Is ChatGPT HIPAA compliant?
Do not put protected health information into an ordinary consumer ChatGPT account. Some OpenAI services can support a HIPAA-compliant workflow under an applicable business associate agreement and the required configuration. That does not make every ChatGPT account, feature, integration, or clinical use eligible. Your practice must establish the agreement, permitted data flow, safeguards, and legal authority for the specific task before using patient information. OpenAI’s HIPAA configuration guidance, HHS cloud-computing guidance.
There is also a separate question: may AI perform the proposed clinical function? A BAA addresses a business associate’s handling of protected information. It does not override restrictions on therapy, authorize independent clinical decisions, or make generated documentation accurate. Illinois makes that distinction particularly important.
Legal and product sources checked on September 11, 2026. The state register below is a dated, selected-state snapshot, not a survey of every applicable law. Vermont remains pending full-text verification. Examples and review questions are original practice illustrations.
Start with the task, not the product name
“We use AI” is too broad to evaluate. A scheduling assistant, an audio recorder, a note-drafting service, and a chatbot that speaks to a patient about treatment have different functions. Describe the proposed action in a single sentence before reviewing a vendor.
For example: “The service receives clinician-entered encounter facts and returns an unsigned progress-note draft.” Compare that with: “The service records the whole session, infers the client’s emotional state, proposes treatment, and messages the client afterward.” Calling both products documentation assistants would hide the questions that matter.
Next, draw the data path in ordinary language. Identify who supplies information, where it goes, what the service creates, where each version remains, and who can access it. Include recordings, transcripts, prompts, drafts, exports, support tickets, and connected services. Ask the vendor to confirm the actual workflow rather than relying on a demonstration account.
This review should produce a usable staff rule: which account and function may be used, for what purpose, with what information, and who reviews the result. If staff cannot tell an authorized workflow from a personal chatbot account, the procurement decision has not yet become a clinical process.
What a BAA does and does not establish
Under HIPAA, a service that creates, receives, maintains, or transmits electronic PHI on behalf of a covered entity can be a business associate. HHS explains that even a cloud provider storing encrypted information without the decryption key can have that status. Where the relationship requires a BAA, encryption is not a replacement for the agreement. HHS cloud-computing guidance.
A BAA sets obligations for the covered relationship, including permitted uses and safeguards. The practice still needs its own risk analysis and compliant operation. Obtain the executed agreement, identify the legal entities it covers, and confirm that the specific service and account are within scope. A vendor’s statement that it “offers BAAs” does not establish that your practice has one.
Use the contract review to answer practical questions. Does the agreement cover the recording function as well as the note draft? What happens when information goes to another service? Which responsibilities belong to the vendor and which belong to your practice? Who receives incident notices? Who can authorize a new integration?
A BAA also does not provide permission for every disclosure. Your clinical purpose, applicable privacy rules, and any additional consent or authorization requirements need separate consideration. A client’s willingness to try a tool cannot create a business associate agreement or waive an otherwise applicable prohibition on the task.
What never goes into a consumer chatbot
For clinical work, keep identifiable patient material out of a consumer chatbot that is outside your approved PHI workflow. That includes progress notes, intake histories, session recordings, transcripts, referral letters, screenshots from the record, insurance documents, and patient messages. Do not paste another person’s material into the service to ask whether it is private enough to upload.
Removing the name is not a complete de-identification method. HIPAA recognizes Safe Harbor and Expert Determination approaches, each with conditions. Narrative details, dates, and unusual combinations of circumstances can matter. HHS also makes clear that free text requires attention, not just labeled identifier fields. HHS de-identification guidance.
Imagine a fictional note about the only school principal in a small town, with an exact appointment date and a distinctive public incident. Replacing the name with “Client A” leaves a potentially recognizable account. Do not describe that edit as HIPAA de-identification.
For general writing practice, create a scenario that is fictional from the beginning. Ask for an outline of an attendance policy or questions for evaluating a vendor without adding patient facts. Keep clinical assessment and real record drafting in the authorized environment. If you are unsure whether a proposed input is identifiable, resolve that question before disclosure through your privacy process.
Progress notes and psychotherapy notes are different
HIPAA’s special category of psychotherapy notes does not include every document written by a therapist. The definition concerns separately maintained notes documenting or analyzing counseling-session conversations, with specified exclusions. Ordinary information such as diagnosis, treatment plans, and progress summaries is treated differently. HHS explains that most disclosures of psychotherapy notes require the individual’s authorization, subject to limited exceptions. HHS psychotherapy-notes guidance.
