Is ChatGPT HIPAA Compliant? A 2026 BAA Guide
A straight answer, what a BAA covers, and how to use OpenAI with health data safely.
ChatGPT is not HIPAA compliant by default. OpenAI will sign a Business Associate Agreement (BAA) for eligible use, but you must set it up first. Without that step, ChatGPT cannot lawfully touch protected health information (PHI).
OpenAI signs a BAA for API use on zero-data-retention endpoints and for sales-managed ChatGPT Enterprise accounts. Consumer ChatGPT tiers get no BAA and must never receive PHI.
This guide explains what a BAA does, which OpenAI surfaces qualify, the compliant build path, and safer alternatives when a BAA is not in place.
Is ChatGPT HIPAA Compliant Out Of The Box?
No. ChatGPT is not HIPAA compliant when you sign up and start typing. HIPAA compliance is never a product feature you get automatically.
HIPAA requires a signed BAA between the covered entity and its vendor before any PHI is shared. No BAA means no lawful PHI use.
OpenAI publishes that it can sign a BAA to support customer HIPAA compliance, but only for specific products and configurations. You have to request it and turn on the right settings.
So the real question is not whether ChatGPT is compliant. It is whether your OpenAI account and surface are set up correctly under a BAA.
Want the whole playbook, not just this page? The Complete Medical Practice AI Implementation Guide (2026) is the full step-by-step rollout for medical & dental practices.
Get the guide — $59 (reg. $89)Which OpenAI Surfaces Can Be Covered By A BAA
OpenAI will sign a BAA for two main paths: the OpenAI API and sales-managed ChatGPT Enterprise accounts. Each has conditions you must meet.
For the API, only zero-data-retention (ZDR) eligible endpoints fall under the BAA. You request the agreement by contacting OpenAI, then run PHI workloads through those endpoints.
For ChatGPT itself, OpenAI states that only sales-managed ChatGPT Enterprise and Edu accounts are eligible for a BAA. OpenAI also markets a dedicated ChatGPT for Healthcare offering built on that Enterprise stack.
Scope changes over time, so confirm the current list on OpenAI's help center before you rely on it. If anything is unclear, email OpenAI and ask them to confirm eligibility in writing.
- OpenAI API on ZDR-eligible endpoints, under a signed BAA.
- Sales-managed ChatGPT Enterprise or Edu accounts that OpenAI confirms are BAA-eligible.
- OpenAI's ChatGPT for Healthcare product, which bundles a BAA on the Enterprise compliance stack.
Consumer ChatGPT Is Never Covered
Consumer ChatGPT tiers are not HIPAA eligible and get no BAA. This includes ChatGPT Free, Plus, Pro, Team, and self-serve Business.
OpenAI is explicit that these tiers cannot be used with PHI. Putting patient data into them is a HIPAA violation, even for a single note.
The risk is easy to miss because these products feel private. A personal login and a paid plan do not create a business associate relationship.
If your staff use the same ChatGPT app they use at home, assume no BAA exists. Treat every one of those surfaces as off-limits for PHI.
What A BAA Covers And What It Does Not
A BAA is a contract that makes OpenAI a business associate responsible for safeguarding your PHI. It is required by HIPAA whenever a vendor handles PHI on your behalf.
The BAA sets rules for how OpenAI may use and protect the data, and how it reports any breach. It shifts specific legal duties onto the vendor.
A BAA does not make you compliant on its own. It covers the vendor's side of a shared responsibility, not yours.
You still own access controls, workforce training, minimum-necessary limits, and audit logging inside your own systems. The contract is the floor, not the whole building.
- Access controls: restrict who can send PHI to the model and who sees output.
- Minimum necessary: send only the health data the task truly needs.
- Audit and logging: record who used the tool, when, and for what.
- Workforce training: teach staff which surface is approved and which is banned.
The Compliant Build: API Plus Zero Data Retention
The cleanest compliant path is the OpenAI API with a signed BAA and zero data retention turned on. This is the option most healthcare products choose.
Zero data retention means OpenAI processes your request and stores no content afterward. The BAA covers only ZDR-eligible endpoints, so your build must stay inside that set.
You request the BAA from OpenAI, get your organization provisioned, then route PHI only through the covered endpoints. Do not assume every API feature is in scope.
Some features, such as live web search against the open internet, are not HIPAA eligible. Check each endpoint against OpenAI's current eligibility list before you send real data.
In our AI-compliance work with healthcare-adjacent and nonprofit clients, the failure we see most is staff pasting client data into consumer AI tools with no BAA. A gated API build removes that temptation by giving them one approved door.
De-Identification: Using ChatGPT Without Triggering HIPAA
You can use consumer ChatGPT for health tasks if the data is not PHI. De-identified data falls outside HIPAA, so no BAA is needed.
