Can employees use ChatGPT and other AI tools with patient data under HIPAA?

HIPAA has no official certification and requires a BAA when a vendor handles PHI on your behalf. What HHS, OpenAI, Anthropic, Microsoft and Google say, de-identification, and current penalty tiers.

Updated September 20, 2026 · 10 min read

The short answer

Employees can use an AI tool with patient data only if the organization has a business associate agreement (BAA) with the vendor for that specific product, or if the data has been properly de-identified first. Free and personal accounts an employee opened on their own almost never meet either condition. This guide is general information, not legal advice.

The hard part is rarely the rule. HIPAA has been clear about business associates for years. The hard part is knowing which AI tools your workforce is actually using, because a BAA you signed for one approved product says nothing about the other five tools people opened in a browser tab.

What HIPAA covers, and who counts as a business associate

The HIPAA Privacy and Security Rules apply to covered entities (health plans, health care clearinghouses and most health care providers) and to their business associates. The rules protect protected health information (PHI), and the Security Rule specifically covers the electronic form, ePHI. Your workforce is part of the picture: the regulation defines it as people whose conduct is under the direct control of the entity, whether or not they are paid.

A business associate is, broadly, a person or company that creates, receives, maintains or transmits PHI on behalf of a covered entity. A software vendor whose system your employees type patient details into fits that description, and so does a subcontractor of a business associate. The formal definition sits in 45 CFR 160.103.

The rule that decides it: the business associate agreement

Under 45 CFR 164.502(e)(1), a covered entity may disclose PHI to a business associate only if it obtains satisfactory assurance that the associate will appropriately safeguard the information, documented in a written contract that meets 45 CFR 164.504(e). The Security Rule repeats the requirement for ePHI at 164.308(b)(1).

HHS’s cloud computing guidance says that when a covered entity uses a cloud service provider to create, receive, maintain or transmit ePHI, the provider is a business associate, and that this applies even when the provider stores only encrypted ePHI and holds no decryption key.

An AI chat service is, technically, a cloud service that receives whatever text is typed into it. That is why the practical question for a compliance officer is not whether the model is accurate. It is whether a signed BAA exists for the exact product in use, and whether the employee is using that product.

Which AI vendors offer a BAA, and for which products

Each vendor below documents its own HIPAA position. We read each official page on September 20, 2026, and the table restates only what the pages say. Terms change, and a product being eligible does not make it covered until the agreement is in place, so verify the current contract before relying on any row.

VendorWhat the official page says is eligibleWhat it says is not covered or is limited
OpenAIA BAA is available for ChatGPT for Healthcare and for sales-managed ChatGPT Enterprise or Edu accounts, and can be requested for the API Platform.Not offered for ChatGPT Business. The pages we reviewed list no BAA for free or Plus accounts.
AnthropicA BAA covers HIPAA-ready Claude Enterprise organizations and the first-party API, once the Primary Owner activates HIPAA settings and accepts it.Claude Free, Pro and Max are outside the commercial BAA. Some features, such as Claude Console and beta products, are excluded.
MicrosoftMicrosoft states that Copilot and Copilot Chat support HIPAA compliance for properly configured implementations, under the Data Protection Addendum and Product Terms.Web search queries are not covered by the DPA and BAA. Consumer Copilot plans are governed by different terms.
GoogleOrganizations subject to HIPAA must enter a Business Associate Amendment with Google. Some Gemini features in Workspace appear in its HIPAA Included Functionality list.Third-party applications and Additional Google Services are outside the BAA.

Two things follow. First, a BAA is a contract for a product tier and an organization, not for a brand, so the same vendor can be fine on one plan and unsuitable on another. Second, the BAA is one control among several. It does not decide who may use the tool, with what data, or how you would notice that someone used it.

Without a BAA: de-identification and minimum necessary

There are two ways an AI tool can lawfully see health-related text without a BAA. One is that the text is not PHI. Under 45 CFR 164.514(b), data is de-identified either by an expert determination, in which a qualified person documents that the risk of identifying an individual is very small, or by the Safe Harbor method, which removes 18 categories of identifiers. These include names, geographic units smaller than a state, dates other than year, phone numbers, email addresses, Social Security numbers, medical record numbers, device identifiers, IP addresses and full-face photographs.

The other is discipline about scope. The minimum necessary standard in 164.502(b)(1) requires reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose. Even with a BAA in place, an employee who pastes a full chart to get a two-line summary has a minimum-necessary problem. A short policy that names what may and may not be entered, with examples, does more than a long one nobody reads.

What a violation can cost

HHS adjusts civil money penalty amounts for inflation every year. The notice published in the Federal Register on January 28, 2026 sets the figures below for violations of the administrative simplification provisions. The tier depends on what the organization knew and how quickly it corrected the problem.

TierMinimum per violationMaximum per violationAnnual limit
Did not know$145$73,011$2,190,294
Reasonable cause, not willful neglect$1,461$73,011$2,190,294
Willful neglect, corrected within 30 days$14,602$73,011$2,190,294
Willful neglect, not corrected within 30 days$73,011$2,190,294$2,190,294

These are civil penalties per the notice. They do not include the cost of investigating, notifying and remediating an incident, which is where the larger number usually sits. In IBM’s 2025 study, the healthcare sector’s average breach cost was the figure below.

