A vendor is a business associate if, on your behalf, they create, receive, maintain, or transmit protected health information.

Read those four verbs literally, because the analysis really does turn on them. The question is not whether a vendor is trustworthy, or careful, or well-reviewed. It's whether PHI passes through their hands.

Some worked examples:

  • A cloud AI scribe. You upload session audio; they process and store it. That's receive and maintain. BAA required.
  • Your EHR. Obviously — they hold the entire record. BAA required.
  • Your email provider, if you email clients about appointments. Receives and transmits PHI. BAA required, and this one is missed constantly.
  • Your accountant, if they see client-identifiable billing. Usually required.
  • The company that makes your word processor, where documents live only on your machine and nothing syncs. No PHI reaches them. Not a business associate.

That last category is the interesting one, and it's where genuinely local software sits.

The conduit exception, and why it's narrower than people think

There's a carve-out for "mere conduits" — entities that only transport PHI without accessing it, like the postal service or an ISP. People reach for this a lot, usually incorrectly.

HHS has read it narrowly. It covers transmission-only services with at most transient access. A cloud storage provider is not a conduit, even if it never looks at your files, because it maintains them persistently. If a vendor holds your data at rest, the exception almost certainly doesn't apply.

What about software that runs entirely on your computer?

If an application processes PHI locally and transmits none of it to the vendor, the vendor never creates, receives, maintains, or transmits it. They aren't a business associate, and no BAA is required.

This is the situation Flowers is in, and it's worth stating the reasoning rather than just the conclusion: your sessions, transcripts, and notes are encrypted on your own Mac and there is no server of ours that receives them. We couldn't produce your client records if a court ordered us to, because we don't have them.

Two honest caveats. First, "runs locally" is a claim you should verify rather than accept — ask any vendor directly whether clinical content is transmitted, and what their app does when it does reach the network. Ours is itemized in our security overview. Second, local architecture doesn't discharge your obligations. Encryption, device security, access controls, retention, and client consent are still yours. It removes a vendor from the risk surface; it doesn't remove you.

When your organization asks anyway

Plenty of group practices, employers, and malpractice carriers have a blanket policy: signed BAA from every software vendor, no exceptions, no analysis. That policy isn't wrong, exactly — it's just a blunt instrument applied to a question it wasn't designed for.

The usual resolution is an attestation letter explaining why the vendor isn't a business associate, which the compliance team files. If the policy is truly inflexible, a vendor can execute a BAA that accurately describes the architecture. Signing one doesn't make a vendor a business associate; it just documents obligations that mostly don't apply.

Either way, the thing to bring to that conversation is the architecture. "Where does the audio go?" answers the BAA question faster than any amount of security marketing.

Clinical notes that never leave your Mac

Flowers transcribes your sessions and drafts the note on your own computer. Free for up to 15 active clients.

Download for Mac
Flowers

Secure, on-device clinical documentation for therapists. Your sessions stay between you and your clients.

Product
Features Pricing Security For students
Get started
Download Blog Contact
© 2026 Flowers App LLC. All rights reserved.
Privacy Policy Terms of Service HIPAA & BAAs

Flowers assists your documentation. It is not a substitute for clinical judgment, and it does not submit claims or guarantee payer compliance. Always review generated content before relying on it.