Do not assume a folder label determines the legal category. Before sending separately maintained process material to a service, review what the material actually contains and what authority would permit the proposed processing. A contract describing “clinical notes” may not resolve the question.
Couples and family work adds a practical issue: one person’s document can contain information about several people. In a fictional case, a spouse’s portal message describes a partner’s symptoms and a child’s school difficulties. The fact that one person sent it does not make unrestricted AI processing a simple individual preference. Review the treatment arrangement, confidentiality obligations, and applicable permissions before using the material.
Substance-use-disorder records can also raise separate requirements under 42 CFR Part 2 when its coverage criteria are met. A substance-use reference in a record does not, by itself, settle applicability. The federal compliance date for the 2024 final rule was February 16, 2026. HHS Part 2 fact sheet.
HIPAA-eligible alternatives: what to evaluate
The relevant alternative is a contracted, reviewed workflow. A more expensive subscription or a product marketed to clinicians is not enough. Consider these routes as categories for due diligence, not endorsements of a particular vendor.
An eligible organizational AI workspace. Services to investigate include ChatGPT for Healthcare, ChatGPT for Clinicians, and an eligible Regulated workspace, identified in OpenAI’s current guidance. Confirm that your exact workspace is covered by the executed BAA and configured for the intended use. Eligibility can differ across features and connections. Read the guidance alongside your agreement, and do not assume a standard consumer subscription has the same coverage. OpenAI guidance on eligible accounts and configuration.
An application using an eligible API service. The interface may be built by another company even when an OpenAI model generates the output. Ask who receives the PHI, which agreements cover each relationship, and whether the relevant endpoints, retention settings, logs, and additional services qualify. Do not assume an API integration inherits approval simply because the underlying provider offers a healthcare arrangement. OpenAI API data controls.
A documentation service within a reviewed clinical system. Ask whether the existing contract actually covers the new AI function. A familiar electronic record does not answer questions about a newly added processor, recording option, or export. Review the complete proposed use before enabling it.
Ordinary clinician documentation. Maintain a workable way to document without the optional AI service. This gives the practice an alternative when a client declines, a vendor changes terms, the system fails, or the task is not lawful. Test that alternative before the first clinical use.
When comparing vendors, ask for written answers about retention of each data type, human access, secondary uses, deletion limits, subprocessors, access controls, and incident handling. Evaluate the answers against your practice’s obligations. “Not used for model training” answers one question about data use; it does not establish the whole privacy and security arrangement.
State AI-law register: checked September 11, 2026
Next source review due: October 11, 2026, with an earlier review if a relevant law or product function changes.
These entries separate legal scope from practical interpretation. The effective dates identify the cited enactments, not a promise that all related law is covered. Review this register before changing a workflow and recheck the official texts when a product adds functions.
Illinois: explicit restrictions on therapeutic functions. The Wellness and Oversight for Psychological Resources Act took effect on August 1, 2025. Section 20 prohibits licensed professionals from allowing AI to make independent therapeutic decisions, communicate directly with clients therapeutically, generate therapeutic recommendations or plans without professional review and approval, or detect emotions or mental states. The review qualification applies to recommendations and plans; it does not create an exception to the separate emotion-detection prohibition. 225 ILCS 155, section 20, official enactment record.
Section 15 permits defined administrative and supplementary support while retaining the licensed professional’s responsibility. For supplementary support involving session recording or transcription, it requires written information about the use and its specific purpose, plus consent before use. Section 10 defines consent as affirmative, written, and revocable, with exclusions for broad terms-of-use acceptance and deceptive agreement. Section 15, definitions in the official Act.
Practical interpretation: do not deploy an AI therapeutic coach that speaks directly with Illinois clients on the theory that a clinician will review its messages later. A BAA or consent form does not remove the stated prohibition. Evaluate each bundled feature separately.
Nevada: defined providers and administrative exceptions. AB 406 took effect on July 1, 2025. NRS 629.610 restricts AI use in providing professional mental and behavioral healthcare directly to patients by the providers it defines. It allows administrative support, including scheduling, records management, billing, operational analysis, and organizing session files or notes. It requires independent accuracy review for AI output used for the specified billing and session-note purposes. Privacy duties remain, and the statute includes a qualification for applicable Department of Education policy. NRS 629.610, AB 406 enacted text.
The covered-provider definition matters, including specified professions and trainees. Separately, NRS 433.567 addresses suppliers of systems specifically programmed to provide an experience a reasonable person would believe is professional mental or behavioral healthcare. Do not collapse that supplier rule into a ban on every general-purpose chatbot. NRS 433.567.
