October 6, 2026

OpenAI API BAA is now self-serve: what it covers and what you still owe

OpenAI added an in-console BAA flow on 5 October. What the API BAA covers, the Modified Retention condition, and the compliance work left to you.

News

OpenAI's standard API BAA can now be accepted through a click-through flow instead of a sales conversation. OpenAI's developer changelog lists, under 5 October 2026, an in-product flow for HIPAA compliance support in the API organization settings. If you're a US healthtech team with protected health information (PHI) anywhere near your prompts, the OpenAI API BAA is now something an eligible org admin can accept in the console. Signing it is the easy half, though. Everything below is what OpenAI's pages said on 6 October 2026, and those pages change.

What changed on 5 October

An eligible organization can accept the standard Business Associate Agreement (BAA) inside the API Platform. OpenAI's Help Center page on the API BAA opens with the rule: "To use the OpenAI API with protected health information (PHI), your organization must first enter into a Business Associate Agreement (BAA) with OpenAI." Completing the flow, it says, enables HIPAA compliance support for the selected organization.

You don't need a big contract for it. The same page states: "An enterprise agreement is not required to sign a BAA for API services."

If the standard terms don't fit, custom terms go through baa@openai.com, and the page says the team responds within 1-2 business days. It also says not to put PHI in those emails, screenshots or attachments. Custom BAAs aren't downloadable from the settings screen.

Who can sign today

Two gates. The first is people: you must be an organization admin with permission to manage organization settings and the authority to accept the agreement for your company. That's a legal-authority question, not a permissions toggle, so decide who that is before you open the page.

The second is usage. The page says self-serve enrollment "requires an established history of API usage." If the BAA section reads "Not eligible yet," your organization doesn't meet the requirements for the self-serve route. The page doesn't say how much history counts, so don't plan around a number. If you don't qualify, the page's other route is the manual request process through baa@openai.com.

One more fact to read before you click: "Once HIPAA compliance support is enabled for your organization, you cannot disable it in the API Platform settings."

What the API BAA covers

The BAA alone doesn't make the API eligible. OpenAI's page on HIPAA-eligible products says HIPAA eligibility for the API "is contingent on Customer's account being provisioned with Modified Retention, unless otherwise specified by OpenAI." Once your org ID has it, the listed endpoints "can be used for processing PHI, even if data is retained, upon execution of the OpenAI BAA." The eligible products are named "API with Modified Retention" and "API FedRAMP with Modified Retention."

The endpoints on the list:

  • Text and reasoning: /v1/chat/completions, /v1/responses, /v1/completions, /v1/moderations, /v1/embeddings
  • Stateful objects: /v1/assistants, /v1/threads, /v1/threads/messages, /v1/threads/runs, /v1/threads/runs/steps (all Assistants API, which OpenAI's changelog says shut down on 26 August 2026), and /v1/vector_stores
  • Files and training: /v1/files, /v1/fine_tuning/jobs, /v1/batches
  • Images: /v1/images/generations, /v1/images/edits, /v1/images/variations
  • Audio and live: /v1/audio/transcriptions, /v1/audio/translations, /v1/audio/speech, /v1/realtime, /v1/live/sessions

If you're building on /v1/responses, our walkthrough for building an AI feature on the Responses API covers the mechanics. It says nothing about PHI, so treat the compliance side as separate work. One API-side exclusion matters here: the data controls documentation says web search with live internet access in the Responses API is not HIPAA eligible and is not covered by a BAA.

Codex running locally with an API key is covered only if your BAA includes the API with Modified Retention as an eligible service. The ChatGPT side is a different story: OpenAI's BAA page says "We do not offer a BAA for ChatGPT Business."

Modified Retention and zero data retention

Modified Retention is the part nobody gets from clicking Enable. OpenAI's BAA and HIPAA guide defines it as an umbrella for four arrangements: Modified Abuse Monitoring, Zero Data Retention, Safety Retention and Eyes Off. It says your account console must show a Modified Retention feature active for the org ID and project before you send HIPAA input, that each org ID needs it separately, and that OpenAI may choose which of the four applies.

OpenAI's data controls documentation describes the approval step. Abuse-monitoring controls and Zero Data Retention are currently subject to OpenAI's prior approval and extra requirements, and you contact sales to ask. The default, for context, is abuse-monitoring logs kept for up to 30 days unless the law or a safety need calls for longer. Under Zero Data Retention, store is always treated as false on /v1/responses and /v1/chat/completions. We couldn't find a stated approval timeline, so budget for the wait as an unknown.

Here's where the two OpenAI pages look like they disagree, and we won't resolve it for you. The HIPAA page lists /v1/vector_stores, /v1/files, /v1/fine_tuning/jobs and /v1/batches as endpoints that can process PHI (it also still names the Assistants endpoints, which are shut down). The data controls documentation doesn't put conversations, agents, vector stores, files, fine-tuning jobs or batches (or the Assistants endpoints) on its Zero Data Retention eligible list, and marks their application state as kept until deleted. The HIPAA page's own wording, "even if data is retained," suggests the two aren't contradicting each other: HIPAA eligibility and ZDR eligibility are separate lists. That's a reading, not OpenAI's statement. One more wrinkle: the data controls table marks only /v1/chat/completions and /v1/responses as eligible under Safety Retention and Private Retention with Private Safety Processing, and says its endpoint limitations still apply to PHI use under those. The HIPAA guide says OpenAI may choose which Modified Retention feature applies to you, so which one you get can change the list you can actually use. So the claim that the BAA covers only ZDR endpoints is wrong per OpenAI's HIPAA page. Check your own endpoint choices against your signed BAA, not against either page.

