HIPAA-Compliant AI Tools
OpenAI HIPAA BAA: what's covered and what isn't
By Mat Steinlin, Head of Information Security
Last updated: July 2026
OpenAI offers a BAA, but which OpenAI product you're using determines whether that BAA applies to you. OpenAI's product lineup has grown significantly, so the answer is now more nuanced than it used to be.
Consumer ChatGPT (Free, Plus, and Team) has no BAA coverage. The API has a self-serve BAA path that does not require an enterprise agreement. ChatGPT Enterprise, ChatGPT for Healthcare, and ChatGPT for Clinicians each have their own BAA paths. If you're using multiple surfaces, each one needs to be covered separately.
Coverage at a glance
Product | BAA available | Notes |
|---|---|---|
ChatGPT Free | No | Consumer product. Do not use with PHI. (Source) |
ChatGPT Plus | No | Consumer product. Do not use with PHI. (Source) |
ChatGPT Team | No | Not designed for regulated data. (Source) |
ChatGPT Enterprise | Yes | Sales-assisted. Contact OpenAI sales. (Source) |
ChatGPT for Healthcare | Yes | Sales-assisted. Built for organizational deployment with centralized admin. (Source) |
ChatGPT for Clinicians | Yes | Self-serve BAA for verified individual U.S. clinicians via Settings > Agreements. Free at launch. (Source) |
OpenAI API | Yes (with Modified Retention) | Self-serve BAA path via baa@openai.com; no enterprise agreement required. Requires Modified Retention provisioning. (Source) |
Codex Local (CLI, IDE, Desktop) | Yes | Covered when signed in with a HIPAA-eligible ChatGPT account, or when using an API key from an account with Modified Retention + BAA. (Source) |
ChatGPT and the OpenAI API are separate products with separate BAA processes. A ChatGPT Enterprise account does not automatically cover API usage. An API BAA does not cover ChatGPT. If you use both surfaces, both need to be covered separately.
The consumer surface risk
The compliance risk with OpenAI isn't usually in production but in the workflows around it.
Engineers use ChatGPT for debugging. Clinicians use it for documentation. Operations staff use it for summarization. Each of these is a potential PHI exposure on a consumer surface with no BAA coverage.
Surveys of healthcare workers find consistent patterns: AI tool use is widespread, and the tools being used are usually consumer products rather than enterprise-contracted ones. According to the AMA's 2026 Physician Survey on Augmented Intelligence, over 80% of physician respondents currently use AI in a professional context (double the share reported in 2023). The same survey found that physicians are significantly more concerned about patient privacy when using non-institutional AI tools (71%) than institutional ones (42%), a gap that reflects how much unsanctioned tool use is already happening.
A signed ChatGPT Enterprise BAA covers the enterprise product. It does not cover the same employee using ChatGPT.com on the same computer for the same type of task. The tool looks identical to the user. The compliance boundary is invisible.
The pattern shows up consistently in healthcare communities: a medical scribe pastes a patient's history of present illness into free ChatGPT for documentation assistance, with no awareness it constitutes a violation. No audit trail. No organizational visibility. No intent to violate.
Part of what sustains this is how recently the Enterprise BAA became available. For years, the dominant view in the OpenAI community was that the terms of service precluded HIPAA compliance entirely. That perception lingers and cuts both ways; some teams who could use a covered surface assume they cannot while others assume consumer ChatGPT is close enough to the enterprise product that the distinction doesn’t matter.
Organizations managing this gap rely on a combination of controls: DLP tools (Nightfall AI is commonly cited by practitioners), site-level blocking of ChatGPT, and "approved tools only" policies. At some organizations, unauthorized ChatGPT use is treated as a terminable offense.
One exception is that verified individual clinicians in the U.S. can sign a self-serve BAA for ChatGPT for Clinicians via Settings > Agreements. This makes individual clinical use with PHI legitimate without an enterprise agreement, but it covers only that clinician's account, not anyone else in the organization.
For a governance framework for finding and managing this usage, see Shadow AI in healthcare.