De-identification means stripping the identifiers that tie data to a person. HIPAA sets a formal standard for this under its Privacy Rule.
In practice, this is harder than deleting a name. Dates, rare conditions, locations, and record numbers can re-identify a patient when combined.
If you cannot be confident the data is truly de-identified, treat it as PHI. When in doubt, use the BAA-covered API path instead.
- Remove names, contact details, record numbers, and account IDs.
- Generalize dates and locations that could pinpoint one person.
- Watch for rare diagnoses or small populations that re-identify by inference.
- Document your de-identification method so you can defend it later.
Compliant Alternatives To Consumer ChatGPT
If a direct OpenAI BAA does not fit, other vendors offer GPT-class models under their own BAA. Two common routes are Azure OpenAI and Claude.
Azure OpenAI runs OpenAI models inside Microsoft Azure, which offers a HIPAA BAA covering in-scope services. Health teams already on Azure often prefer this because the data stays in their existing cloud contract.
Claude, from Anthropic, can also be covered by a BAA on eligible commercial plans. It is a strong option for drafting, summarizing, and reasoning over de-identified or BAA-covered data.
Whichever vendor you pick, the rules are the same. Sign the BAA first, enable the right retention settings, and keep your own access controls tight.
- Azure OpenAI under a Microsoft BAA, for teams standardized on Azure.
- Claude on BAA-covered plans, reviewed on our Claude HIPAA guide.
- Direct OpenAI API with a BAA, for teams that want the source vendor.
Consumer ChatGPT Vs API With BAA Vs Azure OpenAI
The three surfaces differ sharply on whether they can lawfully touch PHI. The table below shows the practical split.
Consumer ChatGPT is convenient but has no BAA, so it is banned for PHI. The API with a BAA and Azure OpenAI are both viable when configured correctly.
Use this as a starting map, not a final answer. Confirm current terms with each vendor before you commit patient data.
- Consumer ChatGPT (Free/Plus/Pro/Team): no BAA available, PHI prohibited, easy staff access is the risk.
- OpenAI API with BAA + ZDR: BAA available, PHI allowed on eligible endpoints, needs an engineering build.
- Azure OpenAI: Microsoft BAA available, PHI allowed on in-scope services, fits teams already on Azure.
Verdict: Can You Use ChatGPT With Health Data?
You can use OpenAI with health data, but only through a signed BAA and the right surface. Consumer ChatGPT stays off the table for PHI.
For most teams, the safe answer is the OpenAI API with a BAA and zero data retention, or Azure OpenAI under a Microsoft BAA. Both require setup before any patient data flows.
If you only need help with de-identified data, consumer ChatGPT can work, as long as the de-identification is genuine and documented.
The one thing you must never do is treat the everyday ChatGPT app as safe for patient notes. Set up the contract and the controls first, then let staff use the tool.
Frequently Asked Questions
- No, not by default. ChatGPT becomes usable with PHI only when you have a signed BAA with OpenAI and use an eligible surface, such as the API on zero-data-retention endpoints or a sales-managed ChatGPT Enterprise account.
- Yes. OpenAI will sign a BAA to support HIPAA compliance for eligible use. You request it from OpenAI, and it applies to the API on ZDR-eligible endpoints and to sales-managed ChatGPT Enterprise or Edu accounts that OpenAI confirms are eligible.
- It can be. OpenAI states that only sales-managed ChatGPT Enterprise and Edu accounts are eligible for a BAA. Self-serve Business, Team, Plus, Pro, and Free are not eligible, so confirm your account type and BAA status directly with OpenAI.
- No. ChatGPT Plus is a consumer tier with no BAA. Entering PHI, including patient notes, is a HIPAA violation. Use a BAA-covered API build or an eligible Enterprise account instead.
- Zero data retention means OpenAI processes your request and stores no content afterward. The OpenAI BAA covers only ZDR-eligible endpoints, so a compliant build routes PHI only through those covered endpoints.
- Yes. Azure OpenAI runs OpenAI models under a Microsoft BAA, and Claude can be covered by a BAA on eligible plans. Both require you to sign the BAA and configure retention and access controls before sending PHI.
- No. A BAA covers the vendor's duties, not yours. You still must handle access controls, minimum necessary, workforce training, and audit logging inside your own systems for full compliance.
- Only if the data is genuinely de-identified under the HIPAA standard, which is more than deleting names. Dates, rare conditions, and locations can re-identify a person. If you are unsure, treat it as PHI and use a BAA-covered path.
The complete AI playbook for medical & dental practices
The Complete Medical Practice AI Implementation Guide (2026): HIPAA-compliant vendor selection, scribes, voice agents, scheduling and intake, front-desk automation, dental-specific plays, and the specialty cuts — for the owner rolling AI into a real practice in 2026.
Get the guide — $59 (reg. $89)