Somewhere in your practice, someone has already pasted something into a chatbot: a tangled referral letter to untangle, an insurance denial to translate, maybe a patient's message to rephrase kindly. So the question is not whether AI arrives; it is already at the front desk. The real question is the compliance one: is ChatGPT HIPAA compliant, and what may a covered practice actually use? The short answer is that consumer AI tools, the free and personal-account versions of ChatGPT, Gemini, and Copilot, can never carry patient information, while covered paths now exist through enterprise agreements, and the distance between the two is a signed agreement plus configuration, not the logo on the tool.
This guide applies the standard compliance test to AI, maps where the major vendors stand as of this writing, explains why a signed agreement is the beginning of the work rather than the end. And closes with the policy and starting uses that let a small practice benefit without gambling patient data.
Is ChatGPT HIPAA Compliant? The Short Answer
An AI vendor is like any other vendor under HIPAA: the moment it receives protected health information on your behalf, it is a business associate, and that requires a Business Associate Agreement before the first patient detail flows. No consumer AI product comes with one. A free chatbot account, a personal Plus subscription, an assistant baked into someone's personal phone, none of these can be made compliant at any level of caution, because the agreement simply does not exist at that tier.
What has changed over the past two years is the other side of the ledger: major AI vendors now offer BAAs on their enterprise and healthcare products. That moves the question from "never" to "only through the covered door, configured correctly." The three-legged test that governs every communication tool governs AI identically: an eligible product tier, an executed agreement. And configuration and use that keep patient information inside the covered boundary. Miss any leg and the stool falls over, no matter how impressive the model is.
Where the Major Vendors Stand
The map below is current as of this writing, and the honest disclaimer belongs up front: AI product names, tiers. And covered-feature lists change faster than any category we cover, so the live vendor documentation is the final word before anything touches PHI.
One structural note applies across all three: each vendor also offers a developer path, an API under its own agreement, which matters to practices only indirectly, as the plumbing behind the healthcare software they buy. When a vendor pitches an AI feature, the useful question is which platform it runs on and whose agreements cover the chain.

OpenAI and ChatGPT
OpenAI signs BAAs for its enterprise-grade products, and it now offers healthcare-specific editions built for clinical organizations, alongside BAA coverage for its developer API for companies building their own tools. The critical boundary sits inside the product family: the consumer tiers, free and paid personal subscriptions, are not BAA-eligible, and even the mid-tier team-style plans have not carried BAA eligibility, so a practice cannot upgrade a personal account into compliance. The pattern to internalize is that eligibility follows the organizational contract, not the payment: a practice that wants ChatGPT for clinical or administrative work with patient data needs the enterprise or healthcare edition under an executed agreement, provisioned and administered by the organization.
Google and Gemini
Google's route runs through the Workspace agreement your practice may already hold: on covered business and enterprise editions with the HIPAA addendum accepted, Google lists its Gemini assistant inside Workspace, and the standalone Gemini app under managed accounts, among the covered functionality. The exclusions are instructive, because they show how feature-level this territory is: consumer Gemini under a personal account is never covered, and some Gemini surfaces have been excluded from coverage even while their siblings are included. The operating rule for a practice on Workspace is to check Google's current covered-functionality list, restrict the AI features to staff who need them, and keep every personal Google account away from patient work.
Microsoft and Copilot
Microsoft folds BAA terms into its standard commercial agreements, and its Copilot assistant inside the commercial Microsoft 365 suite falls within that scope for enterprise customers, while Copilot under a personal Microsoft account does not. Microsoft's deep integration carries its own distinctive risk: an assistant grounded in your practice's mailboxes and file libraries will cheerfully surface whatever the permissions allow, so years of over-shared folders become visible in a way they never were when finding things required effort. Tightening file permissions before enabling an integrated assistant is not optional hygiene; it is the difference between an assistant and an accidental disclosure engine.
The purpose-built clinical category
Alongside the general platforms, a category of healthcare-native AI has matured: ambient scribes that draft visit notes from the conversation, patient-communication drafting tools, and coding assistants, built by vendors whose entire business is clinical and who treat the BAA as table stakes. For many small practices this category is the sensible first real AI adoption, because the vendor's defaults were designed for PHI from the start. Three questions sort this category quickly: does the vendor sign a BAA as a standard step, where is the data processed and retained, and can the tool show the clinician what it heard before anything enters the chart. The evaluation is the same as any business associate: agreement signed, data handling understood, and the arrangement recorded in your risk analysis.
The Agreement Is the Beginning, Not the End
A signed BAA covers the vendor's obligations; everything else stays yours. Coverage is feature-by-feature, and vendors publish lists of which capabilities fall inside the agreement, memory features, connected apps, and automation functions have all been excluded from coverage by one vendor or another even inside covered products, so an administrator has to read the list and disable what falls outside. Minimum necessary still applies: the assistant and the staff using it should touch the least patient information the task requires, which argues for role-based access to AI features rather than tenant-wide enthusiasm.
Human review stays mandatory, because models produce confident errors, and a hallucinated detail in a patient letter is a clinical problem before it is a technical one. Logging belongs on the list too: covered enterprise tiers provide admin visibility and audit trails, and someone should actually review them, because an unread log protects no one. And your risk analysis has to catch up: an AI tool handling PHI is a new system in the inventory, exactly like a new EHR module, and it belongs in the same documentation, the same compliance and risk management services cycle, and the same vendor list your auditors and insurers ask for.
The De-Identification Trap
The most common rationalization deserves its own warning: "I removed the name, so it is not PHI anymore." HIPAA's de-identification standard is far stricter than name removal. Identifiers include dates, locations smaller than a state, ages over a threshold, record numbers, and enough contextual detail that a story can point to a person.
A paragraph describing an unusual presentation in a named town on a specific date can identify a patient with no name attached, and a birthday, a rare diagnosis, or an employer can do it alone. The practical rule for staff is binary and easy to teach: if it came from a patient's chart or story, it does not go into an uncovered tool, edited or not. Genuine de-identification is a deliberate process with defined methods, not a quick redaction on the way to a chatbot.

