Health Biz Scale

AI & Automation

HIPAA-Compliant LLMs: What Small Practices Must Check

HIPAA-compliant LLMs are a contract and configuration question, not a brand one. See which AI tools sign a BAA, which plan tiers are covered, and how to verify.

Mike Kohl·August 16, 2026·26 min read

No large language model is HIPAA compliant on its own. HIPAA-compliant LLMs are ordinary models sitting inside a workflow where three things are true at once. The vendor has signed a Business Associate Agreement with your practice. The product's terms actually permit protected health information on the plan you are paying for. The controls around it, meaning access, logging, encryption and retention, are configured correctly. Miss any one of those and the tool is not compliant, whatever the vendor's homepage says. So the fastest test is not "is this brand HIPAA compliant." It is "will this vendor sign a BAA covering the exact plan tier I am on, in writing, today."

Key Takeaways

  • HIPAA-compliant LLMs are defined by contract and configuration, never by the model itself. There is no certification, and the HHS Office for Civil Rights does not pre-approve or endorse any product as compliant.
  • The plan tier is where most small practices fail. Otter.ai and Fireflies only offer a BAA on Enterprise, and the OpenAI API can be covered while ChatGPT Plus and Team cannot. Same brand, opposite answer. Feature scope is the same trap one level down: Zoom signs a BAA, but AI Companion summaries and transcription get switched off for BAA-covered accounts rather than covered by them.
  • The HIPAA Security Rule never mentions AI. It is technology-neutral, it governs ePHI, and the relevant obligations sit in 45 CFR 164.306, .308, .310, .312 and .316.
  • De-identification is not a loophole you can lean on casually. Free-text clinical narrative re-identifies people through rare conditions, dates, and geography long after the name is stripped.
  • Self-hosting an open-weight model is the default advice in most guides on this topic, and it is the wrong recommendation for a practice of one to ten people. Buy the covered product and get back to the automations that actually pay for themselves.
  • Plenty of LLM use in a practice touches no PHI at all, and that work needs no BAA. Knowing which side of the line you are on is most of the job.

What This Guide Covers

Most HIPAA trouble with AI in a small practice starts somewhere dull: a staff member on the tool the practice already approved, one plan tier below the tier the agreement covers.

I spent 20 years as a software engineer and 15 years as a functional medicine patient, so I read vendor security terms for a living and I have filled out my share of intake forms. Practices rarely land in trouble here through carelessness. They ask the right question, get told yes, and never learn that the yes covered a different product tier than the one on their credit card statement.

This guide assumes a practice of one to ten people. Most writing on the topic assumes a healthtech company with an engineering team, which is how you end up being told to self-host Llama. If you answer your own phone between patients, that advice is useless to you.

What Makes an LLM HIPAA Compliant

An LLM becomes HIPAA compliant when the vendor is contractually bound as your business associate and the workflow around it enforces the Security Rule safeguards. The model itself has no compliance status.

A HIPAA-compliant LLM is a language model reached through a service covered by a signed Business Associate Agreement, on terms that permit protected health information. Its access, logging, encryption and retention must also be configured to meet the HIPAA Security Rule.

What that rules out is marketing language. There is no HIPAA certification body, no audit that earns a badge, and no government list of approved products. HHS does not certify software or endorse vendors. So a company advertising itself as "HIPAA certified" has told you about its marketing department.

Three conditions have to hold at the same time.

One: a signed BAA.

A Business Associate Agreement (BAA) is a written contract that binds a vendor handling protected health information on your behalf to HIPAA's use, disclosure, and safeguard requirements.

Protected health information (PHI) is individually identifiable health information held or transmitted by a covered entity or its business associate. In electronic form it is called ePHI, and ePHI is what the Security Rule governs.

Your practice is the covered entity here. Under HHS guidance on business associates, any vendor that creates, receives, maintains, or transmits PHI on your behalf is a business associate, and you need a written agreement before they touch that data. A privacy policy does not count, and neither does a security whitepaper. HHS publishes sample BAA provisions showing the terms it expects to see.

