# ChatGPT plan and PHI review matrix

Published plan and feature conditions from OpenAI’s guide posted 9 July 2026, checked on 21 September 2026. A separate feature checklist is included in the pack.

Vendor positions are documented and scope-specific. The customer review context and practice prompt are synthetic; no customer agreement or deployment is approved.

Source: https://aona.ai/resources/guides/chatgpt-hipaa-baa-checklist/
Sources checked: 2026-09-21

## The purchasing decision has three parts

### Plan

Identify the eligible service and workspace scope

### Agreement

BAA expressly covers the proposed service

### Feature

Check fields, retention, recipients and enabled controls

| Plan or control | Published position | Customer verification |
| --- | --- | --- |
| ChatGPT Enterprise | Eligible only if expressly identified in the BAA, under the July guide’s scope. | Match the executed BAA and applicable workspace/feature guide. |
| ChatGPT Edu | The same explicit BAA eligibility condition applies in the July guide. | Do not infer PHI permission from education branding alone. |
| ChatGPT Free, Plus or Pro | Not Eligible Services in the July guide. | Keep PHI out of this consumer-plan route. |
| ChatGPT Business | Not an Eligible Service in the July guide. | A paid business plan does not establish BAA coverage. |
| Healthcare or Enterprise/Edu Regulated Workspace | Explicitly outside the July guide; separate workspace guidance applies. | Review that current scope and agreement, not the ordinary Enterprise/Edu feature list. |
| Enterprise/Edu PHI-prohibited fields | Filenames, profile/workspace details, specified GPT Content and support requests. | Keep these fields free of PHI and apply the exact category definitions. |
| Enterprise/Edu retention | Content remains for the agreement term unless deleted earlier or a shorter period is selected. | Set the appropriate retention and perform required removal under the applicable guide. |
| Search, external execution and connected recipients | The July guide restricts specified PHI uses and recommends disabling relevant third-party transmission features. | Review exact feature settings, recipients and sharing permissions before enabling them. |

## Review checklist

- [ ] Match plan and workspace scope
  Identify whether the July Enterprise/Edu guide or separate Healthcare/Regulated guidance applies.
- [ ] Confirm explicit BAA eligibility
  Check the actual named service, permitted purpose and contractual conditions.
- [ ] Review feature and field restrictions
  Validate the current guide, enabled settings, retention, recipients and sharing for the intended input.

## Included example files

- chatgpt-hipaa-baa-review.md
- chatgpt-hipaa-baa-review.csv
- chatgpt-july2026-feature-checklist.csv

## Source references

- HHS: Guidance on HIPAA and cloud computing: https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html (2026-09-21)
- OpenAI: HIPAA Implementation and Configuration Guide, 9 July 2026: https://cdn.openai.com/osa/hipaa-guide.pdf (2026-09-21)
- OpenAI: HIPAA configuration guide for Codex: https://learn.chatgpt.com/docs/hipaa-configuration (2026-09-21)

Use the worksheet within the relevant legal, contractual and technical scope. It is not a certification or a record of an installed-product test.
