Is ChatGPT HIPAA compliant? What clinicians and therapists can (and can’t) do — and how to de-identify first (2026)
Is ChatGPT HIPAA compliant? Not in the version most clinicians log into. ChatGPT Free, Plus, Pro and Business are absent from OpenAI’s own list of HIPAA-eligible products, and on the business accounts its Services Agreement governs, processing protected health information requires a signed Healthcare Addendum. Since January 2026 there is a covered route: OpenAI lists ChatGPT for Healthcare, Enterprise with a Regulated Workspace, ChatGPT for Clinicians, its FedRAMP editions and the API on Modified Retention as the products a BAA can cover (list checked 12 September 2026). Even there, the tool is compliant only inside your organization’s program — and one route that avoids disclosing PHI at all is not to send it: de-identify the record on your own computer against the 18 identifiers, verify what is left, then use any AI on the copy. This page is general information, not medical or legal advice. (Source: OpenAI, “HIPAA eligible products and functionality”, accessed 12 September 2026.)
Is ChatGPT HIPAA compliant? Plan by plan
There is one answer per product, and OpenAI publishes it. For the business products OpenAI’s Services Agreement covers, the wording is blunt: “Customer agrees not to use the Services to create, receive, maintain, transmit, or otherwise process Protected Health Information, unless it has signed the Healthcare Addendum” — defined in the same document as “the OpenAI Healthcare Addendum and Business Associate Agreement provided by OpenAI to Customer”. (Source: OpenAI Services Agreement, §5.4, accessed 12 September 2026.)
| Plan or product | BAA? | What OpenAI’s own pages say |
|---|---|---|
| ChatGPT Free, Plus, Pro | No | None of them appears on OpenAI’s list of HIPAA-eligible products, so there is no BAA to sign for them and no eligible route for PHI. |
| ChatGPT Business | No | “Please note that we don’t offer a BAA for ChatGPT Business” — even though Business data is not used for training by default. |
| ChatGPT Enterprise / Edu | Conditionally | “Only ChatGPT Enterprise or Edu customers that have a sales-managed account are eligible for a BAA for ChatGPT at this time.” The eligible-products list names “ChatGPT for Enterprise with Regulated Workspace”. |
| ChatGPT for Healthcare | Yes | Supports HIPAA-compliant use through “Enterprise security controls. No training on data. Data retention controls. Availability of a Business Associate Agreement (BAA) with OpenAI.” |
| ChatGPT for Clinicians | Yes, self-serve | “Free for verified clinicians in the United States… designed for individual use, including the ability to sign a Business Associate Agreement (BAA)”, signed in ChatGPT under Settings > Agreements. |
| ChatGPT FedRAMP | Yes | Named on the HIPAA-eligible products list, alongside “API FedRAMP with Modified Retention”. |
| API Platform | Yes, with Modified Retention | “To use the API Platform, an enterprise agreement is not required to sign a BAA.” Eligibility is “contingent on Customer’s account being provisioned with Modified Retention”. |
| ChatGPT Health (consumer feature) | Not addressed | Its privacy notice sets training defaults for health conversations and connected records; it does not mention HIPAA or a BAA at all. |
(Sources: OpenAI, BAA eligibility, HIPAA eligible products, ChatGPT for Healthcare, ChatGPT for Clinicians, ChatGPT Health Privacy Notice (updated 29 June 2026), all accessed 12 September 2026.)
“No training” and “HIPAA eligible” are different switches. OpenAI says data from ChatGPT Business, Enterprise, ChatGPT for Healthcare, Edu, ChatGPT for Teachers and the API “isn’t used for training our models, unless you have explicitly opted in” — and ChatGPT Business still gets no BAA. (Source: OpenAI enterprise privacy, accessed 12 September 2026.) The reading is the same across the industry press: HIPAA Journal’s 2026 update states “Generic ChatGPT services are not HIPAA compliant… However, OpenAI now offers ChatGPT for Healthcare that can support HIPAA compliance under specific conditions”, and Witness AI puts the consumer side plainly: “Consumer tiers (Free, Plus, Pro, and ChatGPT Business) are not eligible for HIPAA BAAs.” (Sources: HIPAA Journal, 13 January 2026; Witness AI, “ChatGPT Enterprise and HIPAA: What a BAA Covers”, 21 July 2026 (updated 22 July); both accessed 12 September 2026.)
