Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & Research SupplyReagents, PPE & instruments — chain-of-custody documented.Fast, traceable sourcing built for regulated research environments, from bench consumables to instrumentation.Shop lac.us CodeCASRAIlac.us

Using AI With PHI in Research: HIPAA Rules and the BAA Question

ChatGPT and most AI tools are not HIPAA compliant by default. This guide covers when a Business Associate Agreement applies, which AI product tiers actually qualify, and how to handle PHI in research prompts safely.

Ask about Using AI With PHI in Research: HIPAA Rules and the BAA Question

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Short answer: no version of ChatGPT is “HIPAA compliant” on its own, because HIPAA compliance is not a property of a piece of software — it is a property of a signed contract. A covered entity or business associate can lawfully put PHI into an AI tool only after a Business Associate Agreement (BAA) is in place covering that specific product and tier, and only within the terms that BAA sets. Put PHI into an AI tool with no BAA behind it and the disclosure itself is the HIPAA violation, regardless of how secure the vendor’s infrastructure actually is.

Quick answer: is ChatGPT HIPAA compliant?

Product / tier BAA available? Can PHI be entered?
ChatGPT Free, Plus, Team No No — do not enter PHI
ChatGPT Business No (OpenAI explicitly excludes this tier) No
ChatGPT Enterprise / ChatGPT Edu Yes, but only for sales-managed accounts that request and sign one Only after the BAA is executed and the account is configured accordingly
OpenAI API platform Yes — no enterprise agreement required; request via a case-by-case review Only after the BAA is executed; not all API services are in scope

Last verified 16 August 2026 directly against OpenAI’s own enterprise privacy page and its Help Center article “How can I get a Business Associate Agreement (BAA) with OpenAI for the API Services?” Vendor BAA terms change; re-confirm current tier eligibility directly with the vendor before relying on this table for a live decision.

Why “is [tool] HIPAA compliant” is the wrong question

HIPAA does not certify software products, and there is no government or industry seal that makes a tool “HIPAA compliant” in the abstract. What HIPAA actually requires is that a covered entity (a health plan, health care clearinghouse, or health care provider that transmits health information electronically) obtain a signed Business Associate Agreement before letting a business associate — any outside person or entity that creates, receives, maintains, or transmits protected health information (PHI) on the covered entity’s behalf — access that PHI (45 CFR 160.103, definitions of “covered entity” and “business associate”). An AI vendor processing PHI on a research team’s behalf is a business associate under that definition the moment PHI reaches its systems, whether that happens through an uploaded file, a pasted note, or a single sentence typed into a chat prompt.

So the real question is never “is this AI tool secure enough” — it’s “has my institution executed a BAA with this specific vendor, for this specific product and tier, and am I using it inside the terms that BAA sets?” A tool can have excellent security and still be an unauthorized disclosure if no BAA exists; a tool can have a signed BAA and still be misused if PHI is entered into a product tier or feature the BAA doesn’t cover (this is exactly the trap with ChatGPT: a BAA can exist for the Enterprise/Edu tier while the free consumer product used by the same person on the same laptop has none).

This “does a contract exist, and does the disclosure fall inside it” framing is the same one CASRAI’s guide to HIPAA and the HIPAA-in-clinical-research pathways use for any third-party disclosure — an AI vendor is not a special case under the Privacy Rule, it is an ordinary business associate relationship that happens to route data through a large language model instead of a database.

Decision flow: can I put PHI into an AI tool?

