[nonimo]
EN
Download

HIPAA compliant AI: BAAs, plans and the 18 identifiers

· Updated · Written and maintained by Joaquín Trapero, Nonimo

HIPAA compliant AI is not something you can buy, because HHS certifies no product at all, ChatGPT or any other. What OpenAI does offer is narrower: six products it calls HIPAA eligible, which can come with a BAA, including ChatGPT for Healthcare and a ChatGPT for Clinicians plan that is free at launch.

The Free, Plus and Business plans most offices already use are missing from that list, and for Business, OpenAI puts the refusal in writing. If the question on your desk is simply whether ChatGPT is HIPAA compliant, our page for healthcare practices takes it head on.

Eligible is not the same thing as compliant. What gets judged is the practice: the agreement it signed, the plan on its invoice, the features turned on, and what its staff type. This guide takes those four in order. Then it walks the 18 safe harbor identifiers one by one, with what our own tool catches in a referral letter and what it misses. If a record has already been pasted, whether that was a breach is a separate question.

HIPAA compliant AI starts with the BAA: OpenAI’s plans one by one

HIPAA’s duties fall on covered entities and their business associates, and nowhere in it is there a process for approving software. The vendor’s part is set by 45 CFR 164.502(e): a practice may pass PHI to a business associate after getting satisfactory assurance, and that assurance has to be written down in a contract. The practical question, then, is which ChatGPT plans OpenAI will sign that contract for.

OpenAI answers it across two help center pages:

ChatGPT planBusiness associate agreementWho accepts it
Free, Plus and ProNot on OpenAI’s eligible listNobody
BusinessRefused in writing by OpenAINobody
Enterprise or Edu, through salesAvailable; the list names Enterprise with Regulated WorkspaceThe organization, through sales
ChatGPT for HealthcareAvailableThe organization
ChatGPT for CliniciansAvailable, signed inside the productThe individual clinician
API with Modified RetentionAvailableThe organization, by request to OpenAI

OpenAI Help Center, HIPAA eligible products and functionality, and its BAA article; both read September 23, 2026. Two FedRAMP versions for government are also on the list.

HHS does not certify AI products, and says so

One HHS page exists because consultants kept claiming the department’s blessing for their training kits. Its answer: neither HHS nor its Office for Civil Rights labels anyone or anything HIPAA compliant. Asked which cloud vendors are compliant, OCR declined to name any.

Nor does a practice have to certify itself. HHS gives private Security Rule certificates no standing, and one on the wall would not prevent a later finding of violation. A compliance badge on a vendor site is advertising. What OpenAI does with a conversation on each plan is a separate matter, set out plan by plan in its own guide.

What “supports HIPAA compliant use” is telling you

Read the vendors closely and they agree with HHS. OpenAI writes of features that “support HIPAA compliance”, Microsoft of “properly configured implementations”, Anthropic of plans that are “HIPAA ready”. Each phrase points back at the customer, and none claims the product itself is compliant.

Blog roundups of HIPAA compliant AI tools drop the qualifier. Before buying, reread what the vendor actually wrote and find the part about the customer. For a practice, that part starts at the front desk, in the few seconds before someone pastes a referral.

ChatGPT for Clinicians: free at launch, with its own BAA

ChatGPT for Clinicians is a version of ChatGPT that OpenAI offers free at launch to verified clinicians in the United States: physicians, nurse practitioners, physician assistants and pharmacists. Signing up takes an existing ChatGPT account, a valid NPI and a license that a third party verifies.

The business associate agreement comes with it, as a step the clinician completes alone. OpenAI’s help page says an eligible clinician reviews and signs it inside ChatGPT, under Settings, then Agreements. It also says content in this workspace is not used to train OpenAI’s models, and that image generation is not available in it.

Two workspaces behind one login

When a clinician signs up, OpenAI creates a new ChatGPT for Clinicians workspace, and the existing ChatGPT workspace stays available. The two sit side by side in the account switcher, under the same login, and an agreement signed in one does not cover the other.