How to get a BAA with OpenAI
The path depends on which product you're using.
API: Email baa@openai.com with details about your company and use case. OpenAI responds within 1-2 business days and completes most BAAs within a few business days. No enterprise agreement required. Your account will need to be provisioned with Modified Retention before HIPAA-eligible endpoints are available.
ChatGPT Enterprise or ChatGPT for Healthcare: Contact OpenAI's sales team. Only sales-managed accounts are eligible. Plan for several weeks depending on deal size and legal review.
ChatGPT for Clinicians: Verified individual U.S. clinicians can sign a BAA directly in Settings > Agreements; no sales process required. For organizational deployment covering multiple users, use ChatGPT for Healthcare instead.
If you're already on Azure: Teams using OpenAI models through Azure OpenAI Service are covered under their Microsoft Azure BAA, not a direct OpenAI agreement. See Azure OpenAI for the comparison.
What the OpenAI Healthcare Addendum requires of you
OpenAI's Healthcare Addendum is a separate document that accompanies the BAA and imposes specific customer obligations. Compliance with the Healthcare Addendum and OpenAI's HIPAA Compliance and Implementation Guide is required as a condition of the agreement.
Eligible services only. PHI may only be transmitted through Eligible Services: the Zero Retention API, ChatGPT Enterprise, and explicitly designated services. Third-Party Services, Plugins, Actions, Third-Party GPTs, shared links, and templates are not eligible services and may not be used to transmit or disclose PHI.
Healthcare activity requirements. For any use involving the practice of medicine, billing, coding, claims processing, or clinical research ("Healthcare Activities"), you must: (i) test the services for accuracy in your specific use cases, and (ii) ensure that only duly trained and qualified individuals who maintain the required licenses, certifications, or authorizations perform such Healthcare Activities.
Workforce training. You must train your personnel and other relevant data custodians on their obligations under the Healthcare Addendum and ensure compliance.
No AI-as-human misrepresentation. You must not represent to any upstream customer or other party that the services were performed by a human or that the output was human-generated.
Customer content responsibility. You are solely responsible for the development, content, and integrity of HIPAA Input; ensuring accurate patient matching so input is properly matched to output; and ensuring HIPAA Output is returned to the appropriate upstream customer.
Upstream customer agreements. If you provide HIPAA Output to upstream customers, you must have written agreements requiring those customers to comply with all applicable laws and regulations, and to comply with the healthcare activity requirements above.
What OpenAI's BAA covers
The OpenAI Enterprise BAA establishes:
OpenAI as a business associate under HIPAA
Prohibition on using your data for model training
Data handling and safeguard obligations on OpenAI's infrastructure
Breach notification requirements per HIPAA's Breach Notification Rule (45 CFR § 164.410)
Data retention and deletion terms (consult your specific agreement for timelines)
The no-training policy applies across HIPAA-eligible products: API data is not used to train models, and the same applies to ChatGPT for Healthcare and ChatGPT for Clinicians. What matters legally is what your specific BAA says. Policies can change; contracts are enforceable.
What OpenAI's BAA doesn't cover
The same infrastructure gap that applies to every vendor in this guide. The BAA governs OpenAI's handling of PHI on their infrastructure. Your audit logging, log storage, key management, and access controls remain your responsibility.
The audit logging gap is significant enough that standalone products have been built specifically to address it. Traceprompt, which launched to solve audit logging for LLM calls, is one example of a product category that exists because the model provider's own logging is not sufficient for HIPAA purposes.
Web Search coverage depends on which surface you're using. In HIPAA-eligible ChatGPT products (Enterprise, Healthcare, Clinicians), Web Search is covered: OpenAI configures those workspaces to use its own search index rather than sending queries to third-party providers like Bing.
For the OpenAI API, the distinction is different: live internet Web Search via the web_search tool is explicitly not HIPAA eligible and not covered by a BAA. Offline/cache-only Web Search with a ZDR-enabled project is eligible.
