Yes for most of what a practice does, and no for the part containing patient information, unless you are on a tier where the vendor has signed a Business Associate Agreement. OpenAI signs one for the API, and for ChatGPT Enterprise or Edu on a sales-managed account, and says plainly that it does not offer one for ChatGPT Business. The more useful half of the answer is that a large share of daily practice work contains no patient information at all.

This is not legal advice; a real compliance decision needs your own counsel. What follows is the regulation and what the vendors put in writing.

What HIPAA actually asks

HIPAA has no opinion about software. It has an opinion about information. The definition at 45 CFR 160.103 covers health information that identifies a patient and is "transmitted by electronic media", which a chat box does as much as an HL7 feed. Nothing in the text carves out "I was only asking it to reword a letter."

Once an outside vendor handles that information for you, it is a business associate. The definition lists "data analysis, processing or administration" among the functions that count, which is what a language model does to text. The vendor's assurance that it will safeguard the information "must be documented through a written contract" (45 CFR 164.502(e)). That is the BAA. The definition reaches subcontractors too, so an AI scribe built on somebody else's model API needs its own downstream agreement. Ask your scribe vendor who is underneath them.

Which tools will sign, as of 13 August 2026

OpenAI will sign for the API Platform, by email to [email protected], with no enterprise agreement required. For ChatGPT itself, only Enterprise or Edu customers on a sales-managed account qualify, plus a separate in-product flow for clinicians using ChatGPT for Clinicians. OpenAI's page says it does not offer a BAA for ChatGPT Business. ChatGPT for Healthcare also exists, described by OpenAI as "a secure workspace designed to support HIPAA compliance".

Anthropic's HIPAA-ready services are its first party API and Enterprise plans with HIPAA switched on; Cowork "is not an Eligible Service under Anthropic's BAA in any configuration". Google signs a Cloud BAA covering an enumerated Covered Products list, whose AI entries include "Gemini Enterprise", "Gemini Enterprise Agent Platform" and "Generative AI on Gemini Enterprise Agent Platform". Microsoft makes you sign nothing extra: its BAA reaches in-scope services through the Product Terms by default.

Vendors rarely say your consumer plan is excluded. They publish a list of what is covered, your plan is not on it, and absence from the list is the answer.

Exhibit 1

Every major vendor will sign, and almost none of them will sign for the plan you already have.

Vendor Will sign a BAA on Not covered Vendor page date OpenAI API Platform, via [email protected] ChatGPT Enterprise or Edu on a sales-managed account ChatGPT Business Help page, about 2026-07-30 Anthropic Claude API on the HIPAA-ready configuration; Claude Enterprise with HIPAA activated Cowork, in any configuration 2026-07-01 Google Google Cloud services on the enumerated Covered Products list anything not on the covered list; Pre-GA offerings 2026-08-11 Microsoft in-scope services, automatically through the Product Terms services outside the in-scope list Azure HIPAA page, 2024-10-10
Note: every row comes from that vendor's own documentation, not from a comparison site. last-verified: 2026-08-13. These lists move fast, and two of the four pages above had changed within the previous five weeks, so open the vendor's page and check the row before you rely on it.

The fine print that catches people

A compliant account is not the same thing as a compliant workflow. Anthropic's covered models "can't be accessed from organizations or workspaces with zero data retention (ZDR) enabled", so the setting that sounds most protective is the one that takes you off the covered list. OpenAI's documentation says "Web Search with live internet access is not HIPAA eligible and is not covered by a BAA", so one toggle inside an otherwise covered account puts that request outside the agreement. Some API endpoints sit outside coverage too; check the current exclusions list.

Is ChatGPT HIPAA compliant?

The phrase does not describe anything. No product is HIPAA compliant, because compliance is a property of your practice, not of a tool. The vendors say so more plainly than their resellers do. Microsoft: "Does having a BAA with Microsoft ensure my organization's compliance with HIPAA? No." Google: the covered entity "is responsible for building a HIPAA compliant solution using the approved Google Cloud services". Anthropic's own word for its offering is HIPAA-ready. The overclaiming lives in third party marketing, not in the vendors' legal pages.