Two: terms that permit the use. Most people skip this one. A vendor can sign a BAA and still keep terms of service that reserve the right to train on your data, retain inputs indefinitely, or pass content to subprocessors you never evaluated. When a BAA sits alongside terms permitting broad secondary use, that conflict does not resolve in your favour. Read the data-use clause, not the compliance page.

Three: configuration. HIPAA-eligible means the service can be run compliantly, not that it arrives that way. On the major cloud platforms you pick the retention settings, the access model, the logging and the region yourself. A misconfigured Azure OpenAI deployment under a perfectly valid BAA will still lose you data.

If you are still working out which automations belong in your practice at all, start with the build order for practice automation before you evaluate any specific LLM vendor. Compliance questions get much simpler once you know which two or three tools you actually need.

The Plan Tier Trap: Same Tool, Different Answer

The same brand can be compliant on one plan and a violation on the plan directly below it. It is the most reliable way a careful practice ends up out of compliance, and I have yet to find another guide on this topic that names it.

Two-column comparison titled Same Tool, Different Compliance. The covered-by-a-BAA column lists OpenAI API, Otter.ai Enterprise, Fireflies Enterprise and Google Vertex AI. The not-covered column lists ChatGPT Plus, Otter.ai Pro, Fireflies Free and the Gemini consumer app.
The same four vendors appear on both sides. Only the plan tier changes, and the plan tier is what the Business Associate Agreement attaches to.

The mechanics are simple enough. A vendor builds a consumer product and an enterprise product on the same underlying technology. The enterprise contract includes a BAA, the consumer contract does not, and the consumer terms often keep training rights the enterprise terms strip out. Both products share a name, an interface and a logo, so the invoice is the only thing telling you which one you are on.

VendorCovered by a BAANot coveredWhat changes between them
OpenAIAPI, ChatGPT EnterpriseChatGPT Free, Plus, TeamContracting path and data-retention commitments
AnthropicAPI, Claude for Enterpriseclaude.ai consumerEnterprise agreement vs consumer terms
GoogleVertex AI (Google Cloud)Consumer GeminiDifferent product entirely, not a tier of the same one
Otter.aiEnterprise plan onlyBasic, Pro, BusinessBAA is gated to the top plan
FirefliesEnterprise tier onlyLower tiersBAA is gated to the top plan
ZoomEligible paid plansFreeAI Companion features are separately restricted, see below

The Otter.ai row is the one that catches practices. Otter publishes its HIPAA position and will sign a BAA, but only for Enterprise customers. A practice on Otter Pro or Otter Business has a paid plan, a professional-looking product and no BAA. If that account has been transcribing patient calls or case discussions, PHI has been going to an uncovered vendor the whole time.

Nobody was careless. The question "is Otter HIPAA compliant" simply has two correct answers, and the internet keeps handing you the flattering one.

The rule to take away: the compliance question is never "which brand." It is "which brand, on which plan, under which signed agreement, as of what date." Write the plan name into your vendor documentation. A year from now, nobody will remember which tier you were on when you asked.

Which AI Tools Will Sign a BAA

This table covers the AI tools independent practices actually have open, rather than the open-weight research models that dominate other guides on this topic. Compiled 16 August 2026. Rows carrying a source link were checked against the vendor's own published documentation; the remainder reflect vendor and industry reporting at that date.

Treat every row as a starting point for your own verification, never as a substitute for it. Vendors change these terms without announcement, and the only status that protects you is the one in your signed agreement.

