Skip to content
Back to blog
Healthcare7 Sept 20266 min readRanjan Singh

Is ChatGPT HIPAA Compliant?

The answer depends entirely on which ChatGPT, and the tiers most clinicians actually have open are the ones OpenAI will not sign a BAA for. Checked against OpenAI's own documentation on 9 September 2026.

In short

HIPAA compliance is a property of a deployment, not of a brand, so no product is compliant on its own. As of 9 September 2026 OpenAI offers a Business Associate Agreement for ChatGPT for Healthcare, ChatGPT for Clinicians, a regulated-workspace configuration of Enterprise, the FedRAMP environment, and the API under modified retention. It does not offer one for Free, Plus, Pro, Go, Team or Business, and its consumer ChatGPT Health feature explicitly says it is not for covered-entity use. A signed BAA fixes obligations on the vendor under 45 CFR 164.504(e); it does not transfer the covered entity's own duties, so the question of whether the model needed the identifiers at all comes first.

This question gets asked as though ChatGPT were one thing. It is now at least eight things with different contracts, and the difference between them decides whether a paste is a workflow or a disclosure. Everything below was checked against OpenAI's own documentation on 9 September 2026, which matters more than usual here: these terms change, and an answer from six months ago is not evidence about today.

Why no software is HIPAA compliant on its own

Start with the part that is not about OpenAI at all. No software is HIPAA compliant by itself. Compliance is a property of a deployment, the contract behind it and the way people use it, so a vendor can only ever be HIPAA eligible, meaning it will sign a Business Associate Agreement and operate under it. Any product page claiming the software itself is compliant is describing something that does not exist as a category.

Which ChatGPT products can OpenAI sign a BAA for?

On that test, OpenAI's current documentation names the products it will sign a BAA for: ChatGPT for Healthcare, ChatGPT for Clinicians, ChatGPT for Enterprise with Regulated Workspace, ChatGPT FedRAMP, and the API under modified retention, including the FedRAMP variant. The API route is the least gated of these. OpenAI's help documentation says a BAA can be requested by email to its BAA address without an enterprise agreement in place, and describes a turnaround of a few business days.

The list of what is not eligible is the more useful half, because it is where most people already are. ChatGPT Free, Plus, Pro, Go, Team and Business are all outside it, and OpenAI states plainly that it does not offer a BAA for ChatGPT Business. Note the naming carefully: the eligible tier is described as Enterprise with Regulated Workspace rather than Enterprise generally, and an older help article still on the site describes a broader sales-managed Enterprise or Edu path. The two do not quite agree, which is a good reason to get the scope in writing rather than inferring it from a marketing page.

ChatGPT Health is not ChatGPT for Healthcare

The most likely place to go wrong right now is a name collision that OpenAI created itself. ChatGPT Health, launched on 23 July 2026, is a consumer feature that connects Apple Health and, for eligible providers, medical records from systems including Epic and Oracle Health into ordinary ChatGPT conversations for logged-in US users on the free and paid consumer tiers. It sounds like the clinical product. It is not. OpenAI's help documentation says it "is not intended for clinical or covered-entity use and does not offer a Business Associate Agreement."

ChatGPT for Healthcare is the separate, separately branded enterprise product that does carry a BAA, and even inside it the coverage has an edge worth reading. OpenAI's documentation says content shared with it is not used to train models, and then says improved memory is disabled by default there and is not covered under the BAA, with the instruction that PHI should not be entered when using that feature. That is a good illustration of the general shape of these agreements: the BAA covers a defined configuration, not every button in the interface.

What the consumer tiers do with what you type

For the consumer tiers, the training default runs the other way. OpenAI says that for its individual services it may use your content to train its models, and switching that off is a setting the user has to find, under Data Controls. There is a trap attached: submitting thumbs up or thumbs down feedback on a response can put that entire conversation back into training even when the opt-out is on. On the API side the defaults are better, with training off unless an organization opts in and inputs retained up to 30 days for abuse monitoring, and Zero Data Retention available only on approval and not on every endpoint. None of that is a substitute for a BAA, and the separate question of what happens to retained content under a court order is covered in is ChatGPT confidential.

What a BAA obligates, and what it does not

So suppose you have the right tier and a signed agreement. It is worth being precise about what that document does. Under 45 CFR 164.504(e) a BAA obliges the business associate not to use or disclose PHI beyond the contract, to apply Security Rule safeguards, to report breaches and security incidents back to you, to bind its subcontractors to the same terms, to make records available to HHS, and to return or destroy PHI when the arrangement ends. Those are real obligations and they are worth having.

What it does not do is move your own duties onto the vendor. HHS guidance and the structure of the rule both point the same way: the covered entity keeps its independent Privacy and Security Rule obligations, is expected to act if it learns a business associate is violating the contract, and answers for its own minimum-necessary, access and workforce-training failures regardless of who else signed what. A BAA is a control you have added, not a shield you have acquired. It also says nothing about whether sending the identifiers was appropriate in the first place.

What about Azure OpenAI?

Azure OpenAI Service is the other route people take, and the reason is contractual rather than technical: Microsoft covers its in-scope cloud services under its standard BAA terms through its data protection addendum, so an organization already licensed with Microsoft may find the paperwork is done. Confirm that the specific service and the specific endpoints you intend to use are inside the current in-scope list before relying on it, because the list is maintained separately from the product and does change.

Does the model need the identifiers at all?

All of which leads to the question that should come before the procurement one. Does the model need the identifiers at all? Most clinical and administrative prompts, summarize this note, draft this appeal letter, explain this denial code, work exactly as well when the name, the record number and the dates of service have been replaced. The identifiers are almost never what the model is reasoning about. They are just what happened to be in the paragraph you copied, and the eighteen Safe Harbor identifiers are a concrete checklist for which ones they are.

Where the paste actually happens

That is the gap Omit Protect sits in, and it is free permanently and needs no licence. It runs in the tray, watches for a paste into an AI tool, and takes the identifiers out on the way in, so what reaches the model is a note with the clinical content intact and the patient removed. When the real value genuinely has to go in the box, a separate shortcut pastes the original and records that you chose to. It is not a compliance product and it does not replace a BAA or an assessment. It changes what is in the clipboard at the one moment you still control, which is the difference between a disclosure you have to account for and a paste that never contained PHI.

Get the next one by email

New benchmarks and release notes as they go up. Nothing else, and unsubscribe by replying.

New posts onlyunsubscribe by replying