Skip to the answer
HIPAA and AI · updated 8 October 2026 · every source linked in the text

HIPAA compliant AI: if I take the name out, can I paste the note into ChatGPT?

Jane Roe, 64F, MRN 4471923, admitted 10/02/2026 with chest pain.
Daughter Mary Roe, cell 555-0142. Patient lives at 22 Birch Lane, Springfield.

A synthetic line from a note. Seven identifiers, marked. Take out “Jane Roe” and six remain, and the two in amber are the daughter’s. Our free masking tool catches about three in four identifiers on text it has never seen, so every line still gets read back.

Short answer

No, taking the name out is not enough. Real patient text can go to an AI tool when a business associate agreement (BAA) covers that exact plan; if you are employed, that means a tool your hospital has signed one for and approved. ChatGPT Free, Plus, Pro and Business offer no BAA, and neither do Claude Free, Pro, Max and Team, even when the clinic pays. The other lawful route is de-identification: an expert’s documented determination, or all eighteen Safe Harbor identifiers removed for the patient and their relatives, employers and household members, with nothing left that your organization knows could identify them.

On this pageShort answer · What “HIPAA compliant AI” means · Which plans offer a BAA · De-identified health information · What we measured · What the tool will not do · Before you paste · Discharge summary template · Questions · Sources

The question, in the words people use

The question usually arrives with a note already open. These are from public threads in the last two years:

“I make sure that I do not pass any personal patient PHI in ChatGPT but at time I also worry that I may by mistake pass some information.”

r/FamilyMedicine, December 2025

“I put a name and generate a note and paste into EMR. I don’t give the AI birthday or MRN.”

r/Psychiatry, March 2026

“if I take vague notes from sessions with clients and input it into ChatGPT in temporary mode, is there a HIPAA violation?”

r/therapists, September 2025

Each of them draws the line in a different place: no PHI at all; a name but no birthday or MRN, in an AI scribe the writer assumes is compliant; vague notes. The rule draws it in one place, and it is further out than most of us assume.

What “HIPAA compliant AI” means, and what it does not

No AI product is HIPAA compliant on its own, because HHS certifies no product. The Office for Civil Rights says so directly in its cloud guidance: OCR does not endorse, certify, or recommend specific technology or products. (HHS, cloud computing guidance). A “HIPAA compliant” badge on a vendor’s site is the vendor’s own claim. HHS also says it does not recognize private organizations’ “certifications” regarding the Security Rule, and that they do not absolve covered entities of their legal obligations under the Security Rule (HHS FAQ 2003).

What makes an AI tool usable with patient text is a contract. A vendor that receives or keeps protected health information on your behalf is a business associate (45 CFR 160.103), and the covered entity may hand it PHI only with written assurances, which is the business associate agreement (45 CFR 164.502(e)). HHS’s business associate guidance, last reviewed on 30 July 2026, gives two examples that match this question: a [t]hird-party vendor Artificial Intelligence (AI) chatbot on a provider’s patient portal, and the vendor of an app, that provides transcription services to a physician (HHS, business associates).

So when a vendor says its AI is HIPAA compliant, ask your privacy officer one narrower thing: has our organization signed a BAA with this vendor that covers this plan and the features I will use? Until the answer is yes, the plan is not a place for patient text.

Civil money penalties are imposed on the covered entity or business associate (45 CFR 160.402), from $145 to $2,190,294 per violation depending on the tier, at the amounts in force since 28 January 2026 (45 CFR 102.3). That does not leave the person who pasted out of it: the organization must sanction staff who break its privacy policies (45 CFR 164.530(e)). And if you own a practice that bills health plans electronically, the organization is you.

Which plans offer a BAA, in the vendors’ own words

Read on 8 October 2026 from each vendor’s own pages. These pages change often, the BAA covers only what your organization signs, and we did not audit any of these companies.

Product or planBAA, as the vendor states it
ChatGPT Free, Plus, Pro and BusinessNo. For clarity, ChatGPT services for consumers (e.g., Free, Plus, Pro) and ChatGPT Business are not Eligible Services. And: If Customer is not using an Eligible Service, Customer may not upload, transmit, or process PHI with ChatGPT. (OpenAI HIPAA Guide, July 2026)
ChatGPT for CliniciansListed among the services an OpenAI BAA can include (OpenAI HIPAA Guide, July 2026).
ChatGPT Enterprise or Edu with the Regulated Workspace, ChatGPT for HealthcareEligible when your organization has a BAA with OpenAI that includes them (OpenAI HIPAA Guide, July 2026).
Claude Free, Pro, Max and TeamNo. Team plans and individual plans (Free, Pro, and Max) can’t enable HIPAA. (Anthropic)
Claude EnterpriseA click-to-accept BAA that only the organization’s Primary Owner can accept, and enabling it doesn’t bring every feature under your BAA (Anthropic).
Gemini in Google Workspace and the Gemini app, through a Workspace accountIncluded in Google’s BAA as Workspace services, with Gemini in Google Chrome excluded (Google Cloud). Administrators must review and accept a BAA before using PHI in Google services. (Google Workspace Admin Help)
Microsoft Copilot and Copilot Chat with a work account (formerly Microsoft 365 Copilot)Microsoft says both support HIPAA compliance for properly configured implementations, and that HIPAA compliance doesn’t apply to web search queries as they aren’t covered by the DPA and Business Associate Agreement (BAA) (Microsoft).
The four AI scribes in our testScribeberry, Heidi and Freed include a BAA in the terms you accept when you sign up (Scribeberry, Heidi, Freed); Twofold’s pricing page says Every Twofold account receives a signed BAA. (Twofold)