One ChatGPT login, two workspaces in the account switcher ChatGPT for Clinicians Business associate agreement: signed under Settings, Agreements OpenAI's condition: you are authorized to sign for the account The existing workspace A personal Free, Plus or Pro plan Not on OpenAI's eligible list Stays available after signing up, one click away in the switcher
ChatGPT for Clinicians and the workspace that stays next to it. Source: OpenAI Help Center, read September 23, 2026

At 6 p.m., with a waiting room still full, nothing on screen says which of the two is open. The agreement protects a workspace, not a person, and a referral drafted in the other one leaves the practice with no contract behind it. The fix is one sentence in the practice policy naming the workspace that may hold patient details.

The condition OpenAI writes into its own help page

OpenAI’s instruction for this plan is not to share PHI unless a BAA is in place and you are authorized to sign a BAA for your account. That second condition is where a practice should stop and ask. A physician employed by a group, or working under a hospital’s privacy program, may not be the person entitled to enter agreements about its patients’ information.

This guide does not answer that question, because it depends on employment terms and on who the covered entity is. It is a question for your Privacy Officer and your counsel, and the answer belongs in writing. OpenAI itself points organizations that want one agreement covering several users to ChatGPT for Healthcare. A short AI policy is the natural place to record which of the two your practice uses.

What the BAA leaves out, even on a covered plan

Signing is not the end of it, because each of the four big providers carves features out of its own covered plan. They sit in the same window, behind the same login, and the contract stops short of them. OpenAI states the principle bluntly: the fact that you can click on a feature does not, by itself, mean the agreement covers it.

ProviderWhat the agreement carves out
OpenAIImproved memory, Sites, cloud Codex, scheduled tasks triggered by events, browser and network access in cloud Work
AnthropicCowork, beta features, and whatever connectors or Claude in Chrome send to third parties
GoogleGemini in Chrome, carved out of a Gemini app that is otherwise listed
MicrosoftCopilot’s web search queries, which the DPA and the BAA leave out

Each provider’s own HIPAA documentation, read September 23, 2026. Google’s list is dated August 31, 2026.

How the boundary works at OpenAI

OpenAI tells customers to keep PHI out of those features entirely, and warns that anything missing from both of its lists is not covered by default. The uncovered features are disabled by default. An administrator can enable them for a group of users, and OpenAI says that access is intended only for uses that involve no PHI.

So a covered workspace can hold an uncovered feature, switched on for a good reason, used by someone who believes the whole workspace is covered. OpenAI adds that recently added functionality may not appear on its page at all, which makes the page worth a calendar reminder.

Is Claude, Gemini or Copilot HIPAA compliant?

The answer has the same shape everywhere. At Anthropic, only the Primary Owner of a Claude Enterprise organization can activate HIPAA and accept the agreement; other owners and admins cannot. The Claude guide goes through that coverage table. Google says customers who have not signed its BAA must not use PHI in Workspace services at all.

Microsoft puts it in a footnote: HIPAA compliance “doesn’t apply to web search queries”. With web search on, Copilot may fetch from Bing whenever it judges the web would improve an answer, so it is the software, not the person typing, that can step outside the agreement. Our Copilot guide shows where that setting lives, and the Gemini guide does the same for Google.

The 18 HIPAA identifiers, and what ChatGPT should never see

Send an AI vendor nothing but de-identified text and it stops being a business associate: OCR’s cloud guidance says as much, and the Privacy Rule places no limits on de-identified data. It is the one clean way out of the whole regime, and the one practices most often believe they have taken when they have not. The word also does not travel abroad unchanged, as our comparison of deidentified and anonymized data explains.

The safe harbor route, at 45 CFR 164.514(b)(2), names eighteen categories, lettered (A) to (R). Each has to go for the patient and equally for the patient’s relatives, employers and household members. The tables below take them in the rule’s order, with where each turns up in a practice and what Nonimo does with it.