USD 7.42 million

was the average cost of a data breach in the healthcare industry in IBM’s Cost of a Data Breach Report 2025.

IBM Security, Cost of a Data Breach Report 2025

There is no official HIPAA certification

Vendors sometimes advertise themselves as HIPAA certified. HHS’s FAQ on the subject says it does not endorse or otherwise recognize private organizations’ certifications regarding the Security Rule, and that such certifications do not absolve covered entities of their legal obligations. What a vendor can legitimately offer is a signed BAA, documented safeguards and evidence of how they operate.

That is also the standard Tangerin AI holds itself to. It does not claim to be HIPAA certified or HIPAA compliant, because there is no such credential to hold.

Why you cannot prove what you never saw

A BAA covers the tools you approved. A privacy officer who is asked whether PHI reached an unapproved AI service needs to answer from records, not from belief, and without an inventory of the AI tools in use the honest answer is that nobody knows. The same IBM study puts numbers on how common that gap is.

63%

of the organizations that suffered a breach said they had no AI governance policies in place to manage AI or to prevent workers from using shadow AI.

IBM Security, Cost of a Data Breach Report 2025

USD 670,000

is what a high level of shadow AI added to the average breach cost in the same study.

IBM Security, Cost of a Data Breach Report 2025

Tangerin AI addresses the inventory piece, and only that piece. It sees usage metadata, such as which AI tool a workstation reached and how often, and never the content of a conversation or a prompt. It tracks HIPAA as one of its frameworks and does not certify anyone. It does not offer a BAA or a data processing agreement today, and it does not replace the contracts described above.

A starting path, in five steps

This is our reading of a practical sequence, not regulatory text. It puts discovery before policy because a policy written without knowing the tools tends to be rewritten.

  • 1. Inventory. Find out which AI tools are used, by which teams and how often, including the ones nobody approved. See how to build an AI-BOM.
  • 2. Classify by data. Mark the tools that could plausibly receive PHI, such as those used by clinical, billing and support staff.
  • 3. Sort by contract. For each tool, record whether a BAA exists for the exact plan in use. Tools without one are prohibited for PHI.
  • 4. Write the policy. Say what data may be entered, what must be de-identified first, and who approves new tools. See the annotated AI usage policy template.
  • 5. Keep evidence. Records of what was found, decided and remediated are what you show a regulator or a covered-entity customer. See how the same idea works in the NIST AI RMF guide.

To see which AI tools employees are actually using, the AI tool catalog is public and free to browse, and the free assessment shows in a few minutes how your governance compares. For background on the underlying problem, read what Shadow AI is.

Frequently asked questions

Can employees paste patient information into ChatGPT?

Not into a service your organization has no business associate agreement with. If the text contains protected health information and the tool is used on behalf of a covered entity, HIPAA requires a BAA first, and the pages we reviewed do not list OpenAI's consumer plans among the products it offers one for. Whether a specific paste is a violation depends on the facts, so ask counsel.

Does HIPAA require a business associate agreement with an AI vendor?

If the vendor creates, receives, maintains or transmits PHI on your behalf, yes: 45 CFR 164.502(e)(1) requires satisfactory assurance in a written contract, and HHS says a cloud provider that handles ePHI for a covered entity is a business associate. This holds even if the provider only stores encrypted data and has no key.

Can we use AI tools with de-identified data?

Data that meets the de-identification standard in 45 CFR 164.514(b) is no longer PHI. There are two methods: an expert determination, or removing the 18 identifiers listed in the Safe Harbor method. Pasting notes with the name removed is not enough, because dates, locations, record numbers and other listed identifiers also count.

Is there a HIPAA certification for AI tools or for companies?

No official one. HHS says it does not endorse or recognize private organizations' certifications regarding the Security Rule, and that such certifications do not absolve covered entities of their legal obligations. Treat “HIPAA certified” and “HIPAA compliant” badges as marketing, and read the contract instead.

What are the civil penalties for a HIPAA violation?

HHS's January 28, 2026 inflation adjustment sets four tiers by level of culpability. The minimum per violation runs from $145 to $73,011, and the per-violation maximum is $73,011, or $2,190,294 in the willful-neglect tier not corrected within 30 days. Amounts are adjusted every year, so check the current notice.

Does Tangerin AI read our employees' conversations with AI tools?

No. Tangerin AI sees only usage metadata, such as which AI tool was used and how often, and never the content of a conversation or a prompt. It tracks HIPAA as one of its frameworks, but it does not certify anyone, and it does not offer a business associate agreement today.

Sources

Found it useful? Share it

LinkedInX

Instagram does not open links from outside the app — we copy it for you to paste in a story or bio.

Where does your company stand today?

The free assessment is 9 questions, 5 minutes and no signup. It returns your maturity level per dimension and a prioritised action plan — enough to know where to start without buying anything.