Skip to main content

Plain Answers · Healthcare

Is ChatGPT HIPAA compliant?
No product is. Deployments are.

No AI chatbot is "HIPAA compliant" as a product, and that isn't a knock on any one of them. Compliance is a property of how a system is deployed and governed, not a badge a vendor earns. What matters is whether a Business Associate Agreement covers the exact product you're using, where the processing happens, and what gets retained.

Rules that may apply to you

Depending on what you do and who you serve, you may be subject to rules such as the ones below. We link the official sources and leave the interpretation to your privacy officer or health care counsel. This is a starting point, not a complete list, and nothing on this page says what these rules require of you.

Why there's no yes-or-no answer

Health privacy rules generally attach to organizations and the vendors who work for them, not to a piece of software. That's why the same chatbot can be fine in one arrangement and a problem in another. If your practice is a covered health care provider, you may be subject to the federal HIPAA rules and, in California, to the Confidentiality of Medical Information Act, among others. Both are linked above. Your privacy officer or counsel can tell you how they apply to you; we can't, and neither can a vendor's sales page.

In practice, the conversation with any vendor that would handle patient information starts with a Business Associate Agreement — a BAA — the contract health care organizations commonly put in place with such vendors. So the useful question is never "is this chatbot compliant?" It's "is there a signed agreement that covers this product, on this plan, for this use?" If you opened the account with a personal email and clicked "I agree," you almost certainly didn't sign one.

What to ask the vendor — in writing

  1. Will you sign a BAA for this specific product and plan? Vendors that offer one often limit it to certain products or tiers. Get the product name into the agreement.
  2. Is our data used to train or improve your models? Ask which document makes that promise.
  3. How long are prompts, outputs, uploads, and logs kept? Ask about safety-monitoring copies too, and whether retention can be set to zero.
  4. Can your staff or contractors read our conversations? Under what circumstances, and is it logged?
  5. Which subcontractors touch the data? Ask for the list, and whether each one is under a written agreement with the vendor.
  6. Where is it processed and stored?
  7. What happens to our data when we leave?
  8. How, and how fast, will you tell us about a security incident?

A good answer names a document, a product, and a number. A weak answer is a marketing page with "HIPAA-ready" or "enterprise-grade security" on it and nothing you could hold anyone to.

A signed BAA is the start, not the finish

A contract covers the vendor. It doesn't cover how your staff use the tool. Before go-live, ask your privacy officer two things: whether the new tool belongs in your security risk assessment, and how much of a chart should ever go into a prompt. Pasting an entire record to get help wording one paragraph is the habit to watch for. A model can't leak what it was never given.

California adds its own layer

California practices may also be subject to state medical-privacy law, including the Confidentiality of Medical Information Act linked above. How the state and federal rules fit together for your practice is a question for your counsel. For planning purposes it means a California clinic may have two sets of questions to satisfy, and a vendor's answer about HIPAA doesn't automatically answer the second set. Ask vendors about both, by name.

What we check when we deploy

  • A one-page data map. Every place a prompt, file, transcript, or log comes to rest. If we can't draw it on one page, the design is too complicated.
  • Nothing leaves. The AI server gets firewall rules that block outbound traffic. Then we unplug the uplink and confirm it still answers.
  • Individual logins, by role. The front desk and the clinicians don't see the same things. No shared passwords.
  • Logs are patient data too. A record of who asked what contains the same information as the chart. It gets the same encryption and the same retention schedule.
  • The backup drive. In a small office it's the thing most likely to walk out the door. It's encrypted or it doesn't exist.
  • Model updates by file, not by opening a port.
  • Our own paperwork. If we support a system that holds patient information, we may need an agreement of our own with you. We're willing to sign a BAA, and we'd expect to have that conversation before we touch anything.

What a private deployment changes — and what it doesn't

When the model runs on a server in your own office, no outside AI vendor receives patient information, so most of the vendor questions above fall away and retention becomes your decision. A single 24GB graphics card — the class of hardware that runs the assistant on this website — is enough to draft and summarize for a small practice. Entry servers run $1,500 to $7,500, and the compliance-driven design work around them is what moves a project toward the higher end of our published ranges.

What it doesn't change: you still need the risk analysis, the access controls, the policies, and the staff training. Anyone who tells you a box makes you HIPAA compliant is selling the box. For the general, non-medical version of this question, see Is ChatGPT safe for business documents?

FAQ

Quick answers.

Is ChatGPT HIPAA compliant?
No AI chatbot is "HIPAA compliant" as a product. Compliance is a property of how a system is deployed and governed, not a badge a vendor earns. The questions that matter are whether a signed Business Associate Agreement covers the specific product and plan you use, where the processing happens, and what is retained. Ask the vendor in writing, and review the answers with your privacy officer or counsel.
What is a BAA, and do I need one for an AI tool?
A Business Associate Agreement, or BAA, is the contract health care organizations commonly put in place with vendors that handle patient information on their behalf. Whether you need one with a particular AI vendor depends on what that vendor would do with your data. Your privacy officer or counsel should make that call before any patient information goes in.
Does running AI on our own server make us HIPAA compliant?
No. It removes an outside AI vendor from the data path, which simplifies the vendor questions and puts retention in your hands. You still need a risk analysis, access controls, audit logs, written policies, and staff training. A server is one component of a compliant deployment, never the whole thing.

Next: what this looks like in a real practice.

Behavioral health carries some of the strictest confidentiality expectations in medicine, so it's where we've thought hardest about in-house AI. See what we build for therapy practices.

Private AI for Therapists

© 2024–2026 Integral Business Intelligence. Archivist™, Interchange™, and Sentinels™ are trademarks of Integral Business Intelligence.

Website v3.2.0 design and development by Integral Business Intelligence with assistance from AI.