HIPAA compliance isn't something software can be. It's a property of an arrangement between two organisations, and the tool is only one part of it.
The answerable version is: is there a Business Associate Agreement covering the exact service you're about to use? For consumer ChatGPT, there isn't.
There is no HIPAA certification. No regulator inspects software and issues a badge, and any vendor implying otherwise is selling something. HIPAA regulates covered entities and the business associates who handle protected health information on their behalf.
So "is this tool HIPAA compliant" has no answer. "Is this vendor my business associate for this service, under a signed agreement" has exactly one, and it is the question that determines whether you are allowed to paste.
| What you're using | Where it stands |
|---|---|
| Consumer ChatGPT free or personal paid | No. No BAA is offered for it. Pasting PHI into it discloses protected health information to a third party with no authorisation — which is the definition of the thing HIPAA prohibits. |
| Enterprise and API arrangements | Possible. Some providers will enter a BAA covering specific services on request. Possible is not the same as in place: someone has to have actually signed it, for the service you are using. |
| Models hosted inside a cloud platform a major provider's managed AI service | Often the practical route. The large cloud providers maintain BAAs and publish which of their services are covered. The list is specific, it is per-service, and it changes — read it rather than assuming your service is on it. |
| A clinical AI product | Usually yes, and that's what you're paying for. What makes these usable is the paperwork behind them, not the model inside them. |
Verify this yourself before relying on it. Vendor terms and covered-service lists change, and this page is not a substitute for the current documentation or for your compliance officer. What doesn't change is the shape of the question, which is why that is what this page is mostly about.
Bind the vendor to safeguard PHI, restrict what they may use and disclose it for, require them to report breaches to you, and flow the same obligations down to their own subcontractors. It makes them accountable to you in a way they otherwise aren't.
Make the disclosure automatically appropriate. HIPAA's minimum necessary standard still applies: you may disclose only what is needed for the purpose. Pasting an entire discharge summary to get help rewriting one paragraph fails that test whether or not a BAA exists.
And a BAA covering your organisation's enterprise account does nothing at all about the personal account somebody used at home. The agreement covers a service, not a person's intention.
This is where careful people get caught, because it feels like it solves the problem.
HIPAA's Safe Harbor method requires eighteen identifier types to be removed — names, all geography finer than a state, every date more specific than a year, phone and fax numbers, email addresses, SSN, medical record and account numbers, device identifiers, URLs, IP addresses, biometric identifiers, full-face photographs, and any other unique code. The alternative route, Expert Determination, requires a qualified person to formally assess re-identification risk and document it.
The list is that long for a reason: a rare diagnosis, plus an admission date, plus a town of thirty thousand people identifies exactly one person. Clinical narratives are built out of narrowing details, which is precisely what re-identification needs.
The fuller version of this argument, with the alternative that actually works, is on the health and legal records page.
If nobody can answer the first one quickly and in writing, the answer is no. Not "probably fine" — no. This is the one category on this site where the consequences can land on an individual personally rather than only on their employer.
Escalate today, and don't pre-assess it yourself. Tell your privacy officer or compliance lead plainly what was pasted and where.
HIPAA's breach notification rule runs to 60 days, and the assessment of whether an impermissible disclosure is a reportable breach is a formal one with defined factors — it is not a judgement call for the person who made the disclosure. If the same material was also privileged, tell the supervising lawyer immediately; there are steps that can be taken to argue against waiver and they weaken with every day of delay.
Reporting it promptly is the right call and organisations that punish it get told less next time. If you are the one writing the policy, say so explicitly — there's a paragraph you can copy on the for teams page.