An Azure service that provides access to OpenAI’s GPT-3 models with enterprise capabilities.
For Azure, a separate BAA does not need to be created or signed in most cases.
The HIPAA BAA is available by default through the Microsoft Product Terms and the Microsoft Products and Services Data Protection Addendum (DPA). Microsoft states that execution of the customer’s licensing agreement includes execution of the HIPAA Business Associate Agreement for covered entities and business associates under HIPAA.
What to do:
- Verify that the Azure services in use are in scope for HIPAA BAA coverage. Microsoft directs customers to review the list of cloud services in audit scope for the HIPAA BAA.
- Retrieve the contractual documents for records and auditors:
- Microsoft Product Terms
- Microsoft Products and Services Data Protection Addendum (DPA)
- Microsoft HIPAA BAA
- If copies of audit and compliance reports are needed, use the Service Trust Portal. Azure customers can also retrieve Azure certificates and audit reports in the Azure portal through the audit reports blade in Microsoft Defender for Cloud.
- Do not use a custom organization BAA with Microsoft. Microsoft cannot use a customer’s BAA.
Important limitation: Having the BAA in place does not make an Azure deployment HIPAA compliant by itself. The organization remains responsible for its own compliance program, internal processes, and ensuring its Azure usage aligns with HIPAA and the HITECH Act.