See what our clients say about working with Bonami Software across 200+ projects for 18+ industries. EXPLORE NOW!
We don't just build software. We deliver results. EXPLORE NOW!
See why businesses choose Bonami Software for reliable, scalable solutions. EXPLORE NOW!
We turn ideas into scalable products with proven delivery across 18+ industries. EXPLORE NOW!
See what our clients say about working with Bonami Software across 200+ projects for 18+ industries. EXPLORE NOW!
We don't just build software. We deliver results. EXPLORE NOW!
See why businesses choose Bonami Software for reliable, scalable solutions. EXPLORE NOW!
We turn ideas into scalable products with proven delivery across 18+ industries. EXPLORE NOW!

2 HIPAA + AI series · Platforms

Is ChatGPT, Claude or Gemini HIPAA Compliant?

None of them is, out of the box. All three providers offer a Business Associate Agreement for some products and not others, and each BAA has its own exclusions. Here is what OpenAI, Anthropic and Google actually cover as of October 2026, and what stays your responsibility either way.

By Bonami Healthcare & AI Engineering 15 min read
In this article
  1. The short answer
  2. What “HIPAA compliant” really means
  3. Four layers of responsibility
  4. Side-by-side comparison
  5. ChatGPT and the OpenAI API
  6. Claude and Anthropic
  7. Gemini and Google
  8. Through Azure, AWS or Google Cloud
  9. What you still configure
  10. Can I use this tool with PHI?
  11. FAQ

Key takeaways

  1. No consumer version of ChatGPT, Claude or Gemini comes with a BAA. Do not put PHI into them.
  2. All three providers offer BAA coverage for specific business products: OpenAI for its healthcare, regulated enterprise and API offerings; Anthropic for Claude Enterprise and its API once HIPAA-ready; Google through Workspace and Google Cloud.
  3. Every BAA has exclusions. Features such as live web search, beta tools, connectors and certain APIs can fall outside coverage even on an eligible plan.
  4. APIs come with retention conditions: OpenAI requires Modified Retention, and Anthropic’s newest models require 30-day retention.
  5. The BAA is the start of compliance, not the end. Configuration, access control, minimum necessary use and your own risk analysis remain your job.
01 · The answer

The short answer

Short answer

ChatGPT, Claude and Gemini are not HIPAA compliant by default. Each provider offers a BAA for certain business products: OpenAI for ChatGPT for Healthcare, Regulated Enterprise workspaces, ChatGPT for Clinicians and its API; Anthropic for Claude Enterprise and its API; Google for Gemini in Workspace and on Google Cloud. Used under that BAA and configured correctly, they can support HIPAA-compliant use.

Interest in this question has jumped as clinicians and health systems adopt these tools. U.S. Google searches for “is claude hipaa compliant” went from roughly 100 a month in late 2025 to about 1,000 a month through the summer of 2026, according to DataForSEO estimates, while “is chatgpt hipaa compliant” has held steady at 700 to 1,000 a month.

0

consumer apps from the three providers that come with a BAA

OpenAI, Anthropic and Google docs, Oct 2026
6

OpenAI products listed as HIPAA-eligible with a BAA

OpenAI Help Center
11x

growth in monthly U.S. searches for “is claude hipaa compliant” in a year

DataForSEO, Sep 2025 to Aug 2026
02 · Definitions

What “HIPAA compliant” does and does not mean for an AI tool

HIPAA applies to covered entities (healthcare providers that bill electronically, health plans and clearinghouses) and to their business associates, the vendors that create, receive, maintain or transmit protected health information on their behalf. An AI provider processing your patients’ data is a business associate, and HIPAA requires a written Business Associate Agreement before PHI goes to them.

That is why the honest answer to “is this AI tool HIPAA compliant?” is always conditional. A vendor can do three things: offer products whose security and data handling are suitable for PHI, sign a BAA covering those products, and document what is in and out of scope. It cannot run your access controls, decide what your staff type into it, or perform your risk analysis.

