Skip to content
    HIPAA & Compliance 7 min 2026-08-28

    Is ChatGPT HIPAA compliant?

    The short answer is no by default — and the long answer is about your deployment, not the tool. What a BAA does and doesn't cover, and what actually decides compliance.

    The short answer: the ChatGPT most people use is not HIPAA compliant, and no setting inside it changes that. The Free, Plus, and Pro tiers — and ChatGPT Business — come with no business associate agreement, which means protected health information cannot legally touch them. Paste a patient name into a consumer chatbot and you haven't bent a rule, you've disclosed PHI to a vendor with no BAA. The longer answer is more useful, because OpenAI does sell tiers that can handle PHI — and because "is the tool compliant" is the wrong question in the first place.

    The default answer is no — by OpenAI's own rules

    This isn't our reading between the lines; it's OpenAI's published position. OpenAI's HIPAA implementation guide says it plainly: without a BAA with OpenAI, you may not use the services with protected health information. And its HIPAA-eligibility page draws the tier line explicitly — consumer ChatGPT (Free, Plus, Pro) and ChatGPT Business are not eligible services, and OpenAI does not offer a BAA for them at any price. The tiers that are HIPAA-eligible with a signed BAA: ChatGPT for Healthcare, ChatGPT Enterprise with the Regulated Workspace (sales-managed accounts only), ChatGPT for Clinicians, and the API with Modified Retention enabled.

    What the enterprise tiers change — and what they don't

    A signed BAA and a HIPAA-eligible tier clear the first two items on the compliance checklist: a business associate relationship exists, and your data isn't training anyone's model. What they don't do is make your practice compliant. Compliance is a property of the whole deployment — who can use the tool, what PHI goes in, where outputs and transcripts live, whether every PHI interaction is logged, and whether anything is provably deleted on schedule. An enterprise ChatGPT contract moves the burden to your side of the table; it doesn't discharge it. The full checklist lives in our HIPAA-compliant AI guide — it's the test we'd hold any tool to, ours included.

    "But I de-identify the data first"

    De-identification is a real path under HIPAA — and a much narrower one than most people assume. The safe-harbor standard requires stripping eighteen categories of identifiers, including dates more specific than a year and any detail that could re-identify the patient in combination. "I removed the name" doesn't come close. If your de-identification is genuinely complete, the data isn't PHI and the BAA question dissolves; if it's almost complete, you're disclosing PHI to an ineligible service. In a busy front office, "almost" is the realistic outcome — which is why a written rule beats individual judgment here.

    What a practice should actually do

    First, govern the use that's already happening. Your staff are using AI chatbots today, on some account, with some data. An employee AI-use policy that names approved tools and draws the PHI line is the cheapest compliance control you can deploy this week.

    Second, match the tier to the task. General drafting, coding help, and anything PHI-free can live on ordinary business tiers. Anything touching patient data needs a HIPAA-eligible tier with a signed BAA — or shouldn't happen in a chatbot at all.

    Third, consider whether a chatbot is the right shape. Most of the value practices want from AI — insurance verification, intake, documentation — isn't a person typing into a chat window; it's a system doing the work with scoped access and an audit trail. Private deployment, where the AI runs on infrastructure you control, is the strongest posture for that: the data paths are yours to define and log. That's the architecture behind our Hosted Private AI — HIPAA-ready by design, with compliance achieved in the deployment, documented step by step.

    The bottom line

    ChatGPT is HIPAA-eligible only on the tiers OpenAI explicitly lists, only with a signed BAA, and only as one item inside a deployment your practice can defend. If you're deciding where AI actually belongs in your workflows — and which parts need the regulated posture — that's exactly what an assessment maps before anything gets bought.

    Frequently asked questions

    Brian Kelly

    Founder, Automated Edge

    Brian has spent twenty-plus years operating Managed Service Provider and Managed Security Service Provider environments for SMBs. Automated Edge applies that operational discipline to AI — assess, build, operate.

    Talk to a MAISP, not a consultant.

    Thirty minutes with the engineers who'll build and operate your AI — not the SDR queue. We listen, then we tell you the truth about whether AI fits.

    Book a Strategy Call

    Free · 30 min · no pitch