Reviewed by Jonathan West · Updated Jul 17, 2026

ChatGPT Enterprise and Codex for Medical Practices

A plain, compliance-first look at how a regulated practice can use OpenAI's enterprise tools.

Reviewed by Jonathan West · Updated Jul 17, 2026

ChatGPT Enterprise is OpenAI's business version of ChatGPT, an AI assistant your staff reach through chat, with admin and security controls built for organizations. Codex is OpenAI's cloud-based software engineering agent that writes, reviews, and debugs code, and it is available to ChatGPT Business and Enterprise users.

ChatGPT Enterprise is different from the consumer version in ways that matter for a regulated practice. OpenAI states it does not train its models on your business data by default, encrypts data at rest and in transit, is SOC 2 compliant, and adds an admin console with SSO, SCIM, and domain verification for managing accounts.

Medical practices care because patient information is protected under HIPAA. Stronger admin and data controls help, but a tool alone is not 'HIPAA compliant.' What you put into the tool, the plan you are on, and whether you have the right agreement in place decide whether use is appropriate.


What ChatGPT Enterprise and Codex Actually Are

ChatGPT Enterprise is the same chat assistant your team may already know, packaged with controls a business needs. Staff can draft documents, summarize information, and answer everyday questions inside one workspace.

Codex is a separate, technical tool. It is a coding agent that can write features, fix bugs, answer questions about a codebase, and propose changes for review. For most clinical and front-office staff, Codex is not the tool they will use day to day; it matters mainly if your practice has developers maintaining software.

  • ChatGPT Enterprise: a chat assistant for drafting, summarizing, and Q&A
  • Codex: a coding agent for technical teams, available on Business and Enterprise plans
  • Both run under your OpenAI account and the controls set by your admins

Want help deciding what is safe to use now and what needs a BAA first? Layer3 Labs can map it for your practice.

Book a Consultation

How Your Data Is Handled

OpenAI states it does not use ChatGPT Enterprise business data, inputs, or outputs to train or improve its models by default. This is a meaningful difference from the consumer product and is central to any compliance review.

ChatGPT Enterprise encrypts data at rest using AES-256 and in transit using TLS 1.2 or higher, and it is SOC 2 compliant. OpenAI also offers data residency options in several regions for eligible plans.

  • Business data is not used for model training by default
  • Encryption at rest (AES-256) and in transit (TLS 1.2+)
  • SOC 2 compliance and regional data residency on eligible plans
Confirm the exact data terms that apply to your account before any patient data is involved.

HIPAA and the BAA Question

Under HIPAA, your practice needs a Business Associate Agreement (BAA) with a vendor before it handles protected health information on your behalf. Without a BAA in place, you should not put PHI into the tool.

OpenAI can support a BAA on eligible paths. OpenAI offers a BAA for its API and for ChatGPT for Healthcare, and BAA eligibility for ChatGPT itself is limited to sales-managed Enterprise or Edu accounts. Verify your eligibility and current terms directly on OpenAI's trust portal.

  • A BAA is required before any PHI is processed by a vendor
  • OpenAI offers a BAA via the API and ChatGPT for Healthcare; ChatGPT BAA eligibility is limited to sales-managed accounts
  • A model by itself is never 'HIPAA compliant' — your setup and agreements decide compliance

Where It Helps a Practice Today

The lowest-risk starting points are tasks that do not require patient identifiers. Drafting general patient education, summarizing public clinical guidance, and writing internal policies are good first uses.

Tasks that touch PHI, such as summarizing a specific patient's chart, should wait until you have a BAA and a clear internal policy. Even then, a clinician must review any output before it informs care or goes into a record.

  • Draft general patient education and intake materials (no identifiers)
  • Summarize public guidelines and write internal SOPs
  • Prepare templates for common letters and forms
  • Hold PHI-involving uses until a BAA and policy are in place

Controls to Set Before You Roll Out

ChatGPT Enterprise gives admins tools to manage who has access and how the tool is used. Use them before staff begin, not after.

Pair the technical controls with a short written policy so staff know what they may and may not enter, and who to ask when unsure.

  • Turn on SSO and SCIM so access follows your directory
  • Verify your domain and assign admin roles
  • Write a one-page 'what not to paste' policy for staff
  • Keep usage analytics on to review adoption and misuse

How Layer3 Labs Helps

Layer3 Labs helps regulated small and midsize businesses adopt AI without guessing at the compliance details. For a medical practice that means matching the right OpenAI plan to your duties and confirming what is needed before any PHI is involved.

We translate the vendor's terms into a plain rollout plan: which tasks are safe now, which need a BAA first, and what to write down so an auditor can follow your reasoning.


What you need to run ChatGPT Enterprise and Codex for medical practices

The first question most medical practices teams ask is whether their current setup can handle ChatGPT Enterprise and Codex. For the standard cloud version, the answer is usually yes: ChatGPT Enterprise and Codex runs on the provider's servers, so the computers and internet connection you already have are enough to start — there is no server to buy and nothing to install across the firm.

What you do need is two things: access (a business plan or the API) and a tool to work in. Whoever wires ChatGPT Enterprise and Codex into your workflows will move fastest inside an AI IDE — Cursor is the most popular and connects to ChatGPT Enterprise and Codex directly — while the rest of the team uses ChatGPT Enterprise and Codex's own apps day to day.

The exception is compliance. If HIPAA and protected health information mean client data cannot leave your systems, the cloud version is off the table and you move to a private, on-prem setup: self-hosting an open-weights model on hardware you control. In practice that is a workstation with a strong GPU (an NVIDIA RTX 4090 build) or a large-memory Mac Studio for mid-size models, or RunPod to rent the same power by the hour. Our open-weights models for business guide walks through the full build.

Rule of thumb: most medical practices teams start on the cloud version with the computers they already have. Budget for an on-prem build only if HIPAA and protected health information rule out sending data to a third party.

Frequently Asked Questions

  • No tool is 'HIPAA compliant' on its own. ChatGPT Enterprise offers controls that support compliance, but you also need a Business Associate Agreement before any protected health information is involved, plus your own policies and safeguards.
  • OpenAI can support a BAA on eligible paths. It offers a BAA for its API and for ChatGPT for Healthcare, and BAA eligibility for ChatGPT itself is limited to sales-managed Enterprise or Edu accounts. Verify your eligibility on OpenAI's trust portal before relying on it.
  • OpenAI states it does not use ChatGPT Enterprise business data, inputs, or outputs to train its models by default. Confirm the exact terms that apply to your account, because consumer plans are handled differently.
  • Not until you have a BAA and an internal policy in place. Start with tasks that use no patient identifiers, such as general education content and internal documents.
  • Codex is OpenAI's coding agent for writing and reviewing software. Most medical practices do not need it unless they have developers maintaining applications. For clinical and front-office work, ChatGPT Enterprise is the relevant tool.
  • It includes an admin console with SSO, SCIM provisioning, domain verification, and usage analytics, so access follows your directory and admins can see how the tool is used.
  • Begin with tasks that involve no patient identifiers, set your admin controls, and write a short staff policy. Bring in a BAA and a clear PHI policy before any patient data is processed.

Get a Compliance-First AI Plan for Your Practice

Book a free 30-minute AI compliance review with Layer3 Labs. We will map safe first uses, flag what needs a BAA, and give you a clear rollout plan.

Book Your Free Review
Disclosure: Layer3 Labs is reader-supported. When you buy through links on this page we may earn an affiliate commission, at no extra cost to you. Our picks are chosen on the merits — commissions never influence the ranking.