HIPAA-compliant ChatGPT: what OpenAI for Healthcare and a BAA actually give you
OpenAI announced the line on 8 January 2026 — “We’re introducing OpenAI for Healthcare, a set of products designed to help healthcare organizations deliver more consistent, high-quality care for patients” — and the help page for ChatGPT for Healthcare spells out what the product contributes: enterprise security controls, no training on the data, retention controls, and the availability of a Business Associate Agreement with OpenAI. (Sources: OpenAI, “Introducing OpenAI for Healthcare”, 8 January 2026; OpenAI help; accessed 12 September 2026.)
A solo clinician does not have to buy an enterprise contract to get that far. ChatGPT for Clinicians is “free for verified clinicians in the United States”, currently physicians (MD/DO), nurse practitioners, physician assistants and pharmacists; it is “designed for individual use, including the ability to sign a Business Associate Agreement (BAA)”, reviewed and signed “in ChatGPT under Settings > Agreements”. Content shared with it “is not used to train OpenAI’s models”. OpenAI’s own warning is the part to read twice: “Do not share PHI in ChatGPT for Clinicians unless a BAA is in place and you are authorized to sign a BAA for your account.” (Source: OpenAI, ChatGPT for Clinicians, accessed 12 September 2026.)
On the API, the phrase to unlearn is “zero data retention”. HIPAA eligibility there “is contingent on Customer’s
account being provisioned with Modified Retention… the endpoints listed below can be used for
processing PHI, even if data is retained, upon execution of the OpenAI BAA” — 21 named endpoints, including
/v1/chat/completions, /v1/responses, /v1/audio/transcriptions and
/v1/realtime. Features outside that perimeter are excluded even inside an eligible workspace:
improved memory, event-triggered scheduled tasks, Sites, browser use for Work in the cloud, and Codex in the cloud.
(Source:
OpenAI, HIPAA eligible products and functionality,
accessed 12 September 2026.)
And a signed BAA binds the vendor, not your workflow. It does not decide what the minimum necessary disclosure was, document your risk analysis or train your staff; those stay with the covered entity. “We have a BAA” is the first line of a compliance answer; HIPAA-compliant AI is a property of the whole program around the tool.
What counts as PHI — and when it stops
The definition comes first, the list second. Under 45 CFR 160.103, individually identifiable health information is health information, including demographic information, created or received by a health care provider, plan, employer or clearinghouse, relating to a person’s health, care or payment for care, and that “identifies the individual” or “with respect to which there is a reasonable basis to believe the information can be used to identify the individual”. Protected health information is that information once a covered entity or business associate holds or transmits it, in any form or medium. The 18 categories in the next section are not this definition — they are the list Safe Harbor tells you to remove.
The corollary matters more than either: “Health information that does not identify an individual and with respect to which there is no reasonable basis to believe that the information can be used to identify an individual is not individually identifiable health information.” De-identification is the switch that lets you share a record or feed it to AI. (Sources: 45 CFR 160.103, 45 CFR 164.514(a); accessed 12 September 2026.)
