Back to Blog
Compliance

BAA for an AI Vendor: What Dental Practices Must Ask

A signed BAA is the floor, not the diligence. What a dental practice should verify before any AI vendor touches a patient photo in 2026.

Smile PreVue Team··10 min read
BAA for an AI Vendor: What Dental Practices Must Ask

A signed business associate agreement is the floor of vendor diligence, not the whole of it. A BAA makes an AI vendor legally accountable for the protected health information it touches, but it does not tell you where a patient photo gets processed, how long it is retained, or whether it is used to train a model. Those are separate questions, and they are the ones that separate a serious vendor from a risky one.

This is general education for practice owners, not legal advice. If your situation is complicated, your healthcare attorney is the right call.

What does a BAA actually cover when an AI vendor handles patient photos?

A BAA is a contract required under HIPAA whenever a vendor creates, receives, maintains, or transmits protected health information on behalf of a covered entity. Your practice is the covered entity. The vendor is the business associate. The agreement obligates them to safeguard the data, report breaches, and pass the same obligations down to their own subcontractors.

What the agreement does not do is describe the architecture. Two vendors can hand you a nearly identical BAA and run completely different data paths underneath it. One might process the image inside a HIPAA-eligible cloud service under its own BAA with the cloud provider. The other might pipe it through a consumer API that was never covered by anything.

One thing worth settling early: a photo of a patient's face, tied to a name, an appointment, or a proposed treatment plan, is PHI. Practices sometimes treat the camera roll as a gray area because a photo feels less clinical than a chart note. It is not. Our earlier piece on what HIPAA-grade smile simulation actually means covers that ground in more depth.

Why is a signed BAA suddenly not enough in 2026?

Because the proposed direction of federal policy shifts the standard from having the agreement to being able to show how you evaluated the vendor behind it.

In January 2025, the HHS Office for Civil Rights published a notice of proposed rulemaking to modernize the HIPAA Security Rule. The comment period closed in March 2025. As of August 2026 it is still a proposed rule. OCR had a final action target of May 2026 that came and went, and the current regulatory agenda pushes final action to 2027. More than a hundred hospital and provider groups have formally asked HHS to withdraw or substantially scale it back, arguing the compliance cost was underestimated for smaller providers.

So nothing here is a deadline. What matters is the direction, because it is unlikely to reverse:

  • Multifactor authentication and encryption of ePHI at rest and in transit would move from "addressable" to required.
  • Agreements would need to define a business associate's specific cybersecurity obligations, with annual written verification that those controls are actually in place, analyzed by a qualified professional.
  • Supporting requirements include a current inventory of hardware and software assets, a network map, network segmentation, vulnerability scanning at least every six months, annual penetration testing, and business associate breach notification within 24 hours.
  • AI systems are named inside the scope of the risk analysis, which means an AI tool stops being a side tool sitting outside the compliance program.

Read that list as one sentence: a signature collected once at signup is being replaced by evidence you can produce on request. A practice that already asks vendors real questions is not going to feel this change. A practice that files the PDF and moves on will.

Which questions separate a compliant AI vendor from a risky one?

Five questions. They take about ten minutes on a sales call, and the quality of the answer tells you more than the length of the contract.

Where is the image processed, and under what agreement? Ask for the actual cloud service and whether the vendor holds a BAA with that provider. "It's secure" is not an answer. "It runs on a HIPAA-eligible service under our BAA with the cloud provider" is.

Is the image retained after the simulation, and for how long? There is no universally correct answer here, but there is a correct behavior: the vendor should know the number without checking.

Is patient data ever used to train or improve a model? This is the question most likely to produce a pause. You want an unambiguous no, in writing, covering both the vendor and its upstream model provider.

Who are the subprocessors, and are they covered downstream? Every vendor of any size has them: cloud, hosting, analytics, error monitoring. HIPAA requires those obligations to flow down. Ask for the list.

Can the vendor produce evidence of its controls? Not a promise. Evidence. A named privacy or security officer, a documented incident response process with a defined clock, a risk register, a subprocessor matrix. Any vendor serious about healthcare has these on a shelf.

Keep it at that level. You are not running a formal audit. You are testing whether the vendor thought about the problem before you asked.

How do the common setups compare?

Most practices are choosing among four broad approaches, and they are not equivalent when a patient's face is involved.

