Compliance decisions
ChatGPT
ChatGPT and HIPAA: plans, BAAs and features
OpenAI’s 9 July 2026 guide permits ChatGPT Enterprise or Edu PHI use only when the BAA expressly identifies the service as eligible; it excludes Free, Plus, Pro and Business. Healthcare and Regulated Workspaces have a separate guide. Check the applicable workspace agreement and feature conditions before sending patient information.
For Healthcare privacy, security and procurement teams
The matrix separates published conditions from the customer’s actual approval.
Vendor positions are documented and scope-specific. The customer review context and practice prompt are synthetic; no customer agreement or deployment is approved.01
Start with the plan and the applicable guide
The official HIPAA Implementation and Configuration Guide is posted 9 July 2026. Its Enterprise/Edu section requires a BAA expressly identifying the relevant service as eligible and says Free, Plus, Pro and ChatGPT Business are not eligible. Payment alone therefore does not establish the permission to process PHI.
The guide explicitly excludes ChatGPT for Healthcare and Enterprise or Edu with the Regulated Workspace, which have separate guidance. Preserve that distinction. The matrix records what this source establishes, not an assertion that every feature in every workspace has the same eligibility.
Source context: OpenAI: HIPAA Implementation and Configuration Guide, 9 July 2026
02
Match the agreement to the intended patient-data use
HHS explains that a cloud provider handling ePHI on behalf of a regulated entity can be a business associate, including where it maintains encrypted information without the key. Review the required agreement, permitted purpose and complete data flow rather than relying on a product privacy statement.
List the workspace, authorised staff, task, data categories and recipients. The July guide also places device security, monitoring and backup responsibilities with the customer and prohibits using the service to maintain PHI as part of a designated record set. It is not a replacement for the organisation’s clinical records system.
Source context: HHS: Guidance on HIPAA and cloud computing · OpenAI: HIPAA Implementation and Configuration Guide, 9 July 2026
03
Review fields, features and retention separately
Within its Enterprise/Edu scope, the July guide prohibits PHI in filenames, profile details, workspace name/image, specified GPT Content and support requests. Its GPT Content list includes instructions, conversation starters and uploaded files; do not confuse that configuration category with a blanket statement about every ordinary conversation attachment.
The same guide describes customer-controlled retention and feature restrictions. Check the current guide and actual settings before enabling a feature. A BAA for the base service does not eliminate the need to review search, network access, connected recipients and sharing.
Source context: OpenAI: HIPAA Implementation and Configuration Guide, 9 July 2026
04
Do not merge different Codex and workspace scopes
The July Enterprise/Edu guide lists Codex as unsupported for PHI within that guide’s scope. The separate live Codex HIPAA guide describes conditional local use for Healthcare, Clinicians or Regulated workspaces with an applicable BAA and required access, and explicitly excludes Codex cloud.
These statements must not be flattened into “Codex is always covered” or “Codex is never covered”. Identify the actual workspace, sign-in method and applicable guide. The current feature article and the customer’s agreement should resolve the proposed configuration; do not choose a more permissive row from another scope.
Source context: OpenAI: HIPAA Implementation and Configuration Guide, 9 July 2026 · OpenAI: HIPAA configuration guide for Codex
05
Turn the review into a staff rule and safe test
Record the permitted account, task, fields and feature set so staff can distinguish the approved route from a personal account or excluded feature. Include processing intermediaries in the review: an AI provider’s BAA does not automatically establish Aona’s or another vendor’s contractual role.
Practise with invented records before PHI enters the selected path. Record the intended and observed control action, and keep the contractual decision separate from the test. A successful synthetic block is evidence about that path, not HIPAA certification or professional approval.
Source context: HHS: Guidance on HIPAA and cloud computing · OpenAI: HIPAA Implementation and Configuration Guide, 9 July 2026
Put it into practice
ChatGPT plan and PHI review matrix
Published plan and feature conditions from OpenAI’s guide posted 9 July 2026, checked on 21 September 2026. A separate feature checklist is included in the pack.
Vendor positions are documented and scope-specific. The customer review context and practice prompt are synthetic; no customer agreement or deployment is approved.
