PHI and Caspio AI: What Your Updated BAA Now Covers

October 1, 2026

If your Caspio account is on the HIPAA Edition and under the updated Business Associate Agreement (BAA), protected health information (PHI) may be used in Caspio’s HIPAA-eligible AI features: Caspi, the in-app Chat AI Agent, and the AI Connector Extensions (OpenAI GPT, Google Gemini, and Anthropic Claude). Caspio holds the signed agreements with the AI providers. The only BAA you sign is with Caspio.

For those accounts, that includes file and knowledge-base uploads in the covered features, within the providers’ HIPAA-eligible endpoints under Caspio’s signed provider agreements. If you were told earlier to keep PHI out of AI uploads, that guidance was correct at the time, but it has changed for HIPAA Edition accounts under the updated BAA. The Caspio MCP Server and Customer-Controlled AI Connections sit outside the BAA.

This article explains what Caspio’s agreements and features cover. It is not legal advice; your counsel and compliance officer make the call for your organization.

What Changed in Caspio’s Updated BAA?

Caspio has released an updated customer BAA that adds provisions for AI. Under the updated BAA that comes with the HIPAA Edition, PHI may be used in Caspio’s HIPAA-eligible AI features, including file and knowledge-base uploads, within the providers’ HIPAA-eligible endpoints under Caspio’s signed provider agreements. The earlier guidance was to keep PHI out of those uploads.

What did not change: your applications work the way they did, and the platform safeguards, including role-based access, encryption, and audit logging, apply to AI work just as they do to everything else in your account. The platform is independently audited annually for HIPAA, SOC 2 Type II, and GDPR.

The updated BAA text, including Amendment No. 1 (AI Provisions), is the source of truth for exact scope. It is published at caspio.com/legal/baa and was last updated July 31, 2026. Ask your compliance officer to read it. If your account is already on the HIPAA Edition, the updated BAA applies to it automatically, through Caspio’s Terms of Service. Your account manager can confirm this for your records. If anything in this article reads differently from the BAA text, the BAA governs.

Which Caspio AI Features Are Covered for PHI, and Who Holds the Agreements?

Caspio’s HIPAA-eligible AI features operate under signed Business Associate Agreements. For accounts on the HIPAA Edition, the covered capabilities are:

  • Caspi, Caspio’s AI application builder.
  • The Chat AI Agent, a chat capability you add to your applications for your end users. It answers from your app’s data or its own knowledge base, and it is governed by role and field-level security.
  • All three AI Connector Extensions: OpenAI GPT, Google Gemini, and Anthropic Claude.

These agreements are between Caspio and the providers behind each capability. You sign only one BAA, with Caspio, which is included with the HIPAA Edition, a one-year HIPAA add-on to your plan. You do not negotiate with or hold an agreement with any AI provider for these capabilities.

In HIPAA terms, the chain has three links. You are the covered entity or business associate. Caspio is your business associate. The AI providers sit behind Caspio as its subcontractors, under agreements Caspio holds. The rules provide for exactly this: a business associate may allow a subcontractor to handle PHI on its behalf, provided that the business associate obtains satisfactory assurances that the subcontractor will appropriately safeguard it (45 CFR 164.502(e)(1)(ii)).

For a general explainer of the chain, see What a BAA Actually Covers (and What It Doesn’t).

Diagram of three parties in a row: your organization, Caspio, and AI providers. One link joins your organization to Caspio, labeled your BAA with Caspio, the only one you sign. A second link joins Caspio to the AI providers, labeled Caspio's signed Business Associate Agreements. No link joins your organization to the AI providers. A panel under the second link lists what Caspio's agreements cover for HIPAA Edition accounts: Caspi, the Chat AI Agent, and the AI Connector Extensions OpenAI GPT, Google Gemini, and Anthropic Claude. A separate dashed zone shows the Caspio MCP Server and Customer-Controlled AI Connections outside the BAA.

