Is ChatGPT HIPAA compliant?
Only on specific OpenAI products — ChatGPT for Healthcare, ChatGPT for Clinicians, sales-managed Enterprise or Edu, or the API with Modified Retention — and never on free, Plus, Pro or ChatGPT Business accounts.
Applies to ChatGPT and the OpenAI API. Last reviewed against OpenAI's own documentation. Next review December 18, 2026.
Reviewed by Lisa Tran, CISSP — Healthcare Information Security Executive.
What you must do
- Use one of the products OpenAI lists as eligible: ChatGPT for Healthcare, ChatGPT for Enterprise with Regulated Workspace, ChatGPT FedRAMP, ChatGPT for Clinicians, the API with Modified Retention, or API FedRAMP with Modified Retention.
- Individual US clinicians: ChatGPT for Clinicians is free for verified physicians, nurse practitioners, physician assistants and pharmacists. Sign up with a valid NPI and licence, then review and sign the agreement in ChatGPT under Settings → Agreements before sharing any patient information.
- Organizations wanting ChatGPT: contact OpenAI sales. Only sales-managed Enterprise or Edu accounts are eligible.
- API: email baa@openai.com with company and use-case details. OpenAI responds in one to two business days and reviews case by case.
- API: your organization ID must be provisioned with Modified Retention before patient information may be processed, and only eligible endpoints may be used.
- Leave non-covered ChatGPT functionality disabled — it is off by default. If an administrator enables it, restrict it to work involving no patient information.
- Do not share patient information with third-party GPTs or connected apps without your own agreements in place with those third parties.
Does ChatGPT sign a business associate agreement?
Yes. OpenAI offers one. ChatGPT for Healthcare, ChatGPT for Clinicians, Enterprise with Regulated Workspace, sales-managed Enterprise or Edu, or the API with Modified Retention. Not ChatGPT Business and not any consumer plan. API: email baa@openai.com with company and use-case details. ChatGPT Enterprise, Edu or Healthcare: contact OpenAI sales. ChatGPT for Clinicians: verify your NPI and licence at signup, then sign in-product under Settings → Agreements.
What this means in practice
OpenAI's eligibility runs by product, not by how much you pay, and the naming actively misleads. ChatGPT Business sounds like the obvious purchase for a clinic, and OpenAI states plainly that it does not offer an agreement for it. Free, Plus and Pro are out too. What is eligible is a specific set: ChatGPT for Healthcare, ChatGPT for Clinicians, Enterprise with a Regulated Workspace, sales-managed Enterprise or Edu, the FedRAMP variants, and the API with Modified Retention.
For a solo or small practice the useful surprise is ChatGPT for Clinicians, which is free for verified US physicians, nurse practitioners, physician assistants and pharmacists. You sign up with a valid NPI and licence, then sign the agreement in-product under Settings and Agreements before sharing anything about a patient. Note that image generation is not supported there.
If you are building on the API, the sequence is strict: email OpenAI, wait for a case-by-case review, and confirm your organization ID has actually been provisioned with Modified Retention before any patient information is sent. Non-covered functionality is off by default; leave it that way.
How organizations get this wrong
The specific mistakes we see with ChatGPT, not generic advice.
- Buying ChatGPT Business seats for the practice because the name implies a work-grade tier, when OpenAI states no agreement is offered for it.
- A clinician drafting a referral letter in their personal Plus account and treating deletion of the chat as sufficient protection.
- Emailing OpenAI about the API and starting to send patient data before the organization ID is actually provisioned with Modified Retention.
- An administrator switching on additional ChatGPT functionality that ships disabled, then letting staff use it for clinical work.
What the agreement does not cover
- Consumer ChatGPT — Free, Plus and Pro accounts are not eligible and have no agreement.
- ChatGPT Business. OpenAI states plainly that it does not offer an agreement for it.
- Any additional ChatGPT functionality an administrator enables outside the covered list.
- Any API endpoint not on OpenAI's published eligible-endpoint list.
- Third-party GPTs and connected apps, which carry their own terms.
- Image generation, which is not supported in ChatGPT for Clinicians.
Alternatives
Listed on merit. We take no payment for placement and use no affiliate links.
Microsoft Azure OpenAI Service
Runs OpenAI models inside Azure, covered by Microsoft's agreement for eligible services
Google Cloud Vertex AI
Gemini models under Google Cloud's agreement, which lists covered services explicitly
Signing the agreement is step one. Proving it is step two.
Once you have the agreement with ChatGPT, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.
$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.
Sources
Every statement above comes from OpenAI’s own published documentation, read on the date shown.
- HIPAA Eligible Products and Functionality — OpenAI. Published July 27, 2026. Read July 29, 2026.
- ChatGPT for Clinicians — OpenAI. Published July 27, 2026. Read July 29, 2026.
- How can I get a Business Associate Agreement (BAA) with OpenAI for the API Services? — OpenAI. Published July 28, 2026. Read July 29, 2026.
Change history
- — First published.
This page is information, not certification and not legal advice. It reflects OpenAI’s published documentation as read on July 29, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.
Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.