ChatGPT and HIPAA: What Your Practice Can Use

George
By George
13 September 2026
Consumer versus covered enterprise AI

Somewhere in your practice, someone has already pasted something into a chatbot: a tangled referral letter to untangle, an insurance denial to translate, maybe a patient's message to rephrase kindly. So the question is not whether AI arrives; it is already at the front desk. The real question is the compliance one: is ChatGPT HIPAA compliant, and what may a covered practice actually use? The short answer is that consumer AI tools, the free and personal-account versions of ChatGPT, Gemini, and Copilot, can never carry patient information, while covered paths now exist through enterprise agreements, and the distance between the two is a signed agreement plus configuration, not the logo on the tool.

This guide applies the standard compliance test to AI, maps where the major vendors stand as of this writing, explains why a signed agreement is the beginning of the work rather than the end. And closes with the policy and starting uses that let a small practice benefit without gambling patient data.

Is ChatGPT HIPAA Compliant? The Short Answer

An AI vendor is like any other vendor under HIPAA: the moment it receives protected health information on your behalf, it is a business associate, and that requires a Business Associate Agreement before the first patient detail flows. No consumer AI product comes with one. A free chatbot account, a personal Plus subscription, an assistant baked into someone's personal phone, none of these can be made compliant at any level of caution, because the agreement simply does not exist at that tier.

What has changed over the past two years is the other side of the ledger: major AI vendors now offer BAAs on their enterprise and healthcare products. That moves the question from "never" to "only through the covered door, configured correctly." The three-legged test that governs every communication tool governs AI identically: an eligible product tier, an executed agreement. And configuration and use that keep patient information inside the covered boundary. Miss any leg and the stool falls over, no matter how impressive the model is.

Where the Major Vendors Stand

The map below is current as of this writing, and the honest disclaimer belongs up front: AI product names, tiers. And covered-feature lists change faster than any category we cover, so the live vendor documentation is the final word before anything touches PHI.

One structural note applies across all three: each vendor also offers a developer path, an API under its own agreement, which matters to practices only indirectly, as the plumbing behind the healthcare software they buy. When a vendor pitches an AI feature, the useful question is which platform it runs on and whose agreements cover the chain.

Three AI vendors coverage compared

OpenAI and ChatGPT

OpenAI signs BAAs for its enterprise-grade products, and it now offers healthcare-specific editions built for clinical organizations, alongside BAA coverage for its developer API for companies building their own tools. The critical boundary sits inside the product family: the consumer tiers, free and paid personal subscriptions, are not BAA-eligible, and even the mid-tier team-style plans have not carried BAA eligibility, so a practice cannot upgrade a personal account into compliance. The pattern to internalize is that eligibility follows the organizational contract, not the payment: a practice that wants ChatGPT for clinical or administrative work with patient data needs the enterprise or healthcare edition under an executed agreement, provisioned and administered by the organization.

Google and Gemini

Google's route runs through the Workspace agreement your practice may already hold: on covered business and enterprise editions with the HIPAA addendum accepted, Google lists its Gemini assistant inside Workspace, and the standalone Gemini app under managed accounts, among the covered functionality. The exclusions are instructive, because they show how feature-level this territory is: consumer Gemini under a personal account is never covered, and some Gemini surfaces have been excluded from coverage even while their siblings are included. The operating rule for a practice on Workspace is to check Google's current covered-functionality list, restrict the AI features to staff who need them, and keep every personal Google account away from patient work.

Microsoft and Copilot

Microsoft folds BAA terms into its standard commercial agreements, and its Copilot assistant inside the commercial Microsoft 365 suite falls within that scope for enterprise customers, while Copilot under a personal Microsoft account does not. Microsoft's deep integration carries its own distinctive risk: an assistant grounded in your practice's mailboxes and file libraries will cheerfully surface whatever the permissions allow, so years of over-shared folders become visible in a way they never were when finding things required effort. Tightening file permissions before enabling an integrated assistant is not optional hygiene; it is the difference between an assistant and an accidental disclosure engine.

The purpose-built clinical category

Alongside the general platforms, a category of healthcare-native AI has matured: ambient scribes that draft visit notes from the conversation, patient-communication drafting tools, and coding assistants, built by vendors whose entire business is clinical and who treat the BAA as table stakes. For many small practices this category is the sensible first real AI adoption, because the vendor's defaults were designed for PHI from the start. Three questions sort this category quickly: does the vendor sign a BAA as a standard step, where is the data processed and retained, and can the tool show the clinician what it heard before anything enters the chart. The evaluation is the same as any business associate: agreement signed, data handling understood, and the arrangement recorded in your risk analysis.

The Agreement Is the Beginning, Not the End

A signed BAA covers the vendor's obligations; everything else stays yours. Coverage is feature-by-feature, and vendors publish lists of which capabilities fall inside the agreement, memory features, connected apps, and automation functions have all been excluded from coverage by one vendor or another even inside covered products, so an administrator has to read the list and disable what falls outside. Minimum necessary still applies: the assistant and the staff using it should touch the least patient information the task requires, which argues for role-based access to AI features rather than tenant-wide enthusiasm.