See What an AI BAA actually covers for the full breakdown, including the common failure pattern where compliant API usage coexists with non-compliant log storage.
OpenAI vs. Azure OpenAI: which path is right
For teams already running infrastructure on Azure, the Azure OpenAI path is frequently faster and simpler. The BAA comes through your existing Microsoft enterprise agreement rather than a separate OpenAI sales process. The trade-off is that Azure OpenAI has a slight lag on model availability compared to the direct OpenAI API. See Azure OpenAI for the full comparison.
Among practitioners in healthcare IT, the Azure route is often the explicitly recommended path: "BAA signed OpenAI API via Azure" has become shorthand for the compliant option.
For teams not already on Azure, or who need features available only through the direct API, the OpenAI Enterprise path is the route.
What you still need to build
A signed OpenAI BAA resolves OpenAI's obligations. The compliance work that sits between your application and the model (audit logging, encrypted log storage, key management, access controls) is yours to build regardless of which OpenAI surface you're using or how many BAAs you've signed. See HIPAA-Compliant AI: What Developers Need to Know for the full technical requirements.
For teams who prefer not to build that layer themselves, Aptible LLM Gateway handles it as a managed compliance layer. One Aptible BAA covers all supported models, including OpenAI. You don't build the logging pipeline; you don't implement PHI de-identification in application code; you don't manage model-level key scoping.
FAQs
Is ChatGPT HIPAA compliant?
It depends on which product. ChatGPT for Healthcare and ChatGPT Enterprise have BAA coverage through OpenAI's sales team. ChatGPT for Clinicians offers a self-serve BAA for verified individual U.S. clinicians. ChatGPT Free, Plus, and Team have no BAA coverage and are not appropriate for use with PHI.
Does the OpenAI API come with a BAA?
Not automatically, but it doesn't require an enterprise agreement either. Email baa@openai.com with your company and use case details. OpenAI reviews requests individually and most are approved within a few business days. Your account will also need to be provisioned with Modified Retention. Many teams assume their API key is covered when it isn't. The BAA is a separate step.
How do I get a BAA with OpenAI?
It depends on the product. For the API, email baa@openai.com; no enterprise agreement required, usually resolved in a few business days. For ChatGPT Enterprise or Healthcare, contact OpenAI sales. For ChatGPT for Clinicians, eligible individual clinicians can sign directly in Settings > Agreements.
Can my team use ChatGPT for patient documentation?
Only if they're using ChatGPT Enterprise and your organization has a signed BAA in place. Consumer ChatGPT tiers have no BAA coverage. Clinical staff using ChatGPT.com for documentation is a HIPAA violation.
Is there a difference between OpenAI's BAA and Azure OpenAI's BAA?
Yes. Direct OpenAI and Azure OpenAI are different products with different legal entities and different BAA processes. A BAA with OpenAI covers usage of OpenAI products. A BAA through Microsoft Azure covers Azure OpenAI Service. If you use both, you need both covered. See Azure OpenAI.
Does OpenAI train models on my data?
No, across all HIPAA-eligible products. The no-training policy applies to the API, ChatGPT for Healthcare, and ChatGPT for Clinicians. What matters legally is what your specific BAA says. Policies can change; contracts are enforceable.
What's next
If your team is already on Azure, the Azure-hosted path to OpenAI models is often faster and simpler than a direct OpenAI Enterprise agreement: Azure OpenAI.
For teams using OpenAI alongside other vendors, see Managing BAAs across multiple AI vendors for how to manage the compliance surface across your full stack.
__
Getting a BAA with OpenAI is the starting point. But the API and ChatGPT are separate agreements, and if you're using OpenAI alongside other models, that's more contracts to negotiate and more surfaces to keep covered as your stack evolves.
Aptible LLM Gateway routes your OpenAI traffic through a managed compliance layer: automatic audit logging, PHI de-identification before the model, and encrypted log storage, all covered under one Aptible BAA alongside every other supported model. No separate OpenAI BAA required. Talk to an engineer to see if it fits your stack.