For healthcare & therapists

AI and patient confidentiality for healthcare & therapists

Published 3 July 2026 · Updated 17 July 2026 · Occlira team

You can use AI on clinical work safely — but not with identifiable patient data in it. The safe path is to de-identify the record on your own computer first, use the AI on the de-identified version, then restore the details locally. This page is general information, not medical or legal advice.

Short answer. Consumer AI has no Business Associate Agreement, so pasting identifiable patient data into it is a HIPAA problem — and removing only the name doesn’t fix it. De-identify against the full 18-identifier list locally with Occlira, then use any AI tool on the de-identified copy — with no BAA to sign, because the data never leaves your computer.

What counts as PHI — and when it stops

Protected health information is health information tied to one of HIPAA’s 18 identifiers and held by a covered entity or business associate. The important corollary: once data is properly de-identified under 45 CFR 164.514(a) it’s no longer PHI, and the Privacy Rule no longer restricts its use. De-identification is the switch that lets you share a record or feed it to AI. The full 18-identifier list is in what is PII?

HIPAA’s two de-identification methods

There are exactly two. (Source: HHS.)

  • Safe Harbor — remove all 18 identifiers, with no actual knowledge the remainder could re-identify anyone. The list explicitly includes (P) biometric identifiers such as voice prints and (Q) full-face photographs — so audio and images are squarely in scope, not just text.
  • Expert Determination — a qualified expert certifies the re-identification risk is “very small” and documents it. It’s a residual-risk standard, not a claim of zero risk.

The BAA trap: any cloud AI tool touching PHI is a business associate

This is where clinicians get caught. Under HHS guidance, any cloud service — an AI scribe, a summarizer, an online redactor — that creates, receives, maintains or transmits ePHI is a business associate that needs a signed BAA, and that holds even for a “no-view” service that only stores encrypted data and lacks the decryption key. (Source: HHS, FAQ 2076.) OCR has enforced it — a $2.7M settlement over ePHI stored on a cloud server with no BAA. AI medical scribes are business associates too: no BAA, hard stop. (Source: Medcurity.)

The way out isn’t a BAA — it’s not sending PHI at all. De-identify locally with Occlira and the tool never becomes a business associate, because it never receives PHI. Start the free trial →

Why pasting patient data into consumer AI is the risk

Free and consumer AI tools have no BAA, and most retain and train on what you enter by default. Pasting identifiable patient information into one is a disclosure to a business associate with no agreement in place — a compliance failure and a breach exposure at once. And the stakes are high: healthcare has been the costliest sector for breaches for 14 straight years (a $7.42M US average in 2025, taking ~279 days to contain). (Source: IBM.) Tellingly, 2025’s largest healthcare breach hit a business associate, exposing 62M+ people — the case for minimizing which third parties ever touch identifiable data. (Source: HIPAA Journal.)

Session and consultation recordings

Recordings are PHI, and the voice itself is an identifier. To share a session recording or feed it to AI, you have to strip identifiers from both the audio and the transcript — masking the name in the text leaves it audible in the recording. Psychotherapy notes get extra HIPAA protection, so keep them out of AI entirely unless de-identified. Occlira transcribes locally and bleeps the audio; see remove personal data from audio recordings.

Occlira de-identifying a consultation recording on-device: a synced transcript with spoken names and numbers flagged, and a waveform showing the bleeped segments.
De-identifying a session recording locally — the spoken identifiers are bleeped in the audio and masked in the transcript.

The EU angle: Article 9 special-category data

For EU-facing care, patient health data is GDPR Article 9 special-category data: processing is prohibited by default unless an Article 9(2) condition applies — explicit consent, or the healthcare-provision condition — on top of a normal Article 6 lawful basis. And pseudonymized patient data is still personal data; only true anonymization leaves GDPR’s scope. See use AI without breaking the GDPR.

Where Occlira helps

TaskHow Occlira helps
Ask AI about a case or a noteDe-identify the record first, run the AI on the copy, restore locally.
Summarize a session with AIStrip patient identifiers before the note or transcript is sent.
Share records for referral or researchRemove identifiers so the shared copy isn’t PHI.
Session & consultation recordingsTranscribe locally, bleep names in the audio, mask the transcript.
Patient photos & scansBlur faces and strip EXIF/metadata on your device.
Access requests (DSAR / records requests)Redact other people’s data before releasing records.

How Occlira fits — and what it isn’t

Occlira detects and removes patient identifiers from documents, spreadsheets, email, audio and images entirely on your own computer — no cloud, no account. Because it never receives the data, there’s no business-associate relationship to manage with Occlira and nothing to sign a BAA for: the identifiers are stripped before any AI or cloud tool sees the file. It also flags indirect identifiers, not just names, which is what Safe Harbor actually requires.

Occlira flagging patient identifiers — names, dates, an address, a phone number and a record number — in a clinical note for local review before a clinician uses an AI tool.
Occlira flags the identifiers in a clinical note so you can remove them locally, before any AI tool sees the record.
Please note. Occlira is a tool that helps you de-identify — it is not a HIPAA-compliance guarantee (compliance is a property of your organisation and processes, not any one tool), and nothing here is legal or medical advice. Reversible anonymization is pseudonymization, which is still personal data under the GDPR. See exactly what stays on your device on the Data & Privacy Practices page.

Frequently asked questions

Consumer ChatGPT isn’t built for PHI: it has no Business Associate Agreement, and pasting identifiable patient information into it is a disclosure to a business associate with no agreement in place. You can still use AI safely by de-identifying the patient data on your own computer first, so the tool never receives PHI.

Removing the name alone isn’t enough. HIPAA’s Safe Harbor method requires removing all 18 identifiers, and you must have no actual knowledge the rest could still re-identify the person — dates, ZIP, a rare condition and other quasi-identifiers can single someone out. De-identify against the full list, not just the name.

They’re HIPAA’s two de-identification methods. Safe Harbor (45 CFR 164.514(b)(2)) means removing all 18 listed identifiers. Expert Determination (164.514(b)(1)) means a qualified expert certifies the re-identification risk is “very small” and documents it. Once data meets either standard it’s no longer PHI.

Yes. Any cloud service — including an AI scribe or ambient documentation tool — that creates, receives, maintains or transmits ePHI is a business associate and needs a signed BAA before it processes a single encounter. A vendor that won’t sign one, or reserves the right to use PHI to train its models, is a hard stop.

No. HHS is explicit: a cloud provider that stores ePHI is a business associate even if it only holds encrypted data and lacks the decryption key. Encryption is not an exemption from the BAA requirement.

No — once health data is properly de-identified under 45 CFR 164.514(a), it’s no longer PHI and the Privacy Rule no longer restricts its use. That’s exactly why de-identifying before you use AI or share a file is the safe move.

Session recordings are PHI, and a voice print is itself an identifier. Transcribe locally, then remove identifiers from both the audio (bleep the names and numbers) and the transcript. Occlira does this on your device — see redact audio recordings.

Occlira runs entirely on your own computer and never receives your data, so there’s no business-associate relationship to manage with Occlira and nothing to sign a BAA for. It’s a tool that helps you de-identify — not a HIPAA-compliance guarantee, and not legal or medical advice.

Keep patient data on your own machine

De-identify records and recordings locally, then use any AI tool on the copy. Free for 14 days on Windows and macOS.

More: redact Word, PDF & Excel · is ChatGPT safe for confidential data? · local vs cloud redaction · how your data is handled