The 18 HIPAA identifiers (the Safe Harbor list)
This is the working checklist behind every “de-identify it first” instruction on this page — the identifiers of the individual, and of relatives, employers and household members, that Safe Harbor requires you to remove. The general version, with non-clinical examples, is on what is PII?; here is the clinical read. (Sources: HHS de-identification guidance (Wayback capture 11 September 2026; content last reviewed 3 February 2025), 45 CFR 164.514(b)(2)(i)(A)–(R); accessed 12 September 2026.)
| Identifier | Where it hides in a clinical record |
|---|---|
| (A) Names | The patient, relatives, household members, employers. |
| (B) Geographic subdivisions smaller than a state | Street address, city, county, precinct, ZIP code “and their equivalent geocodes”. Only the first three ZIP digits may survive, and only where that three-digit area holds “more than 20,000 people”; for smaller areas the three digits are “changed to 000”. |
| (C) All elements of dates except year | Date of birth, admission, discharge, death — plus “all ages over 89 and all elements of dates (including year) indicative of such age”, which may be aggregated into “age 90 or older”. |
| (D) Telephone numbers | The patient’s mobile number written into a referral or an intake form. |
| (E) Fax numbers | The patient’s own fax number on a scanned form. |
| (F) Email addresses | The patient’s address anywhere in the note, including a forwarded message header. |
| (G) Social security numbers | Intake forms and billing exports. |
| (H) Medical record numbers | The MRN in the header of every printed page. |
| (I) Health plan beneficiary numbers | Member IDs on insurance cards and claims. |
| (J) Account numbers | Billing and patient-portal account references. |
| (K) Certificate/license numbers | A driver’s license quoted in an ID check, a professional license number. |
| (L) Vehicle identifiers and serial numbers | Including license plate numbers — common in incident and injury notes. |
| (M) Device identifiers and serial numbers | Pump, pacemaker and implant serial numbers. |
| (N) Web URLs | A link to a patient’s page or a shared file. |
| (O) IP addresses | Telehealth logs and message metadata. |
| (P) Biometric identifiers, including finger and voice prints | A voice print is on the list; a recording can stay identifying after the spoken names are removed. |
| (Q) Full-face photographs and any comparable images | Full-face clinical photography and comparable images — a photo in the chart, a video still. |
| (R) Any other unique identifying number, characteristic, or code | A study ID, an internal code, or a detail rare enough to point at one person; the rule adds “except as permitted by paragraph (c) of this section”, its re-identification-code provision. |
The list reaches past text. (P) biometric identifiers, including finger and voice prints puts a voice print on the list, so a recording can carry an identifier that no edit to the transcript removes, and (Q) full-face photographs and any comparable images puts clinical photography there. Removing all 18 is also not the end of the test: Safe Harbor holds only if “the covered entity does not have actual knowledge that the information could be used alone or in combination with other information to identify an individual who is a subject of the information”. A rare diagnosis in a small town can fail that clause with every listed identifier gone.
HIPAA de-identification: Safe Harbor vs Expert Determination
There are exactly two routes to the de-identification of PHI, and they carry different costs. (Source: HHS (Wayback capture 11 September 2026), accessed 12 September 2026.)
- Safe Harbor — remove all 18 identifiers listed above, with no actual knowledge that the remainder could re-identify anyone. Mechanical, auditable, and the one an individual clinician can actually run.
- Expert Determination — under 45 CFR 164.514(b)(1)(i) a qualified expert determines “that the risk is very small that the information could be used, alone or in combination with other reasonably available information, by an anticipated recipient to identify an individual who is a subject of the information”, and documents the analysis. A residual-risk standard that still needs the expert.
The BAA trap: cloud AI processing PHI on your behalf is a business associate
This is where clinicians get caught. Cloud AI processing PHI on your practice’s behalf generally requires a BAA, and HHS is direct about why: “When a covered entity engages the services of a CSP to create, receive, maintain, or transmit ePHI… on its behalf, the CSP is a business associate under HIPAA” — an AI scribe, a summarizer or an online redactor included. Encryption does not buy an exemption: “This is true even if the CSP processes or stores only encrypted ePHI and lacks an encryption key for the data.” HHS repeats it in FAQ 2076, which answers the “no-view” pitch with a flat “Yes, because the CSP receives and maintains… electronic protected health information”. (Sources: HHS cloud computing guidance (Wayback capture 7 September 2026; content last reviewed 23 December 2022), HHS FAQ 2076 (Wayback capture 11 May 2026); accessed 12 September 2026.)
