
ChatGPT is not HIPAA compliant on a personal account, free or paid. HIPAA compliance for ChatGPT requires a business associate agreement with OpenAI, and OpenAI’s published Healthcare Addendum limits it to named business offerings, such as ChatGPT Enterprise and API organizations OpenAI has approved, with third-party GPTs and plugins excluded. Without that agreement, keep patient information out.
We read each vendor’s own pages in September 2026. OpenAI’s help center and trust portal refused our automated requests, so the OpenAI details below come from its Healthcare Addendum and developer documentation, which we could read. Confirm your plan with OpenAI in writing. This is general information, not legal advice. For what AI tools do with ordinary business data, see our AI data privacy questions for small business; this post covers patient data only.
Which AI tools will sign a BAA?
| Tool or plan | BAA status, checked September 2026 | Watch for |
|---|---|---|
| ChatGPT on a personal account | Not an eligible service in OpenAI’s Healthcare Addendum | Block it for staff who handle PHI |
| ChatGPT Enterprise | Eligible service under the addendum | Third-party GPTs, plugins, actions and shared links are excluded |
| OpenAI API | BAA-eligible endpoints, for organizations OpenAI approves | Web search with live internet access is not covered |
| ChatGPT Business, ChatGPT Edu, ChatGPT for Healthcare | Not named in the addendum; OpenAI offers its BAA with enterprise plans | Get the covered plan named in writing |
| Claude Enterprise | BAA once the Primary Owner enables HIPAA in organization settings | Cowork and data sent to third parties through connectors are not covered |
| Claude API | BAA signed by the Primary Owner, then enabled by Anthropic | Batch, Files, Code Execution and Web Fetch are not covered |
| Claude Team, Free, Pro and Max | Cannot enable HIPAA | Keep PHI out |
| Microsoft Copilot and Copilot Chat | In scope of Microsoft’s BAA through its Data Protection Addendum | Web search queries and Anthropic models with Data Retention fall outside it |
| Gemini in Google Workspace | Included Functionality under Google’s BAA | Gemini in Chrome is excluded |
Will OpenAI or Anthropic sign a BAA?
Both will, for specific offerings. OpenAI’s Healthcare Addendum (version 111124, still posted by OpenAI in September 2026) makes its BAA part of the contract and defines Eligible Services as the Zero Retention API, ChatGPT Enterprise, and anything else OpenAI identifies in writing. PHI may go only through those services. The addendum rules out third-party GPTs, plugins and actions, API use outside an approved organization ID, and endpoints not eligible for zero retention.
OpenAI’s newer developer documentation on data controls refers to a Business Associate and Healthcare Addendum and to BAA-eligible endpoints, says Zero Data Retention needs OpenAI’s prior approval, and says web search with live internet access is not covered by a BAA. The two documents are not identical, which is one more reason to get your covered services named in writing.
Anthropic publishes its terms in its help center article on BAAs. A Claude Enterprise organization gets BAA coverage only after its Primary Owner turns on HIPAA under Data and privacy and accepts the BAA, a change Anthropic says cannot be reversed from organization settings. API customers sign the BAA, then ask Anthropic to enable it. Team and individual plans cannot enable HIPAA.
Is Microsoft 365 Copilot covered by Microsoft’s BAA?
Yes, with exceptions. Microsoft renamed Microsoft 365 Copilot to Microsoft Copilot, and Copilot Chat along with it, and lists both among the services covered by its HIPAA BAA. Its enterprise data protection page says they support HIPAA compliance for properly configured implementations, but web search queries sent to Bing are not covered by the Data Protection Addendum or the BAA. Microsoft also says Anthropic models with Data Retention run under Anthropic’s own terms rather than Microsoft’s, and stay off until an administrator opts in. Copilot works within each user’s existing permissions, so oversharing in SharePoint becomes a Copilot problem; our Microsoft 365 HIPAA settings guide covers the tenant side.