The four scribes we tested each give every account a BAA; that says nothing about any other scribe. The general chatbots keep the BAA for specific work and clinician offerings, and the personal plans are not among them. If you are employed, a BAA you accept on your own account is not one your employer signed, and your employer’s policy still decides.

De-identified health information: what Safe Harbor requires beyond the name

Safe Harbor (45 CFR 164.514(b)(2)) removes these eighteen, for the patient and for their relatives, employers and household members:

  1. Names.
  2. Every geographic unit smaller than a state: street address, city, county, precinct, ZIP code and their geocodes. The first three digits of a ZIP code may stay only if that three digit area holds more than 20,000 people; otherwise they become 000.
  3. Every element of a date except the year, for dates directly related to the patient (birth, admission, discharge, death); all ages over 89, and every date element, the year included, that points to such an age, though these may be grouped as 90 or older.
  4. Telephone numbers.
  5. Fax numbers.
  6. Email addresses.
  7. Social Security numbers.
  8. Medical record numbers.
  9. Health plan beneficiary numbers.
  10. Account numbers.
  11. Certificate and license numbers.
  12. Vehicle identifiers and serial numbers, license plates included.
  13. Device identifiers and serial numbers.
  14. Web addresses (URLs).
  15. IP addresses.
  16. Biometric identifiers, finger and voice prints included.
  17. Full face photographs and any comparable images.
  18. Any other unique identifying number, characteristic or code.

Two things in the rule catch people out. The list applies to the patient’s relatives, employers and household members as well as the patient. And it applies to free text: HHS says the standard makes no distinction between data entered into standardized fields and information entered as free text (HHS de-identification guidance). After the list, Safe Harbor adds a second condition: you must have no actual knowledge that what remains could identify the person. HHS’s own examples include a revealing occupation, such as a former president of the State University, and a rare clinical event that was publicized. Clinicians’ own names are not on the list: HHS says only the names of the patient and of their relatives, employers and household members must come out, and adds that the covered entity would need to consider whether additional personal names contained in the data should be suppressed to meet the actual knowledge specification.

The other route is expert determination: someone with the statistical and scientific expertise the rule describes finds that the risk of the information identifying the person is very small, and documents how (45 CFR 164.514(b)(1)).

The note at the top of this page is synthetic. It holds seven identifiers. Taking out “Jane Roe” leaves six, and two of them belong to the daughter. The age of 64 stays, because only ages over 89 count, and the year 2026 may stay without the day and month. This is the gap our free masking tool was built for. On that exact note it masks all seven and leaves the age, in your browser; then it asks you to read the result back, because the identifiers no rule can see, like a rare diagnosis or an unusual job, are caught by the reader.

What we measured

The masking tool, on a set built to break it

We wrote 30 synthetic snippets that hold 108 identifiers across all eighteen categories, with the hard cases over-represented: nicknames, initials, towns written without a state, addresses described in words, ages and dates written every way we could think of. In its default mode the tool masked 78 of the 108 (every snippet and every result is in that file), masked 2 in part and missed 28. On the easier corpus built into the page, which you can run yourself, it masks 63 of 67 identifiers fully and one more in part, and 99.9% of the characters it masks belong to an identifier.

CategoryMaskedWhat it missed
Names22 of 31nicknames (Bobby, Rob), initials (J.R.), a surname alone, the first name in an all-caps “ROE, JANE M.” header (the surname was caught), an employer’s name
Places smaller than a state8 of 16a town written without its state or with the state spelled out (“Fairview, Tennessee”), “the blue house past the gas station”, a street corner, a PO box
Dates and ages over 8917 of 20“3/28” and “the 14th” with no year, an age written in words
Phone, fax, email, record numbers, health plan, account, license, vehicle, web address26 of 26none in this set
Social Security numbers2 of 4a number written with spaces, the last four digits alone
Device identifiers and IP addresses2 of 4a serial after a lowercase label, an IPv6 address
Biometrics, photographs, any other unique characteristic1 of 7“the only known case in the county”, “the town’s only veterinarian”, an identical twin of a news anchor, a photo filename

The narrative items in the last row, the only veterinarian and the twin, are the ones no rule set will ever fix, and it is why Safe Harbor carries the actual-knowledge condition. On 8 October 2026 the first run masked 73. Before publishing we taught it a bare seven-digit phone number, ages written as “94F” or “Age: 97”, dates written as a month name and a day (“Mar 2”) or a month and a year, and birth years that put the age over 89, and the table shows the result. Because the rules were tuned against this set, read 78 as a best case for these patterns. So we ran a second set the rules never saw: 20 new snippets with 85 identifiers, written after the tuning by someone who never read the tool’s rules, with the labels checked by a second reader. The tool masked 62 of the 85, 2 in part, and missed 21. About three in four, on both sets: that is the number to plan around, and the reason the tool asks you to read every line back.

