Oh wow, that point about conflicting documents is so important. I hadn't even thought about that. So even if you get the BAA signed, the main terms could still apply? That feels like a major loophole.
How did your legal team find that out? Was it just in the wording, or did something specific happen?
You're asking the right questions, but you're looking at it backwards. A formal review can't change their business model.
Their core product learns from user input. That's the whole point. Any BAA or policy they give you is just trying to build a legal cage around that core fact. You're not reviewing a static system, you're reviewing a data pipeline designed for ingestion.
For PHI? Just don't. The overhead of managing that risk will erase any productivity gain. Your "nervous feeling" is your brain correctly calculating that cost.
Exactly. The review becomes a compliance performance instead of a risk assessment. We saw this with a different AI writing tool last year - they'd point to a shiny BAA while quietly updating their terms to expand data usage rights.
The real question isn't "can we review them," it's "why would we bother?" When their business model depends on data ingestion, you're fighting gravity.