Provider comparisons
OpenMed Router vs OpenRouter: HIPAA, Model Access, and Price
OpenRouter signs no HIPAA business associate agreement, by its own statement. How it compares to a BAA-backed open source inference API on price and access
TL;DR
OpenRouter does not offer a HIPAA business associate agreement, by its own published statement - so it cannot carry PHI regardless of its Zero Data Retention controls. If your workload never touches PHI, use it; if it does, you need a BAA-backed API.
If you are building a clinical product, it's common to ask 'What routing options are available to me?'. OpenRouter is the obvious first stop - one API across hundreds of models. Then you look at whether PHI can go through it, and the answer changes your architecture.
Here is a direct comparison.
What OpenRouter actually offers
OpenRouter is a routing layer rather than an inference host. You send an OpenAI-compatible request, it selects a provider, and it returns the result.
- Breadth. 500+ models across 80+ providers on the paid plans, plus 25+ free models on the free tier.
- Routing controls. Automatic provider failover, opt-in model fallback chains, and preferred vendor selection.
- Spend governance. Per-key limits, guardrails, and workspace budgets, with the deeper controls gated to higher plans.
- One unified API. A single integration, with the model swapped by parameter.
For a non-regulated workload this is a strong product, and the free tier is the fastest way to test an idea.
The BAA question
This is the part that decides healthcare use cases. From OpenRouter's own post on team AI spend:
We're SOC 2 Type 2 compliant but don't offer a HIPAA business associate agreement (BAA), so a health-data workload that needs a BAA isn't a fit for that specific requirement today.
It is worth reading in full, but that sentence is a deal-breaker for most healthcare organizations. HIPAA requires a BAA before a vendor handles PHI. No BAA means no PHI, which means no clinical workload.
Zero Data Retention is not a BAA
This is the most common confusion we see, so it is worth separating cleanly.
OpenRouter does offer Zero Data Retention controls. Their ZDR documentation states you can enforce ZDR globally, per model group, per guardrail, or per request. It also notes that some endpoints do not train on your data but do retain it, for example to scan for abuse or for legal reasons.
Zero Data Retention is a data-handling property. A BAA is a legal instrument that makes a covered entity and a downstream vendor business associates under HIPAA. They are not substitutes. You can have careful retention controls and still be unable to put PHI through a service.
What a BAA changes in practice
A BAA is not paperwork for its own sake. It converts an informal data relationship into a contractual one: the vendor becomes a business associate with defined obligations under the Security Rule, covering access controls, audit logging, and how PHI is handled and destroyed. It also gives you a named counterparty if something goes wrong.
On our side that means zero-retention isolated inference, AES-256 encryption in transit and at rest, and audit trails you can hand to a security reviewer.
Pricing
OpenRouter spans 500+ models across 80+ providers on its paid plans, with 25+ free models on the free tier.
OpenMed Router publishes per-token rates for the open source catalog:
| Model | Input $/M | Output $/M | Context |
|---|---|---|---|
| GLM-5.3-Flash | $0.15 | $0.50 | 1,048,576 |
| DeepSeek-V4-Flash-Vision-Exp | $0.14 | $0.28 | 1,048,576 |
| DeepSeek-V4.1-Flash | $0.30 | $1.20 | 1,048,576 |
| MiniMax M3 | $0.30 | $1.20 | 512,000 |
| Qwen3.8-27B | $0.80 | $4.00 | 262,144 |
| DeepSeek-V4-Pro | $1.32 | $3.96 | 1,048,576 |
| GLM-5.3 | $1.40 | $4.40 | 1,048,576 |
| Kimi K3 | $3.00 | $15.00 | 1,048,576 |
Our own comparison puts closed-source inference on Azure OpenAI and Bedrock at roughly $30 per million tokens against roughly $3 per million for open weights, a gap of up to about 10x. Treat any vendor cost comparison as directional: your real number depends on your mix of input, output, and cached tokens.
Where OpenRouter is the better choice
- Your workload never touches PHI. Internal tooling, documentation, marketing copy, code generation. No PHI means no BAA is needed, and OpenRouter's breadth is hard to match.
- You need closed-source frontier models today. Proprietary models are coming soon to OpenMed Router (we've had a surprising number of requests for this!), but if you need GPT or Claude without HIPAA-compliance this week, OpenRouter already routes to them.
- You want to prototype for free. The free tier is the cheapest way to test an idea.
- You need a long tail of niche models or providers.
Where a BAA-backed API is the better choice
- Anything clinical. Patient messaging, summarization, coding support, prior authorization, or retrieval over records - all of it is PHI handling.
- You specifically want an on-prem solution. Our AI inference experts can help set you up with on-prem systems, delivering local LLMs airgapped from the outside world (e.g for biotech companies or healthcare orgs who are super cautious about sensitive data).
- You want one compliance surface. One BAA, one retention posture, one audit trail, instead of a chain of subprocessors to document for your security review.
The decision rule
Ask one question first: will PHI ever appear in the prompt or the response?
If no, OpenRouter might be a better fit. If yes, you need a BAA before anything else, and OpenRouter is not an option for that workload.
This is the gap OpenMed Router exists to fill: the same unified-API pattern, with a signed BAA, zero-retention isolated inference, and AES-256 encryption in transit and at rest. The HIPAA compliance guide covers what a valid AI BAA has to mandate, and the model catalog lists every model currently available.
Ready to put open source models under your BAA? Join the waitlist now.
Chris Williams, MD
Chris Williams, MD is a physician, clinical AI researcher and the co-founder of OpenMed Router, working to make open source AI models safely accessible to healthcare organizations under HIPAA. He writes about clinical AI, model selection, compliance, and the practical adoption of open source inference in clinical and operational workflows.
Join the waitlist