“HIPAA compliant” can mean

  • The vendor will sign a BAA for this specific product
  • The product has security controls suitable for ePHI
  • Customer data is not used for training
  • Retention can be configured to meet your needs

It never means

  • Every feature of the product is covered
  • Any plan or account type is covered
  • Your organization is compliant by using it
  • You can skip your own risk analysis and policies

The same logic applies to cloud services. HHS guidance is explicit that a cloud provider storing ePHI is a business associate even if it only holds encrypted data and has no key. Being a business associate does not make the customer’s use compliant; it creates obligations on both sides.

03 · Responsibility

Product, agreement, implementation, and you

Most confusion about AI and HIPAA comes from blending four separate questions into one. Keep them apart and the vendor comparison becomes much easier to read.

Layer 1Product capabilityWhat the software can do

Encryption, admin controls, audit logs, data residency, retention settings and the absence of training on your data. This is what product pages describe. It is necessary and not sufficient.

Layer 2Provider agreementWhat the vendor commits to

The signed BAA and its implementation guide: which products and features are covered, which are excluded, what retention is required, and what happens in a breach. This is where most surprises are.

Layer 3ImplementationHow you set it up

Which plan and region, which features are switched on, who can access it, what data flows in, how outputs are stored, and whether excluded features are disabled. Two organizations with the same BAA can end up in very different places.

Layer 4Your compliance programWhat you remain accountable for

Risk analysis, policies, workforce training, minimum necessary use, sanctions, incident response and breach notification. None of this transfers to a vendor. Our post on the Privacy Rule vs the Security Rule explains how these obligations divide.

The comparison below covers layers 1 and 2 for each provider. Layers 3 and 4 are covered at the end of this article and in depth in our HIPAA-compliant AI requirements checklist.

04 · Comparison

ChatGPT vs Claude vs Gemini for HIPAA: side by side

Each cell summarizes the provider’s own documentation as of October 5, 2026. Filter by product type, or on a phone, switch between providers.

HIPAA and BAA availability for OpenAI ChatGPT, Anthropic Claude and Google Gemini by product type
Product typeOpenAIChatGPT · APIAnthropicClaude · APIGoogleGemini · Workspace · Cloud
Consumer appspersonal accounts No BAA ChatGPT Free, Go, Plus and Pro are not eligible services under OpenAI’s BAA. No BAA Claude Free, Pro and Max cannot enable HIPAA. No BAA route BAAs are offered through Workspace and Google Cloud, not personal Gemini accounts.
Consumer health featuresrecords connected by patients No BAA Health in ChatGPT is not intended for covered-entity use and has no BAA. Not HIPAA-ready Health-record connectors on Pro and Max are a consumer feature. Not applicable No equivalent consumer health-record feature covered here.
Small-team plansself-serve workplace tiers No BAA OpenAI does not offer a BAA for ChatGPT Business. No BAA Team plans cannot enable HIPAA. Workspace BAA Gemini app and Gemini in Workspace are included functionality once an admin accepts the Workspace BAA.
Enterprise and healthcare editionsorganization-managed BAA available ChatGPT for Healthcare, Enterprise with Regulated Workspace (sales-managed Enterprise or Edu), ChatGPT for Clinicians. BAA available Claude Enterprise with HIPAA-ready configuration, enabled by a Primary Owner. BAA available Gemini Enterprise is on the Google Cloud BAA product list.
Developer APIfirst-party BAA, with conditions Requires Modified Retention on the organization. Request via baa@openai.com. BAA, with conditions HIPAA-ready API organization; non-eligible features are blocked. Not on BAA list The Gemini Developer API through Google AI Studio is not listed. Use Agent Platform.
Through a cloud platformyour cloud BAA applies Azure Microsoft offers its HIPAA BAA through the Product Terms. Confirm the specific Foundry model and feature are in scope. AWS and Google Cloud Amazon Bedrock is a HIPAA-eligible AWS service; Google says Claude on Agent Platform supports HIPAA. Agent Platform Generative AI on Gemini Enterprise Agent Platform (formerly Vertex AI) is on the Cloud BAA list.
Training on business datadefault setting Off by default Business, Enterprise, Edu and API inputs are not used to improve models by default. Excluded Commercial products, including the API and Claude for Work, are outside the consumer training setting. Off without permission Workspace Gemini chats are not used to train models without permission.
Default API retentionbefore any special arrangement Up to 30 days Abuse monitoring logs up to 30 days; Responses API stores state 30 days unless store is off. 30 days Inputs and outputs deleted within 30 days, with exceptions. Newest “Covered Models” require 30-day retention. Per service terms Paid Gemini API logs prompts for a limited period for abuse detection. Check Agent Platform data settings.