Shadow AI: The Policy Problem Already in the Building
Staff adopt helpful tools without asking; that is the entire history of shadow IT, and AI is its fastest chapter. The response that works is not prohibition theater, which drives use underground, but a short written AI policy that names what is allowed, what is banned. It also names where the covered tools live: approved tools listed by name, patient information permitted only in the covered ones, consumer accounts banned for work content of any kind, and a no-blame channel for staff to ask before trying something new.
Pair the policy with the technical layer, managed browsers and the visibility your provider's monitoring gives into the broader security stack, and with ten minutes of training that explains the why, since staff who understand the de-identification trap police themselves better than any filter. The organizational side of this risk, beyond the compliance angle, is mapped in our companion piece on where AI risk actually lives for small businesses.
What a Small Practice Can Safely Do Today
The safe starting sequence is unglamorous and effective. Begin with the zero-PHI uses that need no agreement at all: drafting job postings, policy templates, patient-education handouts on general topics, and website copy, valuable work with nothing regulated in it. If your practice already runs a covered productivity suite, the built-in assistant under your existing agreement is the natural second step, enabled for specific roles after permissions are tightened and the covered-feature list is checked. Reserve the clinical uses, note drafting, chart summarization, patient-message replies, for purpose-built tools or enterprise editions under executed agreements, adopted one workflow at a time with human review built in.

Adopt one workflow at a time and measure it for a month, error rate, time saved, staff friction, before expanding, because AI programs fail by enthusiasm more often than by caution. And write the two-line rule into the AI policy on day one: patient information only in named, covered tools; everything else, no exceptions. That sequence gets a practice real benefit this quarter without a single uncovered disclosure, which is precisely the outcome we build toward with the healthcare practices we support from Ventura County to downtown.
Frequently Asked Questions
So, is ChatGPT HIPAA compliant? Through the covered enterprise door with the agreement signed and the configuration held, it can be, and everywhere else it is a breach waiting for a busy afternoon, so if you want the covered door opened properly for your practice, book an AI readiness review with GlobeVM and we will bring the vendor map with us.
Comments
0 Comments