Model providers

ToolBAA availableRequirementNotes
OpenAI APIYesBusiness/API contractingNot the same agreement as consumer ChatGPT
ChatGPT EnterpriseYesEnterprise agreement
ChatGPT Free / Plus / TeamNoThe most common mistake in small practices
Anthropic APIYesAPI contracting
Claude for EnterpriseYesEnterprise agreement
Claude.ai consumerNo
Google Vertex AIYesGoogle Cloud, HIPAA-eligible services
Gemini consumer appNoDistinct product from Vertex AI
AWS BedrockYesAWS BAA, HIPAA-eligible services onlyYou configure the safeguards
Microsoft Azure OpenAIYesAzure BAA, eligible servicesConfiguration remains your responsibility

Ambient scribes and clinical documentation

ToolBAA availableNotes
FreedYes, included by defaultPurpose-built for clinical documentation
Heidi HealthYes, for US practicesHolds ISO 27001 and SOC 2 Type II
AbridgeYesEnterprise healthcare contracting
Nuance DAXYesEnterprise healthcare contracting

General meeting notetakers and transcription

This is the risky category, because these tools were built for sales teams and later added healthcare language.

ToolBAA availableThe catch
Otter.aiYes, Enterprise onlyBasic, Pro and Business cannot get a BAA
FirefliesYes, Enterprise tier onlyLower tiers are not covered
FathomStates HIPAA compliance with a BAAConfirm current terms directly before storing PHI
Zoom AI CompanionFeature is restricted under a BAAZoom signs a BAA; the AI summary and transcription features get disabled rather than covered
GranolaNoNo HIPAA offering or BAA at time of writing

Two rows there need spelling out.

Granola has no HIPAA offering at all. It is a well-built notetaker with a large user base, which is how it ends up in practices. If it runs during any conversation where a patient is discussed by name, PHI is going to a vendor with no agreement in place.

Zoom AI Companion works backwards from what people assume. Zoom will sign a BAA and publishes its HIPAA position. But AI Companion features, including meeting summaries and transcription, are turned off for accounts operating under that BAA, because those features fall outside its scope. A practice that got a Zoom BAA and then switched AI Companion on for clinical team meetings has achieved the opposite of what it wanted. The BAA is the reason to leave the feature off.

The pattern to watch: tools your practice uses for non-clinical work are the ones most likely to be out of scope. No one procures a general notetaker through a compliance review. It shows up because one person liked it.

Is ChatGPT HIPAA Compliant?

ChatGPT is not HIPAA compliant on the Free, Plus, or Team plans, and it can be used compliantly through the OpenAI API or ChatGPT Enterprise under a signed BAA with the right retention configuration. The answer depends entirely on which product you are using.

The consumer plans do not come with a BAA, which settles it. No configuration, internal policy, or careful prompting makes a consumer plan usable for PHI, because the contract underneath it does not exist. Say nothing about OpenAI's security either way; this is a contracting question.

The business path works. OpenAI offers a BAA for qualifying API and Enterprise customers, and that contracting path carries data-handling commitments the consumer product does not. A practice can build a compliant workflow on it.

The same structure applies to the other two major models. Anthropic offers a BAA for its API and enterprise products while claude.ai consumer is excluded. Google's compliant path is Vertex AI inside Google Cloud, not the consumer Gemini app, which is a different product rather than a lower tier of the same one.

A note on what "compliant" buys you. A BAA does not make the model accurate. It makes the data handling lawful. Clinical review of every output remains your obligation regardless of which tier you are on, and no agreement transfers clinical responsibility to a vendor.

Practices ask a second, much calmer question about ChatGPT: how to get found by it. No PHI involved, different rules entirely, and I have covered how practices surface inside ChatGPT results separately.

The Tools Already Sitting in Your Practice

The riskiest AI in most small practices is whatever arrived without a procurement decision: the meeting notetaker, the transcription app, the browser extension somebody installed on a Tuesday.

Run this inventory this week. Twenty minutes, and it is the highest-value compliance work available to a small practice.

  1. Open your video conferencing settings and check whether AI summaries or transcription are enabled. If you have a BAA with that provider, confirm whether the AI features sit inside or outside its scope. For Zoom specifically, expect them to be outside it.
  2. List every notetaker anyone on the team has connected to a calendar. These join meetings automatically once installed. A tool nobody remembers approving is still recording.
  3. Check the plan tier on each one, not the brand. Log in and read the billing page. This is the step that finds the Otter Pro account.
  4. Ask each staff member which AI tools they personally use for work. Not to assign blame. Personal accounts are extremely common and completely invisible to any audit that only looks at what the practice pays for.
  5. Check browser extensions on any machine used for clinical work. Extensions with page-read permissions can see anything on screen, including your EHR.

