Last updated: 6 October 2026
Quick Answer: No, ChatGPT is not HIPAA compliant on its own, and OpenAI signs a BAA for six named products only. Those six are ChatGPT for Healthcare, Enterprise with Regulated Workspace, Clinicians, FedRAMP, and the API and API FedRAMP with Modified Retention. Free, Plus, Pro and Business are not among them, and your configuration still decides compliance.
Whether staff can put patient data into ChatGPT depends on which product they signed into and what contract sits behind it, not on how capable the model is.
HIPAA does not certify software. It puts duties on covered entities and on the business associates they hand protected health information to, and the contract carrying those duties is the Business Associate Agreement, or BAA. So the question is not whether ChatGPT as a brand is compliant, but whether the product your staff signs into is one OpenAI will sign that BAA for. OpenAI publishes that list and edits it often.
Is ChatGPT HIPAA compliant?
No ChatGPT product carries HIPAA compliance on its own, because compliance describes an organization and its practices, not a tool. What OpenAI offers is HIPAA eligibility: a defined set of products it will cover with a BAA. Outside that set there is no documented route to processing protected health information.
| OpenAI product | BAA available? | How you get it | Notes |
|---|---|---|---|
| Free, Go, Plus, Pro | No documented route | Not offered | Not on the eligible list |
| ChatGPT Business | No | Not offered | "We do not offer a BAA for ChatGPT Business" |
| ChatGPT Enterprise | Yes, as a Regulated Workspace | OpenAI sales | Not every Enterprise workspace qualifies |
| ChatGPT Edu | Yes | OpenAI sales | Same sales-managed route |
| ChatGPT for Healthcare | Yes | OpenAI sales | Central admin controls |
| ChatGPT for Clinicians | Yes | In product, Settings > Agreements | Verified US clinicians, individual use |
| OpenAI API | Yes | Self-serve, Settings > Organization | Needs usage history and Modified Retention |
| FedRAMP products, ChatGPT and API | Yes | FedRAMP offering | Listed separately |
Compiled from OpenAI's HIPAA eligible products and functionality page, read 6 October 2026, which is the authoritative version.
Which ChatGPT plans will OpenAI sign a BAA for?
Two routes, plus FedRAMP. Enterprise with a Regulated Workspace, Edu and ChatGPT for Healthcare go through OpenAI sales. The API and ChatGPT for Clinicians are self-serve. Nothing else has a published route, which rules out every consumer plan and ChatGPT Business.
Is ChatGPT Enterprise HIPAA compliant?
Only where it is sold as a Regulated Workspace. The product on the eligible list is "ChatGPT for Enterprise with Regulated Workspace", not the Enterprise workspace you may already pay for. OpenAI routes Enterprise and Edu through sales, per its guide to getting a BAA. Ask your account team in writing which SKU you are on.
Is ChatGPT Business HIPAA compliant?
No, and OpenAI is direct: "We do not offer a BAA for ChatGPT Business." The admin controls Business carries, SSO included, do not create a BAA route. If a practice is on Business and staff handle PHI, the plan has to change, not the usage policy.
Is ChatGPT for Clinicians HIPAA compliant?
It is the one eligible product an individual can set up without procurement. OpenAI describes it as free for verified US clinicians: physicians, nurse practitioners, physician assistants and pharmacists, verified through a third party using an NPI. The BAA is signed under Settings > Agreements. Teams needing central controls are pointed to ChatGPT for Healthcare.
Can healthcare staff use ChatGPT with patient data?
Only inside a product OpenAI covers with a BAA, configured the way the agreement assumes, with the functionality outside the BAA switched off. Eligibility is not blanket: OpenAI lists features the agreement does not cover, and says features absent from its covered list are not automatically covered.
The functionality OpenAI placed outside the BAA on 6 October 2026:
- Chat. Workspace agents with agent-owned connections, internet access in Canvas and code blocks.
- Work. Browser and network access for Work in the cloud, event-triggered scheduled tasks.
- Codex. Computer History, Codex in the cloud, administering Codex security.
- Workspace. Sites, improved memory.
In ChatGPT for Healthcare and Enterprise with Regulated Workspace these are off by default, and an admin can enable them per role for work that never touches PHI. The wider picture across plans is in our guide to whether ChatGPT is safe for confidential business data.