Utah: duties for defined mental health chatbots. The chapter’s original effective date is May 7, 2025; the retrieved definitions record an amendment by the 2026 General Session. Coverage concerns generative conversational technology represented, or reasonably understood, as offering therapy or helping manage mental-health conditions. Scripted-only tools and tools that only connect users with human therapists are excluded from that definition. Utah Code 13-72a-101.
The chapter restricts sale or sharing of covered user information, with specified exceptions; regulates advertising and use of user input for advertising; and requires clear AI disclosure before access, after the specified seven-day gap, and when asked. These are scoped duties, not a blanket authorization for clinical deployment. Section 201, section 202, section 203.
Vermont: pending full-text verification. The operative provisions associated with H.816 and Act 156 have not been verified here because the complete enacted text could not be retrieved on September 11, 2026. “Pending” describes this source review, not the bill’s legislative status. No Vermont permission, prohibition, effective date, or compliance checklist is asserted. Consult the official H.816 status record and enacted-text endpoint before making a Vermont-specific decision.
Consent has to describe the actual service
For an otherwise lawful use, explain the task in plain language. Describe whether the service receives audio, a transcript, or selected information entered by the clinician. Identify the processor, material retention and access arrangements, what the clinician reviews, and the available alternative. Resolve unknowns before asking the client to agree.
A fictional client might accept note support using selected facts while declining session recording. Check whether the system can honor that distinction. Do not offer choices on a form that the software cannot implement. In family or group care, obtain a separate review of whose agreement and authority are required rather than adapting an individual form by changing its title.
Make withdrawal operational. Staff need to know how to stop capture, remove an automated meeting participant, and prevent the next appointment from inheriting an old setting. Explain accurately what stopping future use can accomplish and what it cannot undo about prior processing or records that must be retained.
These are recommended discussion elements, not a universally sufficient consent form. Illinois’s specific written-consent requirement applies within the scope described above. HIPAA authorization and any other applicable recording or confidentiality requirements need their own analysis. Avoid using a broad “technology consent” clause as the answer to every question.
Review the clinical record before signing
Treat generated text as an unverified draft. In Nevada, the statute expressly requires independent accuracy review for the specified uses. For a broader professional reference, the American Counseling Association’s AI resources address clinicians’ responsibilities when considering these tools. The following review process is a practical recommendation, not a quotation from a statute.
Compare the draft with your actual encounter information. Check who said what, the time frame, symptoms, functional effects, interventions delivered, client response, and agreed next steps. Delete observations that were not made. Correct omissions that change the clinical meaning. Do not let a polished sentence supply evidence you never obtained.
Pay particular attention to negation and uncertainty. “Did not ask about current suicidal thoughts” is not equivalent to “denied suicidal thoughts.” “Client reports a previous diagnosis” is not the same as a diagnosis established today. In a couples session, a partner’s report is not automatically a direct observation of the identified client.
Review plans and billing-related statements separately. Confirm that the note describes services actually provided and decisions actually made. A proposed treatment should not become an agreed intervention because the model placed it under a plan heading. If an important assessment was not completed, address the clinical gap instead of editing the prose to look complete.
After signature, correct discovered errors through the applicable record process rather than silently replacing the record. Keep the practice’s AI procedures specific about who reviews, who signs, how corrections are handled, and when recurrent problems require suspension of the tool.
Make the approval decision reviewable
Before first use, assemble a short record of the decision: the exact task, approved service and account, relevant agreements, data categories, applicable legal restrictions, consent process, review owner, and fallback workflow. Test it with fictional information, including a declined recording and a failed connection.
Revisit the decision when the product changes. A new therapeutic messaging function should receive a new task review. A new processor should receive a data-flow review. A new jurisdiction should receive a legal review. The fact that an earlier version was acceptable does not answer those changed questions.
If patient information enters an unauthorized service, stop further disclosure and use the practice’s privacy and incident-response process promptly. Preserve the information needed to assess what happened. Do not assume deletion resolves the incident or that every event automatically has the same notification consequence. HHS sets out the applicable framework in its Breach Notification Rule guidance.
Continue with structured learning
Our planned AI in Clinical Practice: Ethics, Consent and Documentation course develops vendor review, consent, and documentation decisions through guided exercises. Approvals are in progress; no current CE approval or state-specific acceptance is claimed.
For a shorter introduction to everyday confidentiality decisions, explore the free one-hour ethics course. Check its approval status and your license requirements before relying on it for renewal credit.