Is ChatGPT HIPAA Compliant? What About Claude, Perplexity, and Other AI Tools?

ChatGPT, Anthropic, Claude, Gemini, and Google AI logos on desktop monitor questioning HIPAA Compliance of AI tools in healthcare.

The version of ChatGPT that most people open in a browser is not HIPAA Compliant. Neither is the everyday version of Claude or Perplexity. That does not mean AI is off limits in healthcare. It means compliance depends on which plan you use, whether you have signed a Business Associate Agreement (BAA), and how you actually use the tool.

This guide covers where each major AI tool stands, what a BAA does and does not cover, and how you can still use AI to help build patient-facing forms without putting Protected Health Information (PHI) at risk.

The short answer

No mainstream AI chatbot is HIPAA Compliant in its free or standard consumer form. You cannot legally put PHI into the version of ChatGPT, Claude, or Perplexity that you sign up for with an email address.

Compliance is possible, but only on specific tiers. Each vendor offers a BAA that covers particular products, usually their enterprise plan or their developer API, and only after you sign the agreement and configure the account correctly. Even then, the BAA covers some features and excludes others.

The safe rule for any clinic or practice: assume an AI tool is not compliant until you have a signed BAA in hand that names the exact product you plan to use.

What actually makes an AI tool HIPAA Compliant

No software is “HIPAA Compliant” as a permanent property. HIPAA compliance is a state you reach by meeting requirements, not a badge a product carries.

For an AI tool to legally process PHI, three things have to be true at the same time.

First, the vendor has to sign a BAA with you. A BAA is the contract that makes the vendor legally responsible for protecting the PHI you send them. Under HIPAA, any vendor that creates, receives, maintains, or transmits PHI on your behalf is a business associate and needs a BAA. The U.S. Department of Health and Human Services explains the requirement in its guidance on business associate contracts. No BAA means no compliance, period.

Second, you have to be on a plan the BAA actually covers. Vendors almost never extend the BAA to free or standard consumer plans. Coverage is limited to enterprise tiers or the API.

Third, you have to use the tool the way the agreement requires. That usually means turning off training on your data, setting the right data retention, restricting who has access, and keeping PHI out of features that sit outside the BAA.

Miss any one of these and the tool is not compliant, even if the other two are in place.

Is ChatGPT HIPAA Compliant?

ChatGPT is not HIPAA Compliant on the Free, Plus, or Team plans. OpenAI does not sign a BAA for those tiers, so PHI should never go into them.

OpenAI does sign a BAA for its API Platform and for ChatGPT Enterprise. On those products, a covered entity can use the technology with PHI once the BAA is executed and the account is configured to exclude the data from model training. If your practice wants to build an AI feature into an application, the API route with a signed BAA is the common path. If your team wants the ChatGPT interface itself, that requires ChatGPT Enterprise, not the consumer plans.

So the honest answer to “is ChatGPT HIPAA Compliant” is: the ChatGPT that almost everyone uses is not, but OpenAI’s enterprise and API products can be with a BAA.

Is Claude HIPAA Compliant?

Claude follows the same pattern. The consumer plans, Free, Pro, and Max, are not covered by a BAA and cannot be used with PHI. Team plans are not covered either.

Anthropic provides a BAA for its HIPAA-ready services, which are the first-party API and Claude Enterprise. To activate it on Claude Enterprise, the organization’s primary owner turns on HIPAA Compliance in the account settings and accepts the BAA. For the API, the primary owner signs the BAA and coordinates with Anthropic to enable it.

Two details matter for accuracy. Covered use requires standard 30-day data retention, so zero-data-retention configurations are not eligible. And the BAA does not cover every feature; certain capabilities sit outside of it, so you cannot assume the whole product is in scope just because your plan qualifies.

Is Perplexity HIPAA Compliant?

Perplexity is not HIPAA Compliant on its Free, Pro, or Max consumer plans, and its standard API is not covered. Consumer data can be used to train models unless you opt out, which is the opposite of what a compliant workflow needs.

Perplexity’s enterprise offerings can support regulated use, but only when a BAA has been executed as part of an enterprise agreement. There is no self-serve BAA you can accept with a click. Until that contract is signed and names your deployment, Perplexity should be treated as not compliant.

What about Gemini and other AI tools?

Google offers a BAA for Gemini through Google Workspace and through Vertex AI on Google Cloud, so Gemini can be used with PHI on those covered, configured plans. The consumer version of Gemini is not covered. The pattern repeats across the market: enterprise and cloud or API tiers can be brought into compliance with a BAA, while the free consumer app cannot.

Quick comparison

AI TOOLBAA AVAILABLE?CAN BE COMPLIANT ONNOT COMPLIANT ON
ChatGPT (OpenAI)YesAPI Platform, ChatGPT Enterprise (with BAA)Free, Plus, Team
Claude (Anthropic)YesFirst-party API, Claude Enterprise HIPAA-ready (with BAA)Free, Pro, Max, Team
PerplexityYes, negotiatedEnterprise plans with an executed BAAFree, Pro, Max, standard API
Gemini (Google)YesGoogle Workspace, Vertex AI (with BAA)Consumer Gemini app

Availability of a BAA is not the same as being compliant. A BAA makes compliance possible on the named product. Configuration and correct use finish the job.

The most common mistake: pasting PHI into a chatbot

The single most frequent HIPAA problem with AI is simple. A staff member pastes a patient’s message, chart note, or intake details into a consumer chatbot to summarize or reword it. On a free or standard plan, that data may be retained and used to improve the model, and there is no BAA covering it. That is a disclosure of PHI to a vendor with no agreement in place.

The fix is a rule everyone on the team understands: no patient identifiers go into any AI tool that is not on a covered plan with a signed BAA. If you only need help with wording or structure, remove the identifiers first.

You can still use AI to build a HIPAA-Compliant form

Here is the part that surprises people. You can use ChatGPT or Claude to help create a patient intake form, a consent form, or a screening questionnaire, and the result can be perfectly HIPAA Compliant. Using AI to draft a form is not the compliance risk. The risk is where the live form collects and stores PHI once patients start filling it out.

Drafting and collecting are two separate steps. When you ask an AI to write the questions, structure the sections, or even generate the HTML for a form, no patient data is involved. You are working with a blank template, not real PHI, so a consumer AI plan is fine for that stage.

The compliance question starts the moment a real patient submits real information. That data has to land in an environment that encrypts it, logs access, and is covered by a BAA. That is the gap HIPAAtizer fills.

You can generate a form with AI, then bring it into HIPAAtizer to make the live version compliant. Because HIPAAtizer works from the form’s HTML structure, an AI-drafted form can become a HIPAA-Compliant online form: submissions are encrypted in transit and at rest, every submission is logged in an audit trail, e-signatures are supported, and HIPAAtizer signs a BAA that covers the full form lifecycle, not just storage. The form embeds on WordPress, Squarespace, Webflow, or Wix, so the patient-facing collection point stays in a compliant environment.

The division of labor is clean. AI helps you design and write the form. HIPAAtizer handles the PHI once the form goes live. You get the speed of AI without putting patient data through a tool that was never built to protect it.

For a plain-language breakdown of which everyday tools are and are not HIPAA Compliant, see the HIPAAtizer tool compliance hub.

Using AI safely in a healthcare practice

A short checklist for keeping AI use inside the lines.

Frequently Asked Questions

Is the free version of ChatGPT HIPAA Compliant?

No. OpenAI does not sign a BAA for the Free, Plus, or Team plans, so PHI cannot legally be entered into them. Only the API Platform and ChatGPT Enterprise can be used with PHI, and only after a BAA is signed.

Still have questions? Contact us