IdentifierWhere it turns upWhat Nonimo does
(A) NamesHeader, salutation, relatives in the historyMasks a name after a label such as Patient: or a title such as Ms.; a name in running prose stays
(B) Geography below state levelAddress line, county, ZIP codeMasks a street address and a city with state and ZIP; a county or a ZIP alone stays
(C) Dates except the year, and ages over 89Birth, admission, discharge, deathMasks birth and death dates after their label; admission and discharge dates stay
(D) Telephone numbersHeader, callback lineMasks them after Phone, Mobile, Tel. or Call
(E) Fax numbersReferral cover sheetMasks them after Fax
(F) Email addressesHeader, portal messagesMasks them anywhere, without a prompt

45 CFR 164.514(b)(2)(i)(A) to (F).

Nonimo catches most of the first six by the label printed in front of them. Intake paperwork prints its field names, which is why a form comes out better than a clinician’s narrative.

Free text counts the same as a form field

Asked about free text, HHS answers in its de-identification guidance that structured fields and narrative are treated alike. If a listed identifier can be recognized for what it is, it has to come out, whether it sits in a box on a form or halfway through a sentence.

Patient: · DOB: · MRN: · SSN: · MBI: · Phone: · Email: Labeled fields: the label in front says what the value is Header of the letter "...admitted on the 2nd, home a week later. Her daughter drives her..." Narrative: dates, relatives and places with no label in front
The same rule covers both parts of a letter. Source: HHS de-identification guidance, question 3.10

The narrative is where the hard identifiers live: a date written as the 2nd, a daughter named in passing, a small town. The next six are mostly numbers, where a label helps.

IdentifierWhere it turns upWhat Nonimo does
(G) Social Security numbersOlder intake forms, billingMasks as a general [REFERENCE_1]: with dashes anywhere, nine digits behind their label. An SSN label of its own comes with the next version
(H) Medical record numbersHeader of every noteMasks as [REFERENCE_1] after MRN, Medical record number or Chart number; a label of its own comes with the next version
(I) Health plan beneficiary numbersInsurance card, prior authorizationMasks a Medicare MBI after MBI as [REFERENCE_1]. A member ID or group number stays readable in this version; the next masks a member ID behind its label
(J) Account numbersBilling, payment plansMasks a bank account after its label; a card number that passes its check digit, anywhere
(K) Certificate and license numbersDriver’s license on fileMasks a driver’s license after its label; a professional license number stays
(L) Vehicle identifiersAccident and injury claimsMasks a plate after License plate. A VIN stays readable in this version and is masked with the next

45 CFR 164.514(b)(2)(i)(G) to (L).

The insurance card is the one a front desk handles most, and it prints its own labels, which is the only reason member IDs can be caught at all, from the next version on. The SSN, the ITIN and the EIN carry no check digit, so a label, or the dashes of an SSN, is what tells them apart from any other nine digits.

The clinician’s name is not on the list

HHS answers directly that there is no explicit requirement to remove the names of providers or workforce members. The list covers the patient and the patient’s family, employer and household. Other names come in only through the actual knowledge test, or because another law or a confidentiality duty calls for it.

The same reading applies to the referring physician’s NPI: it identifies the clinician, not the patient. Removing it does no harm, but a note does not fail the safe harbor because a doctor signed it.

IdentifierWhere it turns upWhat Nonimo does
(M) Device identifiers and serial numbersPacemaker and implant recordsStays as typed
(N) Web addressesPortal links in messagesStays as typed
(O) IP addressesAccess logs, telehealth ticketsStays as typed
(P) Biometric identifiersVoiceprints and fingerprintsNot text; Nonimo reads text only
(Q) Full-face photographsWound photos, ID scansNot text; Nonimo reads text only
(R) Any other unique codeClaim, case and policy numbersMasks it after Claim number, Policy number, Case ref or Reference; a code with no label stays

45 CFR 164.514(b)(2)(i)(M) to (R).

Partial identifiers and the actual knowledge test

Two traps sit outside the tables. A fragment of an identifier still counts: HHS gives initials and an SSN’s last four digits as its own examples of what fails. And an empty checklist is not the end, because the practice must also not know, clearly and directly in HHS’s words, that the leftover details point to the patient.