OCR has enforced the point. Its 2016 announcement is titled “Widespread HIPAA vulnerabilities result in $2.7 million settlement with Oregon Health & Science University”, and the settlement page records that “the settlement includes a monetary payment by OHSU to the Department for $2,700,000”. ePHI stored in a cloud service with no business associate agreement in place was one finding in a broader investigation, not the whole case. (Source: HHS, OHSU settlement, 18 July 2016 (Wayback capture 11 May 2026), accessed 12 September 2026.) The rulebook underneath is moving slowly: HHS has shifted the proposed Security Rule amendments (RIN 0945-AA22) to its long-term agenda, with July 2027 identified as the anticipated timeframe for final action. (Source: Clark Hill, 13 July 2026, accessed 12 September 2026.)
The way out of the trap isn’t a better contract — it’s not sending PHI. De-identify the record locally with Occlira and check what is left against Safe Harbor: if the copy you paste carries no identifiers, the AI vendor never receives protected health information and never becomes your business associate. Start the free trial →
HIPAA-compliant ChatGPT alternatives and PHI-anonymizing wrappers
Search for a HIPAA-compliant ChatGPT and you meet the wrappers. CompliantChatGPT describes itself as “a HIPAA-compliant conversational AI platform that generates clinical documentation, SOAP notes, differential diagnoses”, and its method is close to ours in shape: it “identifies PHI, replaces it with tokens in your messages to anonymize it” before the message reaches the model, restoring them afterwards; its site states that a BAA is available. BastionGPT says it is “HIPAA compliant, with a signed BAA on every plan, including the free trial” and that PHI “stays in a private, isolated environment”; elsewhere on the page it adds: “Never given to OpenAI, never used to train AI, and never sold to third parties.” Its plans are priced at $20 and $45 per user per month, and $75 per user per month for deployments of 100 or more. (Sources: compliantchatgpt.com, bastiongpt.com; own claims, accessed 12 September 2026.)
The structural difference is where the tokenizing happens. On both services, by their own descriptions, the record reaches the vendor’s servers so that the vendor can strip or isolate the PHI — which is why a BAA with that vendor is part of the offer. De-identifying on your own computer removes that step: the file with identifiers in it never leaves the machine you already control. Both models are defensible; they just put the trust boundary in different places.
Why pasting patient data into consumer AI is the risk
A paste into a consumer account is a disclosure to a vendor with no agreement in place — a compliance failure and a breach exposure in one move. The industry figures below are context for what a health data breach costs, not a measurement of AI leaks. IBM’s 2026 report puts the global average cost of a breach at $4.99 million, “a 12% increase over last year and a record high”, and HIPAA Journal’s coverage of the same report gives the sector line: “Healthcare continues to face the highest breach costs, with an average cost of $6.64 million per incident, although healthcare data breach costs have fallen by 10.5% year-over-year from a global average of $7.42 million in 2025.” (Sources: IBM, Cost of a Data Breach 2026; HIPAA Journal, 29 July 2026; accessed 12 September 2026.)
Where those losses land is documented too. HIPAA Journal counts 772 healthcare data breaches of 500 or more individuals in 2025, “the worst ever year for large healthcare data breaches”, exposing the PHI of 139,721,832 people — and the largest single entry is a business associate: “Conduent Business Services LLC | NJ | Business Associate | 62,224,658”. It is a reminder that every additional party holding PHI is another place it can be lost. (Source: HIPAA Journal, 5 June 2026, accessed 12 September 2026.)
