If you're putting patient data in ChatGPT, you need a business associate agreement with the provider first. Under HIPAA, any vendor working with protected health information for you counts as a business associate. That's true even if you never called them one.

This question keeps coming up, and a lot of what people are saying about it is just wrong. I pulled this together from public guidance, not from client work, so treat it as general information. This isn't legal advice for your specific case. At ChatFuse, we've broken it down to 3 main questions you have to answer.

Patient data in AI tools Three questions that decide it.
Is it PHI ? 18 identifiers, not just names
Is there a BAA ? signed, for that specific product
Can you prove it ? audit trail, after the fact
Compiled by ChatFuse from public HIPAA guidance.

You can't use patient data with most consumer AI apps. The important part is what comes next.

What makes something protected health information?

Protected health information is any detail about someone's health or care that can be linked back to them. That link is a lot wider than you'd think. Under the HIPAA rule, there are 18 specific identifiers that make information personal, like dates more specific than a year, names, geographic areas smaller than a state, phone numbers, email, medical record numbers, and even full facial photos.

So just deleting a name doesn't make data anonymous. If you have a patient's visit date, their zip code, and their condition, that's often enough to figure out who it is. The regulation sees it that way too.

This also applies to things you might not consider official records. A quick screenshot shared in a chat contains everything visible on that screen. A photo holds more data than the person taking it meant to share. Our standard at ChatFuse for any regulated work is simple: if you wouldn't send it to an external vendor over email, don't put it into an AI prompt. Either way, it's left your hands.

Does a business associate agreement fix it?

It's a must, but that doesn't make it enough. A business associate agreement legally obligates a vendor to protect PHI, which you have to have before you can even send them that data. But having one doesn't guarantee your team is on the secure version of the product, or that it's set up right.

A common and expensive mistake The same brand, two different products.
Consumer tier No BAA, personal login
  • Signed up with a work email
  • Terms differ from the business tier
  • No audit trail you can reach
  • Feels identical to the covered version
Covered tier BAA in place
  • Signed agreement for that product
  • Configured to the agreed terms
  • Access logged and retrievable
  • Named owner inside your practice
Staff cannot tell these apart from the interface, which is why policy alone does not hold.

Clinicians and marketers sometimes use their own accounts for tasks that cross into work. That means they skip any purchasing process, so no one verifies that the plan they're on is actually the one the company's business associate agreement applies to. It's a clear example of what we call shadow AI on personal accounts in a healthcare context.

Is de identified data safe to use?

De identification has to be done right, not just guessed at. HIPAA gives you 2 official ways to do it, and you have to meet one of them. You can get an expert to certify the risk is very small, or you can remove all 18 types of identifiers. They work like this:

RouteWhat it requires
Expert determinationA qualified person certifies the re identification risk is very small
Safe harbourAll 18 identifier categories removed: dates reduced to the year, ages over 89 grouped, nothing below state level

Data that fits the safe harbour rules isn't considered protected health information anymore. It's a high bar to clear: you've got to drop exact dates down to just the year, you can't list any location smaller than the state, and anyone older than 89 has to be in a single group. But if you do it right, that information is completely free from HIPAA. That makes it the most straightforward path for the everyday analytical and drafting tasks a practice needs to do.

What about marketing and administrative work?

A lot of marketing and admin work can be done without ever touching protected health information. That's the simplest place to start. Think about writing a patient education piece, creating service pages, mapping out a campaign, or condensing public research. None of that uses a person's private details, so the risk just isn't there.

Our approach at ChatFuse is to keep the job and the record apart. If the AI doesn't require patient data to function, then it shouldn't get any. That's how we set up most of our work in regulated industries. The systems that already have the identifiable info keep it, and the AI handles everything else around the edges. That same idea, of not putting identity where it doesn't belong, is what we talk about in rate limiting without storing PII.

What does a compliant setup look like?

A compliant setup needs a few things. You've got to have an agreement that names the exact product you're using. The configuration has to line up with what that agreement says. You need access controls so only the right people can get to certain things. And you need a log that sticks around long enough to answer a question that comes up months later. Everyone assumes your data is encrypted while it's moving and when it's stored.

That audit trail is the piece everyone forgets. If someone asks in November about something that occurred in June, keeping logs for just 30 days doesn't help. Not being able to piece together what actually happened becomes its own compliance problem.

ChatFuse insists on one more item for these setups: a named owner inside the practice. Agreements get old, product tiers change, and people leave. If nobody's job includes paying attention, a setup that was fine when it started can drift out of compliance without anyone meaning for it to. Who that person should be is covered in who owns AI in your company.

Does using multiple AI models make this harder?

Whether you've got compliance headaches with a bunch of AI models really comes down to one question: are they all under a single contract? If you're running 5 different tools, that's 5 separate vendors you need to vet. It also means 5 different sets of terms and conditions to track. And that's how things fall out of date without anyone realizing it.

At ChatFuse, we route your requests through more than 100 models from places like OpenAI, Anthropic, Google, and Meta, but it all happens under one agreement and a single data policy. So you only have that one relationship to manage, not a whole list that keeps getting longer. The way we built this entire system is explained in how ChatFuse serves consumers and enterprises from one platform. And if you're wondering what you should get in writing before using any outside AI, our piece on AI vendor questions covers exactly that.

Can you put patient information into ChatGPT?

You can't use a normal consumer account for protected health information. You need a business associate agreement for any product handling PHI, and consumer tiers almost never offer that. But if you properly de identify the data so it meets HIPAA rules, that's a different story, and it's usually the way to go.

Does removing a patient's name make data de identified?

No. To meet the safe harbour standard, you have to strip out all 18 types of identifiers. That means no exact dates beyond the year, no specific geographic info smaller than a state, and no contact information or unique record numbers. Just taking a name out isn't enough. If that data can still be linked back to a person, it's considered PHI.

Is ChatGPT HIPAA compliant?

A service can't be compliant by itself. It depends on having a signed business associate agreement for your plan, the way you set it up, and how your team handles access. You should ask the company what exactly their BAA includes.

Can healthcare marketing teams use AI at all?

Yes, a lot of what they do doesn't involve protected health info. Drafting educational material, service descriptions, or research briefs usually means no patient identifiers are used. It's far easier to just keep that kind of data out of the process from the start than to have to guard it once it's in.

What happens if staff use AI with patient data by accident?

Any possible leak of protected health information has to be treated as a real event that needs a full investigation. That means you have to have logs that go back far enough to prove exactly what did or didn't happen. The most effective way to stop this isn't a ban; it's giving your team an approved tool they actually prefer to use over the outside option. Blocking things just pushes the problem somewhere you can't see it. More on that is in our piece about shadow AI.

The one thing to take away

This isn't about whether AI is permitted for medical use. The actual issue is if the particular data you're using with a particular tool falls under a business associate agreement. Most offices can completely sidestep this problem by not putting any identifiable patient information into the system to begin with.

You can Start free with ChatFuse right now. Our promises about your data are all detailed on our security page.

Back to Blog

Written by Nico

Share

Comments

Loading comments…