The rule does leave room for a code. Section 164.514(c) lets a covered entity tag records so it can match them up again later, provided the tag is not built from the patient’s own details and never leaves the entity. A placeholder whose real value never leaves your workstation fits that description, but the text around it is de-identified only once all eighteen categories are gone as well.

A referral letter through Nonimo 0.2.8, before and after

Here is a real run: an invented letter, typed the way a clinic writes one, through version 0.2.8 for Mac and for Windows on September 23, 2026.

Typed                                    What reached ChatGPT
Patient: Marisol Quintanar               Patient: [PERSON_1]
DOB: 02/30/1958                          DOB: [RECORD_FIELD_1]
MRN: 00482913                            MRN: [REFERENCE_1]
SSN: 000-12-3456                         SSN: [REFERENCE_2]
MBI: 1EG4TE5MK73                         MBI: [REFERENCE_3]
Phone: (507) 555-0142                    Phone: [RECORD_FIELD_2]
Email: mquintanar@example.org            Email: [EMAIL_1]
Address: 1400 Example Avenue,            Address: [ADDRESS_1]
  Owatonna, MN 55060
Referring physician NPI: 1234567893      Referring physician NPI: 1234567893

Every detail is made up so that it cannot belong to anyone. The calendar has no February 30, and Social Security never issues area 000. The phone number sits in the 555-0100 to 555-0199 block reserved for fiction, and example.org is a domain kept for documentation. The MBI and NPI are the sample values CMS uses in its own guides.

The email went without a prompt, because its shape leaves no doubt. The other changes were made in view, each shown with its reason and a way to reverse it, and when the reply comes back Nonimo puts the real details back on the same machine.

It takes a letter from many identifiers to a few, and the few it leaves, such as a date written in the narrative or a relative named in passing, still make it protected health information. The guide on redaction and privilege makes the same point about legal files.

Nonimo on the workstation: an invented referral letter in which the patient's name, date of birth, SSN, phone and email have become placeholders
Nonimo 0.2.8 for Mac (Windows works the same way), with the shorter invented referral from our page for practices

That capture uses a shorter referral, with the name, date of birth, SSN, phone and email replaced, and it shows how each change looks, and can be undone, before anything is sent. The same example, and what a practice gets from it, is on our page for healthcare practices.

Who enforces HIPAA and AI: OCR, the states and the FTC

OCR’s list of resolution agreements, read on September 23, 2026, contains no case about PHI typed into a chatbot for general use. What fills it is ransomware and missing risk analyses. None of that makes pasting permitted. It tells you enforcement still arrives through the familiar Security Rule gaps, which an AI tool can widen.

The rest of the picture comes from elsewhere: guidance OCR wrote for the cloud, one state attorney general, and two state laws that reach where HIPAA does not.

WhoLawWhat kind of caseWhat it can cost
OCR, at HHSHIPAA Privacy and Security RulesSecurity Rule gaps such as ransomware and missing risk analyses; no chatbot case so farA resolution agreement
Texas attorney generalDeception, not privacyPieces Technologies, 2024: the advertised accuracy of a clinical AI productA settlement
FTCConsumer protection lawAI companies, in its January 2024 statementExisting law, applied in full
WashingtonMy Health My Data ActConsumer health data outside HIPAA’s PHI; the person harmed can sueDamages a court may treble, with the increase capped at $25,000
CaliforniaCivil Code 56.06Companies selling software built to keep medical informationBeing treated as a provider of health care

Who acts on HIPAA and AI, as set out in the sections below. OCR’s list read September 23, 2026.

OCR’s cloud guidance already answers most of it

The cloud guidance OCR wrote years before chatbots already settles most AI questions. Holding only encrypted ePHI, without the key, does not release a vendor from business associate status. The conduit exception is for services that merely transmit, storing nothing beyond what the transmission needs, and a chat history is storage. Using a vendor to keep ePHI with no agreement in place breaches 164.308(b)(1) and 164.502(e).

Server location matters less than people expect: OCR accepts ePHI stored abroad, under an agreement and with the location considered when assessing risk. The pressure on that point tends to come from contracts instead, often from the exclusions in a cyber policy.

