WritingCohereCoherepublished Nov 13, 2025seen Jun 26

Hipaa Business Associate Agreements For Custom Model Development

Open original ↗

Captured source

source ↗

North Mini Code. Cohere's first model for developers.

Learn more

Nov 13, 2025

2 minutes read

HIPAA Business Associate agreements for custom model development

We are pleased to offer a HIPAA-compliant Business Associate agreement (BAA) to enable customers across the healthcare industry to work with us to develop secure custom models that meet their specific business needs.

!Blog Post Featured Image

For healthcare providers, insurers, and technology partners, compliance is not just a legal requirement, it’s a cornerstone of trust and reliability. That’s why we at Cohere are pleased to offer a HIPAA-compliant Business Associate agreement (BAA) to enable customers across the healthcare industry to work with us to develop secure custom models that meet their specific business needs.

##### What is HIPAA?

The Health Insurance Portability and Accountability Act (HIPAA) sets federal standards in the United States for protecting personal health information (PHI). It applies to covered entities like insurance companies, doctors, and clinics who directly collect and handle PHI to provide healthcare services to individual patients or clients. It also applies to “Business Associates,” like technology providers, that need to use or disclose PHI in order to perform services on behalf of HIPAA-regulated entities.

##### Steps to setting up a BAA with Cohere for custom model development

1. Contact your dedicated Account Executive or [support@cohere.com](mailto: support@cohere.com) to discuss your use case. 2. After a review of the use case, HIPAA-related compliance checks, and an agreement on commercial matters, Cohere will provide a BAA that covers the custom model development process and the transmission of HIPAA-regulated data to Cohere for the purpose of developing a custom model on your behalf. 3. Once the custom model is developed, it is deployed in your own private deployment environment.

##### Benefits of LLM customization with Cohere

  • Robust security measures: Our infrastructure is designed with multiple layers of security, including encryption, access controls, and regular audits
  • Data protection: We implement strict protocols to ensure that PHI is handled, stored, and transmitted securely
  • Compliance monitoring: Continuous monitoring and updates ensure ongoing adherence to HIPAA regulations

Learn more about Cohere’s customization offerings.

##### Other Cohere offerings for HIPAA-regulated entities

  • Private deployments: All private deployments without customization, including private deployments of North and Cohere models, are suitable for HIPAA-regulated entities. No BAA is required with Cohere as Cohere does not use or receive PHI (or any other customer data) for this type of deployment.
  • Managed cloud LLM/AI platforms: Cohere’s models hosted or accessed through cloud AI platforms (e.g., Amazon Bedrock, Amazon SageMaker, Microsoft Azure, and OCI Generative AI Service) are suitable for HIPAA-regulated entities. Customers must request to enter into a BAA with the cloud service provider and would be subject to the provider's own internal review and checks. For more information, we recommend reaching out directly to the third-party providers of interest. No BAA is required with Cohere as Cohere does not use or receive PHI (or any other customer data) for this type of deployment.

At this time, Cohere does not offer a BAA for Cohere-hosted products and applications, such as Cohere's SaaS platform, so these offerings are not suitable for HIPAA-regulated entities.

##### Conclusion

Cohere’s offerings for HIPAA-regulated entities reflect our continued commitment to meeting high standards of data security and supporting healthcare organizations in their mission to deliver innovative, data-driven solutions while safeguarding privacy.

To explore our full approach to secure AI, governance, and enterprise readiness, visit our Trust Center.

Notability

notability 5.0/10

Substantive post on HIPAA compliance for custom models.