Contact Us

Is ChatGPT HIPAA Compliant in 2026?

9 min read
Banner card with the title: Is ChatGPT HIPAA Compliant in 2026?
is chatgpt hipaa compliant is chatgpt business hipaa compliant is there a hipaa compliant chatgpt is chatgpt health hipaa compliant is chatgpt enterprise hipaa compliant is chatgpt for clinicians hipaa compliant

TL;DR

  • OpenAI signs BAAs for six named products only. No consumer plan and no ChatGPT Business among them.
  • A signed BAA does not make your use compliant. Configuration, retention and staff behaviour still decide that.
  • Several features sit outside the BAA even inside an eligible workspace, and OpenAI names them.

Last updated: 6 October 2026

Quick Answer: No, ChatGPT is not HIPAA compliant on its own, and OpenAI signs a BAA for six named products only. Those six are ChatGPT for Healthcare, Enterprise with Regulated Workspace, Clinicians, FedRAMP, and the API and API FedRAMP with Modified Retention. Free, Plus, Pro and Business are not among them, and your configuration still decides compliance.

Whether staff can put patient data into ChatGPT depends on which product they signed into and what contract sits behind it, not on how capable the model is.

HIPAA does not certify software. It puts duties on covered entities and on the business associates they hand protected health information to, and the contract carrying those duties is the Business Associate Agreement, or BAA. So the question is not whether ChatGPT as a brand is compliant, but whether the product your staff signs into is one OpenAI will sign that BAA for. OpenAI publishes that list and edits it often.

Is ChatGPT HIPAA compliant?

No ChatGPT product carries HIPAA compliance on its own, because compliance describes an organization and its practices, not a tool. What OpenAI offers is HIPAA eligibility: a defined set of products it will cover with a BAA. Outside that set there is no documented route to processing protected health information.

OpenAI product BAA available? How you get it Notes
Free, Go, Plus, Pro No documented route Not offered Not on the eligible list
ChatGPT Business No Not offered "We do not offer a BAA for ChatGPT Business"
ChatGPT Enterprise Yes, as a Regulated Workspace OpenAI sales Not every Enterprise workspace qualifies
ChatGPT Edu Yes OpenAI sales Same sales-managed route
ChatGPT for Healthcare Yes OpenAI sales Central admin controls
ChatGPT for Clinicians Yes In product, Settings > Agreements Verified US clinicians, individual use
OpenAI API Yes Self-serve, Settings > Organization Needs usage history and Modified Retention
FedRAMP products, ChatGPT and API Yes FedRAMP offering Listed separately

Compiled from OpenAI's HIPAA eligible products and functionality page, read 6 October 2026, which is the authoritative version.

Which ChatGPT plans will OpenAI sign a BAA for?

Two routes, plus FedRAMP. Enterprise with a Regulated Workspace, Edu and ChatGPT for Healthcare go through OpenAI sales. The API and ChatGPT for Clinicians are self-serve. Nothing else has a published route, which rules out every consumer plan and ChatGPT Business.

Is ChatGPT Enterprise HIPAA compliant?

Only where it is sold as a Regulated Workspace. The product on the eligible list is "ChatGPT for Enterprise with Regulated Workspace", not the Enterprise workspace you may already pay for. OpenAI routes Enterprise and Edu through sales, per its guide to getting a BAA. Ask your account team in writing which SKU you are on.

Is ChatGPT Business HIPAA compliant?

No, and OpenAI is direct: "We do not offer a BAA for ChatGPT Business." The admin controls Business carries, SSO included, do not create a BAA route. If a practice is on Business and staff handle PHI, the plan has to change, not the usage policy.

Is ChatGPT for Clinicians HIPAA compliant?

It is the one eligible product an individual can set up without procurement. OpenAI describes it as free for verified US clinicians: physicians, nurse practitioners, physician assistants and pharmacists, verified through a third party using an NPI. The BAA is signed under Settings > Agreements. Teams needing central controls are pointed to ChatGPT for Healthcare.

Can healthcare staff use ChatGPT with patient data?

Only inside a product OpenAI covers with a BAA, configured the way the agreement assumes, with the functionality outside the BAA switched off. Eligibility is not blanket: OpenAI lists features the agreement does not cover, and says features absent from its covered list are not automatically covered.

The functionality OpenAI placed outside the BAA on 6 October 2026:

In ChatGPT for Healthcare and Enterprise with Regulated Workspace these are off by default, and an admin can enable them per role for work that never touches PHI. The wider picture across plans is in our guide to whether ChatGPT is safe for confidential business data.

Is ChatGPT Health HIPAA compliant?

Health in ChatGPT is a consumer feature for logged-in Free, Go, Plus and Pro users in the United States aged 18 or over. It does not appear on OpenAI's HIPAA eligible product list, and no BAA covers it.

What else does HIPAA require beyond a signed BAA?

