Is ChatGPT HIPAA Compliant? What a Clinic May (and May Not) Paste Into Each Plan
Disclaimer: This content is for educational purposes only and does not constitute medical, legal, or financial advice. CPT descriptions are original summaries — not official AMA text. Always verify billing and credentialing details with your payer. Read full disclaimer
Short answer: ChatGPT is not HIPAA compliant by default — but for the first time, OpenAI now sells versions that can be. The free and personal plans (Free, Go, Plus, Pro) cannot be used with patient information under any settings configuration, because OpenAI offers no Business Associate Agreement for them — and, notably, it excludes ChatGPT Business too. What OpenAI will sign a BAA for is a specific, short list: ChatGPT Enterprise (sales-managed accounts), its new ChatGPT for Healthcare product, ChatGPT for Clinicians, and its API with modified retention. Everything below is sourced from HHS's own guidance and OpenAI's current documentation — because most of what ranks for this question is out of date.
What Does HIPAA Actually Require Before You Paste Patient Data Into an AI Tool?
HIPAA's rule here is contractual, not technical. The U.S. Department of Health and Human Services' Office for Civil Rights (the regulator that enforces HIPAA) defines a business associate as "a person or entity that performs certain functions or activities that involve the use or disclosure of protected health information on behalf of, or provides services to, a covered entity." A vendor whose servers process your patients' information — which is exactly what happens when a chat message is sent to ChatGPT — fits that description. And before a clinic (a "covered entity," in HIPAA's terms) may disclose protected health information (PHI — anything that identifies a patient and relates to their health or care) to such a vendor, HHS says it must first obtain written assurances in a business associate contract, commonly called a BAA.
That's the whole test, in plain English: no signed BAA, no patient data — regardless of how good the tool is, how careful the clinician is, or which privacy toggles are switched off. The training opt-out in ChatGPT's settings changes what OpenAI does with your text; it does not change the fact that a third party received it without the contract HIPAA requires.
This is also why forum-lawyer folk wisdom on both sides misses the point. Practitioners in professional subreddits put it bluntly — "Running medical records through OpenAI is a big no no" (u/jackfrommo, r/Lawyertalk) — while others in the same thread report that "HIPAA compliant enterprise AI models" work fine for medical chronologies (u/litigationfool, r/Lawyertalk). Both are right, about different products. The question was never "is ChatGPT safe?"; it's "does this specific plan come with a BAA, and what does that BAA actually cover?"
Does ChatGPT Offer a HIPAA BAA? What OpenAI's Own Policy Says
Yes — narrowly, and more narrowly than most of the pages ranking for this question claim. OpenAI's current BAA policy says: "Only ChatGPT Enterprise or Edu customers that have a sales-managed account are eligible for a BAA for ChatGPT" — and it explicitly excludes ChatGPT Business. If you've read elsewhere that this tier offers BAA coverage, that is no longer what OpenAI's own documentation says. Note the routing, too: for a ChatGPT Enterprise or Edu BAA, the same page directs you to contact OpenAI's sales team, while the baa@openai.com address — where requests are reviewed "on a case-by-case basis" — is the channel for API BAA requests. Either way, a BAA is something OpenAI may sign with you, not a checkbox at checkout.
Beyond Enterprise, OpenAI now maintains an explicit list of HIPAA-eligible products: ChatGPT for Healthcare, ChatGPT for Enterprise with Regulated Workspace, ChatGPT FedRAMP, ChatGPT for Clinicians, and its API with modified retention. Two of those are new, healthcare-specific products:
- ChatGPT for Healthcare — "an enterprise version of ChatGPT built for clinicians, administrators, and researchers" in "a secure workspace designed to support HIPAA compliance," with a BAA, role-based access controls, data residency options, and a commitment that "content shared with ChatGPT for Healthcare is not used to train OpenAI's models." OpenAI's announcement names early partners including AdventHealth, Boston Children's Hospital, Cedars-Sinai, Stanford Medicine Children's Health, and UCSF — large health systems, which tells you who this product is priced and shaped for.
- ChatGPT for Clinicians — for individual clinicians, with what OpenAI describes as "a separate in-product BAA flow." Details beyond that sentence (price, exact feature set) aren't published in the pages we could verify, so treat this tier as promising-but-confirm-directly.
Two caveats even on the covered tiers. First, the same OpenAI page notes that not every feature is inside the BAA — some functionality is disabled by default and not covered when enabled, and OpenAI states that its BAA does not apply to running the Codex Local Client (a coding tool that executes on your own computers) on the customer's machines, or to third-party services that tool accesses. A BAA covers a defined scope, not everything with the logo on it. Second, for API users, OpenAI's enterprise privacy page states it can sign BAAs, offers zero data retention "for eligible endpoints if you have a qualifying use-case," and otherwise may retain API inputs and outputs "for up to 30 days" — and an enterprise agreement is not required for an API BAA. That last route matters for clinics whose PHI would flow through a vendor's software (a dictation tool, say) rather than a chat window: ask that vendor whose API sits underneath and whether a BAA chain exists all the way down.