I have watched this inventory turn up a live transcription tool nobody in leadership knew about, on a consumer plan, at a practice that thought of itself as cautious with technology. These tools are good, cheap, and installable in 30 seconds, which is how they get past people who would never sign off on them formally.

In functional medicine, where visits run an hour and produce dense narrative notes, the pull toward a transcription tool is strong. Longer visit, more writing, more appeal. The benefit is real. Take it from a vendor that will sign the agreement.

The same pressure shows up anywhere the intake conversation is long enough that writing it up eats the evening. I hear it constantly from naturopathic practices running 90-minute initial consults with a single administrator.

What the HIPAA Security Rule Actually Requires of AI

The Security Rule requires nothing specific about AI, because it is technology-neutral and predates all of this. It requires that electronic protected health information be protected through administrative, physical, and technical safeguards, and those obligations apply to an LLM exactly as they apply to a server.

The relevant sections of the Security Rule map onto AI systems like this:

CitationWhat it requiresWhat that means for an LLM
45 CFR 164.306General security standards, protection against reasonably anticipated threatsThe AI workflow is in scope for your overall security posture
45 CFR 164.308Administrative safeguards including risk analysis and risk managementYou must run and document a risk analysis covering the AI tool
45 CFR 164.310Physical safeguards, workstation and device controlsCovers the laptop the tool runs on and who can see the screen
45 CFR 164.312Technical safeguards: access control, audit controls, integrity, authentication, transmission securityUnique logins, logged interactions, encryption in transit and at rest
45 CFR 164.316Policies, procedures, and documentationYour AI-use policy has to exist in writing and be retained

Five practical obligations fall out of that.

Run a risk analysis that names the tool. Section 164.308 makes risk analysis a required implementation specification, and a risk analysis that does not mention the AI tools processing your PHI is incomplete. This is the single most commonly cited gap in OCR settlements across all technology categories, not only AI.

Enforce unique user identification. Shared logins break audit controls under 164.312. If four staff members use one AI account, no log can tell you who submitted what.

Keep audit logs. You need to be able to reconstruct who accessed what and when. If a vendor cannot show you a usage log, you cannot satisfy this for their portion of the workflow.

Encrypt in transit and at rest. Any credible vendor does this. Confirm it in writing rather than assuming it.

Write the policy down. Section 164.316 requires documentation, and a verbal understanding that staff should not paste patient information into chatbots is not a policy. One page naming the approved tools, the approved plan tiers, and the prohibited uses satisfies this and takes an afternoon.

Where the 2026 Security Rule Update Stands

As of this writing in August 2026, the proposed HIPAA Security Rule update is still proposed and has not been finalized. HHS published a notice of proposed rulemaking and public reporting through 2026 indicates the final rule has been delayed rather than issued.

That matters for planning, so be careful with what you do about it. The proposal would tighten several things that are currently addressable rather than required, including encryption and multi-factor authentication, and it would raise the bar on asset inventory and risk analysis documentation. If it is finalized in something close to its proposed form, practices that treated the addressable specifications as optional will have the most work to do.

The practical move is not to wait. Almost everything in the proposal is already good practice under the existing rule. A practice that runs a documented risk analysis, encrypts its data, enforces MFA, and keeps a current inventory of systems touching PHI is largely prepared either way. That inventory should list your HIPAA-compliant LLM tooling alongside the EHR.

Because the status can change between when this is written and when you read it, check the HHS regulatory initiatives page for the current position rather than trusting any article's snapshot, including this one. The proposed rule document itself is public if you want the primary source.

Three Ways a Small Practice Can Deploy an LLM Compliantly

There are three viable routes to HIPAA-compliant LLMs for a practice of one to ten people, and they are not equally realistic despite what most guides on this topic imply.