Is ChatGPT Health HIPAA compliant?
Health in ChatGPT is a consumer feature for logged-in Free, Go, Plus and Pro users in the United States aged 18 or over. It does not appear on OpenAI's HIPAA eligible product list, and no BAA covers it.
What else does HIPAA require beyond a signed BAA?
A BAA is the written "satisfactory assurances" HHS requires before a covered entity hands PHI to a vendor, and the Privacy Rule fixes its contents at 45 CFR 164.504(e). HHS's own list of business associate examples now includes a third-party vendor AI chatbot on a provider's patient portal.
OpenAI says the same about its own agreement: "Accepting a BAA and enabling HIPAA compliance support do not, by themselves, make your application HIPAA compliant." What sits on top of the contract is yours:
- Access controls. Only people who need PHI reach the workspace or endpoint handling it.
- Audit logs. Who asked what, when, and what came back, retained long enough for review.
- Minimum necessary. Prompts carry the smallest slice of record that answers the question.
- Retention settings. The API org ID must carry Modified Retention before PHI moves.
- Staff policy. Written, acknowledged, refreshed when the product changes.
- Vendor risk review. BAA, subcontractor chain and covered-feature list, on a schedule.
Teams that want this built rather than documented bring in an engineering partner who has shipped OpenAI integrations under a BAA.
Is there a HIPAA compliant ChatGPT alternative?
Three routes, not equivalent. Stay with OpenAI and move onto one of the six eligible products. Use another vendor's eligible service: AWS lists Amazon Bedrock among its HIPAA eligible services and requires an AWS business associate agreement before any PHI reaches it. Or deploy a private assistant inside infrastructure your own team administers.
The trade is who holds the controls. A managed cloud service is the better choice when you want the vendor carrying the infrastructure duties. A self-hosted deployment is the better fit when your security team needs the inference, documents and logs on systems it administers. Both shapes are covered in our guide to ChatGPT Enterprise alternatives and custom assistants.
How do you keep a human in the loop on healthcare AI workflows?
Put review where an error would reach a person or a record, not everywhere. Four control points cover most clinical and administrative workflows.
| Workflow step | Who reviews | What is logged |
|---|---|---|
| Output reaches a patient | Clinician or care coordinator | Prompt, output, reviewer ID |
| Write-back to the record | Clinician with charting rights | Field, old and new values, timestamp |
| Low-confidence output | Named reviewer for the queue | Confidence signal, routing reason |
| Routine audit sample | Compliance or quality lead | Sampled cases, corrective actions |
Voice workflows need the same discipline plus a disclosure at the start of the call. Our write-up on AI voice agents for healthcare covers handoffs.
What mistakes should a healthcare AI use policy prevent?
Each clause exists to stop a failure someone has already had.
- An unapproved tool in daily use. Name the product and the plan tier, because the tier carries the BAA.
- PHI in a surface nobody reviewed. State what counts as PHI and which features stay off limits.
- Prompt hygiene nobody taught. Require de-identified prompts where the task allows it.
- Retention assumed, not checked. Record which option each org ID carries.
- An incident reported late. One route, one owner, one deadline, privacy officer named.
- Training that happened once. Retrain when the covered-feature list changes.
How Origins AI Chat AI keeps patient data inside your environment
Origins AI (originshq.com) builds and deploys self-hosted enterprise AI, and Origins AI Chat AI is its private assistant platform. The company holds no HIPAA attestation and we make no compliance claim for it. Its product page documents controls your compliance team can review against the duties above.
According to the Origins AI Chat AI product page, read today, the platform deploys on your own servers or inside your own AWS, Azure or GCP account, with no shared tenancy. Identity runs through SAML 2.0 or OIDC, with role-based access control and document-level scoping. Every message, model call and retrieval event is logged with user ID, timestamp and session context, and the log is exportable. Stores and logs use AES-256 at rest and TLS 1.3 in transit, and PII is masked before storage.
Origins AI reports that with self-hosted models in on-premise or air-gapped deployments, conversation data never leaves your network. In a hybrid deployment the submitted context goes to the hosted model you route to, so a reviewer should ask which mode you run. The healthcare engineering page covers delivery.
Talk to an engineer
Scoping a private assistant for a clinical workload? Book a call to review the deployment, identity and audit design.


