ChatGPT on free, Plus, and Team plans is not HIPAA compliant and must not receive protected health information. OpenAI will enter into a Business Associate Agreement for Enterprise and API use with zero data retention configured. Without a signed BAA in place, any PHI entered is a reportable disclosure.
Short answer
ChatGPT on free, Plus, and Team plans is not HIPAA compliant and must not receive protected health information. OpenAI will enter into a Business Associate Agreement for Enterprise and API use with zero data retention configured. Without a signed BAA in place, any PHI entered is a reportable disclosure.
HIPAA compliance is not a property of software. It is a property of an arrangement: a signed Business Associate Agreement, plus configuration and practice that match it.
Where each OpenAI product stands
| Product | BAA available | Safe for PHI |
|---|---|---|
| Free and Plus | No | No |
| Team | No | No |
| Enterprise | Yes, on request | Yes, once signed |
| API | Yes, with zero data retention | Yes, once signed |
The key point for individual clinicians: your personal Plus subscription cannot be made compliant by turning off training. Training controls are a privacy setting, not a contractual protection, and HIPAA cares about the contract.
What counts as PHI here
The eighteen identifiers apply as they always do. In practice the accidental disclosures look like this:
Pasting a chart note to "make this readable for the patient"
Asking for a differential using a real date of birth and MRN
Uploading a scanned referral letter
Dictating a summary that names the patient and the practice
De-identification is a legitimate path. Strip names, dates more specific than year, geographic detail below state, and record numbers, and the remaining clinical question is generally not PHI. Be honest about whether a rare condition plus a small town is genuinely de-identified.
Getting a BAA
Enterprise customers request one through their OpenAI account contact. API users request it through the platform's trust and compliance route, and it is tied to zero data retention on the endpoints you use. Keep the signed agreement with your other business associate records, and note which endpoints and workspaces it covers, because it does not extend to a clinician's personal Plus account on the same laptop.
Record keeping
If AI assisted output ends up in patient care or documentation, your compliance team will eventually ask what was asked and what came back. Exporting conversations and converting them to PDF gives you a fixed, dated record that can be retained under your existing document policy rather than living inside a vendor's interface. Store those records with the same protection as any other PHI containing document.
Practical policy for a practice
No PHI on any plan without a signed BAA on file.
Approved de-identification checklist for clinicians using consumer accounts.
Named workspace for compliant use, personal accounts kept off clinical work.
Sessions relevant to care exported and retained under the practice's records policy.
Frequently asked questions
Can I make ChatGPT Plus HIPAA compliant?
No. A BAA is not offered for Plus, and no setting substitutes for one. Use Enterprise or the API with zero data retention.
Is de-identified clinical data allowed?
Properly de-identified information is outside HIPAA, but de-identification has to be genuine. Rare conditions plus location detail can still be identifying.
Does turning off training make ChatGPT compliant?
No. Training controls reduce privacy exposure but do not create the contractual relationship HIPAA requires.
What happens if PHI was already entered?
Treat it as a potential disclosure, follow your breach assessment process, delete the conversation, and document what happened.