HIPAA NOTICE
VERSION 1.0 LAST UPDATED: Sep 10, 2026
LLM API Inc. (“LLM API,” “Spendbase,” “we,” “us,” or “our”) provides an AI model routing and gateway service (the “Service”) as described in our Terms of Use. This notice explains how the U.S. Health Insurance Portability and Accountability Act of 1996, as amended (“HIPAA”), applies — and does not apply — to your use of the Service.
WE ARE NOT A HIPAA COVERED ENTITY OR BUSINESS ASSOCIATE
LLM API is not, by default, a “Covered Entity” or “Business Associate” as those terms are defined under HIPAA (45 C.F.R. § 160.103). A formal Business Associate Agreement is not part of our standard Terms of Use. If your organization’s use case requires PHI processing, we’re open to discussing your specific requirements — please contact us at [email protected] to explore whether any arrangement can be made. Discussing your requirements does not guarantee that any such arrangement will be offered. Absent our prior written approval, the Service is not configured, audited, or certified to support the processing, storage, or transmission of Protected Health Information (“PHI”)
DO NOT SUBMIT PHI WITHOUT A PRIOR WRITTEN APPROVAL
You must not submit, transmit, or otherwise process any PHI through the Service unless you have first received our prior written approval expressly authorizing that use. In the absence of such written approval:
- any PHI submitted to the Service is submitted entirely at your own risk;
- we disclaim all liability for any resulting non-compliance with HIPAA or any other applicable health data protection law; and
- this is in addition to, and does not limit, the disclaimers and limitations of liability set out in our Terms of Use.
A violation of this Notice constitutes a violation of our Terms of Use, including the indemnification obligations set out therein.
THIRD-PARTY AI PROVIDERS
The Service routes your requests to independent Third-Party Providers (including, but not limited to, Azure OpenAI, AWS Bedrock, and Google Vertex AI, as listed at llmapi.ai/models). Some of these providers may separately offer HIPAA-eligible services or their own BAAs directly to their enterprise customers, under those providers’ own agreements. Any such arrangement exists solely between you and that provider — it does not extend to, or apply through, your use of the Service, and we make no representation as to whether routing requests to a given provider through the Service qualifies as HIPAA-eligible processing.
IF YOU ARE SUBJECT TO HIPAA AND WANT TO USE THE SERVICE
If you are a Covered Entity, a Business Associate, or otherwise subject to HIPAA, and you wish to use the Service to process PHI, you are solely responsible — before submitting any PHI — for:
- Reviewing our Data Processing Agreement (available at llmapi.ai/dpa) to independently assess whether the technical and organizational measures described there meet your compliance obligations. For the sake of clarity, our DPA is designed to address obligations under the EU General Data Protection Regulation and other applicable data protection laws; it does not itself constitute, guarantee, or represent compliance with HIPAA or the HIPAA Security Rule.
- Contacting our representative or our privacy team at [email protected] if additional or different arrangements are required for your specific use case.
- Not submitting any PHI through the Service unless and until you have completed the above assessment and our prior written approval, if required, has been obtained.