You can use ChatGPT or any AI tool with patient information only on a plan your organization has a signed business associate agreement (BAA) for. HIPAA settings must be on. ChatGPT Free, Plus, Pro and Business don't qualify. Otherwise, fully de-identify the data first, or don't paste it.
Takeaways
The BAA is the dividing line
PHI can go only into a tool whose vendor has signed a BAA with you for that plan.
It's plan-specific
ChatGPT for Healthcare can be covered. ChatGPT Plus can't. Claude Enterprise can. Claude Team can't.
Features matter too
OpenAI and Anthropic both exclude certain features even under a BAA.
Send the minimum
Even with a BAA, share only the PHI the task needs.
What counts as patient data under HIPAA
Protected health information (PHI) is individually identifiable health information that a covered entity or business associate holds or sends. A name next to a diagnosis is PHI. So is a phone number on a refill list, a date of service on a claim, or a medical record number in a spreadsheet.
The test isn't whether the data looks clinical. It's whether it relates to a person's health, care or payment, and could identify them. A list of patient names and phone numbers from your scheduling system is PHI because it reveals who your patients are.
The BAA requirement
HIPAA defines a business associate as anyone who "creates, receives, maintains, or transmits PHI" on behalf of a covered entity. An AI vendor that processes your prompts and uploads fits that definition. HHS has said a cloud provider that stores ePHI is a business associate even if the data is encrypted.
So before PHI goes into an AI tool, you need a signed BAA with that vendor. The BAA is the contract that binds them to protect the data, report breaches, and limit what they do with it. No BAA means you have disclosed PHI to a vendor with no obligations to you.
Check three things, not one:
- The plan. Vendors sign BAAs for specific tiers only.
- The settings. Some plans need an admin to turn HIPAA on.
- The feature. Some features stay excluded even under the BAA.
Which mainstream AI tools can be covered (October 2026)
This list is current as of October 1, 2026. Vendors change terms often, so confirm on their legal pages before you rely on it.
| Feature | No BAA available | BAA-eligible |
|---|---|---|
| ChatGPT (OpenAI) | Free, Plus, Pro, Business (formerly Team) | ChatGPT for Healthcare; Enterprise or Edu with Regulated Workspace (sales-managed); ChatGPT for Clinicians (eligible accounts); API with Modified Retention |
| Claude (Anthropic) | Free, Pro, Max, Team. Cowork is not yet covered on any plan | Enterprise, once the Primary Owner enables HIPAA; first-party API |
| Microsoft Copilot | Consumer Copilot on a personal Microsoft account (for personal use; no BAA coverage stated) | Microsoft Copilot and Copilot Chat with a work (Entra) sign-in. Web search queries are not covered |
| Google Gemini | Consumer Gemini; Gemini in Chrome | Gemini in Workspace and the Gemini app under the Workspace BAA |
| Otter.ai | All plans except Enterprise | Enterprise only, with a signed BAA |
| Grammarly | All plans except Business Enterprise | Grammarly for Business Enterprise only |
A few details that trip people up:
- ChatGPT Business is not covered. OpenAI renamed ChatGPT Team to Business in August 2025. Its help center says "we don't offer a BAA for ChatGPT Business." Only sales-managed Enterprise and Edu accounts can get one.
- ChatGPT for Clinicians is free for verified US physicians, nurse practitioners, PAs and pharmacists. OpenAI says HIPAA support "is available through a BAA for eligible accounts."
- Claude Enterprise is not covered by default. Anthropic says standard Enterprise plans "do not include BAA coverage without action from a Primary Owner." Enabling HIPAA is one-way.
- Microsoft's BAA comes through the Data Protection Addendum by default. Copilot Chat gets enterprise data protection when users sign in with their Entra work account.
- Gemini in Chrome is excluded. Google's guide says access "via Gemini in Chrome is not HIPAA compliant."
For a deeper look at OpenAI specifically, read is ChatGPT HIPAA compliant.
Excluded features, even with a BAA
Both major model vendors carve out features:
- OpenAI excludes some features under its BAA, including improved memory, browser use in cloud work, and cloud Codex. The API's Web Search is not HIPAA eligible.
- Anthropic excludes Cowork, the Console, beta features, Web Fetch, Computer Use, MCP connectors and Claude in Chrome, among others. Claude Code is covered only with zero data retention on qualified accounts.
Your AI acceptable use policy should list these by name.
An AI workspace with the BAA included
Rivvi's free plan covers you and two colleagues, with a HIPAA BAA. No card. No clock.
Minimum necessary still applies
A BAA doesn't mean you can send everything. HIPAA's minimum necessary standard requires covered entities and business associates to "make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose." Disclosures for treatment and to the patient are exceptions.
In practice:
- To draft a reminder script, the AI doesn't need patient names. Use a template field.
- To find patients overdue for a visit, it needs dates of last visit, not diagnoses.
- To summarize a payer report, drop columns you won't use, like SSNs or full addresses.
De-identification: when data stops being PHI
De-identified data is not PHI, and HIPAA doesn't restrict it. There are two ways to get there.
Safe Harbor means removing 18 identifiers, and having no actual knowledge that what's left could identify someone. The 18 are:
- Names
- Geographic units smaller than a state (the first 3 ZIP digits may stay if that area has over 20,000 people)
- All date elements except year, and ages over 89 (group them as 90 or older)
- Phone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate and license numbers
- Vehicle identifiers, including plates
- Device identifiers and serial numbers
- URLs
- IP addresses
- Biometric identifiers, like finger and voice prints
- Full-face photos
- Any other unique identifying number, characteristic or code
Expert Determination means a qualified expert finds that the risk of re-identification is "very small" and documents the method.
Hand de-identification fails often. Dates of service, small-town ZIP codes and free-text notes slip through. If staff can't reliably strip all 18, treat the file as PHI and use a covered tool.
A simple decision path for staff
- Does the data identify a patient? If no, any approved tool is fine.
- If yes, is the tool on a plan with a signed BAA and HIPAA settings on? If no, stop.
- Is the feature you're using covered? If no, stop.
- Are you sending only what the task needs? Trim it, then go.
Rivvi was built so that step 2 is always yes. It's a HIPAA-compliant AI workspace where staff upload patient lists, payer reports and spreadsheets and work with them. The free plan includes a HIPAA BAA. Patient data is not used to train third-party models, and PHI access is logged. Compare it with general tools in Rivvi vs ChatGPT.
Use AI with patient data, with a BAA
You and two colleagues, with a HIPAA BAA. No card. No clock.
Sources
- OpenAI: HIPAA Implementation and Configuration Guide (July 9, 2026)
- OpenAI: How can I get a BAA with OpenAI
- OpenAI: HIPAA eligible products and functionality
- OpenAI: ChatGPT Business rename FAQ
- OpenAI: Making ChatGPT better for clinicians
- OpenAI API: Your data
- Anthropic: Business Associate Agreements for commercial customers
- Anthropic: HIPAA-ready Enterprise plans
- Microsoft: Enterprise data protection in Copilot
- Microsoft: Copilot FAQ
- Microsoft: HIPAA/HITECH offering
- Google Workspace: HIPAA Included Functionality
- Google: Workspace and Cloud Identity HIPAA implementation guide
- Otter.ai: HIPAA
- Grammarly: Is Grammarly HIPAA compliant?
- eCFR: 45 CFR 160.103 definitions
- eCFR: 45 CFR 164.502 minimum necessary
- eCFR: 45 CFR 164.514 de-identification
- HHS: Can a CSP be considered a conduit? (FAQ 2077)