Whether you can put patient data in ChatGPT, or any AI tool, comes down to whether that provider has signed a business associate agreement with you, because under HIPAA a vendor handling protected health information on your behalf is a business associate whether or not anyone called it that.
This comes up constantly and the answers circulating are mostly guesswork. What follows is written from public guidance rather than from any client engagement, and it is general information rather than legal advice for your situation.
The short answer for the consumer version of most AI products is no. The longer answer is where the useful detail lives.
What makes something protected health information?
PHI is health information that can be tied to an individual, and the tie is broader than most people assume. The HIPAA de identification standard lists 18 identifiers, including names, dates more specific than a year, geographic detail smaller than a state, phone numbers, email addresses, medical record numbers and full face photographs.
That breadth is why "I removed the name" is not de identification. A record with an appointment date, a zip code and a diagnosis can frequently be re identified, and the rule treats it accordingly.
It also catches things people do not think of as records at all. A screenshot pasted into a chat window carries whatever was on screen, and a photograph carries more than the subject intended. The ChatFuse rule of thumb in regulated work is that anything you would not email to an outside contractor should not go into an AI prompt either, because in both cases it has left your control.
Does a business associate agreement fix it?
It is necessary and not sufficient. A BAA makes the vendor contractually accountable for safeguarding PHI, which is the legal precondition for sending it to them at all. It does not by itself mean the product is configured safely or that your staff are using the covered version.
- Signed up with a work email
- Terms differ from the business tier
- No audit trail you can reach
- Feels identical to the covered version
- Signed agreement for that product
- Configured to the agreed terms
- Access logged and retrievable
- Named owner inside your practice
The failure we see most is a clinician or a marketer using a personal account for something work adjacent. No procurement happened, so nobody checked, and the tier in use is not the tier the agreement covers.
Is de identified data safe to use?
Safer, and only if the de identification meets the standard rather than the intuition. HIPAA recognises two routes: expert determination, where a qualified person certifies the re identification risk is very small, and safe harbour, where all 18 identifier categories are removed.
Safe harbour is stricter than people expect. Dates have to be reduced to the year, ages over 89 are grouped, and geography above the state level only. Data that has been through that is genuinely outside the rule, which makes it the most practical route for the analysis and drafting work most practices actually want.
What about marketing and administrative work?
Most of it never needs PHI in the first place, which is the easiest win available. Drafting a patient education article, writing service page copy, planning a campaign or summarising public research involves no identifiable individual and carries none of this risk.
The discipline ChatFuse applies is separating the task from the record. If the AI does not need the patient to do the job, do not give it the patient. ChatFuse deployments in regulated settings are usually scoped exactly this way, with the identifiable data staying inside the systems already covered and the AI working on everything around it.
What does a compliant setup look like?
An agreement covering the specific product, a configuration that matches it, access controls that limit who can reach what, and an audit trail that survives long enough to answer a question raised months later. Encryption in transit and at rest is assumed rather than notable.
The part most often missing is the trail. If an incident is raised in November about something that happened in June, a 30 day log tells you nothing, and being unable to reconstruct events is its own finding.
Worth adding one thing ChatFuse insists on in these deployments: a named person inside the practice who owns the arrangement. Agreements go stale, products change tiers, and staff turn over. Without somebody whose job includes noticing, a setup that was compliant when it was signed drifts without anyone deciding to let it.
Does using multiple AI models make this harder?
It depends entirely on whether they sit behind one agreement. A practice using 5 separate AI tools has 5 vendors to assess and 5 sets of terms to keep current, which is where things quietly drift out of compliance.
ChatFuse routes across more than 100 models from OpenAI, Anthropic, Google and Meta under one agreement and one data policy, so the assessment is a single relationship rather than a growing list. Our post on AI vendor questions covers what to establish in writing before any of them touch your data.
Frequently asked questions
Can you put patient information into ChatGPT?
Not into a consumer account. Sending PHI to any vendor requires a business associate agreement covering that specific product, and consumer tiers generally are not offered under one. De identified information that meets the HIPAA standard is a different matter and is usually the practical route.
Does removing a patient's name make data de identified?
No. The safe harbour standard requires removing 18 categories of identifier, including dates more precise than a year, geography below state level, contact details and record numbers. A record stripped only of a name can often be re identified and is still treated as PHI.
Is ChatGPT HIPAA compliant?
A product is not compliant on its own. Compliance depends on whether there is a signed business associate agreement covering the tier you are using, how it is configured, and how your organization controls access. Ask the vendor which specific products they will cover under a BAA.
Can healthcare marketing teams use AI at all?
Yes, and most of their work never touches PHI. Writing patient education content, service pages, campaign plans and research summaries involves no identifiable individual. Keeping identifiable data out of those workflows entirely is simpler than trying to protect it inside them.
What happens if staff use AI with patient data by accident?
Treat it as a potential incident and investigate, which requires having logs that go back far enough to establish what happened. The practical prevention is giving staff a sanctioned tool that is easier to use than the unapproved one, since bans reliably move usage out of sight. See shadow AI for why.
If you take one thing from this: the question is not whether AI is allowed in healthcare. It is whether the specific data going into the specific product is covered, and most practices can avoid the question entirely by keeping identifiable records out of the workflow.
Start free with ChatFuse, or read the data commitments on the security page.
Comments
Loading comments…