Is ChatGPT HIPAA-Compliant? The Answer Depends on Which Tier Your Staff Opened

ChatGPT Free, Plus, Pro, Team and Business cannot be covered by a business associate agreement with OpenAI. Here is what that means for a medical practice, and what a compliant path looks like.

Ed

HIPAA Compliance, Agentic AI Security, Zero-Miss Intake, AI receptionist, business associate agreement

Cold math. Warm front desk. Somewhere between the two sits a coordinator with a browser tab open, pasting a patient's chart note into ChatGPT to turn it into a polite rescheduling email. She is trying to do good work quickly. Under the HIPAA Privacy Rule, she has just made a disclosure.

The question practice owners ask is whether ChatGPT is HIPAA-compliant. The question that actually decides the answer is narrower: does OpenAI offer a business associate agreement for the specific product surface your staff is using. For most practices, on most tiers, the answer is no — and that gap, not a data leak, is the violation. The Department of Health and Human Services Office for Civil Rights has said so in its own words, and 45 CFR 160.103 leaves very little room to argue.

The short answer: only certain OpenAI products are HIPAA-eligible, and the consumer tiers are not among them

OpenAI publishes its own list of HIPAA-eligible products. As of July 2026 that list contains six entries: ChatGPT for Healthcare, ChatGPT for Enterprise with Regulated Workspace, ChatGPT FedRAMP, ChatGPT for Clinicians, API with Modified Retention, and API FedRAMP with Modified Retention. ChatGPT Free, Plus, Pro, Team and Business appear nowhere on it.

OpenAI is more explicit still in its help documentation on business associate agreements: "Only ChatGPT Enterprise or Edu customers that have a sales-managed account are eligible for a BAA for ChatGPT at this time. Please note that we don't offer a BAA for ChatGPT Business." A business associate agreement, or BAA, is the written contract HIPAA requires before a vendor may handle protected health information on your behalf.

So the practical answer for a MedSpa, a cosmetic surgery practice or a behavioral health group running on ordinary paid seats is that the tool in front of your staff cannot be brought into compliance by policy, training or good intentions. There is no agreement available to sign.

The violation is the missing agreement, not the leak

This is where most coverage of the question gets the structure backwards. It treats consumer AI as a data-breach risk — something that becomes a problem if information escapes. HIPAA does not work that way.

45 CFR 164.502(e)(1)(i) permits a covered entity to disclose protected health information to a business associate only "if the covered entity obtains satisfactory assurance that the business associate will appropriately safeguard the information," and 164.502(e)(2) requires those assurances be "documented through a written contract." The Security Rule repeats the requirement for electronic protected health information at 164.308(b), as a required implementation specification rather than an addressable one.

OCR's guidance on HIPAA and cloud computing closes the remaining escape hatches. A cloud service provider is generally not a "conduit" like the postal service. Encryption does not exempt the vendor: a provider "meets the definition of a business associate, even if the CSP cannot view the ePHI because it is encrypted and the CSP does not have the decryption key." And the conclusion OCR draws is unambiguous: "without entering into a BAA with the CSP, the covered entity (or business associate) is in violation of the HIPAA Rules."

Nothing has to leak. The paste itself is the event.

Business associate coverage is granted per product and per feature, not per vendor

"Does Anthropic sign a BAA" and "does Google sign a BAA" are the wrong questions, because every major vendor answers yes at the company level and no at most of the surfaces a practice actually touches. The primary documents make this plain.

  • OpenAI will sign a BAA for the API platform without an enterprise agreement, by request to its BAA address. But its platform documentation carves features out even inside that agreement: "Web Search with live internet access is not HIPAA eligible and is not covered by a BAA."

  • Anthropic covers the first-party API and Claude Enterprise, and only after an organization's Primary Owner affirmatively activates HIPAA compliance in settings. Its own documentation states that "Standard Claude Enterprise plans do not include BAA coverage without action from a Primary Owner," and publishes a per-feature matrix excluding several tools outright.