WHO SIGNS WHAT: Your organization signs one BAA, with Caspio. Caspio holds the signed agreements with the AI providers. The Caspio MCP Server and Customer-Controlled AI Connections sit outside the BAA and ship disabled by default.

Caspio AI features covered by Caspio’s agreements for HIPAA Edition accounts, and AI tools and connections outside the agreements
Covered by Caspio’s agreements
(HIPAA Edition accounts)
Outside the agreements
Caspi Caspio MCP Server
The Chat AI Agent Customer-Controlled AI Connections
AI Connector Extensions: OpenAI GPT, Google Gemini, Anthropic Claude Consumer AI tools, such as the ChatGPT app
Your own AI provider account, if you connect one

Which AI Tools and Connections Are Outside Caspio’s BAA?

Three things sit outside Caspio’s agreements: the Caspio MCP Server and Customer-Controlled AI Connections, consumer AI tools such as the ChatGPT app, and any AI provider account you connect yourself.

The Caspio MCP Server and Customer-Controlled AI Connections. The Caspio MCP Server connects your Caspio account to AI assistants such as ChatGPT and Claude. It and Customer-Controlled AI Connections are outside every BAA Caspio holds, and they ship disabled by default. If you enable them, each API profile has no access until you grant it, table by table, view by view. For patient data, use the covered capabilities inside the HIPAA Edition: Caspi, the Chat AI Agent, and the AI Connector Extensions. Customer-Controlled AI Connections is the updated BAA’s own term; read the BAA text for what it includes.

Consumer AI tools. Consumer products such as the ChatGPT app are separate from the AI services that power Caspio’s AI features, and nothing Caspio signs covers them. A staff member pasting PHI into a consumer chatbot is outside this entire arrangement.

Your own AI provider connection. Connecting your own AI provider is an optional path, never a requirement. If you choose it, that connection sits under your organization’s own agreement with that provider, not under Caspio’s.

What Stays Your Responsibility When You Use PHI With Caspio AI?

When you use PHI with Caspio’s AI features, responsibility for four areas remains with your organization: your BAA with Caspio, access controls and roles, minimum-necessary choices, and your policies, risk analysis, and training. Caspio’s agreements cover Caspio’s side of the chain.

  1. Your BAA with Caspio. Without the HIPAA Edition and the updated BAA in place for your account, nothing in this article applies to it.
  2. Access controls and roles. The Chat AI Agent is governed by role and field-level security, and you configure both.
  3. Minimum-necessary choices. HIPAA asks you to make reasonable efforts to limit PHI to the minimum necessary for the intended purpose (45 CFR 164.502(b)(1)). AI Connector Extensions send only the fields you configure to the model you choose, so configure only what the task needs. Apply the same judgment to any information you place in a knowledge base.
  4. Policies, risk analysis, and training. The Security Rule requires an accurate and thorough assessment of risks to electronic PHI (45 CFR 164.308(a)(1)(ii)(A)) and a security awareness and training program for your whole workforce (45 CFR 164.308(a)(5)(i)). Turning on AI features changes how PHI is used in your environment, so reflect it in both, and in your written policies.

A HIPAA Checklist Before You Turn on Caspio AI for PHI

Use this checklist to confirm your account, safeguards, and internal policies are ready before using Caspio AI with PHI.

  1. Confirm the HIPAA Edition is active on your account. If it is, the updated BAA applies to it.
  2. Have your compliance officer read the AI provisions in the published BAA.
  3. Add the AI features you plan to use to your risk analysis.
  4. Decide which covered capabilities you will use, and keep PHI work on those.
  5. Leave the Caspio MCP Server and Customer-Controlled AI Connections off for anything that touches PHI. They ship disabled; keep them that way.
  6. Apply minimum necessary. Send only the fields a task needs to an extension, and review documents before they go into a knowledge base.
  7. Review roles and field-level security for every user group that will reach an AI feature.
  8. Update written policies and train staff, including the rule against putting PHI into consumer AI tools.

Frequently Asked Questions

Can we use PHI with Caspio's AI features?

