Q: Can OpenMetal provide a BAA for HIPAA-covered workloads?
OpenMetal is HIPAA compliant at the organizational level. For workloads involving protected health information, OpenMetal may be able to sign a Business Associate Agreement (BAA) with covered entities on any OpenMetal infrastructure, regardless of deployment region; BAA availability is confirmed with the OpenMetal sales team.
Learn about confidential computing
The BAA covers OpenMetal’s role as a business associate in handling or processing PHI on behalf of a covered entity. It applies to bare metal dedicated servers, Hosted Private Cloud clusters, and GPU server deployments [Verify with the OpenMetal team]. Because the compliance is at the organizational level, customers in Los Angeles, Amsterdam, and Singapore can request a BAA even though those facilities do not hold HIPAA as a facility-operator certification.
Ashburn (NTT DATA VA1) is the only OpenMetal location where HIPAA is also a facility-operator certification, alongside SOC 1/2 Type II, ISO 27001, PCI DSS, and NIST 800-53 HIGH. Organizations that require both a BAA and a facility-level HIPAA certification in their risk assessment documentation should deploy in Ashburn. Los Angeles (Digital Realty LAX10) holds SOC 2, SOC 3, ISO 27001, and PCI DSS at the facility level; HIPAA coverage there is OpenMetal’s org-level compliance only.
To request a BAA, contact the OpenMetal team directly. BAA execution is a pre-deployment step for covered entities and should be completed before PHI is ingested into the environment.
Interested in OpenMetal Products?
Schedule a Consultation
Get a deeper assessment and discuss your unique requirements.

