“BAA available” means the provider offers one for that product. It still has to be signed and the product configured as the BAA requires. Sources are listed at the end.

05 · OpenAI

Is ChatGPT HIPAA compliant? OpenAI in detail

OpenAI reorganized its healthcare offering in 2026. It now lists six HIPAA-eligible products available with a BAA: ChatGPT for Healthcare, ChatGPT for Enterprise with Regulated Workspace, ChatGPT FedRAMP, ChatGPT for Clinicians, the API with Modified Retention and the API FedRAMP with Modified Retention. Everything else, including the plans most people use, is outside the BAA.

OpenAIChatGPT, ChatGPT for Healthcare, ChatGPT for Clinicians, API BAA for specific products

Covered

  • ChatGPT for Healthcare, an enterprise edition for clinicians, administrators and researchers
  • Sales-managed ChatGPT Enterprise or Edu with Regulated Workspace
  • ChatGPT for Clinicians, with an individual BAA signed in settings
  • API endpoints including Chat Completions, Responses, Assistants, Files, vector stores, Batch, embeddings, audio and Realtime, once Modified Retention is in place

Conditions

  • API BAA requires the organization to be provisioned with Modified Retention (Modified Abuse Monitoring, Zero Data Retention, Safety Retention or Eyes Off)
  • API BAA requested via baa@openai.com; an enterprise agreement is not required
  • API web search is eligible only in offline, cache-only mode in a ZDR project
  • Improved memory is off by default in ChatGPT for Healthcare and not covered

Not covered

  • ChatGPT Free, Go, Plus, Pro and ChatGPT Business
  • Health in ChatGPT, the consumer health experience
  • Live internet web search through the API, and Codex Cloud
  • In ChatGPT: internet access in Canvas and code blocks, scheduled tasks, Sites and improved memory, among others

What changed for the OpenAI API

Older articles say an OpenAI BAA requires zero data retention. That is no longer the whole picture. OpenAI’s current HIPAA guide requires Modified Retention, a family of arrangements that includes ZDR but also Modified Abuse Monitoring and others. Once an organization is provisioned, OpenAI says the listed endpoints can be used for PHI “even if data is retained.” That matters for builders: endpoints that store state, such as Assistants, Files and vector stores, are on the BAA list even though they are not eligible for ZDR.

By default, API abuse-monitoring logs are kept for up to 30 days, and the Responses API keeps application state for 30 days unless store is turned off. OpenAI does not use API, Business, Enterprise or Edu data to train its models by default.

ChatGPT for Clinicians

This is the most consequential change for individual practitioners. OpenAI describes ChatGPT for Clinicians as free for verified U.S. physicians, nurse practitioners, physician assistants and pharmacists, with a BAA that eligible clinicians can sign under Settings > Agreements. It fills a gap that previously pushed clinicians toward consumer plans. For clinicians employed by a health system, the employer’s approved-tools policy still applies.

Disclosure

Bonami is an OpenAI Select Partner in the OpenAI Partner Network. We also build on Anthropic and Google models. Every provider claim in this comparison comes from that provider’s own published documentation, linked in the sources.

06 · Anthropic

Is Claude HIPAA compliant? Anthropic in detail

Anthropic offers a BAA covering what it calls HIPAA-ready services: its first-party API and Claude Enterprise plans. In 2026 it made this self-serve. A Primary Owner of an eligible Enterprise organization can turn on HIPAA-ready configuration in organization settings and accept the BAA with a click, and Anthropic launched Claude for Healthcare in January 2026 as a set of HIPAA-ready tools and connectors for providers, payers and health tech companies.