Human review stays mandatory, because models produce confident errors, and a hallucinated detail in a patient letter is a clinical problem before it is a technical one. Logging belongs on the list too: covered enterprise tiers provide admin visibility and audit trails, and someone should actually review them, because an unread log protects no one. And your risk analysis has to catch up: an AI tool handling PHI is a new system in the inventory, exactly like a new EHR module, and it belongs in the same documentation, the same compliance and risk management services cycle, and the same vendor list your auditors and insurers ask for.

The De-Identification Trap

The most common rationalization deserves its own warning: "I removed the name, so it is not PHI anymore." HIPAA's de-identification standard is far stricter than name removal. Identifiers include dates, locations smaller than a state, ages over a threshold, record numbers, and enough contextual detail that a story can point to a person.

A paragraph describing an unusual presentation in a named town on a specific date can identify a patient with no name attached, and a birthday, a rare diagnosis, or an employer can do it alone. The practical rule for staff is binary and easy to teach: if it came from a patient's chart or story, it does not go into an uncovered tool, edited or not. Genuine de-identification is a deliberate process with defined methods, not a quick redaction on the way to a chatbot.

Redacted chart still identifies patient

Shadow AI: The Policy Problem Already in the Building

Staff adopt helpful tools without asking; that is the entire history of shadow IT, and AI is its fastest chapter. The response that works is not prohibition theater, which drives use underground, but a short written AI policy that names what is allowed, what is banned. It also names where the covered tools live: approved tools listed by name, patient information permitted only in the covered ones, consumer accounts banned for work content of any kind, and a no-blame channel for staff to ask before trying something new.

Pair the policy with the technical layer, managed browsers and the visibility your provider's monitoring gives into the broader security stack, and with ten minutes of training that explains the why, since staff who understand the de-identification trap police themselves better than any filter. The organizational side of this risk, beyond the compliance angle, is mapped in our companion piece on where AI risk actually lives for small businesses.

What a Small Practice Can Safely Do Today

The safe starting sequence is unglamorous and effective. Begin with the zero-PHI uses that need no agreement at all: drafting job postings, policy templates, patient-education handouts on general topics, and website copy, valuable work with nothing regulated in it. If your practice already runs a covered productivity suite, the built-in assistant under your existing agreement is the natural second step, enabled for specific roles after permissions are tightened and the covered-feature list is checked. Reserve the clinical uses, note drafting, chart summarization, patient-message replies, for purpose-built tools or enterprise editions under executed agreements, adopted one workflow at a time with human review built in.

Stepped path to safe AI

Adopt one workflow at a time and measure it for a month, error rate, time saved, staff friction, before expanding, because AI programs fail by enthusiasm more often than by caution. And write the two-line rule into the AI policy on day one: patient information only in named, covered tools; everything else, no exceptions. That sequence gets a practice real benefit this quarter without a single uncovered disclosure, which is precisely the outcome we build toward with the healthcare practices we support from Ventura County to downtown.

Frequently Asked Questions

No, never. Free and personal-subscription AI accounts carry no Business Associate Agreement, so any patient information entered is a disclosure to an uncovered vendor, regardless of how the text is edited. This applies equally to consumer Gemini, personal-account Copilot, and every other consumer AI tool: no agreement, no PHI, no exceptions.
No. HIPAA's de-identification standard covers far more than names, including dates, specific locations, record numbers, and combinations of details that could identify someone. A described case can be identifiable with no name attached. The teachable rule for staff: if it came from a chart or a patient's story, it stays out of uncovered tools entirely.
As of this writing, the major platforms offer BAAs on their enterprise tiers: OpenAI for its enterprise and healthcare editions and its API, Google for Gemini within covered Workspace editions, and Microsoft for Copilot within commercial Microsoft 365, alongside a maturing category of healthcare-native tools such as ambient scribes. Eligibility and covered features change frequently, so confirm the vendor's current documentation before any PHI use.
No. The agreement covers the vendor's obligations; the practice still owns configuration, feature-level coverage checks, role-based access, minimum-necessary use, staff training, human review of outputs, and updating its risk analysis. A covered tool used carelessly, or a covered product with an uncovered feature enabled, fails just as surely as a consumer account.
Yes, through the covered door: purpose-built ambient scribes and enterprise AI under executed agreements are doing exactly this in practices today, with a clinician reviewing every output before it enters the record. The line to hold is that drafting happens inside covered tools with human sign-off, never by pasting visit details into a consumer chatbot.
Four things, briefly: the approved tools by name, the rule that patient information goes only into covered tools, a ban on consumer and personal accounts for any work content, and a no-blame path for staff to propose new tools. Add ten minutes of training on why edited patient stories still count as PHI, and revisit the policy quarterly, because this category moves faster than any other you govern.

So, is ChatGPT HIPAA compliant? Through the covered enterprise door with the agreement signed and the configuration held, it can be, and everywhere else it is a breach waiting for a busy afternoon, so if you want the covered door opened properly for your practice, book an AI readiness review with GlobeVM and we will bring the vendor map with us.

Comments

0 Comments