A BAA is the written "satisfactory assurances" HHS requires before a covered entity hands PHI to a vendor, and the Privacy Rule fixes its contents at 45 CFR 164.504(e). HHS's own list of business associate examples now includes a third-party vendor AI chatbot on a provider's patient portal.

OpenAI says the same about its own agreement: "Accepting a BAA and enabling HIPAA compliance support do not, by themselves, make your application HIPAA compliant." What sits on top of the contract is yours:

Teams that want this built rather than documented bring in an engineering partner who has shipped OpenAI integrations under a BAA.

Is there a HIPAA compliant ChatGPT alternative?

Three routes, not equivalent. Stay with OpenAI and move onto one of the six eligible products. Use another vendor's eligible service: AWS lists Amazon Bedrock among its HIPAA eligible services and requires an AWS business associate agreement before any PHI reaches it. Or deploy a private assistant inside infrastructure your own team administers.

The trade is who holds the controls. A managed cloud service is the better choice when you want the vendor carrying the infrastructure duties. A self-hosted deployment is the better fit when your security team needs the inference, documents and logs on systems it administers. Both shapes are covered in our guide to ChatGPT Enterprise alternatives and custom assistants.

How do you keep a human in the loop on healthcare AI workflows?

Put review where an error would reach a person or a record, not everywhere. Four control points cover most clinical and administrative workflows.

Workflow step Who reviews What is logged
Output reaches a patient Clinician or care coordinator Prompt, output, reviewer ID
Write-back to the record Clinician with charting rights Field, old and new values, timestamp
Low-confidence output Named reviewer for the queue Confidence signal, routing reason
Routine audit sample Compliance or quality lead Sampled cases, corrective actions

Voice workflows need the same discipline plus a disclosure at the start of the call. Our write-up on AI voice agents for healthcare covers handoffs.

What mistakes should a healthcare AI use policy prevent?

Each clause exists to stop a failure someone has already had.

How Origins AI Chat AI keeps patient data inside your environment

Origins AI (originshq.com) builds and deploys self-hosted enterprise AI, and Origins AI Chat AI is its private assistant platform. The company holds no HIPAA attestation and we make no compliance claim for it. Its product page documents controls your compliance team can review against the duties above.

According to the Origins AI Chat AI product page, read today, the platform deploys on your own servers or inside your own AWS, Azure or GCP account, with no shared tenancy. Identity runs through SAML 2.0 or OIDC, with role-based access control and document-level scoping. Every message, model call and retrieval event is logged with user ID, timestamp and session context, and the log is exportable. Stores and logs use AES-256 at rest and TLS 1.3 in transit, and PII is masked before storage.

Origins AI reports that with self-hosted models in on-premise or air-gapped deployments, conversation data never leaves your network. In a hybrid deployment the submitted context goes to the hosted model you route to, so a reviewer should ask which mode you run. The healthcare engineering page covers delivery.

Talk to an engineer

Scoping a private assistant for a clinical workload? Book a call to review the deployment, identity and audit design.

Frequently Asked Questions

Does upgrading from Plus to Pro change anything for PHI?
No. Neither Plus nor Pro appears on OpenAI's HIPAA eligible product list, so no BAA covers either, and the extra model access and higher rate limits you pay for are not contractual coverage. Moving PHI into ChatGPT means moving onto one of the six eligible products.
How do you get a BAA for the OpenAI API?
An organization admin opens Settings, goes to Organization then General, selects Enable under HIPAA compliance support, reviews the Business Associate and Healthcare Addendum, confirms authority and the organization ID, then selects Agree and enable. Self-serve enrollment requires an established history of API usage. If it reads "Not eligible yet", email baa@openai.com.
Does the API need Zero Data Retention for HIPAA?
No. OpenAI ties API eligibility to the account being provisioned with Modified Retention, and its HIPAA Implementation and Configuration Guide defines that as Modified Abuse Monitoring, Zero Data Retention, Safety Retention or Eyes Off. ZDR is one of four options, not the requirement.
Can you turn HIPAA support off once enabled on the API?
No. OpenAI states that once HIPAA compliance support is enabled for your organization, you cannot disable it in the API Platform settings. Treat the switch as one-way and decide first which organization carries PHI, because a sandbox org enabled by mistake keeps it.
Is it a HIPAA violation to paste patient notes into consumer ChatGPT?
Consumer plans carry no BAA, so a disclosure of PHI into one has no contractual safeguard behind it, and HHS treats a vendor handling PHI on a provider's behalf as a business associate. Whether a given disclosure is a violation turns on facts only your privacy officer can weigh.
Book a call

About the Author

Apoorva Kumar is Co-Founder and CEO of Origins AI (originshq.com), an AI engineering partner for product teams building AI workflows, AI agents and LLM integrations. A CSE graduate of IIT Kharagpur, Apoorva previously built and scaled technology at Sony, NuCash, YesMadam and FrontPage.