AnthropicClaude Enterprise, Claude API, Claude Code BAA for HIPAA-ready services

Covered

  • Claude Enterprise with HIPAA-ready configuration: chat, projects, artifacts, file creation and code execution without network access, voice, web search, research and skills
  • First-party API, including prompt caching, structured outputs, memory, web search, and the bash and text editor tools
  • Claude Code, only with zero data retention enabled

Conditions

  • Enabling HIPAA-ready configuration is a one-way decision
  • The BAA covers only the organization that accepted it
  • The newest “Covered Models” require 30-day retention and cannot run with ZDR, so they cannot be used under the BAA in Claude Code
  • Connectors, MCP servers and enterprise search can be used, but data flows to third parties are not covered
  • Some feature coverage depends on when the BAA was accepted

Not covered

  • Free, Pro, Max and Team plans
  • Claude Console, Cowork and beta features such as Claude in Office
  • API: Batch, Files, code execution and web fetch
  • Consumer health-record connectors on Pro and Max

On the API side, Anthropic enforces scope technically: a HIPAA-enabled organization that calls a non-eligible feature gets an error rather than silently sending PHI out of scope. Its documentation also warns against putting PHI into JSON schema definitions for structured outputs, a detail worth passing to your developers.

Check the BAA, not just the docsWhen we reviewed Anthropic’s pages for this article, two of them disagreed on a few features, including computer use and web search. Anthropic states that the signed BAA and its implementation guide govern. Confirm coverage for each feature you plan to use against those documents.

For consumer plans, Anthropic changed its terms in August 2025 so that Free, Pro and Max users choose whether their chats are used for training. Commercial products, the API, and Claude accessed through Amazon Bedrock or Google Cloud were excluded from that change.

07 · Google

Is Gemini HIPAA compliant? Google in detail

Google’s answer runs through two existing agreements rather than a Gemini-specific one. The Google Workspace BAA lists the Gemini app (excluding Gemini in Chrome), the Gemini Mac app and Gemini in Workspace as included functionality as of August 31, 2026. The Google Cloud BAA covers Gemini Enterprise and generative AI on Gemini Enterprise Agent Platform, the 2026 name for what was Vertex AI.

GoogleGemini in Workspace, Gemini Enterprise, Agent Platform BAA through Workspace or Cloud

Covered

  • Gemini app and Gemini in Workspace (Gmail, Docs, Drive and more) under the Workspace BAA
  • Gemini Enterprise, Gemini Code Assist and Gemini in BigQuery under the Cloud BAA
  • Gemini models through generative AI on Gemini Enterprise Agent Platform

Conditions

  • A Workspace or Cloud admin must review and accept the BAA
  • The legacy free edition of Workspace cannot accept a BAA
  • Google says not to use pre-GA offerings with PHI unless expressly noted
  • Workspace sharing, retention and data protection settings still need configuring

Not covered

  • The consumer Gemini app on personal Google accounts
  • Gemini in Chrome
  • The Gemini Developer API through Google AI Studio, which is not on Google’s BAA list
  • NotebookLM, which is not on the Workspace included-functionality list as of August 31, 2026

The AI Studio point trips up a lot of developers. Google’s Gemini API terms say that on unpaid services, human reviewers may read inputs and outputs, and warn against submitting sensitive personal information. Paid usage is not used to improve Google’s products, but the developer API still does not appear on either BAA list. For PHI, build on Agent Platform under the Cloud BAA.

For consumer Gemini, Google says a subset of chats is reviewed by humans and reviewed chats are kept for up to three years. That alone rules it out for patient information. Google’s former healthcare model line, MedLM, was retired in September 2025.

08 · Cloud routes

Using these models through Azure, AWS or Google Cloud

Many healthcare organizations never sign a BAA with a model company at all. They use models through the cloud where their PHI already lives, under the BAA they already have with that cloud. In that case the cloud provider, not the model developer, is the business associate and data processor.

Microsoft Azure

Microsoft makes its HIPAA BAA available through the Product Terms by default to covered entities and business associates, and lists HIPAA BAA among its Foundry Tools certifications. Confirm the specific model and feature you use are in scope.

