Is ChatGPT HIPAA Compliant? Which AI Tools Sign a BAA

Illustration of a robot in a bright medical office holding a tablet checklist, beside a shield and padlock icon and an open file drawer

ChatGPT is not HIPAA compliant on a personal account, free or paid. HIPAA compliance for ChatGPT requires a business associate agreement with OpenAI, and OpenAI’s published Healthcare Addendum limits it to named business offerings, such as ChatGPT Enterprise and API organizations OpenAI has approved, with third-party GPTs and plugins excluded. Without that agreement, keep patient information out.

We read each vendor’s own pages in September 2026. OpenAI’s help center and trust portal refused our automated requests, so the OpenAI details below come from its Healthcare Addendum and developer documentation, which we could read. Confirm your plan with OpenAI in writing. This is general information, not legal advice. For what AI tools do with ordinary business data, see our AI data privacy questions for small business; this post covers patient data only.

Which AI tools will sign a BAA?

Tool or planBAA status, checked September 2026Watch for
ChatGPT on a personal accountNot an eligible service in OpenAI’s Healthcare AddendumBlock it for staff who handle PHI
ChatGPT EnterpriseEligible service under the addendumThird-party GPTs, plugins, actions and shared links are excluded
OpenAI APIBAA-eligible endpoints, for organizations OpenAI approvesWeb search with live internet access is not covered
ChatGPT Business, ChatGPT Edu, ChatGPT for HealthcareNot named in the addendum; OpenAI offers its BAA with enterprise plansGet the covered plan named in writing
Claude EnterpriseBAA once the Primary Owner enables HIPAA in organization settingsCowork and data sent to third parties through connectors are not covered
Claude APIBAA signed by the Primary Owner, then enabled by AnthropicBatch, Files, Code Execution and Web Fetch are not covered
Claude Team, Free, Pro and MaxCannot enable HIPAAKeep PHI out
Microsoft Copilot and Copilot ChatIn scope of Microsoft’s BAA through its Data Protection AddendumWeb search queries and Anthropic models with Data Retention fall outside it
Gemini in Google WorkspaceIncluded Functionality under Google’s BAAGemini in Chrome is excluded

Will OpenAI or Anthropic sign a BAA?

Both will, for specific offerings. OpenAI’s Healthcare Addendum (version 111124, still posted by OpenAI in September 2026) makes its BAA part of the contract and defines Eligible Services as the Zero Retention API, ChatGPT Enterprise, and anything else OpenAI identifies in writing. PHI may go only through those services. The addendum rules out third-party GPTs, plugins and actions, API use outside an approved organization ID, and endpoints not eligible for zero retention.

OpenAI’s newer developer documentation on data controls refers to a Business Associate and Healthcare Addendum and to BAA-eligible endpoints, says Zero Data Retention needs OpenAI’s prior approval, and says web search with live internet access is not covered by a BAA. The two documents are not identical, which is one more reason to get your covered services named in writing.

Anthropic publishes its terms in its help center article on BAAs. A Claude Enterprise organization gets BAA coverage only after its Primary Owner turns on HIPAA under Data and privacy and accepts the BAA, a change Anthropic says cannot be reversed from organization settings. API customers sign the BAA, then ask Anthropic to enable it. Team and individual plans cannot enable HIPAA.

Is Microsoft 365 Copilot covered by Microsoft’s BAA?

Yes, with exceptions. Microsoft renamed Microsoft 365 Copilot to Microsoft Copilot, and Copilot Chat along with it, and lists both among the services covered by its HIPAA BAA. Its enterprise data protection page says they support HIPAA compliance for properly configured implementations, but web search queries sent to Bing are not covered by the Data Protection Addendum or the BAA. Microsoft also says Anthropic models with Data Retention run under Anthropic’s own terms rather than Microsoft’s, and stay off until an administrator opts in. Copilot works within each user’s existing permissions, so oversharing in SharePoint becomes a Copilot problem; our Microsoft 365 HIPAA settings guide covers the tenant side.

Rules to give staff who handle PHI

  1. Use only AI tools the practice has approved, signed in with a work account covered by a BAA.
  2. Never paste patient details into a personal account, a browser extension or a third-party GPT.
  3. Check every output. OpenAI’s addendum puts accuracy testing on the customer and limits clinical, billing and coding use of outputs to qualified people who hold the licenses those tasks require.
  4. Before using a tool without a BAA, remove all 18 identifiers listed in 45 CFR 164.514(b)(2), often called the safe harbor method.

Where NetSys fits

Our AI security assessment reviews the AI tools in use, the permissions behind them and how data is handled. We then help you settle on an approved list and log each vendor’s BAA with the rest of your HIPAA compliance program. If a vendor will not sign, read what to do when a vendor refuses a BAA. Practices weighing AI phone answering can start with our AI receptionist for medical offices, and Google Workspace users can check how Gemini fits Google’s BAA.

Frequently asked questions

Is ChatGPT Plus HIPAA compliant?

No. ChatGPT Plus is a personal plan, and OpenAI’s Healthcare Addendum does not list personal plans as eligible services, so no BAA covers what staff type into it. A practice that wants ChatGPT near patient information needs an eligible business offering under a signed BAA, set up the way OpenAI’s terms require.

Is Claude HIPAA compliant?

Claude can be used with PHI only under Anthropic’s BAA, on a HIPAA-ready Enterprise organization or an enabled API organization. Anthropic says Team and individual plans cannot enable HIPAA, Claude Code is covered only with zero data retention on qualified accounts, and some features, such as Cowork, remain outside the BAA.

Does OpenAI train its models on API data?

Not by default. OpenAI’s developer documentation says data sent to the API has not been used to train or improve its models since March 1, 2023, unless a customer opts in. That is a training policy, not a BAA: by default, abuse monitoring logs that can include prompts are kept for up to 30 days.

Can staff use AI tools with de-identified patient data?

Yes, if the data is truly de-identified. HIPAA allows two methods: an expert determination, or removing all 18 identifiers in 45 CFR 164.514(b)(2), from names and dates to device serial numbers and IP addresses, with no actual knowledge that what remains could identify the patient. Deleting names alone does not qualify.

Does a BAA make AI answers safe for patient care?

No. A BAA covers how the vendor protects PHI, not whether the output is right. OpenAI’s addendum says its services are not a substitute for trained clinicians and puts accuracy testing on the customer. Keep a licensed person responsible for anything an AI tool drafts for a chart, a claim or a patient.

Sources (checked September 2026)

HIPAA Compliance Services

Discuss hipaa compliance services for your business.

Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.

Explore HIPAA Compliance Services 845-203-3914