Clinic Note / 5 minute read
Is ChatGPT HIPAA compliant for a therapy practice?
By The New Business School teaching team. Updated .
ChatGPT is not automatically HIPAA compliant for a therapy practice. OpenAI offers specific HIPAA eligible products and features under a BAA, but the practice must verify that its exact account and workflow are covered. It must also complete a risk analysis, set access controls, train staff, and follow its written privacy and security policies.
You will be able to ask the questions that separate a covered workspace from an unapproved chat account.
Use a four layer decision
Treat "Is ChatGPT HIPAA compliant?" as four smaller questions:
- Does the practice have a signed BAA with OpenAI?
- Does the BAA cover the exact product, workspace, feature, and retention mode?
- Has the practice completed a risk analysis and put the needed safeguards in place?
- Does the proposed use follow the practice's policies and the HIPAA Rules?
All four answers must be supported. A vendor's security page can help with the review, but it does not replace the practice's agreements, configuration, and risk analysis.
OpenAI's current guidance lists HIPAA eligible products such as ChatGPT for Healthcare, ChatGPT Enterprise with Regulated Workspace, ChatGPT for Clinicians, and certain API configurations. The list and eligible features can change. Check the current terms before each new workflow or material feature change.
Separate safe practice work from PHI work
Your team can learn the tool without patient information. Draft a blank intake form. Rewrite a public office policy. Build a synthetic progress note example. Create a staff checklist. These tasks let the team learn how the model behaves while the formal review is still open.
Do not assume that removing a name removes every identifier. Do not use a personal workspace for convenience. Do not let one staff member approve a tool for the whole practice through habit.
Clinician example
A group practice wants therapists to turn rough notes into structured drafts. The owner buys a new account and sees "enterprise" in the plan name. She does not treat that label as approval. The privacy lead checks the BAA, eligible workspace, retention, access, audit controls, and incident process. The team documents the approved prompt and review step before rollout.
The decision record is short, but it names the evidence behind each answer.
Your turn
Copy this sentence and fill every blank:
We may use [exact product and feature] for [specific task] because [agreement] covers it, [policy owner] approved the risk analysis on [date], [roles] can access it, and [reviewer] checks every output before [final action].
If you cannot fill one blank with a document, person, or date, keep PHI out and take the gap to your privacy lead or counsel.
Save this recap
- No ChatGPT plan is automatically compliant for every practice.
- The BAA must cover the exact service and feature.
- The practice owns its risk analysis, configuration, and policies.
- Staff can train with synthetic information while approval is pending.
- Review the terms again when the product or workflow changes.
Frequently asked questions
Which ChatGPT plans can be covered by an OpenAI BAA?
OpenAI currently lists ChatGPT for Healthcare, ChatGPT Enterprise with Regulated Workspace, ChatGPT for Clinicians, and certain API configurations among its HIPAA eligible products. Eligibility and covered features can change, so verify the current terms before use.
Is ChatGPT Business covered by an OpenAI BAA?
OpenAI's current BAA guidance says it does not offer a BAA for ChatGPT Business. A practice should check the current product terms rather than infer coverage from a plan name.
Who decides whether our workflow complies with HIPAA?
The practice remains responsible for its use of PHI. It should document its risk analysis, agreements, configuration, permitted uses, access controls, review process, and incident response with qualified privacy or legal support.
Sources checked
This article is educational and is not legal, compliance, or clinical advice. Check your state law, licensing rules, contracts, and current vendor terms with qualified counsel.
Put the checklist to work
BRING ONE PRACTICE WORKFLOW.
In a 75 minutes, one to one session, you will map the data, review the risks, and leave with one useful workflow or a clear build plan. Keep patient information out of the training session.