Straight Answers · Compliance

Can I use ChatGPT for patient notes?

Not on a Free, Plus, Pro, or Team plan. Those tiers cannot sign a Business Associate Agreement, so putting protected health information into them is a HIPAA problem regardless of how careful you are. Enterprise plans and API access with the right settings can be covered.

Last reviewed 2026-08-04 · John DeLucchi, PT, DPT, MBA

The plan you are on decides this, not how careful you are with the text you paste. A Business Associate Agreement is the contract that lets a vendor legally handle protected health information on your behalf. No BAA, no PHI. That is the whole rule.

Every major AI vendor draws the same line in the same place, and it is not where most clinicians assume.

Where the line actually falls

  • Anthropic (Claude). Claude Enterprise is eligible once the organization's Primary Owner activates HIPAA compliance in settings. The API is eligible with a signed BAA. Claude Code only with Zero Data Retention enabled. Free, Pro, and Max are not eligible. Neither are Workbench, Console, or Claude Cowork.
  • OpenAI (ChatGPT). ChatGPT Enterprise and the API configured for zero data retention are the covered paths. Consumer Free and Plus are not, and standard Business workspaces are not.
  • Google, Microsoft, Amazon. Google Cloud including Vertex AI, Azure OpenAI, and AWS Bedrock all sign BAAs for commercial accounts.

The word doing all the work

A PT described their clinic's setup on Reddit last year, and it is worth reading closely because almost everything in it is right:

Our outpatient clinic has started using an AI scribe program for documentation and I actually like it. All the patients sign a consent form for use and it is HIPPA compliant obviously. I find that it cuts down on my documentation time and allows me to be more present during my evaluations instead of scribbling down every detail. I review the summary it provides, add my own notes, proof read, and so far it has been a good experience.

r/physicaltherapy

Consent forms. Review. Proofreading. That is a clinician doing this properly. The single word carrying all of the risk is obviously. Compliance was assumed, not confirmed, and nothing in a product's marketing obligates it to be true.

This is not a knowledge gap on the clinician's part. Vendors are genuinely hard to pin down on it. A hospitalist put that side of it plainly:

I keep asking where the data goes, they give me corporate word salad. Asked about the BAA, got some generic document that doesn't explain their security, asked if patient notes train their model and the response was literally 'we value privacy' like that means anything.

r/medicine

Three questions that end the conversation

You do not need to become a security expert. You need three answers in writing, and any vendor who cannot produce them in a day has told you something.

  1. Will you sign a BAA covering the specific plan we are on? Not the product family. The plan. This is where most of these conversations end.
  2. Is our data used to train your models, and can you point me to that in the contract? A privacy page is marketing. The contract is the answer.
  3. Where is the data stored and how long is it retained? Retention windows have real consequences. Anthropic's covered models require 30-day retention, which is why zero data retention and BAA coverage are mutually exclusive on some products.

What you can do on a consumer plan

Plenty, as long as no patient information is involved. Draft a policy. Rewrite a handout into plainer language. Build a staff onboarding checklist. Rehearse a difficult conversation. Summarize a paper you are reading. None of that is PHI and none of it needs a BAA.

The line is the data, not the tool. Stay on the right side of it and a consumer plan is genuinely useful. Cross it and the plan you chose is the finding in the audit.

Sources

Get the next one

New answers on AI in MSK care, written for clinicians and operators.

Free. Low volume. Unsubscribe in one click.