Here is a scene that plays out in small practices every week. The front desk needs to send a slightly awkward letter to a patient. Someone opens ChatGPT, types in the patient's name, the situation, a few details, and asks for a polished draft. Thirty seconds later they have a good letter. It feels like a win.

It is a HIPAA violation.

Not because the letter was wrong, and not because ChatGPT is insecure. It is a violation because your practice has no agreement with OpenAI that allows patient information to go there.

The missing piece: no business associate agreement

HIPAA requires a covered entity to have a business associate agreement with any outside company that handles protected health information on its behalf. The agreement makes that company legally accountable for the data.

As of 2026, OpenAI offers a business associate agreement only for its API platform and for ChatGPT Enterprise and Edu, both sales-managed and reviewed case by case. There is no BAA for ChatGPT Free, Plus, Team, or Business.OpenAI Help Center

So the moment a name and a health fact go into the consumer version of ChatGPT, your practice has disclosed protected health information to a vendor with no agreement in place. The individual staff member was trying to be efficient. The practice is the one exposed.

This is not unique to OpenAI. It applies to any general AI tool your team might reach for: the free tier of a writing assistant, a browser extension, a note-taker that joins calls. If it touches PHI and has not signed a BAA with you, it is off limits.

The surface matters, not just the brand

It gets more specific. Even inside tools that do offer healthcare agreements, coverage can depend on which part of the product you use.

Google's Workspace HIPAA business associate agreement covers the Gemini app as a core service. But it excludes Gemini in the Chrome browser, and it excludes Google Contacts. Same account, same login, one surface covered and another not.

The takeaway is not "avoid these tools." It is that "we have a BAA with Google" is not a complete answer. You need to know which surface your team is actually using.

What your staff can still do with AI

The line is patient data, not AI. Work that contains no PHI is fine in ordinary tools:

  • Policy and procedure drafts
  • Staff training material
  • Marketing copy and social posts about the practice
  • General administrative writing with no patient attached
  • Learning and research, as long as you are not pasting in real cases

Plenty of useful work fits there. The problem is only when a specific person's health information enters a tool that has no agreement covering it.

The safe way to start

Front-office AI that helps a practice usually does not need PHI at all. Filling cancellations, working the recall list, confirming appointments, and requesting reviews all run on scheduling data and contact details. Those are not clinical facts, so they open up a much wider set of tools.

Where a workflow genuinely needs patient health information, it should run inside a platform you already have a business associate agreement with, such as your practice management system or your patient communication tool. The AI adds the automation. The PHI never leaves the system that is cleared to hold it.

Two steps to put this on solid ground:

  1. Write a one-page AI policy. Which tools are approved, for what, and the bright line: no patient information in any tool without a signed BAA. Most practices have nothing written down, which is how the letter-drafting habit starts.
  2. List the tools that touch patient data. Your practice management system, your comms platform, your billing tool, and confirm each has a current agreement. This is also the inventory a proposed HIPAA Security Rule update would require, so it is worth having either way.

The bottom line

Your team is not wrong to want AI's help with the front-desk grind. They just need a version of it that does not route patient information through a tool your practice never signed an agreement with.

For a walk through where AI safely fits in a small practice, see the front-office playbook, or get a breakdown for your practice specifically. No call needed.

This is general information, not legal advice. Confirm how HIPAA applies to your practice with your own compliance counsel.

Common questions

Is ChatGPT HIPAA compliant?

The everyday versions are not. As of 2026, OpenAI signs a business associate agreement only for its API platform and for ChatGPT Enterprise and Edu, and those are sales-managed accounts. There is no BAA for ChatGPT Free, Plus, Team, or Business, so using them with protected health information is a HIPAA violation regardless of how careful the individual user is.

Can our staff use ChatGPT at all?

Yes, for work that contains no protected health information: general administrative writing, policy drafts, training material, marketing copy about the practice. The line is patient data. If a task needs a name attached to a health fact, it does not belong in a consumer chat tool.

What is a business associate agreement?

It is a contract required by HIPAA between a covered entity, like your practice, and any vendor that handles protected health information on your behalf. It makes the vendor legally responsible for protecting that data. Without one in place, sharing PHI with the vendor is not allowed, even if the vendor's security is good.

See where your GTM team stands

The GTM AI Readiness Assessment scores you across data, automation, AI depth, ownership, process, and GTM alignment, then names the one workflow to build first. About three minutes, no call needed.

Take the Assessment