What is a BAA HIPAA and why Brauni signed one with Google Cloud and AWS

If you use clinical software, you'll probably ask yourself: what about my data when it's "in the cloud"? Who's responsible if something goes wrong? The software provider? The infrastructure provider?
These questions have a specific legal answer in the health world: the Business Associate Agreement, or BAA. In this article we explain to you what it is and why the fact that Brauni has signed this agreement with the world's two largest cloud providers (Google Cloud and AWS) raises the standard of protection for your patients' data.
What is HIPAA?
HIPAA (Health Insurance Portability and Accountability Act) is the U. S. federal law that sets the global gold standard for health data protection. It defines the PHI (Protected Health Information), which includes names, diagnoses, and session notes - basically everything a health professional handles on a daily basis.
Note
Although Brauni complies with the 25.326 Personal Data Protection Act in Argentina, we adopt HIPAA because its technical controls are much more rigorous for clinical practice.
What is a BAA?
It is a legally binding contract required by HIPAA. It is not a generic "term and condition." It is a commitment where the infrastructure provider (Google or AWS) accepts legal liability on:
- Encrypt data at all times
- Do not use the information for advertising or own analytics
- Report any security incidents immediately
- Allow constant audits of your data centres
What if there's no BAA?
Without an BAA, the infrastructure provider has no specific legal obligation on the health data it stores. It may use the data for its own purposes, not report a security breach, or fail to implement the controls that HIPAA requires.
In practice, most generic cloud services don't sign BAAs. are only providers that offer specific services for the health sector and are willing to take on that legal responsibility.
Important
Not all clinical software providers have a BAA with their infrastructure provider. Before entrusting your data to any platform, ask: do they have a signed BAA? If the answer is no or do not know what it is, it is an important warning signal.
Why do we sign with Google Cloud and AWS?
At Brauni we do not leave security at random. Our infrastructure is hybrid and redundant, taking advantage of the best of each provider:
AWS (Amazon Web Services)
AWS is the operating heart of Brauni: the databases are hosted here, the application is executed and multi-region storage backups are maintained within the United States. By signing the BAA with AWS, we ensure that each clinical record is under specific legal protection for health data.
Google Cloud (Vertex AI)
This is where the magic of our artificial intelligence occurs. Thanks to BAA, we use advanced models (such as Gemini) with the assurance that your data never used to train global models from Google.
Benefits of our two-way partnership
Military grade encryption
Both providers use AES-128 for saved data and TLS 1.3 for data in transit. This automatically applies to all services that Brauni uses, including databases, file storage, and communications between services.
Controlled Data Residence
We control exactly where the information lives, ensuring that it does not move without our permission. We can choose the specific geographic region where the data is stored in both providers.
Zero AI training with your data
This is the most critical point. Both Google’s BAA and AWS’s explicitly prohibit the use of your clinical information to power their public algorithms. In addition, our terms and conditions expressly establish it: neither Brauni nor its infrastructure providers will process, use or analyze clinical or personal data for the training of AI models. Brauni has its own policy of not using clinical data to train AI, which applies independently of BAA.
The full chain of responsibility
When using Brauni, each part has a defined role:
- Professional is the controller of the data: responsible for the consent, ethics and configuration of the access controls in your account
- Brauni acts as a data processor: responsible for the application, field-by-field encryption and security logic, processing information only according to professional instructions
- AWS and Google Cloud provide physical and digital infrastructure where the data reside, under BAA contract
Each link has specific legal obligations. There are no grey areas or "good will": there are contracts.
What does this mean to you?
It means that your clinical data is protected by contract across the chain, not just by promises. If a provider does not sign a BAA, it may legally have no specific obligations on the health data it stores. With Brauni, that does not happen.
We choose the world's leaders in infrastructure and formalize the relationship with the most stringent agreements that exist because we understand that your patient's trust is your most valuable asset.
Do you have any doubts about how we protect privacy? Write to soporte@brauni.io. We are here to give you peace of mind.
Free Brauni test for 30 days, no card
Automatic session notes, digital medical records and more.
Start for freeBrauni complies with the principles of Argentina's Personal Data Protection Act 25.326 and is aligned with the international standards of HIPAA for the management of protected health information (PHI). BAA with Google Cloud and AWS cover all services used to process clinical data.
Related articles

Privacy and Security
What is Patient Privacy Monitoring and why any health app should have it
Encrypting clinical data is not enough. We explain what Patient Privacy Monitoring is (UEBA applied to health), why HIPAA demands it, and how Brauni detects suspicious access to medical records in real time.

Privacy and Security
Where your patient data is stored and why we chose AWS
We show you exactly where your patients' clinical data live in the AWS cloud, the world's largest and most secure infrastructure, and why that matters to your practice.

Privacy and Security
Security and privacy in Brauni: how we protect your patients' data
Meet the 15+ safety layers that Brauni uses to protect your patients' clinical information: military encryption, multifactor authentication, and more.