Amazon Bedrock

Amazon Bedrock and Bedrock AgentCore are on AWS’s HIPAA-eligible services list, and AWS states that data is not shared with model providers. Claude and other models are available there.

Google Cloud

Gemini models, and partner models including Claude, run on Gemini Enterprise Agent Platform. Google states Claude on Agent Platform supports HIPAA workloads.

One subtlety: Anthropic’s own HIPAA readiness does not extend to Claude on Bedrock or Google Cloud, because those run under the cloud’s agreement. Anthropic also says its 30-day retention for Covered Models applies on every platform, with retained data staying inside AWS or Google Cloud. Read both the cloud’s BAA scope and the model’s terms. Our post on HIPAA cloud infrastructure covers the rest of the cloud setup.

09 · Your side

What your organization still has to configure

Whichever provider you choose, the BAA leaves a predictable list of work on your side. These are the items we see missed most often.

  1. Sign the right BAA for the right account

    The agreement must cover the exact plan, organization or project you use. A BAA on one workspace does not cover a colleague’s personal account.

  2. Turn off what the BAA excludes

    Disable or block excluded features: live web search, beta tools, connectors to uncovered services, memory features and anything pre-GA. Where the provider supports enforcement, use it.

  3. Set retention deliberately

    Know what the provider retains and for how long, and what your own application stores: transcripts, files, embeddings and logs.

  4. Control access with SSO and roles

    Single sign-on, MFA, role-based access, and prompt offboarding. Shared logins defeat audit trails.

  5. Limit what goes in

    Apply the minimum necessary standard to prompts, and de-identify where identity is not needed. Our PHI de-identification work covers the HIPAA standard for this.

  6. Document, train and monitor

    Update the risk analysis, write an acceptable-use policy for AI, train staff on what can and cannot be entered, and review usage logs. Track the vendor through BAA and vendor risk management.

If you are building your own assistant on one of these APIs rather than using the chat products, the architecture matters as much as the agreement. That is the subject of part 1: how to build a HIPAA-compliant AI chatbot or agent.

10 · Decision helper

Can I use this AI tool with patient information?

Answer a few questions about a specific tool and use case. This is a starting point for a conversation with your privacy officer, not a legal determination.

Five questions

Will protected health information be entered, uploaded or processed?

Include names, dates, contact details or record numbers linked to health or care, not just diagnoses.

What kind of product is it?

Pick the closest match for the account you would actually use.

Has your organization signed a BAA that covers this exact product and account?

With the model provider, or with the cloud provider you access it through.

Are the features you use inside the BAA’s scope, and configured as it requires?

For example retention settings, HIPAA-ready configuration, and excluded features such as live web search or beta tools turned off.

Have you updated your risk analysis, access controls, policies and staff training for this use?

Including who may use it, for what, and what must never be entered.

Do not use it with PHI

Consumer AI apps from OpenAI, Anthropic and Google do not come with a BAA. Use an enterprise, healthcare or API offering covered by a signed BAA instead.

Not with this plan

OpenAI does not offer a BAA for ChatGPT Business and Claude Team cannot enable HIPAA. Gemini is the exception if your Google Workspace admin has accepted the Workspace BAA.

Stop until a BAA is in place

Without a signed BAA covering this product, sending PHI to the vendor is generally an impermissible disclosure. Get the agreement first, then check its scope.

Confirm scope before going live

Check each feature against the BAA and the vendor’s implementation guide, and disable anything excluded. This is where most compliant-looking setups go wrong.

Close the gaps on your side

The vendor side looks right. Update the risk analysis, access controls, AI acceptable-use policy and training before staff start entering PHI.

Treat it as PHI

If you are not sure, assume the data is PHI and follow the full path. Identifiers next to anything about care or payment usually are.

HIPAA may not apply to this use

Properly de-identified data is not PHI. Confirm de-identification meets the HIPAA Safe Harbor or Expert Determination standard, and follow your organization’s AI policy either way.

Eligible for HIPAA-compliant use

You have the agreement, the configuration and the program in place. Keep monitoring: vendors change features and coverage often, so review the BAA scope at least when the product changes.

