Judging AI governance

Is ChatGPT HIPAA compliant?

Short answerChatGPT can support a HIPAA-regulated workflow when an organization uses an eligible OpenAI product and covered functionality under an executed Business Associate Agreement, or BAA, with the required configuration. A regular consumer account or ChatGPT Business does not include that BAA coverage.

The direct answer depends on the product, the contract, the enabled features, and the organization’s own safeguards. OpenAI says that accepting a BAA and enabling its HIPAA support do not by themselves make an application compliant. The organization remains responsible for evaluating its use and meeting its obligations.

Which OpenAI products can be covered

As of October 7, 2026, OpenAI lists ChatGPT for Healthcare, ChatGPT Enterprise with Regulated Workspace, ChatGPT FedRAMP, ChatGPT for Clinicians, the API with Modified Retention, and the API FedRAMP with Modified Retention as HIPAA-eligible products available with a BAA. OpenAI says a sales-managed ChatGPT Enterprise or Edu account can request a BAA through sales. It does not offer a BAA for ChatGPT Business.

Coverage follows the eligible product and functionality named by OpenAI. OpenAI’s current list separates covered features from features that remain outside the BAA. A workspace administrator needs to confirm that the feature a team plans to use is included and configured as required.

What to verify before entering PHI

  1. Confirm that the organization has an executed BAA with OpenAI.
  2. Confirm that the exact ChatGPT workspace or API organization is named or enabled under that agreement.
  3. Check OpenAI’s current eligible-functionality list for every feature the workflow uses.
  4. Apply the configuration requirements in the implementation guide provided with the BAA.
  5. Document the organization’s access, review, incident, and workforce procedures for the workflow.

Where Sentinel fits

SUPERWISE® Sentinel replaces emails, phone numbers, account numbers, and API keys with placeholders before a prompt leaves the PC, and logs every request. This changes the supported data in a prompt and creates a record. Sentinel does not make ChatGPT, a workspace, or an organization HIPAA compliant.

Removing those supported values is also different from HIPAA de-identification. HHS describes two routes for de-identification under the Privacy Rule: Expert Determination and Safe Harbor. Sentinel’s documented replacement of four data types does not establish either route. Review where AI data goes, browse the Learn library, and use the AI glossary for terms used in this assessment.

Frequently asked questions

Does OpenAI sign a BAA?
Yes, for eligible OpenAI services and accounts. OpenAI provides a self-serve BAA flow for eligible API organizations, directs sales-managed ChatGPT Enterprise or Edu accounts to sales, and provides a separate flow for eligible ChatGPT for Clinicians users.
Is ChatGPT Enterprise HIPAA compliant?
ChatGPT Enterprise can support HIPAA-regulated use when the organization has OpenAI’s BAA, uses a Regulated Workspace, limits use to covered functionality, completes the required configuration, and meets its own HIPAA obligations.
Can I put patient information into ChatGPT?
A HIPAA-regulated organization should enter PHI only through an eligible OpenAI product and covered functionality after its BAA and required configuration are in place. OpenAI says ChatGPT Business has no BAA.
Is the OpenAI API HIPAA eligible?
Yes, when the organization executes OpenAI’s BAA and uses eligible API functionality with Modified Retention, unless OpenAI specifies otherwise. OpenAI publishes the covered endpoints and configuration requirements.

Sources

  1. OpenAI Help Center, Getting a Business Associate Agreement for the OpenAI API. Read October 7, 2026.
  2. OpenAI Help Center, HIPAA eligible products and functionality. Read October 7, 2026.
  3. U.S. Department of Health and Human Services, Guidance on HIPAA and cloud computing. Read October 7, 2026.
  4. U.S. Department of Health and Human Services, Guidance regarding methods for de-identification of protected health information. Read October 7, 2026.

Reviewed