# ChatGPT plan and PHI review matrix

Vendor positions are documented and scope-specific. The customer review context and practice prompt are synthetic; no customer agreement or deployment is approved.

Published plan and feature conditions from OpenAI’s guide posted 9 July 2026, checked on 21 September 2026. A separate feature checklist is included in the pack.

| Plan or control | Published position | Customer verification |
| --- | --- | --- |
| ChatGPT Enterprise | Eligible only if expressly identified in the BAA, under the July guide’s scope. | Match the executed BAA and applicable workspace/feature guide. |
| ChatGPT Edu | The same explicit BAA eligibility condition applies in the July guide. | Do not infer PHI permission from education branding alone. |
| ChatGPT Free, Plus or Pro | Not Eligible Services in the July guide. | Keep PHI out of this consumer-plan route. |
| ChatGPT Business | Not an Eligible Service in the July guide. | A paid business plan does not establish BAA coverage. |
| Healthcare or Enterprise/Edu Regulated Workspace | Explicitly outside the July guide; separate workspace guidance applies. | Review that current scope and agreement, not the ordinary Enterprise/Edu feature list. |
| Enterprise/Edu PHI-prohibited fields | Filenames, profile/workspace details, specified GPT Content and support requests. | Keep these fields free of PHI and apply the exact category definitions. |
| Enterprise/Edu retention | Content remains for the agreement term unless deleted earlier or a shorter period is selected. | Set the appropriate retention and perform required removal under the applicable guide. |
| Search, external execution and connected recipients | The July guide restricts specified PHI uses and recommends disabling relevant third-party transmission features. | Review exact feature settings, recipients and sharing permissions before enabling them. |

## Review steps

- Match plan and workspace scope: Identify whether the July Enterprise/Edu guide or separate Healthcare/Regulated guidance applies.
- Confirm explicit BAA eligibility: Check the actual named service, permitted purpose and contractual conditions.
- Review feature and field restrictions: Validate the current guide, enabled settings, retention, recipients and sharing for the intended input.

## Source identity

Official source: https://cdn.openai.com/osa/hipaa-guide.pdf
Posted: 9 July 2026
Retrieved: 21 September 2026
SHA-256: fa9aa775e352c29c277a250ba80938025be206af060e4dee824e6b7a8f966607

This guide explicitly excludes ChatGPT for Healthcare and Enterprise/Edu Regulated Workspaces. The separate Codex guide has a different stated scope: https://learn.chatgpt.com/docs/hipaa-configuration

## Feature checklist within the July guide scope

| July 2026 guide area | Documented condition | Scope check |
| --- | --- | --- |
| PHI-prohibited fields | No PHI in filenames, user profile, workspace name/image, GPT Content or support requests. | See Enterprise/Edu section 4 for exact subfields. |
| Unsupported features | Codex, Memories and Search Agent mode are listed as unsupported for PHI. | Applies to this July guide; Healthcare and Regulated Workspace are excluded from its scope. |
| Search and Deep Research | The described browsing capabilities may not be used with PHI. | Confirm the applicable current workspace guide. |
| Canvas code network access | The described external network requests may not be used with PHI. | Review the exact enabled feature and recipient path. |
| Apps/connectors, Code on macOS and third-party GPTs | The guide describes potential third-party transfers and recommends disabling relevant functionality. | If enabling a permitted feature, review actual recipients and conditions. |
| Sharing | Customer must evaluate permissions and ensure relevant recipients are authorised. | Do not infer that all workspace members may access every shared PHI item. |

## Safe practice prompt

Invented scenario: improve a generic reception reminder without adding a patient name, diagnosis, booking date or identifier. No actual patient record or installed-product test result is represented.

Obtain the customer’s applicable BAA and current workspace/feature guidance before approving a real use.

## Source and scope

Guide: https://aona.ai/resources/guides/chatgpt-hipaa-baa-checklist/

Source check: 21 September 2026. General information, not professional approval or a completed control test.

- HHS: Guidance on HIPAA and cloud computing: https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html
- OpenAI: HIPAA Implementation and Configuration Guide, 9 July 2026: https://cdn.openai.com/osa/hipaa-guide.pdf
- OpenAI: HIPAA configuration guide for Codex: https://learn.chatgpt.com/docs/hipaa-configuration