Plan
Identify the eligible service and workspace scope
Agreement
BAA expressly covers the proposed service
Feature
Check fields, retention, recipients and enabled controls
| Plan or control | Published position | Customer verification |
|---|---|---|
| ChatGPT Enterprise | Eligible only if expressly identified in the BAA, under the July guide’s scope. | Match the executed BAA and applicable workspace/feature guide. |
| ChatGPT Edu | The same explicit BAA eligibility condition applies in the July guide. | Do not infer PHI permission from education branding alone. |
| ChatGPT Free, Plus or Pro | Not Eligible Services in the July guide. | Keep PHI out of this consumer-plan route. |
| ChatGPT Business | Not an Eligible Service in the July guide. | A paid business plan does not establish BAA coverage. |
| Healthcare or Enterprise/Edu Regulated Workspace | Explicitly outside the July guide; separate workspace guidance applies. | Review that current scope and agreement, not the ordinary Enterprise/Edu feature list. |
| Enterprise/Edu PHI-prohibited fields | Filenames, profile/workspace details, specified GPT Content and support requests. | Keep these fields free of PHI and apply the exact category definitions. |
| Enterprise/Edu retention | Content remains for the agreement term unless deleted earlier or a shorter period is selected. | Set the appropriate retention and perform required removal under the applicable guide. |
| Search, external execution and connected recipients | The July guide restricts specified PHI uses and recommends disabling relevant third-party transmission features. | Review exact feature settings, recipients and sharing permissions before enabling them. |
Work through your review
Use the checks to organise the evidence you need. Your selections stay in this tab.
0 of 3 reviewed
Example files for this task
Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.
chatgpt-hipaa-baa-review.mdInspect
# ChatGPT plan and PHI review matrix
Vendor positions are documented and scope-specific. The customer review context and practice prompt are synthetic; no customer agreement or deployment is approved.
Published plan and feature conditions from OpenAI’s guide posted 9 July 2026, checked on 21 September 2026. A separate feature checklist is included in the pack.
| Plan or control | Published position | Customer verification |
| --- | --- | --- |
| ChatGPT Enterprise | Eligible only if expressly identified in the BAA, under the July guide’s scope. | Match the executed BAA and applicable workspace/feature guide. |
| ChatGPT Edu | The same explicit BAA eligibility condition applies in the July guide. | Do not infer PHI permission from education branding alone. |
| ChatGPT Free, Plus or Pro | Not Eligible Services in the July guide. | Keep PHI out of this consumer-plan route. |
| ChatGPT Business | Not an Eligible Service in the July guide. | A paid business plan does not establish BAA coverage. |
| Healthcare or Enterprise/Edu Regulated Workspace | Explicitly outside the July guide; separate workspace guidance applies. | Review that current scope and agreement, not the ordinary Enterprise/Edu feature list. |
| Enterprise/Edu PHI-prohibited fields | Filenames, profile/workspace details, specified GPT Content and support requests. | Keep these fields free of PHI and apply the exact category definitions. |
| Enterprise/Edu retention | Content remains for the agreement term unless deleted earlier or a shorter period is selected. | Set the appropriate retention and perform required removal under the applicable guide. |
| Search, external execution and connected recipients | The July guide restricts specified PHI uses and recommends disabling relevant third-party transmission features. | Review exact feature settings, recipients and sharing permissions before enabling them. |
## Review steps
- Match plan and workspace scope: Identify whether the July Enterprise/Edu guide or separate Healthcare/Regulated guidance applies.
- Confirm explicit BAA eligibility: Check the actual named service, permitted purpose and contractual conditions.
- Review feature and field restrictions: Validate the current guide, enabled settings, retention, recipients and sharing for the intended input.
## Source identity
Official source: https://cdn.openai.com/osa/hipaa-guide.pdf
Posted: 9 July 2026
Retrieved: 21 September 2026
SHA-256: fa9aa775e352c29c277a250ba80938025be206af060e4dee824e6b7a8f966607
This guide explicitly excludes ChatGPT for Healthcare and Enterprise/Edu Regulated Workspaces. The separate Codex guide has a different stated scope: https://learn.chatgpt.com/docs/hipaa-configuration
## Feature checklist within the July guide scope
| July 2026 guide area | Documented condition | Scope check |
| --- | --- | --- |
| PHI-prohibited fields | No PHI in filenames, user profile, workspace name/image, GPT Content or support requests. | See Enterprise/Edu section 4 for exact subfields. |
| Unsupported features | Codex, Memories and Search Agent mode are listed as unsupported for PHI. | Applies to this July guide; Healthcare and Regulated Workspace are excluded from its scope. |
| Search and Deep Research | The described browsing capabilities may not be used with PHI. | Confirm the applicable current workspace guide. |
| Canvas code network access | The described external network requests may not be used with PHI. | Review the exact enabled feature and recipient path. |
| Apps/connectors, Code on macOS and third-party GPTs | The guide describes potential third-party transfers and recommends disabling relevant functionality. | If enabling a permitted feature, review actual recipients and conditions. |
| Sharing | Customer must evaluate permissions and ensure relevant recipients are authorised. | Do not infer that all workspace members may access every shared PHI item. |
## Safe practice prompt
Invented scenario: improve a generic reception reminder without adding a patient name, diagnosis, booking date or identifier. No actual patient record or installed-product test result is represented.
