Dental
Is ChatGPT HIPAA Compliant? What Dental and Med Spa Owners Need to Know
By Kevin Sims, Founder, Lumon Studios6 min read
Is ChatGPT HIPAA compliant? Not on its own, and not on the plans most small practices use. HIPAA compliance depends on how you use a tool and whether the vendor has signed a business associate agreement (BAA) with you. As of October 2026, OpenAI says only sales managed ChatGPT Enterprise or Edu accounts are eligible for a ChatGPT BAA, that it does not offer one for ChatGPT Business, and that individual clinicians have a separate path through ChatGPT for Clinicians. So if your dental office or med spa is on Free, Plus, Pro or Business, keep patient information out of it.
This post walks through each option, what counts as patient information, and a workflow that lets your team use AI safely.
Why the BAA is the whole question
HIPAA lets a covered practice share protected health information (PHI) with a vendor only if the practice obtains satisfactory assurances, in the form of a contract or other written arrangement, that the vendor will safeguard it. HHS calls that contract a business associate agreement. HHS also says a cloud vendor that stores PHI is a business associate even if the data is encrypted and the vendor has no key.
So "is ChatGPT HIPAA compliant" really means: will OpenAI sign a BAA for the plan you use, and are you using only the features that BAA covers?
Is ChatGPT HIPAA compliant? The answer plan by plan
Everything below is as of October 2026. Plans and terms change, so confirm with OpenAI in writing before relying on any of it.
Free, Plus and Pro
No BAA. OpenAI's BAA help article limits ChatGPT BAAs to sales managed Enterprise or Edu accounts (plus the separate clinician flow below). On personal plans, OpenAI's data controls page explains that when "Improve the model for everyone" is off, new conversations are not used to train its models, and that Temporary Chats are not used to improve them either. That is good hygiene, but turning off training does not create a BAA.
ChatGPT Business
Better privacy defaults, still no BAA. OpenAI's enterprise privacy page says it does not train on business data by default and that ChatGPT Business completed a SOC 2 Type 2 audit. But the help article states it plainly: "we don't offer a BAA for ChatGPT Business." Business is a solid choice for work that contains no PHI.
ChatGPT Enterprise and ChatGPT for Healthcare
These are the plans where a BAA is possible. OpenAI's published Healthcare Addendum and BAA (the version labeled v.111124) defines the eligible services as the Zero Retention API, ChatGPT Enterprise, and anything else OpenAI identifies in writing. It also says third party services such as plugins, actions, third party GPTs and some collaboration features are not eligible.
OpenAI's ChatGPT for Healthcare help article describes it as an enterprise version of ChatGPT that supports HIPAA compliant use through security controls, no training on data, retention controls and the availability of a BAA. It also warns that the BAA covers only listed eligible products, and that its improved memory feature is not covered. Pricing is based on ChatGPT Enterprise, and the article points "large hospitals and health systems" to sales. Whether OpenAI will sell this to a three chair dental office or a single location med spa is unclear from its public pages. Ask in writing.
ChatGPT for Clinicians
OpenAI's ChatGPT for Clinicians article describes a free version for verified US clinicians that lets an eligible individual sign a BAA under Settings, then Agreements. The eligible list is physicians (MD or DO), nurse practitioners, physician assistants and pharmacists. Dentists are not on that list. A med spa's medical director or nurse practitioner might qualify personally, but OpenAI says it is designed for individual use; a BAA covering several users requires ChatGPT for Healthcare. It is not a front desk tool.
The OpenAI API
Developers can request a BAA for API use by emailing OpenAI, reviewed case by case, according to the same BAA help article. Most practices meet the API indirectly, inside a vendor's product. In that case you need a BAA with the vendor, and HHS says that vendor in turn needs a BAA with its own subcontractors.
What about Claude and Microsoft Copilot?
Claude. Anthropic says it provides a BAA covering its HIPAA ready services, such as its API or Enterprise plans, but standard Claude Enterprise is not covered until the organization's Primary Owner activates HIPAA compliance and accepts the BAA. Several features are excluded, and that page covers only commercial products; consumer plans (Free, Pro, Max) are handled separately.
Microsoft Copilot. Microsoft says Copilot and Copilot Chat support HIPAA compliance for properly configured implementations, and that web search queries are not covered by its data protection terms and BAA. Its HIPAA overview says the Microsoft BAA is available by default to covered entity customers through its Data Protection Addendum. Ask Microsoft or your IT provider which of your subscriptions that covers.