Rules to give staff who handle PHI
- Use only AI tools the practice has approved, signed in with a work account covered by a BAA.
- Never paste patient details into a personal account, a browser extension or a third-party GPT.
- Check every output. OpenAI’s addendum puts accuracy testing on the customer and limits clinical, billing and coding use of outputs to qualified people who hold the licenses those tasks require.
- Before using a tool without a BAA, remove all 18 identifiers listed in 45 CFR 164.514(b)(2), often called the safe harbor method.
Where NetSys fits
Our AI security assessment reviews the AI tools in use, the permissions behind them and how data is handled. We then help you settle on an approved list and log each vendor’s BAA with the rest of your HIPAA compliance program. If a vendor will not sign, read what to do when a vendor refuses a BAA. Practices weighing AI phone answering can start with our AI receptionist for medical offices, and Google Workspace users can check how Gemini fits Google’s BAA.
Frequently asked questions
Is ChatGPT Plus HIPAA compliant?
No. ChatGPT Plus is a personal plan, and OpenAI’s Healthcare Addendum does not list personal plans as eligible services, so no BAA covers what staff type into it. A practice that wants ChatGPT near patient information needs an eligible business offering under a signed BAA, set up the way OpenAI’s terms require.
Is Claude HIPAA compliant?
Claude can be used with PHI only under Anthropic’s BAA, on a HIPAA-ready Enterprise organization or an enabled API organization. Anthropic says Team and individual plans cannot enable HIPAA, Claude Code is covered only with zero data retention on qualified accounts, and some features, such as Cowork, remain outside the BAA.
Does OpenAI train its models on API data?
Not by default. OpenAI’s developer documentation says data sent to the API has not been used to train or improve its models since March 1, 2023, unless a customer opts in. That is a training policy, not a BAA: by default, abuse monitoring logs that can include prompts are kept for up to 30 days.
Can staff use AI tools with de-identified patient data?
Yes, if the data is truly de-identified. HIPAA allows two methods: an expert determination, or removing all 18 identifiers in 45 CFR 164.514(b)(2), from names and dates to device serial numbers and IP addresses, with no actual knowledge that what remains could identify the patient. Deleting names alone does not qualify.
Does a BAA make AI answers safe for patient care?
No. A BAA covers how the vendor protects PHI, not whether the output is right. OpenAI’s addendum says its services are not a substitute for trained clinicians and puts accuracy testing on the customer. Keep a licensed person responsible for anything an AI tool drafts for a chart, a claim or a patient.
Sources (checked September 2026)
- OpenAI Healthcare Addendum and BAA, version 111124 (PDF), checked September 2026.
- Data controls in the OpenAI platform, OpenAI developer documentation, checked September 2026.
- How can I get a BAA with OpenAI?, OpenAI Help Center; returned an access error to our reader in September 2026, so not summarized here.
- Business Associate Agreements (BAA) for Commercial Customers, Claude Help Center, checked September 2026.
- HIPAA-ready Enterprise plans, Claude Help Center, checked September 2026.
- Microsoft HIPAA and HITECH Act offering, Microsoft Learn, checked September 2026.
- Enterprise data protection in Microsoft Copilot and Microsoft Copilot Chat, Microsoft Learn, checked September 2026.
- Anthropic models in Microsoft Online Services, Microsoft Learn, checked September 2026.
- Google HIPAA Included Functionality, for Gemini coverage, checked September 2026.
Related reading
ComplianceIs Google Workspace HIPAA Compliant? BAA, Plans and Setup
Read Article
ComplianceMicrosoft 365 HIPAA Compliance: The BAA, Copilot and Required Settings
Read Article
ComplianceBusiness Associate Agreement for HIPAA Compliance: Does Your IT Company Need One?
Read ArticleAlso on this topic: Shadow AI: Your Employees' Secret ChatGPT Use Is a Data Leak
Discuss hipaa compliance services for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.