What remains your job

The Help Center page is blunt: "Accepting a BAA and enabling HIPAA compliance support do not, by themselves, make your application HIPAA compliant. You are responsible for evaluating your use of the services and meeting your compliance obligations."

The HIPAA guide spells out what that means: customer-side SSO, device security, monitoring, backups and authorization of end users. Its general section also says no PHI in support requests or screenshots, no accounts created for patients, and no use of the services as a designated record set. The ban on PHI in user profiles and workspace names sits in its ChatGPT section. The ChatGPT sections of OpenAI's pages carry a list of features not automatically covered, and that list is about ChatGPT, not the API. Whether your design satisfies HIPAA is for your counsel to decide, not for a blog post or the vendor's checkbox.

How to enable the BAA in the API Platform

These seven steps follow the Help Center page. Do them as the admin who has authority to sign.

1. Select your organization

Pick the organization that will handle PHI. The flow enables HIPAA compliance support for the selected organization.

2. Open the organization settings

Go to Settings > Organization > General.

3. Start the HIPAA flow

Under HIPAA compliance support, select Enable. If the section says "Not eligible yet," your organization doesn't meet the self-serve requirements. The page offers no self-serve fix; the other route it describes is the manual request at baa@openai.com.

4. Download and review the addendum

Download the Business Associate and Healthcare Addendum and have counsel read it. The flow asks you to confirm you've reviewed it, so do that for real.

5. Review the coverage

Read what the flow says is covered, and compare it to the endpoints you actually call.

6. Confirm your authority

Confirm that you have authority to accept the agreement and that you've reviewed it and understand its coverage.

7. Confirm the org and agree

Check the organization name and Organization ID, then select "Agree and enable." The section should then show "Active." Remember there's no disabling it from these settings afterwards.

EU teams

HIPAA is US law, and a BAA says nothing about GDPR. What the data controls documentation does say is that data residency outside the United States requires approval for abuse monitoring controls and a Modified Retention amendment. Regions listed include Europe (EEA and Switzerland), the United Kingdom, Canada, Australia, Japan, India, Singapore, South Korea and the United Arab Emirates. If EU personal data flows to a US vendor, the transfer paperwork is a separate question, and our explainer on the IDTA versus EU SCCs is a starting point. Which obligations apply to you is a question for your counsel.

What this means for your healthcare AI roadmap

The decision isn't "sign the BAA or not." It's whether to put PHI through the OpenAI API at all, and which path gets you there. Standard BAA now is quick and needs no enterprise contract, but it's irreversible for that org and it isn't the full picture without Modified Retention, which needs OpenAI's approval. Custom terms take a conversation. Another vendor is a third path, and we haven't sourced any comparison, so we won't suggest one.

Our judgment: do the slow things first. Ask for Modified Retention approval, line up SSO, logging and backups, and have counsel read the addendum before anyone builds a PHI feature, not after the demo works. Treat approval time as unknown until OpenAI gives you a date. For other OpenAI and vendor changes with dates attached, see AI model releases and pricing: what changes for engineering teams.

FAQ

Does the OpenAI BAA make my app HIPAA compliant?

No. OpenAI's Help Center page says accepting the BAA and enabling HIPAA compliance support don't, by themselves, make your application compliant, and that you're responsible for evaluating your use and meeting your obligations.

Do I need an enterprise contract to get a BAA for the API?

No. The page states an enterprise agreement isn't required to sign a BAA for API services. You do need to be an organization admin with authority to sign, and for the self-serve route, an established history of API usage.

Can I use vector stores, files and batches with PHI?

OpenAI's HIPAA page lists /v1/vector_stores, /v1/files and /v1/batches among endpoints that can process PHI once your org has Modified Retention and the BAA is executed, even if data is retained. The data controls documentation doesn't list them as Zero Data Retention eligible. Those are different lists, so confirm against your signed BAA. The page also still lists Assistants and threads endpoints, but the Assistants API shut down on 26 August 2026.

Can I turn HIPAA compliance support off after enabling it?

Not in the API Platform settings. The Help Center page says once it's enabled, you can't disable it there.

Does ChatGPT Business get a BAA?

No. OpenAI's page says "We do not offer a BAA for ChatGPT Business." Sales-managed Enterprise and Edu plans go through sales.

Share this article

Author Image

HighCircl Editorial Team

The HighCircl editorial team writes about hiring software engineers, nearshore development, and engineering team building. Our articles draw on direct experience sourcing and placing senior developers across Poland, Hungary, Slovakia, Serbia, Slovenia, Romania, and Spain — and on candid conversations with the CTOs and engineering leads who hire them.

HighCircl is a nearshore engineering network that delivers matched candidate shortlists in 72 hours. Every piece of content we publish is informed by real engagement data: actual developer rates, real hiring timelines, and what separates engineering teams that scale cleanly from those that stall.

Take Me to the Experts

Access our network of industry-leading software engineers.

Start Now