  1. Is the information actually PHI? If it has been de-identified under the Safe Harbor or Expert Determination method (45 CFR 164.514(a)-(b)) it is no longer PHI and HIPAA’s use/disclosure restrictions no longer apply to it — see CASRAI’s guide on the 18 HIPAA identifiers and de-identification. If it still contains any of the 18 identifier categories, or falls short of a qualified statistician’s Expert Determination, treat it as PHI and continue.
  2. Does your institution have a signed BAA with this exact vendor, product, and tier? Not “a BAA with this company somewhere” — the specific product. A university-wide Microsoft enterprise agreement does not automatically extend to a research team’s personal ChatGPT subscription, and an OpenAI API BAA for one internal application does not extend to a researcher’s separate ChatGPT Team account.
  3. Is this specific feature/data flow inside the BAA’s scope? Vendors commonly carve out specific services, default logging behavior, or model-training use from their BAA coverage. Confirm the current in-scope list with the vendor and your institution’s privacy office — don’t assume yesterday’s answer still holds, since these lists change as vendors add products.
  4. Has your IRB/privacy office and institutional data-governance process actually reviewed and approved this use? A vendor BAA is necessary but not sufficient — most institutions also require an internal data-use or AI-tool-approval review before PHI-bearing workflows go live, on top of the underlying HIPAA analysis.
  5. If any answer above is no, don’t enter the PHI. Either de-identify the data first, use an approved BAA-covered tool/tier instead, or route the task through an already-approved workflow (e.g., an institution-licensed AI product configured by IT with the BAA already executed).

What counts as “putting PHI in ChatGPT” — it’s broader than most researchers assume

A disclosure happens the moment identifiable health information reaches the vendor’s systems — it does not require uploading a spreadsheet. Each of the following is a PHI disclosure if the underlying account has no BAA behind it:

  • Pasting a clinical note, case description, or chart excerpt into a prompt, even to ask for help summarizing or rephrasing it
  • Uploading a de-identification-pending dataset that still contains dates, geographic subdivisions smaller than a state, or any of the other 18 Safe Harbor identifier categories
  • Asking an AI tool to “clean up” or reformat a recruitment log, adverse-event report, or patient-facing document that still names participants
  • Dictating or transcribing a study visit note through an AI-powered transcription feature that isn’t covered by an institutional BAA
  • Using an AI browser extension or “AI writing assistant” plugin that silently sends page content — including an open EHR or REDCap screen — to a third-party model

None of these require the researcher to intend a “disclosure” in the everyday sense of the word; HIPAA’s use/disclosure framework doesn’t require intent to trigger the obligation.

What a BAA actually has to establish

A HIPAA-compliant BAA is not just a signature — it has to set out, in writing, the business associate’s permitted and required uses of PHI, its obligation to implement appropriate safeguards, its breach-notification duties back to the covered entity, and its obligation to return or destroy PHI at the end of the relationship (45 CFR 164.504(e)). For an AI vendor specifically, the practical questions a research administrator or PI should be asking before treating a BAA as adequate for a given workflow include:

  • Is prompt/output data used to train the underlying model? Enterprise and API BAA terms typically disable training-on-your-data by default; free consumer tiers generally do not, and may use content for model improvement absent an opt-out.
  • What is the data retention window, and can it be shortened or zeroed out? Some enterprise/API configurations support “zero data retention” for approved use cases; confirm this is actually enabled for the workflow in question rather than assumed.
  • Which specific services are covered? A BAA that covers an API platform’s core chat/completions endpoints may explicitly exclude certain add-on features (e.g., some web-browsing or file-search tools) — check the vendor’s current in-scope list, not the product’s general marketing page.
  • Who administers the account? BAA coverage typically attaches to an institutionally-managed, sales-negotiated account — not to an individual researcher’s self-serve subscription, even on a paid tier.

Vendor landscape: what’s actually offered as of this writing

Coverage changes as vendors update their enterprise offerings — confirm current terms directly with the vendor and your institution’s contracting/privacy office before relying on any of this for a live decision.