Three-panel comparison titled Three Routes to a Compliant LLM: a healthcare vendor with the BAA included that fits most practices, a HIPAA-eligible cloud where you own the configuration, and a self-hosted model that needs a real IT function.
Two of these three are realistic for a practice of one to ten people. The third is the one most guides on this topic recommend.
PathWhat it isRealistic monthly costWho it fitsHonest downside
Healthcare-specific vendorA purpose-built product, BAA included, healthcare workflows out of the box$100 to $300 per providerAlmost every independent practiceLess flexible, priced per seat, some vendor lock-in
HIPAA-eligible cloudAzure OpenAI, AWS Bedrock, or Vertex AI under a BAA, with something built on topPlatform usage plus build costPractices with a technical partner and a specific custom needYou own the configuration and therefore the risk
Self-hosted open-weight modelRunning Llama, Mistral or similar on infrastructure you controlHardware plus ongoing engineering timeOrganizations with a real IT functionNot realistic for a small practice, and the guides that recommend it are not written for you

That third row is the standard recommendation across almost every article ranking for this topic, and for this audience it is bad advice.

Self-hosting does give you the strongest privacy posture. No PHI leaves your infrastructure, no third party sees your prompts, and that is why enterprise health systems do it.

It also needs someone to own GPU infrastructure, model updates, security patching, access control, audit logging, uptime, and evaluation of the model's clinical output. That is a job, not a weekend project, and free model weights do not change the staffing math. When a six-person practice with no IT staff self-hosts an LLM, the risk has not gone away. It has moved off a vendor with a compliance team and onto the practice.

For nearly every independent practice I talk to, the answer is the first row. Buy the purpose-built product, sign the BAA, put your attention back on clinical work. The broader question of what to build versus buy usually lands in the same place.

What Compliant AI Actually Costs a Small Practice

A compliant AI setup for a small independent practice runs roughly $150 to $500 a month, and the premium over the consumer version is smaller than most owners assume.

Broken down for a three-provider practice:

Line itemTypical monthly costNotes
Ambient scribe, BAA included$100 to $300 per providerThe largest line, and usually the one worth paying
Covered transcription or notetaking$0 to $150Often unnecessary if the scribe covers clinical documentation
API access for non-clinical automation$20 to $80Usage-based, and low at practice volumes
Compliance and documentation time2 to 4 hours in month one, then 1 hour annuallyYour time, not a vendor invoice

These are planning ranges drawn from published vendor pricing at the time of writing, not quotes. Price the specific tools you are considering before you budget.

The comparison people actually want is the compliant tier against the consumer tier of the same product. In most cases that gap is modest relative to a single patient visit. It is rarely the reason practices postpone the decision. What stops them is that upgrading means an annual contract conversation instead of a credit card, which makes the whole thing feel heavier than it is.

Weigh that against the alternative. HIPAA civil money penalties are tiered by culpability, running from unknowing violations up to willful neglect, with annual caps that HHS adjusts for inflation and publishes on its enforcement pages. But the practical cost of a reportable breach at a small practice is rarely the fine. It is the notification process, the time, and the damage to a reputation you spent years building. When growth runs on trust and referral, that last one is the expensive part, and no marketing plan buys it back quickly.

Over-restricting costs too. Ban AI tools outright and staff move to personal accounts, which is worse than an approved tool on a covered plan. Practices that handle this well spend a little to make the compliant path the easy path, the same logic they apply to every other operational decision in a growing practice.

The Six-Step Vendor Verification Protocol

Use this on every AI tool that might touch PHI. About 30 minutes per vendor, and repeatable, which counts for more than any single tool decision you make this year.

Step 1: Ask for the BAA before anything else. Not "are you HIPAA compliant." Ask: "Will you sign a Business Associate Agreement covering our use, on the plan we are considering?" A vendor that deflects, points to a compliance page, or says certification instead of agreement has answered you.