  • Google states flatly that "Customers who have not signed a BAA with Google must not use PHI in Google Workspace or Cloud Identity services." Its HIPAA Included Functionality list, updated 14 May 2026, does cover the Gemini app inside a Workspace tenant — while excluding Gemini in Chrome, and excluding third-party add-ons entirely.

  • Microsoft is the outlier in a useful direction: its BAA is incorporated by default through the Microsoft Product Terms, with no separate signature. Microsoft also says the quiet part out loud — asked whether a BAA ensures compliance, its answer is "No."

The verification question to hand a vendor is therefore not "are you HIPAA-compliant." It is: name the specific product surface, confirm it appears on your published eligible-products list, and send the agreement. This is the same discipline as the ten-question vendor security questionnaire, applied to a tool nobody procured.

For aesthetic practices, the identifier most often missed is a photograph

The Safe Harbor de-identification standard at 45 CFR 164.514(b)(2) lists eighteen identifier categories that must be stripped before health information falls outside the Privacy Rule. Names, dates, medical record numbers and email addresses are the ones everyone remembers. Category (Q) is the one that matters most in this readership: "Full face photographic images and any comparable images."

For a MedSpa or a cosmetic surgery practice, before-and-after photography is not an edge case. It is the marketing department's primary asset. Uploading a patient's frontal photograph to a consumer image tool for retouching or caption-writing is a disclosure of an identifier, on the same footing as pasting a name.

De-identified information is genuinely outside the rule — 164.502(d)(2) says "the requirements of this subpart do not apply to information that has been de-identified." But Safe Harbor also requires that the practice have no actual knowledge that the residual information could still identify the person. A cropped photo of a distinctive tattoo does not qualify.

An impermissible disclosure is presumed to be a breach until the practice rebuts it

An impermissible disclosure is presumed to be a breach. 45 CFR 164.402 puts the burden on the practice to rebut that presumption through a four-factor risk assessment covering the nature of the information, who received it, whether it was actually acquired or viewed, and the extent to which the risk was mitigated.

If the presumption is not rebutted, 164.404(b) requires individual notice "without unreasonable delay and in no case later than 60 calendar days after discovery." Breaches involving 500 or more individuals go to HHS contemporaneously and appear on the public OCR breach portal; smaller ones are logged and reported annually.

Penalty exposure was adjusted for inflation effective 28 January 2026 (91 FR 3665). The bottom tier — a practice that did not know and would not have known with reasonable diligence — now runs $145 to $73,011 per violation. Willful neglect left uncorrected starts at $73,011 per violation against an annual cap of $2,190,294.

A useful piece of context, stated carefully: as of July 2026 there appears to be no published OCR settlement arising specifically from staff entering PHI into a generative AI tool. That is not evidence the conduct is permitted. OCR's proposed Security Rule update, published 6 January 2025 at 90 FR 898 and still not finalized, says plainly that "ePHI, including ePHI in AI training data, prediction models, and algorithm data that is maintained by a regulated entity for covered functions is protected by the HIPAA Rules," and that a regulated entity using AI "would include the use of such tools in its risk analyses."

The compliant path has three components

First, a BAA-covered surface. That means an enterprise or API tier that appears on the vendor's published eligible list, configured with the retention controls the vendor requires — OpenAI's Modified Retention, or Anthropic's HIPAA-ready organization setting.

Second, minimum necessary. 164.502(b) applies inside a BAA as well as outside it. If a de-identified summary answers the question, the identified record should not be in the prompt at all.

Third, audit controls. 45 CFR 164.312(b) requires mechanisms that "record and examine activity in information systems that contain or use electronic protected health information." This is the practical argument for putting the capability into the practice's stack rather than leaving it on a personal browser tab: a tab produces no log you can hand an investigator. NIST SP 800-66 Revision 2, published February 2024, maps each Security Rule standard to specific controls.

