Vendor compliance profile
Is ChatGPT HIPAA compliant?
ChatGPT should only be used with PHI through an OpenAI product that is explicitly HIPAA eligible, covered by an executed BAA, and configured for the approved workflow. OpenAI currently lists products such as ChatGPT for Healthcare and Enterprise with Regulated Workspace; ordinary consumer or unsupported workspaces should not receive PHI.
Direct compliance answer
ChatGPT HIPAA, BAA, PHI, and SOC 2 snapshot
Last checked: 2026-07-16 | Confidence: High
| Direct answer | ChatGPT should only be used with PHI through an OpenAI product that is explicitly HIPAA eligible, covered by an executed BAA, and configured for the approved workflow. OpenAI currently lists products such as ChatGPT for Healthcare and Enterprise with Regulated Workspace; ordinary consumer or unsupported workspaces should not receive PHI. |
|---|---|
| BAA availability | An OpenAI BAA must cover the exact eligible product and functionality before PHI is introduced. Buyers should confirm the current Healthcare Addendum, eligible product list, workspace type, retention configuration, connectors, files, voice, support, and API endpoint scope. |
| Can it handle PHI? | Prompts, uploaded files, transcripts, and connected tools can contain PHI even when users intend to de-identify data. |
| SOC 2 caveat | OpenAI publishes enterprise privacy and security commitments. Request current SOC 2 evidence through OpenAI's trust or procurement process. |
| What to verify | Whether the exact OpenAI product, account type, endpoint, connector, and workspace are eligible for BAA coverage. Whether retention, training, abuse monitoring, logging, support access, and data export settings match the intended PHI workflow. |
HIPAA status signal
Conditional
BAA public signal
Eligible products only
SOC 2 evidence signal
Public evidence
PHI warning: Prompts, uploaded files, transcripts, and connected tools can contain PHI even when users intend to de-identify data.
Search query answers
Is ChatGPT SOC 2 Type II?
OpenAI provides enterprise security and privacy documentation, and buyers should request the current SOC 2 evidence through OpenAI's trust or procurement process. SOC 2 evidence does not by itself authorize HIPAA PHI use.
Does ChatGPT SOC 2 evidence prove HIPAA eligibility?
No. Treat ChatGPT SOC 2 evidence as security diligence, not a HIPAA answer. Confirm the current report scope and separately verify the eligible OpenAI product, BAA, retention, connectors, support access, and permitted PHI workflow.
What should buyers verify for ChatGPT Enterprise SOC 2 Type II?
For ChatGPT Enterprise SOC 2 Type II review, verify the current report period, service scope, trust services criteria, exceptions, subprocessors, support access, data retention, connector coverage, and whether the specific Enterprise workspace features are included.
Does ChatGPT Enterprise SOC 2 Type II mean HIPAA is covered?
No. SOC 2 Type II evidence can support security review, but HIPAA PHI use still depends on eligible product scope, BAA terms, retention settings, connectors, workspace configuration, and legal or compliance approval.
Can ChatGPT be used with PHI?
ChatGPT should only be used with PHI under eligible OpenAI products, an appropriate BAA, reviewed retention settings, covered endpoints or accounts, and an approved workflow. Consumer ChatGPT and unsupported plans should not receive PHI.
Does ChatGPT Enterprise make HIPAA use automatic?
No. Enterprise security controls and SOC evidence do not automatically approve PHI use. Buyers still need eligible product scope, BAA terms, retention controls, covered account type, configuration, and legal or compliance review.
Which ChatGPT products does OpenAI list as HIPAA eligible?
OpenAI's current public eligibility page lists ChatGPT for Healthcare, ChatGPT Enterprise with Regulated Workspace, ChatGPT FedRAMP, ChatGPT for Clinicians, and specified API offerings among its HIPAA-eligible products. Exact functionality and account coverage still depend on the executed BAA and current product documentation.
HIPAA, BAA, and SOC 2 summary
| HIPAA | OpenAI publishes a current list of HIPAA-eligible ChatGPT and API products. Eligibility is product- and feature-specific and does not extend automatically to consumer ChatGPT or every workspace, connector, model feature, or retention setting. |
|---|---|
| BAA | An OpenAI BAA must cover the exact eligible product and functionality before PHI is introduced. Buyers should confirm the current Healthcare Addendum, eligible product list, workspace type, retention configuration, connectors, files, voice, support, and API endpoint scope. |
| SOC 2 | OpenAI publishes enterprise privacy and security commitments. Request current SOC 2 evidence through OpenAI's trust or procurement process. |
| PHI risk | Prompts, uploaded files, transcripts, and connected tools can contain PHI even when users intend to de-identify data. |
| Category | HIPAA-Compliant AI Chatbots and Assistants |
| Last checked | 2026-07-16 |
| Confidence | High |
Public evidence and open questions
What public sources say
- OpenAI publishes a dedicated HIPAA Eligible Products and Functionality page for ChatGPT and API offerings.
- OpenAI lists ChatGPT for Healthcare and ChatGPT Enterprise with Regulated Workspace among eligible ChatGPT products, subject to its BAA and product guidance.
- OpenAI also lists specified API offerings with modified-retention requirements; buyers must verify the exact endpoint and account configuration.
What remains unconfirmed
- Whether the buyer's exact OpenAI product, endpoint, retention setting, workspace, connector, and support path are covered.
- Whether prompts, uploads, transcripts, outputs, and connected tools can be governed for the intended PHI workflow.