The half nobody writes about

A practice produces a lot of text with no patient in it. Handouts for the waiting room. Your own policies. A job ad for the front desk. A blank appeal letter template. A staff rota by initials. That is ordinary business writing, it can go in an ordinary tool, and the compliance blogs skip it because there is nothing to sell against it. The split is most of the work, and it is the same exercise as sorting which of your tasks are actually sensitive.

Exhibit 2

The same task lands on either side depending on what you actually paste.

No identifier in it an ordinary tool is fine PHI covered tier, signed BAA Patient education handout A practice policy draft Job ad for the front desk Blank appeal letter template Staff rota, initials only A note about a named patient That appeal letter, filled in Anything pasted from a chart Insurer query naming a patient A photo of a patient's face
Note: these are examples of the sort, not a list to copy. The test is whether the text you are about to paste carries one of the eighteen Safe Harbor identifiers, which is why the appeal letter appears in both columns.

De-identification, and its two traps

The Safe Harbor method at 45 CFR 164.514(b)(2) lists eighteen identifiers to remove: names; geography finer than a state; every date element except the year; phone, fax, social security, medical record, health plan, account, licence, vehicle and device numbers; email addresses; URLs and IP addresses; biometrics; full face images; and any other unique code. Take all eighteen out and what remains is no longer PHI.

Two traps sit underneath. The first is in the rule itself: you must also not have "actual knowledge" that what is left can still identify the person. In a small town, or with a rare diagnosis, you usually do. The second is OCR's own warning that the residual risk of re-identification "is not zero". De-identification is a real route out, and more work than the word suggests.

What HHS has said about AI so far

We could find no OCR guidance document on generative AI and HIPAA. What exists is the preamble to the proposed Security Rule update (90 FR 898), where the department writes that it "expect[s] that a regulated entity interested in using AI would include the use of such tools in its risk analyses", and that AI software touching ePHI "would be listed as part of its technology asset inventory". The rule is still proposed. The duty underneath it is not.

We could also find no OCR action naming an AI tool as of 13 August 2026, which is not the same thing as permission. Netskope telemetry reported by The HIPAA Journal in May 2025 put 71% of healthcare workers on personal AI accounts. That tells you how common the habit is. It does not tell you anyone has been penalised for it. Check the date on anything you read about this, this page included. That publication said in January 2026 that OpenAI would not sign for Enterprise; OpenAI's own July 2026 page says it will.

So when is local AI the answer?

A model on hardware you own, run by your own staff, discloses nothing to anyone outside the practice. No business associate, nothing to paper. That follows from the definition at 160.103 rather than from an HHS statement about local software, but it follows cleanly.

The Security Rule does not go away: access control with unique user IDs, an emergency access procedure, audit controls, and encryption, which is "addressable" rather than required and so a decision you write down either way (45 CFR 164.306 and 164.312). Local hosting trades a disclosure problem for a device security problem. For a few practices that is a good trade, and the honest cost is in the piece on keeping it on a machine in the office. If you are a behavioural health practice, Part 2 sits on top of all of this and narrows the answer further.

Sort, then tier, then paperwork, then the house rules your staff will follow. Most practices run it backwards and start by picking a tool. If you would rather not do it alone, we can set the guardrails before the tools.

Common questions

Is a BAA enough to make AI HIPAA compliant?

No, and the vendors say so. Google's position is that the covered entity "is responsible for building a HIPAA compliant solution using the approved Google Cloud services", and Microsoft answers the same question with a flat no. A BAA makes lawful use possible. Your configuration and your staff rules decide whether the use is compliant.

Is ChatGPT HIPAA certified?

Nothing is. Microsoft's compliance page puts it plainly: "There's currently no certification standard that the Department of Health and Human Services approves to demonstrate compliance with HIPAA or the HITECH Act by a business associate." Any badge you are shown is a vendor's claim about itself.

Do I need a BAA to be HIPAA compliant?

You need one with every outside party that creates, receives, maintains or transmits protected health information for you. If a tool never receives patient information, there is nothing to paper. That is why the sorting comes first: it decides how many agreements you need.

Start a conversation

All notes Start a conversation