Can a healthcare practice use ChatGPT or Copilot under HIPAA?
Short answer
Yes, but only with tools covered by a Business Associate Agreement (BAA) and set up correctly. Free and personal AI accounts have no BAA, so protected health information must never go into them. Microsoft covers Microsoft 365 services under its BAA, and OpenAI offers BAAs only for certain business products. Confirm coverage for the exact product and license before any patient data goes in.
Draft · pending expert review
HIPAA doesn't mention AI, but its rules apply the same way they do to email or cloud storage: if a vendor's system handles protected health information (PHI) for you, you need a Business Associate Agreement with that vendor.
The quick test
- Is there a BAA covering this exact product and license?
- Is it set up properly: access limited to the right staff, data retention understood, and audit logging on?
- Is it in your risk analysis? New systems that touch ePHI belong there.
Where practices get into trouble
- Staff pasting visit notes into a personal ChatGPT account to tidy them up
- Recording and transcription apps added without anyone checking their terms
- AI features switched on inside existing software without review
A safer path
Give staff an approved tool that sits under your BAA, write down what may and may not go into it, and train people on the difference.