The first state action came from Texas

Pieces Technologies, a Dallas company, sold four large Texas hospitals a generative AI product that summarized each patient’s condition and treatment for staff. On September 18, 2024, the Texas attorney general announced a settlement over the accuracy figures Pieces had advertised, and billed the case as the first of its kind. The theory was deception, not privacy.

September 18, 2024
Pieces Technologies settles with the Texas attorney general over its advertised accuracy

The lesson for practices is addressed to the buyers, not to Pieces: healthcare entities, the release says, have to weigh whether an AI product is appropriate and “train their employees accordingly”. In January 2024 the Federal Trade Commission made the wider version of that point, that existing consumer protection law applies to AI companies in full.

Washington and California reach past HIPAA

Washington’s My Health My Data Act protects consumer health data and, at RCW 19.373.100, steps aside wherever HIPAA’s definition of PHI applies: it is built for the space HIPAA leaves. Under RCW 19.86.090 the person harmed can sue directly, and a court may treble the damages, with the increase capped at $25,000. HIPAA leaves a second space inside the practice itself: an employee’s FMLA note in the HR file is not PHI at all.

In California, Civil Code 56.06 treats a company selling software built to keep medical information, apps included, as a provider of health care. It is worth asking a vendor about in writing. Public bodies will find the records angle in our guide to AI and public records.

Using ChatGPT under HIPAA in a practice: the order of work

In practice, making AI use HIPAA compliant comes down to a short stack of paperwork, most of which an investigator would ask for anyway. Here is the order a small practice can work through it:

  1. Get the agreement. Both signatures on a BAA naming the product, or the agreement built into ChatGPT for Clinicians, accepted by a person entitled to accept it.
  2. Match the plan to the list. The product on the invoice, word for word, has to be one the vendor calls eligible.
  3. Read the exclusions page. Find out which excluded features are on, and for which roles.
  4. Add it to the risk analysis. The one 45 CFR 164.308(a)(1)(ii)(A) already requires; a new AI tool is a new line in it.
  5. Write down what may be typed. Which workspace may hold patient details, and what comes out before anything is pasted. Our policy template saves drafting from zero.
  6. Train, and keep the record. Section 164.308(a)(5) wants every member of the workforce trained, managers too.
18identifier categories in the safe harbor
60 daysat most from discovery to notify patients of a breach
6 yearsto keep the records the Security Rule asks for
45 CFR 164.514(b)(2), 164.404(b) and 164.316(b)(2)(i)

Section 164.316(b)(2)(i) keeps all of it on file for six years, counted from creation or from the last day it applied, whichever comes later. If a paste does go wrong, 164.404(b) gives 60 calendar days at most from discovery to notify the patients affected, and the breach guide covers how to decide whether it was one.

The Security Rule update is still a proposal

The big Security Rule overhaul appeared as a proposal on January 6, 2025, at 90 FR 898, and stopped there. HHS’s Unified Agenda now files it under Long-Term Actions and pencils in a final rule for July 2027. Until then, encryption and multifactor authentication stay addressable. Addressable still means you either put them in place or record why something equivalent is reasonable instead.

Law firms that hold medical records

ABA Formal Opinion 512, from July 29, 2024, adds a layer for litigators: seven duties to weigh before using generative AI, from competence and client confidentiality to candor toward the tribunal and reasonable fees, drawn from more than a dozen Model Rules. It is a committee’s view, binding on no state by itself. Redaction and privilege is covered in its own guide.

Nonimo in a practice: what it covers and where it stops

Nonimo runs on Mac and Windows computers. Whoever is drafting highlights the passage and hits one key, and the identifiers the app recognizes turn into placeholders right there on the machine, before ChatGPT, Claude or Copilot see anything. When the answer arrives, the placeholders turn back into the real details.

What it keeps on the workstation, encrypted, is set out on the security page.

Nonimo and the business associate agreement

What leaves is still PHI, so the business associate agreement is still needed. Nonimo works alongside the agreement, cutting down what the vendor receives under it.