Step 2: Confirm the plan tier in writing. Get the specific plan name into the email thread. This step catches the Otter and Fireflies problem. "Yes we sign BAAs" and "yes we will sign a BAA for the Business plan you are on" are different sentences.

Step 3: Read the data-use clause, not the compliance page. Look specifically for training rights, retention periods, and subprocessors. A vendor that reserves the right to train on your inputs has terms that conflict with the BAA, and you want that resolved in writing before you sign.

Step 4: Ask which features are in scope. The Zoom situation, generalised. A BAA can cover a platform while excluding specific features. Ask directly: "Which features are excluded from the BAA's scope?" Good vendors answer immediately.

Step 5: Verify the controls you are required to have. Confirm encryption in transit and at rest, per-user accounts, exportable audit logs, and configurable retention. If you cannot get an audit log, you cannot meet 164.312 for that part of your workflow.

Step 6: Document the answers with a date. Save the signed BAA, the plan name, the feature scope, and the date you verified it. Vendors change terms. Your risk analysis needs to show what you knew and when you knew it.

Re-run steps 2 and 4 annually, and any time you change plans. A tier downgrade during a budget review can silently end your coverage.

Where PHI Leaks That Practices Do Not Expect

Ask a practice where PHI might leak and you will hear about pasting chart notes into a chatbot. The quieter leaks are metadata and context, not clinical text.

Diagram titled Where PHI Actually Leaks listing six overlooked exposure points in a small practice: calendar invite titles, meeting recordings, support ticket screenshots, browser extensions, prompt history and personal accounts.
None of these feel like sending data anywhere, which is how they get past practices that are careful about pasting chart notes.
  • Calendar invite titles. "Follow-up: Sarah M, Hashimoto's protocol review" is PHI, and it is visible to every notetaker, scheduling assistant, and calendar integration you have connected.
  • Meeting recordings of clinical team huddles. Patients get discussed by name in case review. If a notetaker is in the room, that conversation is now in a vendor's system.
  • Screenshots in support tickets. A screenshot showing your EHR sent to a software vendor's support desk is a disclosure to a company that may have no BAA with you.
  • Browser extensions. Anything with permission to read page content can read your EHR while it is on screen.
  • Prompt history. Even on a covered plan, prompt history persists according to the retention settings you chose. Default retention is rarely what a practice would pick deliberately.
  • Personal accounts. A staff member using their own ChatGPT account to reword a patient email is outside every agreement you hold, and it will not appear in any vendor audit.
  • Dictation apps on personal phones. Convenient, invisible, and almost never covered.
  • Membership and recurring-visit workflows. Practices running retention programs, common in IV therapy and recurring-treatment models, often connect automation tools to a patient list. The list itself is PHI.

None of these feel like sending data anywhere. They feel like using a tool. So an inventory beats a policy here: staff follow policies about things they recognise as data transfers, and none of these register as one.

Where You Can Use a Regular LLM Freely

Plenty of what an LLM is good at in a practice touches no PHI at all, and none of it needs a BAA. Practices over-restrict here more often than they over-share.

With no patient information involved, you are outside HIPAA's scope entirely. That covers:

  • Drafting and editing marketing copy, service page content, and educational articles for your website. Nothing about content for a practice website involves patient data.
  • Research and summarization of published literature.
  • Writing job descriptions, staff onboarding documents, and internal SOPs.
  • Planning and drafting your patient review request workflow, as long as the drafts use placeholders rather than real names.
  • Building out a content plan or working through answer engine optimization for a healthcare site, which is entirely a marketing exercise.
  • Drafting the pages and articles behind a healthcare SEO program.
  • Working out how a practice earns citations in AI-generated search results.
  • Building campaign assets for a treatment line, which is most of the work in a med spa marketing calendar.
  • Analyzing anonymous, aggregate business metrics: revenue, visit volume, no-show rates by weekday.

The line is whether an individual could be identified. "Draft a follow-up email template for patients starting a thyroid protocol" is fine. "Draft a follow-up email for Sarah, who started her thyroid protocol on the 14th" is not, and the difference is one clause.