What counts as PHI, and what "de identified" means
HHS's de identification guidance describes a Safe Harbor method that removes 18 kinds of identifiers. They include names, all elements of dates except the year (birth dates and appointment dates count), phone numbers, email addresses, medical record numbers, full face photographs, and "any other unique identifying number, characteristic, or code." HHS also says identifiers must be removed from free text, not just from form fields, and that the practice must not have actual knowledge that what remains could identify the person.
In practice, "a patient in her 40s asking whether a crown or an onlay lasts longer" is usually fine. "Maria, DOB 3/14, chart 10422, before photo attached" is not. Be careful with rare details too: in a small town, an unusual procedure plus a job title can identify someone.
A safe workflow for a small practice
- Write a one page AI policy. List approved tools, and say plainly that PHI goes only into tools covered by a signed BAA.
- Use a no PHI plan for writing work. Policies, job posts, generic patient education, website copy and review reply templates do not need patient data.
- Draft with placeholders. Write "[Patient name]" and "[date]" in the AI draft, then fill in the real details inside your practice software.
- Send PHI only through BAA covered systems, such as your practice management system, phone platform or AI scribe.
- Ban personal accounts for work. It is the easiest leak to prevent.
- Have a licensed person review anything clinical before it reaches a patient.
- Recheck every six months. Plan names, eligible features and terms change.
What to watch out for
- Badges are not contracts. "HIPAA compliant" on a vendor page means nothing without a signed BAA.
- Feature gaps inside covered plans. Connectors, third party GPTs, memory and web search can sit outside a BAA even on an eligible plan.
- Med spas outside HIPAA still have rules. A cash only med spa may not be a HIPAA covered entity, but California's medical privacy law can still apply. See AI for med spas.
- Your advisor has the final word. Confirm with your compliance advisor or attorney before putting patient data into any AI tool.
Where to start
Today, tell your team that patient details stay out of every chatbot that lacks a BAA. This week, decide whether you need PHI in an AI tool at all; most front desk writing does not. Our AI for dental offices playbook covers BAA backed options, and our AI assessment or AI consulting services can sort out the rest. CPA firms face a parallel rule set, covered in AI for small CPA firms.
Frequently asked questions
Is ChatGPT Enterprise HIPAA compliant?
ChatGPT Enterprise can be used in a HIPAA compliant way only if OpenAI signs a BAA with your organization and you stay within the covered features. OpenAI says BAAs for ChatGPT are available to sales managed Enterprise or Edu accounts, and its addendum excludes third party services such as plugins and third party GPTs. Get the BAA and the eligible feature list in writing.
Is paid ChatGPT HIPAA compliant?
Paying is not enough. As of October 2026, OpenAI does not offer a BAA for ChatGPT Business, and its BAA article does not extend ChatGPT BAAs to personal plans like Plus or Pro. Turning off model training improves privacy but does not create a BAA, so patient information should stay out of those plans.
Is the ChatGPT API HIPAA compliant?
The API can be, with a BAA. OpenAI says developers can request one by email, reviews each request case by case, and covers most API services with listed exceptions. Its healthcare addendum names the Zero Retention API as an eligible service. If you use an app built on the API, you need a BAA with that app's vendor.
Can I use ChatGPT if I remove patient names?
Removing names alone is not enough. HHS's Safe Harbor method lists 18 identifiers to remove, including dates other than the year, phone numbers, record numbers and full face photos, and it covers free text too. Use placeholders, keep details general, and add real information only inside systems covered by a signed BAA.
Sources
- HHS: Business Associates guidance
- HHS: Guidance on HIPAA and Cloud Computing
- OpenAI Help Center: How can I get a Business Associate Agreement (BAA) with OpenAI?
- OpenAI Help Center: Data controls in ChatGPT
- OpenAI: Enterprise privacy at OpenAI
- OpenAI Healthcare Addendum and BAA (PDF)
- OpenAI Help Center: ChatGPT for Healthcare
- OpenAI Help Center: ChatGPT for Clinicians
- Anthropic Privacy Center: Business Associate Agreements (BAA) for Commercial Customers
- Microsoft Learn: Enterprise data protection in Microsoft Copilot and Microsoft Copilot Chat
- Microsoft Learn: HIPAA and HITECH Act compliance offering
- HHS: Guidance Regarding Methods for De identification of Protected Health Information