ChatGPT for therapists: your notes, your recordings, and clients who use ChatGPT as a therapist
The phrase points at your own paperwork first. Psychotherapy notes are defined in 45 CFR 164.501 as “notes recorded (in any medium) by a health care provider who is a mental health professional documenting or analyzing the contents of conversation during a private counseling session… and that are separated from the rest of the individual’s medical record”, and the definition excludes medication prescription and monitoring, session start and stop times, test results and the treatment-plan summaries that stay in the chart. They also carry their own consent rule: under 45 CFR 164.508(a)(2) “a covered entity must obtain an authorization for any use or disclosure of psychotherapy notes”, except in the cases that paragraph lists — a BAA alone does not authorize the disclosure, and authorization is generally required unless an exception applies. Keep the notes out of any AI unless they are de-identified. A recording needs the same care in the audio and in the transcript: masking a name in the text leaves it audible, a voice print is identifier (P) on the list, and bleeping the spoken names is a step, not a finding that the recording is de-identified. (Sources: 45 CFR 164.501, 45 CFR 164.508(a)(2); accessed 12 September 2026.) The APA’s guidance for practice is the professional frame: “Psychologists must ensure that any tools they select can be used in a manner that is in compliance with HIPAA and other relevant data privacy regulations”, and “AI should augment, not replace, human decision-making”. (Source: APA, “Ethical Guidance for AI in the Professional Practice of Health Service Psychology” (updated July 2025), accessed 12 September 2026.)
Your clients are the other half of the question. Sentio’s survey reports that “48.7% of respondents who both use AI and self-report mental health challenges are utilizing major LLMs for therapeutic support”, and the plainest thing to tell them is what MedicalNewsToday published on 20 October 2025: “Unlike with a human therapist, there is no legal confidentiality when using ChatGPT.” Several states have now drawn a line for practitioners: Illinois’ Wellness and Oversight for Psychological Resources Act “prohibits anyone from using AI to provide mental health and therapeutic decision-making, while allowing the use of AI for administrative and supplementary support services for licensed behavioral health professionals”, with fines up to $10,000; Nevada’s AB 406, as summarized by Wilson Sonsini, “prohibits offering AI systems designed to provide services that constitute the practice of professional mental or behavioral healthcare (such as therapy)” from 1 July 2025, and Utah’s HB 452, also as summarized by Wilson Sonsini, “establishes new rules for the use of artificial intelligence (AI) mental health chatbots”. Check your own state before you automate anything clinical. (Sources: Sentio, 18 March 2025; MedicalNewsToday, 20 October 2025; IDFPR press release, 4 August 2025; Wilson Sonsini on Nevada AB 406, on Utah HB 452; accessed 12 September 2026.)
The EU angle: Article 9 special-category data
For EU-facing care, patient health data is GDPR Article 9 special-category data: processing is prohibited by default unless an Article 9(2) condition applies — explicit consent, or the healthcare-provision condition — on top of a normal Article 6 lawful basis. And pseudonymized patient data is still personal data; only information “rendered anonymous in such a manner that the data subject is not or no longer identifiable” leaves the GDPR’s scope, in the words of Recital 26. See use AI without breaking the GDPR. (Sources: GDPR Art. 9, GDPR Recital 26; accessed 12 September 2026.)
Where Occlira helps
| Task | How Occlira helps |
|---|---|
| Ask AI about a case or a note | De-identify the record first, run the AI on the copy, restore locally. |
| Summarize a session with AI | Strip patient identifiers before the note or transcript is sent. |
| Share records for referral or research | Helps remove identifiers; verify the output meets Safe Harbor or Expert Determination before treating it as de-identified. |
| Session & consultation recordings | Transcribe locally, bleep the spoken identifiers, mask the transcript — a step toward de-identification, not a finding. |
| Patient photos & scans | Blur faces and strip EXIF/metadata on your device, up to 40 photos per batch. |
| Access requests (DSAR / records requests) | Remove other people’s identifiers before releasing records. |
How Occlira fits — and what it isn’t
Occlira detects and removes patient identifiers from documents, spreadsheets and email on your own computer.