  • OpenAI: per OpenAI’s own Help Center, a BAA is available for the API platform without requiring a separate enterprise agreement (requested via a case-by-case review), and for ChatGPT Enterprise or ChatGPT Edu specifically for sales-managed accounts. OpenAI states explicitly that it does not offer a BAA for ChatGPT Business, and free/Plus consumer ChatGPT is not BAA-eligible at all. OpenAI also lists a separate, narrower “ChatGPT for Clinicians” in-product BAA flow for individual eligible clinicians.
  • Microsoft: Microsoft’s standard HIPAA Business Associate Agreement is included by default, via the Online Services Data Protection Addendum, for customers that are covered entities or business associates — but it applies only to the specific cloud services on Microsoft’s published “in-scope” list. Whether a given Azure AI/OpenAI-based service is on that current list is something to confirm directly against Microsoft’s own compliance documentation at the time of use, not assumed from general Azure HIPAA-eligibility claims.
  • Other AI vendors: the same pattern holds industry-wide — a company’s general enterprise BAA does not automatically extend to every AI feature it ships, and free/consumer tiers of any AI product should be treated as non-BAA-covered by default unless the vendor states otherwise in writing.

De-identification as the alternative to a BAA

Where a BAA isn’t in place, or a research use doesn’t need the identifiers at all, de-identifying data before it goes anywhere near an AI tool removes it from HIPAA’s scope entirely under Safe Harbor or Expert Determination (45 CFR 164.514(a)-(b)). This is frequently the more practical path for exploratory or drafting work — summarizing a de-identified case vignette, drafting a generic protocol section, or getting help with statistical code that never touches patient identifiers — none of which need a BAA at all if the identifiers are genuinely removed first. A Limited Data Set (dates and geographic detail retained, direct identifiers removed) is a middle option, but it is still PHI-adjacent for HIPAA purposes and still requires a data use agreement — it does not, on its own, clear a tool for BAA-free AI processing the way full de-identification does.

Practical checklist before a research team uses AI with PHI

  1. Confirm with your institution’s privacy/compliance office whether a BAA already exists with the specific AI vendor, product, and tier you intend to use.
  2. If no BAA exists, don’t proceed with PHI — either request one through institutional contracting, switch to an already-covered tool, or de-identify the data first.
  3. If a BAA exists, confirm the account you’ll actually use is the BAA-covered institutional account, not a personal or self-serve subscription.
  4. Confirm training-on-data and retention settings are configured the way the BAA and your institutional policy require — don’t assume defaults are safe.
  5. Route the specific use case through your institution’s AI-tool-approval or data-governance review, even after the BAA is confirmed — a BAA authorizes the vendor relationship, not any specific use your institution hasn’t separately cleared. CASRAI’s guide on writing an AI acceptable use policy covers how institutions typically structure that approval layer.
  6. Document the decision (which tool, which BAA, which data category, who approved it) the same way you would document any other PHI disclosure pathway.

Frequently asked questions

Can I put PHI in ChatGPT?

Only if your account is on ChatGPT Enterprise or ChatGPT Edu, is sales-managed, and your institution has an executed BAA with OpenAI covering that account — and even then, only within whatever scope and configuration that BAA specifies. PHI should never be entered into ChatGPT Free, Plus, Team, or Business, none of which carry BAA coverage.

Is AI HIPAA compliant in general?

No AI tool is “HIPAA compliant” as an inherent property — HIPAA compliance for any third-party tool depends on whether a Business Associate Agreement is in place covering that specific product, tier, and use, and whether the actual use stays inside what that BAA authorizes. The question has to be asked per vendor, per product tier, and often per feature.

Does de-identifying data before using AI remove the need for a BAA?

Yes, if the de-identification genuinely meets the Safe Harbor or Expert Determination standard under 45 CFR 164.514 before the data reaches the AI tool. Once information is properly de-identified it is no longer PHI, and HIPAA’s use/disclosure and business-associate requirements no longer attach to it. A Limited Data Set is not sufficient for this purpose on its own — it remains within HIPAA’s scope.

What happens if a researcher puts PHI into a non-BAA-covered AI tool by mistake?

That is an unauthorized disclosure of PHI and is handled through the same breach-assessment and reporting pathway as any other unauthorized disclosure — institutions should treat it as a potential reportable incident under the Breach Notification Rule (45 CFR Part 164, Subpart D) and route it to their privacy office immediately rather than treating it as a minor technical slip.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →