Compliance Answer

Is ChatGPT HIPAA Compliant?

The short answer is no, not the version your staff is using. Here is the tier-by-tier reality and what it takes to use AI with PHI safely.

The Verdict

ChatGPT is not HIPAA compliant by default. The free, Plus, and Pro versions offer no Business Associate Agreement, and OpenAI can use consumer conversations to train its models. Pasting PHI into them is a HIPAA violation.

OpenAI now runs four different HIPAA postures under one brand. Consumer tiers with no BAA path. A free ChatGPT for Clinicians with an individual in-product BAA. Sales-managed Enterprise and Edu BAAs. And the ChatGPT for Healthcare enterprise product. Knowing which one your staff are actually using is the compliance question, and on every path, the BAA is the entry ticket, not the compliance program.

Tier by tier (verified against OpenAI's published BAA and product pages, July 2026)
TierBAA availableTrains on your dataVerdict for PHI
ChatGPT Free / Plus / ProNoYes, by default (opt-out exists)Never
ChatGPT Team / self-serve BusinessNo (excluded per OpenAI's BAA article)NoNever, until OpenAI changes eligibility
ChatGPT for Clinicians (free, verified US clinicians: MD/DO, NP, PA, pharmacists)Yes: individual in-product BAA flowConfirm in product termsIndividual coverage only; organizations need ChatGPT for Healthcare
ChatGPT Enterprise / Edu (sales-managed) and ChatGPT for HealthcareYesNoPossible, with controls in place
OpenAI APIYes; no enterprise agreement required; zero-retention-eligible endpoints, case-by-caseNoPossible, for vetted applications

It Can Be Done. Is Your Organization Doing It?

OpenAI's healthcare offering, ChatGPT for Healthcare, launched January 2026 and is rolling out at named institutions including AdventHealth, Cedars-Sinai, HCA, and Stanford Medicine Children's Health, with BAA support, audit logs, and customer-managed encryption keys. That answers "can it be done." It does not answer "is your organization doing it."

During the New York Times copyright litigation, a 2025 federal court order required OpenAI to preserve consumer ChatGPT conversations, including chats users had deleted. OpenAI's obligations under that order ended September 26, 2025, but conversations preserved during the window stay preserved, and enterprise tiers were exempt throughout. The durable lesson is that consumer-tier prompts sit on infrastructure your organization does not control, subject to legal processes nobody will notify you about.

For how HIPAA rules apply to AI tools generally, see the full HIPAA and AI compliance breakdown.

A BAA Is Not a Compliance Program

Five gaps that exist under every BAA, until you close them. Closing them is what a 90-day governance path is built to do.

1

Access control

HIPAA requires knowing who used the tool and limiting PHI access to those who need it. A shared Enterprise login fails this on day one.

2

Audit trails

When OCR asks what happened, you need a record of every prompt that touched PHI. ChatGPT's admin console was not built to be your audit system.

3

Minimum necessary

Staff need training on what belongs in a prompt at all, even under a BAA.

4

Policy

An enforceable acceptable use policy that names approved tools and banned ones. Most organizations discover they have neither.

5

The multi-model problem

A ChatGPT BAA covers ChatGPT. Your staff also use Claude, Gemini, and a dozen note-taking tools. Governing one tool leaves the rest ungoverned.

Your Staff Did Not Wait

Your staff are not waiting for the compliance review. Samsung's engineers leaked source code to ChatGPT three times in twenty days, and healthcare runs the same pattern with higher stakes.

78% of healthcare workers use AI without IT approval, most of it through personal accounts no compliance program has reviewed. The question is not whether ChatGPT can be made compliant. It is whether your organization governs the AI use already happening.

ChatGPT and HIPAA: Common Questions

Is ChatGPT Plus HIPAA compliant?

No. No BAA is available on Plus, and consumer conversations can be used for training. The subscription price does not change the compliance status.

Does OpenAI sign a BAA?

Yes, on several distinct paths: sales-managed ChatGPT Enterprise and Edu accounts, the API (no enterprise agreement required, zero-retention-eligible endpoints), an individual in-product BAA for verified clinicians on ChatGPT for Clinicians, and ChatGPT for Healthcare for organizations. ChatGPT Business is explicitly not BAA-eligible. Get the scope confirmed in your contract before any PHI touches the system.

Is ChatGPT Enterprise HIPAA compliant?

It can support a compliant deployment. BAA, no training on your data, admin controls. Whether your use of it is compliant depends on your access controls, audit trail, training, and policy.

Can doctors use ChatGPT for clinical notes?

Not on consumer tiers with real patient information. With an enterprise agreement, governance controls, and de-identification where required, AI-assisted documentation is achievable. Purpose-built, BAA-covered tools are usually the better fit for clinical documentation.

What if staff already pasted PHI into ChatGPT?

Treat it as a potential breach. Assess what was disclosed, to which account tier, and whether the four-factor breach risk assessment requires notification. Then fix the governance gap that made it possible, because it will happen again.

Get the Policy Before the Incident

The fastest first step is an acceptable use policy your staff can actually follow. Generate a healthcare-ready draft in minutes, then talk to us about governing the tools your teams already use.