This is the same distinction we draw between architectural and policy compliance. A policy telling staff not to paste PHI into ChatGPT is a policy. A front-desk pipeline where the identified record never leaves a BAA-covered boundary is an architecture. For practices evaluating a voice or intake vendor rather than a writing assistant, the same chain-of-custody logic runs through the whole stack — see the BAA chain across an AI voice stack and the medical director's verification checklist. TTR builds intake infrastructure on a HIPAA-Compliant foundation for exactly this reason; the HIPAA-Compliant agent architecture page covers how that boundary is drawn.

Frequently asked questions

Is ChatGPT HIPAA-compliant? Not on the Free, Plus, Pro, Team or Business tiers, because OpenAI does not offer a business associate agreement for them. ChatGPT for Healthcare, ChatGPT for Clinicians, ChatGPT Enterprise with a Regulated Workspace, and the API with Modified Retention appear on OpenAI's published HIPAA-eligible products list.

Can staff use ChatGPT if they remove the patient's name? Only if the information meets the full Safe Harbor standard at 45 CFR 164.514(b) — all eighteen identifier categories removed, including full-face photographs, dates other than year, and any other unique identifying characteristic — and the practice has no actual knowledge that the remainder could still identify the person.

Does encrypting the data or turning off chat history make it compliant? No. OCR's cloud computing guidance states that a provider is a business associate "even if the CSP cannot view the ePHI because it is encrypted." Retention settings change the risk profile; they do not create the contract HIPAA requires.

Has OCR fined anyone for this yet? No published OCR enforcement action as of July 2026 turns specifically on generative AI and PHI. Absence of enforcement is not permission — OCR's own cloud computing guidance treats the missing agreement as the violation.

Is a HIPAA-Compliant AI receptionist a different question? Yes. A vendor deploying a voice or intake agent for your practice is a business associate by design and should present a signed BAA before a single call is routed. The failure mode described here is different: an unmanaged tool nobody procured, on a tier where no agreement exists.

Nobody has audited which tools your staff are drafting patient letters in

You know which staff have a browser. You know that the writing tasks in front of them — recall letters, rescheduling notes, review responses, consult summaries — are exactly the tasks a language model is good at. And you know that no one has audited which tools those tasks are being done in.

When you run that inventory, the finding is usually not malice. It is a coordinator being efficient inside a boundary nobody drew for her. The fix is architectural: put a BAA-covered surface in front of the work, and make the compliant path the fastest one available.

References

  • 45 CFR 160.103, 164.308(b), 164.312(b), 164.402, 164.404, 164.408, 164.502, 164.514 — eCFR, current as of July 2026.

  • HHS Office for Civil Rights, "Guidance on HIPAA & Cloud Computing."

  • OpenAI Help Center, "HIPAA Eligible Products and Functionality" and "How can I get a Business Associate Agreement (BAA) with OpenAI for the API Services?" — accessed 30 July 2026.

  • OpenAI Platform documentation, "Data controls in the OpenAI platform."

  • Anthropic Privacy Center, "Business Associate Agreements (BAA) for Commercial Customers."

  • Google Workspace Help, "HIPAA Compliance with Google Workspace and Cloud Identity"; Google "HIPAA Included Functionality," 14 May 2026.

  • Microsoft Learn, "HIPAA (US) — Azure Compliance" and "HIPAA & HITECH Act — Microsoft Compliance."

  • HIPAA Security Rule NPRM, 90 FR 898, 6 January 2025 — not finalized as of 30 July 2026.

  • HHS, "Annual Civil Monetary Penalties Inflation Adjustment," 91 FR 3665, 28 January 2026.

  • NIST SP 800-66 Rev. 2, "Implementing the HIPAA Security Rule: A Cybersecurity Resource Guide," February 2024.

Next Step

If your premium practice runs more than 100 inbound consult inquiries a month and has no structured measurement of how many never reach a scheduled consultation, your pipeline is leaking revenue. We quantify this for your practice in a 30-minute Intake Leak Audit.