Plan by Plan: What May a Clinic Paste Into Each Version of ChatGPT?
The current lineup is Free, Go, Plus, Pro, Business, and Enterprise (pricing page), plus the healthcare products above. Here is the verdict table, cell by cell from OpenAI's own pages:
| Plan | BAA available? | Trains on your chats by default? | May PHI be pasted in? |
|---|---|---|---|
| Free / Go / Plus / Pro (Plus is $20/month; see pricing for the rest) | No — not eligible at any setting (BAA policy) | Yes, unless you opt out (data-usage page) | No. De-identified or fully non-patient text only |
| ChatGPT Business | No — explicitly excluded (BAA policy) | No (business-data page) | No. Better privacy terms, still no BAA |
| ChatGPT Enterprise | Sometimes — sales-managed accounts only; contact sales (BAA policy) | No (business-data page) | Only after the BAA is signed, and only within its scope |
| ChatGPT for Healthcare | Yes — built for it (product page) | No — not used for training (product page) | Yes, within covered features — some functionality is excluded |
| ChatGPT for Clinicians | Yes — in-product BAA flow (BAA policy) | Listed HIPAA-eligible; verify terms in the BAA flow | After completing the BAA flow — confirm scope before relying on it |
| API (inside another vendor's product) | Yes — no enterprise agreement required; most services covered, with exceptions (BAA policy) | No (business-data page); ZDR available for eligible endpoints (enterprise privacy) | Only if the BAA chain reaches your practice — your vendor needs a BAA with OpenAI and one with you |
One honest note: this table is only as durable as OpenAI's policy pages, which have already changed enough to strand most of what currently ranks for this question. If a compliance decision hangs on a cell, click through and read today's version.
Can You Use ChatGPT for Clinical Notes?
On a BAA-covered tier, within covered features: yes, that's precisely what these products are being sold for. On anything else — which includes every plan an individual clinician can sign up for with a credit card except ChatGPT for Clinicians — the answer is no, and the failure mode is mundane. Nobody plans to breach HIPAA; someone pastes a referral letter into the Plus account they use at home to "clean up the wording," and PHI has now been disclosed to a vendor with no BAA. To be clear about what we know and don't: forum research finds abundant fear of consequences among professionals, not documented discipline for this specific act — the absence of visible enforcement is not evidence of safety, but we won't pretend clinicians are being sanctioned in numbers when we found no such cases.
What about de-identifying first? Genuinely de-identified text — no names, dates, record numbers, or combination of details that could identify the patient — is not PHI, and drafting with it is a reasonable middle path. But real clinical text resists de-identification harder than it seems: the rare diagnosis, the small town, the sequence of events can identify a patient even with the name swapped out. Treat DIY anonymization as risk reduction for borderline material, not a licence. (Our broader guide to ChatGPT and confidential information covers this pattern across professions.)
And say the fine part out loud: most ChatGPT use in a clinic is fine. Drafting the newsletter, explaining a billing code in plain language, summarizing a published guideline — no PHI, no HIPAA question. The workable clinic policy sorts uses rather than banning the tool: public material on whatever plan you like; patient material only into a system with a signed BAA — or into no third-party system at all.
What If No Third Party Ever Touches the Data? AI on Hardware Your Clinic Owns
There is one configuration where the business-associate question doesn't get answered — it never arises. Run the model on a machine inside your practice (what local AI means), and no third party performs functions involving PHI on your behalf: no business associate, no BAA, no case-by-case review, no policy page that can change under you. The custody chain is your staff, your network, your hardware.
Honesty about the trade-offs, because they're real. You buy and maintain the hardware — capable small-office machines run very roughly $800–$1,600+ (an Apple Mac mini, one common choice, starts at $799, with higher-end configurations from $1,599), before you count setup time. Local models trail the frontier cloud models in peak capability — for drafting, summarizing, and rewording they're strong; for the hardest reasoning tasks, less so. And local AI is not automatically compliant: HIPAA's security expectations — access controls, audit trails, encryption, staff training — are still yours, as they are for your EHR. What changes is the shape of the problem: from "what is a vendor doing with our patients' data, under terms that change?" to "how do we run our own equipment?" — a question your practice already knows how to answer. Our options comparison and cost guide lay out both paths with real numbers, and the readiness quiz estimates in two minutes which side of the line your practice sits on.
Next step
Wondering if this fits your office?
The readiness assessment walks through your data sensitivity, current AI use, and what a local setup would actually involve — with an engineer, not a salesperson.
Assess your readiness →Frequently Asked Questions
Ask about this article
Get a plain-language answer drawn from this article. Answers are AI-generated from the text on this page.
Related Templates
External Resources
Authoritative references and tools related to this documentation type.