FAQ

Frequently asked questions about ChatGPT, Claude, Gemini and HIPAA

Is ChatGPT HIPAA compliant?

Not the consumer versions. ChatGPT Free, Go, Plus, Pro and ChatGPT Business are not covered by a Business Associate Agreement. OpenAI offers a BAA for ChatGPT for Healthcare, ChatGPT Enterprise with Regulated Workspace, ChatGPT for Clinicians, ChatGPT FedRAMP and the API with Modified Retention. With a BAA and the right configuration, these support HIPAA-compliant use, but compliance still depends on how your organization uses them.

Which version of ChatGPT is HIPAA compliant?

OpenAI lists ChatGPT for Healthcare, ChatGPT for Enterprise with Regulated Workspace, ChatGPT FedRAMP and ChatGPT for Clinicians as HIPAA-eligible products available with a BAA. For ChatGPT itself, OpenAI says only sales-managed Enterprise or Edu accounts are eligible for a BAA, and it does not offer a BAA for ChatGPT Business.

Is the OpenAI API HIPAA compliant?

The API can be used with PHI under a BAA, which you request by emailing baa@openai.com. OpenAI requires the organization to be provisioned with Modified Retention (such as Modified Abuse Monitoring or Zero Data Retention). Most endpoints are covered once that is in place, but live internet web search is not covered.

Is Claude HIPAA compliant?

Claude is not HIPAA compliant by default on any plan. Anthropic offers a BAA for HIPAA-ready services: its first-party API and Claude Enterprise plans that turn on HIPAA-ready configuration. Free, Pro, Max and Team plans cannot enable HIPAA, and several features, including Claude Console, Cowork and beta features, are excluded from the BAA.

Does Anthropic sign a BAA?

Yes, for HIPAA-ready services. Eligible Enterprise organizations can enable HIPAA-ready configuration from organization settings with a click-to-accept BAA, and API organizations can be set up as HIPAA-ready. The BAA covers only the organization that accepted it, and only listed features. When Claude is used through Amazon Bedrock or Google Cloud, the cloud provider’s BAA applies instead.

Is Gemini HIPAA compliant?

It depends on how you access it. Google lists the Gemini app (excluding Gemini in Chrome) and Gemini in Workspace as included functionality under the Google Workspace BAA, and Gemini models on Gemini Enterprise Agent Platform (formerly Vertex AI) are covered by the Google Cloud BAA. The consumer Gemini app and the Gemini Developer API through Google AI Studio are not on Google’s BAA lists.

Can doctors use ChatGPT with patient information?

Only in a product covered by a BAA and in line with their organization’s policies. OpenAI offers ChatGPT for Clinicians, free for verified U.S. physicians, nurse practitioners, physician assistants and pharmacists, with an individual BAA that can be signed in settings. Clinicians who work for a health system should also follow their employer’s approved tools and policies.

Is it a HIPAA violation to paste patient information into ChatGPT?

If a covered entity or business associate enters PHI into a consumer AI tool without a BAA, that is generally an impermissible disclosure to a vendor, and it may need to be assessed as a potential breach under your breach notification process. Report it to your privacy officer rather than deleting it and moving on.

What does “HIPAA compliant” mean for an AI tool?

Strictly, no software is HIPAA compliant on its own. HIPAA applies to covered entities and business associates. A vendor can offer HIPAA-eligible products and sign a BAA, which is necessary but not sufficient. Your organization still has to configure the product correctly, limit what data goes in, control access, train staff and document the risk analysis.

The takeaway

Asking whether ChatGPT, Claude or Gemini is HIPAA compliant gets a one-word answer: no, not by default. The more useful question is which product, under which agreement, configured how. All three providers now have a credible path for PHI, and all three draw the line in different places. Pick the one whose covered products match the way you actually want to work, then do the configuration and program work that no vendor can do for you.

Choosing an AI platform for patient data?

We help healthcare organizations pick the right model and hosting route, sort out BAA scope, and build the integrations and controls around it.

Global presence

Three offices. One team.

Hi, I'm ARIA. Ask me anything about Bonami's AI agents.