Home / HIPAA-compliant AI

Guide · Updated September 2026

Is AI HIPAA compliant? Wrong question — here's the right one.

There is no such thing as a HIPAA-certified AI tool. Compliance is a property of your deployment — the BAA you sign, the configuration you run, and whether the tool appears in your risk analysis — not of the product. This page covers what actually has to be true before an AI tool touches patient information, which vendors offer a BAA, and where your real exposure usually is: staff already using consumer AI.

Which AI tools offer a BAA?

As of August 2026. Vendor terms change — verify before signing.

Consumer ChatGPT / ChatGPT Health

No BAA. Not for PHI, period. ChatGPT Health (launched Jan 2026) is a consumer product — the name confuses people, but no BAA is offered.

ChatGPT for Healthcare (enterprise)

BAA available. Launched Jan 8, 2026 as an enterprise product. Different thing entirely from consumer ChatGPT Health — verify which one you are actually buying.

OpenAI API (zero-retention) / Enterprise

BAA available for eligible deployments; zero-retention API configurations are the pattern for PHI-adjacent workloads.

Anthropic (Claude Enterprise / API / AWS Bedrock)

BAA paths exist via enterprise agreements and Bedrock. Configuration still decides compliance.

Microsoft 365 Copilot (enterprise SKUs)

Covered under Microsoft's BAA on eligible enterprise licensing. Consumer Copilot is not.

Google Workspace / Google Cloud

BAA available on covered services. Scope of covered services matters — check the current list.

The two ChatGPT rows are the ones that trip people up: ChatGPT Health (consumer, no BAA) and ChatGPT for Healthcare (enterprise, BAA available) launched weeks apart in January 2026 with nearly identical names. Staff hear “there's a healthcare ChatGPT now” and reach for the wrong one.

What counts as a disclosure?

A staff member pasting a patient note into consumer ChatGPT is a disclosure of PHI to a third party — one with no business associate obligations to you. When that happens, HIPAA's breach rules require a four-factor risk assessment (45 CFR 164.402): what was disclosed, to whom, whether it was actually acquired or viewed, and how well the risk was mitigated.

“It was basically anonymous” usually doesn't hold. De-identification under the Safe Harbor standard (45 CFR 164.514(b)) means removing all 18 identifier categories — names, dates, locations, record numbers, and more. A typical clinical note pasted for “summarizing” fails several of them.

Where AI belongs in your risk analysis

The proposed Security Rule update (NPRM, January 6, 2025) would explicitly require a technology asset inventory and risk analysis that includes AI tools. The final rule has not been issued — the federal regulatory agenda currently shows July 2027. You don't need to wait: an inventory of every AI tool touching your data, official or not, is the foundation everything else builds on.

What OCR actually enforces today is instructive. Its Risk Analysis Initiative produced 16 resolution agreements between January and August 2025, and the recurring finding is the same: no adequate risk analysis. The March 2026 MMG Fusion agreement (a dental practice-management vendor breach affecting roughly 15 million individuals) settled at $10,000 with a three-year corrective action plan — the pattern to read there isn't the dollar figure, it's that the missing risk analysis is what gets you. In our read, AI tools your staff quietly adopted are exactly the kind of asset those analyses keep missing. Penalties can reach $2,190,294 per violation category per year at the top tier (2025 adjustment).

The state-law layer on top.

As of September 2026. Reviewed quarterly — state AI law is moving fast.

California AB 3030

Disclosure required when generative AI produces patient clinical communications without clinician review.

California SB 1120

Limits on AI making utilization-review decisions; a licensed clinician must make medical-necessity determinations.

Illinois

Managed-care amendment restricting AI-only coverage decisions.

Texas TRAIGA

Broad AI governance law, effective January 1, 2026.

Colorado SB 26-189

Signed May 14, 2026, effective January 1, 2027; replaces the earlier SB 24-205 framework (with companion bills HB 26-1139 and HB 26-1195).

New York A9149

Pending bill — not law. Watch it if you operate in New York.

Before any AI tool touches PHI

A signed BAA with the vendor (and their subcontractors covered)

Retention and model-training settings verified in writing, not assumed

The tool added to your asset inventory and risk analysis

A policy your staff have actually seen, with a sanctioned alternative to consumer tools

State-law check for every state you operate in

If you don't know which tools are already in use in your organization, that's the first finding of a readiness assessment — mapping actual AI use, sanctioned or not, is where every engagement starts.

Questions we get on this

Can I use ChatGPT with patient data?+

Not the consumer product. Consumer ChatGPT — including ChatGPT Health — offers no BAA, so putting patient information into it is a disclosure to a vendor with no HIPAA obligations to you. Enterprise deployments with a signed BAA and retention controls are a different, workable conversation.

Does a BAA make a tool compliant?+

No. The BAA is necessary, not sufficient. Configuration matters just as much: retention settings, whether your data trains models, who at the vendor can see it, and whether the tool appears in your risk analysis.

Is de-identified data OK in consumer AI?+

Only if it is actually de-identified under HIPAA's standard — Safe Harbor means removing all 18 identifier categories, not just the name. Most notes staff paste into chatbots fail that test.

Do we have to tell patients we use AI?+

In some states, yes in specific situations. California AB 3030 requires disclosure when generative AI writes patient clinical communications without clinician review. State rules differ — check the table above and your counsel.

Do we need a new risk analysis when we add an AI tool?+

Your existing risk analysis needs to account for it. AI tools that touch PHI belong in your asset inventory and risk analysis — and the proposed Security Rule update would make that explicit.

What about staff using AI on personal phones?+

That is shadow AI, and it is the most common exposure we find. You cannot ban your way out of it — you need a policy, an approved-tools list, and a workflow that gives staff a sanctioned option. That is a governance problem, not a firewall problem.

Find out what's already touching PHI in your organization.

The assessment maps every AI tool in actual use — sanctioned or not — and what to do about each.