Is ChatGPT HIPAA compliant?
Short answer
No software is HIPAA compliant on its own. HIPAA governs how doctors, hospitals, health plans and the companies working for them handle patient information, and a clinician at a HIPAA-covered practice or hospital generally may put identifiable patient information into a chatbot only when a business associate agreement (BAA) covers that product and feature. OpenAI's list of products eligible for its BAA leaves out the consumer plans (Free, Go, Plus and Pro), and OpenAI says it offers no BAA for Health in ChatGPT or ChatGPT Business (OpenAI; OpenAI; OpenAI).
HIPAA does not certify software
Google puts it plainly on its own compliance page: "there is no certification recognized by the US HHS for HIPAA compliance" (Google Cloud). What HIPAA regulates is disclosure. A covered entity, such as a practice or hospital, may let a vendor handle protected health information only with "satisfactory assurance" that the vendor will safeguard it, documented in a written contract: the BAA (45 CFR 164.502(e)). HHS's guidance on business associates, as of its July 30, 2026 review, gives as an example a "Third-party vendor Artificial Intelligence (AI) chatbot on a provider's patient portal" (HHS). So the question to ask about any chatbot is whether a signed BAA covers the product and the feature being used.
Which ChatGPT products can be covered
As of Sept. 28, 2026, OpenAI lists these as eligible for its BAA: ChatGPT for Healthcare, ChatGPT for Enterprise with Regulated Workspace, ChatGPT FedRAMP, ChatGPT for Clinicians, its API with modified retention, and API FedRAMP with modified retention (OpenAI). The consumer plans are not on the list. OpenAI says "Health in ChatGPT is not intended for clinical or covered-entity use and does not offer a Business Associate Agreement" (OpenAI), and "we don't offer a BAA for ChatGPT Business" (OpenAI).
A BAA does not cover every feature. OpenAI lists functions that fall outside it even in eligible products, among them improved memory, Codex in the cloud and some agent and cloud settings (OpenAI).
ChatGPT for Clinicians
Since April 22, 2026, ChatGPT for Clinicians has been free to verified U.S. physicians, nurse practitioners, physician assistants and pharmacists (OpenAI), and an eligible individual clinician can sign a BAA in the product's settings (OpenAI). OpenAI adds a condition: "Do not share PHI in ChatGPT for Clinicians unless a BAA is in place and you are authorized to sign a BAA for your account" (OpenAI). OpenAI does not say who is authorized. A physician employed by a hospital or group should ask the employer, usually its privacy officer, before signing.
Turning off training is not a BAA
Consumer ChatGPT may use conversations to train OpenAI's models unless the user turns that off (OpenAI). Opting out changes what OpenAI does with the text; it does not create the written agreement HIPAA requires before patient information goes to a vendor. Genevieve Kanter of the University of Southern California made the point in 2023: "regardless of whether you've opted out, you've just violated HIPAA because the data has left the health system" (USC).
Other chatbots follow the same rule
Anthropic offers a BAA for its first-party API and for Enterprise plans once the plan's primary owner sets it up (Anthropic) and says "Team plans and individual plans (Free, Pro, and Max) can't enable HIPAA" (Anthropic). Google covers Gemini in Workspace under its Workspace BAA (Google Workspace) and Gemini Enterprise under its cloud BAA (Google Cloud), and asks users of consumer Gemini not to enter "confidential information that you wouldn't want a reviewer to see" (Google). Microsoft says Microsoft Copilot and Copilot Chat, as used by organizations under its data protection addendum, support HIPAA compliance "for properly configured implementations" but that web search queries fall outside its BAA (Microsoft).
De-identified information is different
HIPAA does not restrict information that has been properly de-identified (HHS). One method, Safe Harbor, removes 18 kinds of identifiers, including all elements of dates (except the year) directly related to the patient, ages over 89 and "voice prints" (45 CFR 164.514). The other is a qualified expert's determination that the risk of identifying the patient is very small (HHS). A clinical question typed in free text often carries a date, an age or a detail that identifies the patient.
Patients using chatbots on their own
HIPAA generally does not cover an app or chatbot a patient chooses to use. HHS: "In most cases, unless the app is provided to you by a covered entity or its business associate, the HIPAA Rules also do not protect the privacy of data you've downloaded or entered into mobile apps for your personal use" (HHS).
What to check before putting patient information into any chatbot
- Is the exact product on the vendor's HIPAA-eligible list, and has the organization signed a BAA for it?
- Is the feature in use covered? Lists differ: OpenAI excludes improved memory and some agent and cloud settings; Microsoft excludes web search queries.
- Who signed, and for whom? OpenAI says not to share patient information unless the signer is authorized to sign for the account, and points organization-wide use to ChatGPT for Healthcare.
- Is it a work account, not a personal one?
- If there is no BAA, is the text truly de-identified?
- Does the organization permit the tool?
None of the HIPAA settlements and penalties the HHS Office for Civil Rights listed from January 2025 through Sept. 17, 2026, mentions AI or a chatbot (HHS).
What would change this answer
A change to OpenAI's list of HIPAA-eligible products, or a BAA offered for consumer ChatGPT or Health in ChatGPT; the final HIPAA Security Rule, which the federal regulatory agenda lists for July 2027 (reginfo.gov); the first HHS enforcement action involving a chatbot; and state laws that bring health chatbots under medical privacy rules.
General information, not legal or medical advice. Every fact links to its source, and the page shows the date it was last reviewed.