In Anonymize mode, Word and Excel files are rewritten in place with the formatting intact, while PDFs, .eml
messages and scans come out as an anonymized .txt with on-device OCR. Recordings are transcribed
locally and the spoken identifiers are bleeped in the audio; photos get a blur or a solid box over the face and
their EXIF/GPS stripped, up to 40 photos per batch. Detection runs offline — the app uses the network only to activate
the license (via Polar), download its model and check for updates. Occlira does not receive your
files, so this workflow does not make it your business associate; your own compliance program still
applies. It flags dates, addresses, numbers and the other listed identifiers, not just names; contextual clues
such as a rare diagnosis are yours to judge. Free for 14 days on Windows and macOS (Apple Silicon); one-time
license from €149 per seat, with team licenses available.
Frequently asked questions
Not on ChatGPT Free, Plus, Pro or Business: none of them appears on OpenAI’s HIPAA-eligible list, and on business accounts its Services Agreement bars processing PHI without a signed Healthcare Addendum. A BAA is available for ChatGPT for Healthcare, Enterprise with a Regulated Workspace, ChatGPT for Clinicians, ChatGPT FedRAMP and the API on Modified Retention. Your own safeguards still decide whether a use is compliant.
Yes, for named products. OpenAI states that an enterprise agreement is not required to sign a BAA for the API Platform, that only sales-managed ChatGPT Enterprise or Edu accounts are eligible, and that it does not offer a BAA for ChatGPT Business. Verified US clinicians can sign an OpenAI BAA in-product for ChatGPT for Clinicians under Settings > Agreements.
The elements Safe Harbor requires you to strip: names; geography below state level; all date elements except year; telephone, fax and email; SSN; medical record, health plan, account, certificate and license numbers; vehicle and device identifiers; URLs; IP addresses; biometrics including voice prints; full-face photographs; and any other unique identifying number, characteristic or code.
Removing the name alone isn’t enough. Safe Harbor requires removing all 18 identifiers, and you must have no actual knowledge the remainder could still identify the person — dates, ZIP, a rare condition and other quasi-identifiers can single someone out. De-identify against the full list, not just the name.
They are HIPAA’s two de-identification methods. Safe Harbor (45 CFR 164.514(b)(2)) means removing all 18 listed identifiers. Expert Determination rests on 164.514(b)(1)(i): a qualified expert determines “that the risk is very small that the information could be used… to identify an individual”, and documents the analysis. Data that meets either standard is no longer PHI.
Yes. A cloud service that creates, receives, maintains or transmits ePHI on your behalf is a business associate under HHS guidance, and that includes an AI scribe or an ambient documentation tool. A vendor that will not sign a BAA, or whose terms let it train on data you send outside BAA coverage, is a hard stop for PHI.
No. HHS is explicit: lacking an encryption key for the data it receives and maintains “does not exempt a CSP from business associate status and associated obligations under the HIPAA Rules”. Encryption is a safeguard, not an exemption.
No — health information that meets 45 CFR 164.514(a) is not individually identifiable health information, so the Privacy Rule no longer restricts its use. That is why de-identifying before you use AI or share a file is one route that avoids disclosing PHI at all, provided the de-identification holds.
Only on de-identified text, unless your practice runs a BAA-covered product and your policies allow it. Under 45 CFR 164.508(a)(2) a covered entity must obtain an authorization for any use or disclosure of psychotherapy notes, except in listed cases; a BAA alone does not authorize disclosure. A voice print is a listed identifier, and bleeping spoken names is a step, not a de-identification finding.
No BAA is needed: the files stay on your computer. Occlira does not receive your files, so this workflow does not make it your business associate. Treat it as a de-identification tool inside your own compliance program — it does not guarantee HIPAA compliance, and nothing here is legal or medical advice.
Keep patient data on your own machine
De-identify records and recordings locally, check what is left against the 18 identifiers, then use any AI tool on the copy. Free for 14 days on Windows and macOS.
More: redact a Word document · local vs cloud redaction · how your data is handled