Obtain the customer’s applicable BAA and current workspace/feature guidance before approving a real use.
## Source and scope
Guide: https://aona.ai/resources/guides/chatgpt-hipaa-baa-checklist/
Source check: 21 September 2026. General information, not professional approval or a completed control test.
- HHS: Guidance on HIPAA and cloud computing: https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html
- OpenAI: HIPAA Implementation and Configuration Guide, 9 July 2026: https://cdn.openai.com/osa/hipaa-guide.pdf
- OpenAI: HIPAA configuration guide for Codex: https://learn.chatgpt.com/docs/hipaa-configuration
Download chatgpt-hipaa-baa-review.mdchatgpt-hipaa-baa-review.csvInspect
Plan or control,Published position,Customer verification
ChatGPT Enterprise,"Eligible only if expressly identified in the BAA, under the July guide’s scope.",Match the executed BAA and applicable workspace/feature guide.
ChatGPT Edu,The same explicit BAA eligibility condition applies in the July guide.,Do not infer PHI permission from education branding alone.
"ChatGPT Free, Plus or Pro",Not Eligible Services in the July guide.,Keep PHI out of this consumer-plan route.
ChatGPT Business,Not an Eligible Service in the July guide.,A paid business plan does not establish BAA coverage.
Healthcare or Enterprise/Edu Regulated Workspace,Explicitly outside the July guide; separate workspace guidance applies.,"Review that current scope and agreement, not the ordinary Enterprise/Edu feature list."
Enterprise/Edu PHI-prohibited fields,"Filenames, profile/workspace details, specified GPT Content and support requests.",Keep these fields free of PHI and apply the exact category definitions.
Enterprise/Edu retention,Content remains for the agreement term unless deleted earlier or a shorter period is selected.,Set the appropriate retention and perform required removal under the applicable guide.
"Search, external execution and connected recipients",The July guide restricts specified PHI uses and recommends disabling relevant third-party transmission features.,"Review exact feature settings, recipients and sharing permissions before enabling them."
Download chatgpt-hipaa-baa-review.csvchatgpt-july2026-feature-checklist.csvInspect
July 2026 guide area,Documented condition,Scope check
PHI-prohibited fields,"No PHI in filenames, user profile, workspace name/image, GPT Content or support requests.",See Enterprise/Edu section 4 for exact subfields.
Unsupported features,"Codex, Memories and Search Agent mode are listed as unsupported for PHI.",Applies to this July guide; Healthcare and Regulated Workspace are excluded from its scope.
Search and Deep Research,The described browsing capabilities may not be used with PHI.,Confirm the applicable current workspace guide.
Canvas code network access,The described external network requests may not be used with PHI.,Review the exact enabled feature and recipient path.
"Apps/connectors, Code on macOS and third-party GPTs",The guide describes potential third-party transfers and recommends disabling relevant functionality.,"If enabling a permitted feature, review actual recipients and conditions."
Sharing,Customer must evaluate permissions and ensure relevant recipients are authorised.,Do not infer that all workspace members may access every shared PHI item.
Download chatgpt-july2026-feature-checklist.csvBefore you proceed
Keep these distinctions clear
- A plan is not an approval
- Do not copy a BAA decision from one service or feature to another.
- Training is only one question
- A promise about model training does not answer contracting, access, retention or permitted disclosure.
Apply it to employee AI use
Bring your actual data path.
Aona can help teams evaluate visibility and sensitive-input policies on supported installed browser and native paths.
Aona does not approve HIPAA disclosures, supply an OpenAI BAA or certify a workflow as compliant. Its own handling and contractual role need review.
Use the synthetic administrative prompt to agree the account, application, input path and policy outcome for a scoped security evaluation.
Review your use caseFAQ
Questions for this decision
Is ChatGPT Business eligible for PHI under this guide?
Can Enterprise or Edu be used without a BAA?
Do Healthcare and Regulated Workspaces use the same feature list?
Why do the Codex sources describe different eligibility?
Evidence behind the guide
Sources and scope
Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.
- HHS: Guidance on HIPAA and cloud computing
Business-associate roles, BAAs, risk analysis and cloud-service safeguards, including providers without decryption keys.
regulator · checked 2026-09-21 - OpenAI: HIPAA Implementation and Configuration Guide, 9 July 2026
Dated Enterprise/Edu BAA eligibility, excluded consumer/Business plans, PHI-prohibited fields, retention and feature conditions; explicitly excludes Healthcare and Regulated Workspace scope.
vendor · checked 2026-09-21 - OpenAI: HIPAA configuration guide for Codex
Separate Codex Local conditions for the specified Healthcare, Clinicians or Regulated workspace/API paths and an explicit Codex cloud exclusion; not a replacement for every ChatGPT workspace guide.
vendor · checked 2026-09-21