Yes, for accounts on the Caspio HIPAA Edition under the updated BAA. PHI may be used in Caspio’s HIPAA-eligible AI features: Caspi, the Chat AI Agent, and the three AI Connector Extensions (OpenAI GPT, Google Gemini, and Anthropic Claude). Caspio holds the signed agreements with the AI providers behind those features. The Caspio MCP Server and Customer-Controlled AI Connections are outside the BAA.

Can we upload patient documents to an AI knowledge base in Caspio?

Yes, for HIPAA-covered accounts. Under the updated BAA that comes with the Caspio HIPAA Edition, PHI may be used in Caspio’s HIPAA-eligible AI features, including file and knowledge-base uploads, within the providers’ HIPAA-eligible endpoints under Caspio’s signed provider agreements. Limit what you add to what is necessary for the intended purpose. Your compliance officer can read the exact scope in the BAA text; it is published at caspio.com/legal/baa.

Do we need our own BAA with OpenAI, Google, or Anthropic?

No, not for Caspio’s HIPAA-eligible AI features. The only BAA you sign is with Caspio, and it comes with the HIPAA Edition. Caspio holds the signed agreements with the AI providers, covering Caspi, the Chat AI Agent, and all three AI Connector Extensions. You do not negotiate with OpenAI, Google, or Anthropic.

Is the Caspio MCP Server covered by the BAA?

No. The Caspio MCP Server and Customer-Controlled AI Connections are outside every BAA Caspio holds and ship disabled by default. If you enable them, each API profile has no access until you grant it, table by table, view by view. For patient data, use the covered capabilities inside the HIPAA Edition: Caspi, the Chat AI Agent, and the AI Connector Extensions.

Is ChatGPT covered by Caspio's BAA?

No. The consumer ChatGPT app is not covered by any agreement Caspio holds. Neither is an AI assistant such as ChatGPT or Claude that you connect to your account through the Caspio MCP Server. Caspio’s AI features run on OpenAI’s API under a signed BAA. That is the API under contract with Caspio, not the consumer ChatGPT product. For HIPAA Edition customers, Caspio’s agreements with the providers cover Caspi, the Chat AI Agent, and all three AI Connector Extensions.

How do we get detail on data retention and model training?

Retention is governed operationally under the BAAs, and Caspio does not publish a retention configuration. Caspio’s compliance team can walk your compliance officer through retention and training-use detail. Ask your account manager or Caspio Support to arrange that conversation.

Before You Turn on AI For PHI

Talk to your account manager or Caspio Support before you turn AI on for PHI workloads. Confirm the HIPAA Edition is active on your account, have your compliance officer read the BAA text, and discuss any remaining scope questions with Caspio. For the wider picture, see Caspio’s compliance overview.

Call to Action Block Call to Action Block

Recommended Articles

AI software discovery banner

How AI Agents Buy Software, and Why Legibility Wins

READ STORY
10 Questions to Ask Before Connecting AI Banner

10 Questions to Ask Before Connecting AI to Business Data

READ STORY
Caspio AI Chat Agent banner

Add a Role-Aware AI Chat Agent to Your Caspio App

READ STORY
Best AI Tools for Internal Business Apps Banner

Build Internal Tools With AI: Best Tools for Business (2026)

READ STORY

Vibe Coding vs. Low-Code: Key Differences and Where Caspio Fits in 2026

READ STORY
Lovable Alternatives Banner

Lovable Alternatives for Business and Regulated Apps (2026)

READ STORY

Vibe Coding Governance: The IT Leader’s 2026 Checklist

READ STORY
Shadow AI Apps Banner

Shadow AI Apps Are the New Shadow IT: A 2026 Guide

READ STORY

Code Artifact vs. Governed Platform: The Two Architectures

READ STORY
AI App Builders for Regulated Industries Banner

AI App Builders for Regulated Industries: 2026 Buyer's Guide

READ STORY

Secure Alternatives to Vibe Coding for Business Apps (2026)

READ STORY
AI & No Code Banner

AI and No-Code: Generative AI in App Development

READ STORY
Subscribe for More Updates