Teach your team that line explicitly. The alternatives are a blanket ban everyone quietly ignores, or a free-for-all. A medical weight loss clinic produces a lot of non-PHI content work, and restricting it buys no compliance benefit.

Hormone therapy makes a clean test case. Patient education about treatment options is content work with no PHI in it, so a plain consumer model is a fine drafting tool for a hormone clinic building out its library. No HIPAA-compliant LLM required. Paste a lab panel into the same prompt box and the practice is in a different regulatory world, same browser tab.

When an LLM Is the Wrong Tool

Some problems look like AI problems and are better solved with something deterministic, cheaper and more predictable.

Anything requiring exact recall. An LLM generates plausible text. For dosing references, insurance rules, or protocol specifics, use a database or a document. A model that is right 97% of the time is a liability in the 3%.

Structured data extraction from consistent forms. If your intake forms have fixed fields, a form parser is more reliable and much cheaper than a model.

Scheduling logic and reminders. This is rules-based work. Your scheduling software already does it correctly and deterministically.

Anything constituting clinical judgment.

An ambient scribe is an AI tool that listens to a clinical visit and drafts the encounter note for the provider to review, edit, and sign.

Diagnosis, treatment selection and triage are not documentation tasks. An ambient scribe produces a fast first draft that the provider reviews and signs. A model deciding what belongs in the plan is another matter, and no BAA covers that risk.

The first conversation with a prospective patient. Commercial rather than regulatory, and easy to underrate. The first phone call is where someone decides whether they trust you. Do not automate it away to save a few minutes.

This bites hardest in membership models. In concierge medicine, access to a human is the product, and automating the front door undermines the thing the patient is paying for.

The same logic applies to any direct primary care practice charging a monthly fee for relationship and availability. Automate the paperwork around the visit. Leave the door itself alone.

If PHI Already Went Into a Non-Covered Tool

If you have just worked out that patient information went into a tool with no BAA, work through the sequence below. It is a process outline rather than legal advice, and this is one of the situations where bringing in counsel or a compliance advisor early pays for itself.

Stop the flow first. Disable the integration, remove the tool from calendars, and revoke its access before anything else. Do not begin the analysis while data is still moving.

Scope what happened. Determine which tool, which accounts, what date range, what categories of information, and how many individuals. You cannot assess anything without this, and vendor usage logs are usually the fastest way to establish it.

Delete what you can and document what you deleted. Most vendors provide data deletion on request. Ask in writing and keep the confirmation.

Assess whether it is a reportable breach. An impermissible use or disclosure of unsecured PHI is presumed to be a breach unless a risk assessment demonstrates a low probability that the information was compromised. That assessment considers the nature of the information, who received it, whether it was actually acquired or viewed, and the extent of risk mitigation. This is the analysis you want professional help with, because the presumption runs against you.

Notify if required, on the required timeline. Breach notification obligations have specific deadlines and thresholds, and the requirements differ depending on how many individuals are affected.

Fix the cause, not just the instance. Update the risk analysis, write the AI-use policy if it does not exist, and run the tool inventory from earlier in this guide so you find the other ones now rather than next year.

Practices in this position tend to assume they are uniquely careless. They are not. These tools install in seconds and sell themselves as productivity software rather than data processors.

Your First 30 Days

If you do nothing else from this guide, do these six things in this order.

  1. Week 1: Inventory. List every AI tool touching the practice, including personal accounts and browser extensions. Record the plan tier for each, from the billing page rather than from memory.
  2. Week 1: Triage. Split the list into tools that touch PHI and tools that do not. Most will not.
  3. Week 2: Verify. For every tool in the PHI column, run the six-step protocol. Expect at least one surprise.
  4. Week 2: Disable or upgrade. Anything without a valid BAA on your actual plan gets switched off or moved to a covered tier. Those are the only two options.
  5. Week 3: Write the one-page policy. Approved tools, approved tiers, prohibited uses, and who to ask. One page. Section 164.316 requires documentation and this satisfies it.
  6. Week 4: Update the risk analysis and train the team. Twenty minutes with the staff naming the approved tools and the "no names, ever" rule prevents more incidents than any technical control you can buy.