What it may be used for
- Non-PHI drafting, policy research, summarization, and operational support where regulated data is excluded.
- PHI workflows only under eligible OpenAI products, appropriate BAA terms, retention controls, and approved configuration.
- Vendor security review where SOC 2 evidence, data retention, connector scope, and support access are evaluated together.
What not to use it for
- Entering PHI into consumer ChatGPT, unsupported plans, unsupported connectors, or accounts without verified BAA coverage.
- Uploading patient files, transcripts, images, exports, or notes before retention, logging, and covered-product scope are verified.
- Treating ChatGPT Enterprise, SOC 2 evidence, or privacy controls as automatic HIPAA authorization.
What to verify with the vendor
- Whether the exact OpenAI product, account type, endpoint, connector, and workspace are eligible for BAA coverage.
- Whether retention, training, abuse monitoring, logging, support access, and data export settings match the intended PHI workflow.
- Whether prompts, uploads, outputs, transcripts, custom GPTs, files, connectors, and audit logs stay inside covered scope.
- Whether the current SOC 2 report scope covers the services used by the buyer.
Safer alternatives and related profiles
Safer alternatives to consider
- A healthcare-focused AI or transcription vendor with explicit BAA coverage for the exact PHI workflow.
- OpenAI API endpoints only where BAA eligibility, zero-retention requirements, and covered endpoints are verified.
- Manual de-identification or non-PHI workflows when BAA scope cannot be confirmed.
FAQ
Is ChatGPT SOC 2 Type II?
OpenAI provides enterprise security and privacy documentation, and buyers should request the current SOC 2 evidence through OpenAI's trust or procurement process. SOC 2 evidence does not by itself authorize HIPAA PHI use.
Does ChatGPT SOC 2 evidence prove HIPAA eligibility?
No. Treat ChatGPT SOC 2 evidence as security diligence, not a HIPAA answer. Confirm the current report scope and separately verify the eligible OpenAI product, BAA, retention, connectors, support access, and permitted PHI workflow.
What should buyers verify for ChatGPT Enterprise SOC 2 Type II?
For ChatGPT Enterprise SOC 2 Type II review, verify the current report period, service scope, trust services criteria, exceptions, subprocessors, support access, data retention, connector coverage, and whether the specific Enterprise workspace features are included.
Does ChatGPT Enterprise SOC 2 Type II mean HIPAA is covered?
No. SOC 2 Type II evidence can support security review, but HIPAA PHI use still depends on eligible product scope, BAA terms, retention settings, connectors, workspace configuration, and legal or compliance approval.
Can ChatGPT be used with PHI?
ChatGPT should only be used with PHI under eligible OpenAI products, an appropriate BAA, reviewed retention settings, covered endpoints or accounts, and an approved workflow. Consumer ChatGPT and unsupported plans should not receive PHI.
Does ChatGPT Enterprise make HIPAA use automatic?
No. Enterprise security controls and SOC evidence do not automatically approve PHI use. Buyers still need eligible product scope, BAA terms, retention controls, covered account type, configuration, and legal or compliance review.
Which ChatGPT products does OpenAI list as HIPAA eligible?
OpenAI's current public eligibility page lists ChatGPT for Healthcare, ChatGPT Enterprise with Regulated Workspace, ChatGPT FedRAMP, ChatGPT for Clinicians, and specified API offerings among its HIPAA-eligible products. Exact functionality and account coverage still depend on the executed BAA and current product documentation.
Is ChatGPT HIPAA compliant?
ChatGPT should only be used with PHI through an OpenAI product that is explicitly HIPAA eligible, covered by an executed BAA, and configured for the approved workflow. OpenAI currently lists products such as ChatGPT for Healthcare and Enterprise with Regulated Workspace; ordinary consumer or unsupported workspaces should not receive PHI.
Will ChatGPT sign a BAA?
An OpenAI BAA must cover the exact eligible product and functionality before PHI is introduced. Buyers should confirm the current Healthcare Addendum, eligible product list, workspace type, retention configuration, connectors, files, voice, support, and API endpoint scope.
Does SOC 2 mean ChatGPT is HIPAA compliant?
No. SOC 2 evidence can support security diligence, but it does not prove HIPAA compliance, confirm BAA coverage, or approve PHI use. Review HIPAA terms, BAA scope, covered services, configuration, and intended workflow separately.
What should buyers verify before using ChatGPT with PHI?
Whether the exact OpenAI product, account type, endpoint, connector, and workspace are eligible for BAA coverage. Whether retention, training, abuse monitoring, logging, support access, and data export settings match the intended PHI workflow. Whether prompts, uploads, outputs, transcripts, custom GPTs, files, connectors, and audit logs stay inside covered scope. Whether the current SOC 2 report scope covers the services used by the buyer.
Last checked and source notes
- Last checked
- 2026-07-16
- Confidence
- High
- Dataset rows
- 271 vendors
- Reviewed OpenAI's HIPAA Eligible Products and Functionality page, Healthcare Addendum, and HIPAA implementation guidance on 2026-07-16.
- OpenAI product eligibility, retention settings, endpoint scope, connectors, and workspace configuration can materially change risk.
- ComplySaaS did not verify a private OpenAI contract or customer-specific BAA.
- OpenAI HIPAA Eligible Products and Functionality
- OpenAI Healthcare Addendum
- OpenAI HIPAA Implementation and Configuration Guide