Home / HIPAA-compliant AI
Guide · Updated September 2026
There is no such thing as a HIPAA-certified AI tool. Compliance is a property of your deployment — the BAA you sign, the configuration you run, and whether the tool appears in your risk analysis — not of the product. This page covers what actually has to be true before an AI tool touches patient information, which vendors offer a BAA, and where your real exposure usually is: staff already using consumer AI.
As of August 2026. Vendor terms change — verify before signing.
Consumer ChatGPT / ChatGPT Health
No BAA. Not for PHI, period. ChatGPT Health (launched Jan 2026) is a consumer product — the name confuses people, but no BAA is offered.
ChatGPT for Healthcare (enterprise)
BAA available. Launched Jan 8, 2026 as an enterprise product. Different thing entirely from consumer ChatGPT Health — verify which one you are actually buying.
OpenAI API (zero-retention) / Enterprise
BAA available for eligible deployments; zero-retention API configurations are the pattern for PHI-adjacent workloads.
Anthropic (Claude Enterprise / API / AWS Bedrock)
BAA paths exist via enterprise agreements and Bedrock. Configuration still decides compliance.
Microsoft 365 Copilot (enterprise SKUs)
Covered under Microsoft's BAA on eligible enterprise licensing. Consumer Copilot is not.
Google Workspace / Google Cloud
BAA available on covered services. Scope of covered services matters — check the current list.
The two ChatGPT rows are the ones that trip people up: ChatGPT Health (consumer, no BAA) and ChatGPT for Healthcare (enterprise, BAA available) launched weeks apart in January 2026 with nearly identical names. Staff hear “there's a healthcare ChatGPT now” and reach for the wrong one.
A staff member pasting a patient note into consumer ChatGPT is a disclosure of PHI to a third party — one with no business associate obligations to you. When that happens, HIPAA's breach rules require a four-factor risk assessment (45 CFR 164.402): what was disclosed, to whom, whether it was actually acquired or viewed, and how well the risk was mitigated.
“It was basically anonymous” usually doesn't hold. De-identification under the Safe Harbor standard (45 CFR 164.514(b)) means removing all 18 identifier categories — names, dates, locations, record numbers, and more. A typical clinical note pasted for “summarizing” fails several of them.
The proposed Security Rule update (NPRM, January 6, 2025) would explicitly require a technology asset inventory and risk analysis that includes AI tools. The final rule has not been issued — the federal regulatory agenda currently shows July 2027. You don't need to wait: an inventory of every AI tool touching your data, official or not, is the foundation everything else builds on.
What OCR actually enforces today is instructive. Its Risk Analysis Initiative produced 16 resolution agreements between January and August 2025, and the recurring finding is the same: no adequate risk analysis. The March 2026 MMG Fusion agreement (a dental practice-management vendor breach affecting roughly 15 million individuals) settled at $10,000 with a three-year corrective action plan — the pattern to read there isn't the dollar figure, it's that the missing risk analysis is what gets you. In our read, AI tools your staff quietly adopted are exactly the kind of asset those analyses keep missing. Penalties can reach $2,190,294 per violation category per year at the top tier (2025 adjustment).
As of September 2026. Reviewed quarterly — state AI law is moving fast.
California AB 3030
Disclosure required when generative AI produces patient clinical communications without clinician review.
California SB 1120
Limits on AI making utilization-review decisions; a licensed clinician must make medical-necessity determinations.
Illinois
Managed-care amendment restricting AI-only coverage decisions.
Texas TRAIGA
Broad AI governance law, effective January 1, 2026.
Colorado SB 26-189
Signed May 14, 2026, effective January 1, 2027; replaces the earlier SB 24-205 framework (with companion bills HB 26-1139 and HB 26-1195).
New York A9149
Pending bill — not law. Watch it if you operate in New York.
→A signed BAA with the vendor (and their subcontractors covered)
→Retention and model-training settings verified in writing, not assumed
→The tool added to your asset inventory and risk analysis
→A policy your staff have actually seen, with a sanctioned alternative to consumer tools
→State-law check for every state you operate in
If you don't know which tools are already in use in your organization, that's the first finding of a readiness assessment — mapping actual AI use, sanctioned or not, is where every engagement starts.
Not the consumer product. Consumer ChatGPT — including ChatGPT Health — offers no BAA, so putting patient information into it is a disclosure to a vendor with no HIPAA obligations to you. Enterprise deployments with a signed BAA and retention controls are a different, workable conversation.
No. The BAA is necessary, not sufficient. Configuration matters just as much: retention settings, whether your data trains models, who at the vendor can see it, and whether the tool appears in your risk analysis.
Only if it is actually de-identified under HIPAA's standard — Safe Harbor means removing all 18 identifier categories, not just the name. Most notes staff paste into chatbots fail that test.
In some states, yes in specific situations. California AB 3030 requires disclosure when generative AI writes patient clinical communications without clinician review. State rules differ — check the table above and your counsel.
Your existing risk analysis needs to account for it. AI tools that touch PHI belong in your asset inventory and risk analysis — and the proposed Security Rule update would make that explicit.
That is shadow AI, and it is the most common exposure we find. You cannot ban your way out of it — you need a policy, an approved-tools list, and a workflow that gives staff a sanctioned option. That is a governance problem, not a firewall problem.
Find out what's already touching PHI in your organization.
The assessment maps every AI tool in actual use — sanctioned or not — and what to do about each.