So the advice here for a practice handling PHI starts elsewhere. Get the BAA signed, switch to a listed plan, read the exclusions and put the policy, risk analysis and training record on paper. If you then want fewer identifiers leaving the workstation, the plans are on the license page, with central rollout for organizations and a route through a partner who already looks after your IT.

Sources

Checked September 23, 2026. hhs.gov, help.openai.com, americanbar.org and ecfr.gov refuse tools run from the command line, which is a measure against bots, not a dead link; those pages were read through a public copy or reader.

Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.

Common questions

Is there such a thing as HIPAA compliant AI?

Not as a product, because HHS certifies none. OpenAI names six products it calls HIPAA eligible and will cover with a BAA, ChatGPT for Healthcare and ChatGPT for Clinicians among them; Free, Plus and Business are missing from that list. Whether a practice uses AI in a HIPAA compliant way turns on four things: the signed agreement, the plan, which features are on, and what staff type.

Which ChatGPT plans will OpenAI sign a BAA for?

Four ChatGPT products: ChatGPT for Healthcare, ChatGPT for Enterprise with Regulated Workspace, ChatGPT FedRAMP and ChatGPT for Clinicians. Two API offerings complete the list, both with Modified Retention. OpenAI's BAA article says in so many words that ChatGPT Business gets no BAA. Nonimo does not change which plan a practice is on; it works on the text before it reaches any of them.

What is ChatGPT for Clinicians, and does it cover my practice?

It is a version of ChatGPT that OpenAI offers free at launch to verified US clinicians, with a BAA the individual signs under Settings, Agreements. OpenAI says it is designed for individual use and points organizations wanting one agreement for several users to ChatGPT for Healthcare. Whether a clinician employed by your practice may sign for the account is a question for your Privacy Officer and counsel.

Is Claude, Gemini or Copilot HIPAA compliant?

None of them is, for the same reason ChatGPT is not: HHS certifies no products. Anthropic, Google and Microsoft each sign BAAs for specific plans, and each publishes features the agreement does not reach, such as connectors and Claude in Chrome at Anthropic, Gemini in Chrome at Google, and web search queries in Microsoft Copilot.

Which AI tools can a practice use under HIPAA?

Only the ones your organization has under a signed BAA, on a covered plan, with the uncovered features left off, because no AI tool is HIPAA compliant by itself. As of September 26, 2026, OpenAI lists six eligible products, including ChatGPT for Healthcare, ChatGPT for Clinicians and its API with Modified Retention. Anthropic signs for Claude Enterprise, switched on by its Primary Owner, and for the Claude API; Team, Free, Pro and Max cannot turn HIPAA on.

What are the 18 HIPAA identifiers?

They are the eighteen kinds of detail listed in the safe harbor rule, 45 CFR 164.514(b)(2), that must come out: names, any place smaller than a state, every date element except the year, phone and fax numbers, email, Social Security, medical record, health plan and account numbers, licenses, vehicle and device identifiers, URLs, IP addresses, biometrics, full-face photographs and any other unique code, for the patient and for relatives, employers and household members.

Do I have to remove the doctor's name before using AI on a note?

Not under the safe harbor list. In its de-identification guidance, HHS answers that there is no explicit requirement to remove the names of providers or workforce members. They come into play only if they would give you actual knowledge that the patient can be identified, or because another law or a confidentiality duty requires it. The patient's name and those of relatives always go.

If we delete the patient's name, can the note go into ChatGPT?

Not as de-identified text. Every one of the eighteen categories must come out, admission and discharge dates, relatives' names and stray unique codes included, and the practice must also not know that what is left points to the patient. HHS adds that initials or the last four digits of a Social Security number do not pass. Removing one name leaves protected health information.

Can Nonimo make a patient note de-identified under HIPAA?

No, and we do not claim it. On the computer where the text is typed, Nonimo swaps each identifier it recognizes for a placeholder, and the swapped version is what goes to ChatGPT, Claude or Copilot. That cuts what leaves the practice. In our test referral letter, admission dates and a relative's name stayed in place. What leaves is still protected health information, so the business associate agreement is still needed.