ApproachBAA availableWhere the image is processedRetentionFit for chairside use
Consumer photo-editing appNoConsumer cloud, terms written for personal useOften indefinite, per consumer termsNot appropriate for PHI
General-purpose AI chat tool, no BAA in placeNot on a standard consumer planVendor's general infrastructureVaries, may feed product improvementNot appropriate for PHI
Design suite built for the lab workflowVaries by vendor, ask directlyVendor infrastructure, often with a lab handoffVaries, ask directlyBuilt for lab turnaround, not a same-visit consult
Clinical AI on an enterprise cloud under a BAAYesHIPAA-eligible cloud under the vendor's BAADefined, documentedDesigned for it

Smile PreVue sits in that last row. Real patient PHI is processed under a BAA on Google Vertex AI, the subprocessors we rely on are covered by BAAs with us, and the compliance program behind that is documented rather than asserted. You can read the specifics on our security and HIPAA compliance page.

One competitive point worth making honestly: legacy design suites like Digital Smile Design were built to serve the lab. That is a real workflow with real value, and their data path was designed around it, not around a patient sitting in the chair waiting for an answer. That is an architecture difference, not a compliance accusation. Ask every vendor the same five questions regardless of how long they have been around.

What happens to the photo after the simulation?

Retention is a product decision that most vendors never surface, because nobody asks.

The practical test is a good one to carry into any demo: could you explain to a patient, in one plain sentence, where their photo went? If the honest answer is "I'm not sure," you have found the gap.

Worth separating two things that often get blurred. The vendor contract governs what happens to the data. The consent conversation governs whether the patient agreed to it in the first place. A BAA does not consent on your patient's behalf, and consent does not make an insecure vendor safe. You need both.

Where does payment data fit, and why is it a different question?

Because PHI and cardholder data live under different regimes entirely. HIPAA governs the health information. PCI DSS governs the card. A vendor can be genuinely strong on one and thin on the other, and the BAA on your desk says nothing at all about the second.

If your consult ends with the patient paying for the case, that transaction has its own compliance surface. With Smile PreVue, payments run through Stripe at PCI DSS Level 1, and card details are entered directly into Stripe, so they never touch Smile PreVue servers. Patients can pay in full or, subject to approval by the financing provider, pay over time through Affirm, Klarna, or Sunbit. Smile PreVue is not a lender or a bank, and the terms a patient is offered come from the provider, not from us.

The reason this belongs in a vendor-diligence post: the two questions get asked at different times, usually by different people in the practice, and neither one covers the other. Ask both.

Frequently asked questions

Is AI smile simulation HIPAA compliant?

It depends entirely on the vendor's architecture, not on the category. AI smile simulation can be fully HIPAA compliant when the vendor signs a BAA with your practice, processes images on a HIPAA-eligible cloud service under its own BAA with that provider, defines retention, and covers its subprocessors. It is not compliant when any of those links is missing.

Do I need a BAA with an AI vendor if I remove the patient's name from the photo?

Assume yes. De-identification under HIPAA has a specific standard, and full-face photographic images are explicitly listed among the identifiers that must be removed to meet it. A face is not anonymous simply because the file name is.

Can I use a general-purpose AI chat tool to preview a patient's smile?

Not on a standard consumer plan with no BAA in place. It is one of the more common quiet violations in dental practices right now, usually well-intentioned, and it puts identifiable patient images into a service that never agreed to protect them.

What should I keep on file for a vendor?

At minimum: the executed BAA, the subprocessor list, a written answer on retention and model training, and a dated note recording how and when you evaluated the vendor. That last one is the piece most practices skip, and it is exactly the piece the proposed rule leans on.

Is the new HIPAA Security Rule in effect yet?

No. As of August 2026 it remains a proposed rule with no final action published, and the current agenda pushes final action into 2027. Treat it as direction of travel, not a compliance deadline.

The short version

Collect the BAA. Then ask the five questions, write down the answers, and keep them. It is a ten-minute habit that scales down to a solo practice and holds up if the rules tighten.

Smile PreVue was built for the chair: an iPad, no extra hardware, more than 20 VITA shades, about ten minutes to set up, with patient PHI under a BAA on Google Vertex AI from the first photo. You can start a 3-day free trial and put it through the same five questions we just handed you.

HIPAAAI in dentistrypractice operations