None of this needs a compliance consultant or a technical background. It needs an afternoon on billing pages and the willingness to switch off a tool people like. Practices that get this right treat AI compliance as an inventory problem rather than a technology problem, and anyone can solve an inventory problem.

Frequently Asked Questions

Is ChatGPT HIPAA compliant?

Not on the Free, Plus, or Team plans, because OpenAI does not offer a BAA for those products. The OpenAI API and ChatGPT Enterprise can be used compliantly under a signed BAA with appropriate retention configuration. The plan you are on determines the answer, not the ChatGPT brand.

Is Otter.ai HIPAA compliant?

Only on the Enterprise plan. Otter will sign a Business Associate Agreement, but that coverage is restricted to Enterprise customers. Basic, Pro, and Business plan users cannot obtain a BAA and should not use Otter for anything involving protected health information.

Is Claude HIPAA compliant?

The Anthropic API and Claude for Enterprise can be covered by a BAA. The consumer claude.ai product cannot. As with the other major providers, the compliant route runs through enterprise contracting, and the consumer product sits outside it rather than below it.

Is Gemini HIPAA compliant?

The consumer Gemini app is not. Google's compliant path is Vertex AI within Google Cloud, under a Google Cloud BAA covering HIPAA-eligible services. They are separate products rather than tiers of one product, which trips people up constantly.

Is Zoom AI Companion HIPAA compliant?

Zoom will sign a BAA for eligible paid plans, but AI Companion features including meeting summaries and transcription are turned off for accounts operating under that BAA rather than being covered by it. If your practice has a Zoom BAA and AI Companion is enabled, that configuration needs review.

Can any AI be HIPAA compliant?

Yes. HIPAA-compliant LLMs exist wherever the vendor signs a BAA, the product terms permit PHI on your plan, and the safeguards required by the Security Rule are configured. Compliance is a property of the whole workflow. No model is compliant by itself, and no vendor can be certified as compliant, because HHS does not certify or endorse products.

Is de-identifying data enough to use a public LLM?

Often not, and this is where practices get overconfident. Removing names and dates from structured fields is straightforward, but clinical narrative re-identifies people through rare conditions, treatment timelines, and geography. HIPAA recognizes two formal de-identification methods, Safe Harbor and Expert Determination, and casual redaction is neither of them.

Do I need a BAA if the AI never sees a patient name?

If no protected health information is involved at all, HIPAA does not apply and no BAA is needed. That covers most marketing, research, and internal documentation work. Be careful about what counts as identifying, though: a specific condition combined with a date and a small geographic area can identify someone without any name attached.


Written by Mike Kohl, founder of Health Biz Scale. 20 years as a software engineer building and reviewing production systems, and 15 years as a functional medicine patient. I evaluate AI vendor security documentation and BAA terms as part of building AI infrastructure for independent health practices.

Vendor status last verified: 16 August 2026. The BAA table above decays quickly, because vendors change plan eligibility and feature scope without notice. Re-verify before you sign anything.

This guide is general information about HIPAA and AI vendor selection. It is not legal advice, and it does not create an attorney-client or consultant-client relationship. For a suspected breach, a specific contract review, or an enforcement matter, work with qualified counsel or a compliance professional.

Practices that handle this well are not the ones with the biggest compliance budgets. They are the ones that made a list, checked the billing pages, and switched off the two tools that did not belong. Start with the inventory. The rest follows from knowing what you have running.

Want this built instead of read?

I build the systems described in these guides.

Four practices a quarter, for cash-pay and hybrid practices where a patient is worth $3,000 or more. See the four gates before you book anything.

See if your practice fits →

Free Weekly

The Health Biz Playbook

Tactics, data, and case studies for cash-pay practices. No fluff. Unsubscribe anytime.

Related Guides