Dates were the weak spot on the unseen set: 17 of 24 masked, and a month and day written without a year, the way most of us date things on the ward (10/7, 1/12, 10/13, 10/09), was missed every time. Dates written with a year were caught every time.

The one in four a tool misses is what a checklist is for. The Clinician Suite has the 4 page HIPAA Safe Harbor checklist with the mosaic risk test, printable PHI firewall cards for the workstation, eight EHR note skeletons and a 45 page handbook on AI documentation. One payment, 30 day refund. Nothing in it makes any AI tool compliant.

Get the Clinician Suite, $99 See what is inside

We also tried to make the page leak. Its content security policy forbids network requests from the page’s code, form submissions, external images and any script not written inside the page itself (connect-src 'none', form-action 'none', img-src data:, and scripts only from inside the page). In our test seven deliberate attempts to send text out of it (fetch, XHR, beacon, image, WebSocket, prefetch, external script) all failed, while a page without the policy reached the same test server on its first request, which shows the test could see a leak. In normal use the page made no request beyond loading itself.

The AI scribes, on six synthetic encounters

The same logic covers AI scribes. In our graded test of four, each one took the whole encounter we gave it and wrote its note from all of it. That is the job, and it is why a scribe needs a BAA for the same reason a chatbot does.

What the tool will not do

  • It does not de-identify a note in the legal sense. The determination, including the actual-knowledge test, belongs to the covered entity: your employer, through its privacy officer, or you if you own the practice.
  • It does not make any AI tool, plan or use compliant, and it does not replace a BAA or your organization’s policy.
  • It misses what the table above lists, and on text it had never seen it also missed a month and day written without a year (10/7, 1/12), lowercase names and addresses (linda, 9 fenwick ct), license numbers, a social media handle and an age typed as a bare 94. Read every line of the result before you use it.
  • It works on text only. Photographs, scans and audio are outside it.
  • Its Surrogate mode replaces identifiers with realistic fakes and moves every date by one hidden offset, so intervals survive. That output is not Safe Harbor, a real name the tool missed sits among the fake ones with nothing to mark it, and fake names or dates must never travel back into a real chart.
  • Browser extensions, writing assistants in particular, can read any text box, this one included. Turn them off before you paste real text.
  • Whether you may paste real patient text into any web page, this one included, is your organization’s decision. State privacy law that is more stringent than HIPAA still applies (45 CFR 160.203), and substance use disorder records carry their own federal rules (42 CFR Part 2). This page does not cover either.

Before you paste: three questions

  1. Is there a BAA between my organization and this vendor that covers this plan? If you do not know, treat the answer as no until your privacy officer says otherwise.
  2. Does the task need the patient at all? A hospital discharge summary template, a letter template, a patient handout or a rewrite of your own teaching text usually does not.
  3. If I de-identify, did I check all eighteen, for the relatives too, and then read the story itself? A rare disease in a small town is the kind of identifier no tool lists.

The masking tool helps with the third question and only the third, and it runs in your browser.

A hospital discharge summary template needs no patient

The safest paste holds no patient at all. Ask an AI tool for structure, keep the structure, and fill it in inside the chart. This is the skeleton we use. Every *** is a stop you fill in the EHR, never in the chatbot, and eight of its lines answer the eight questions in our free discharge summary check.

DISCHARGE SUMMARY
Admission date: ***    Discharge date: ***
Discharging clinician: ***    Primary care clinician: ***
Principal diagnosis: ***
Secondary diagnoses: ***
Reason for admission: ***
Hospital course, by problem: ***
Key results and procedures: ***
Condition and disposition at discharge: ***
Code status, and the discussion that set it: ***
Medications new, changed and stopped, and why each changed: ***
Allergies: ***
Pending results, and the person who will read each one: ***
Follow up: with whom, on what date: ***
If the symptom returns, the patient will: ***
Teach back, in the patient's words: ***
Capacity, if the patient declined anything: ***
First five minutes for the next clinician: ***

Eight more skeletons with the same stops (ED MDM, AMA discharge, critical care time, consult request, handoff, medical necessity, discharge instructions, portal message replies) are in the Clinician Suite, $99 once.

Questions

Can I put patient information into ChatGPT?

Usually only through a plan your organization holds a BAA for, or after the text is de-identified under 45 CFR 164.514. For the consumer plans and ChatGPT Business, OpenAI’s own HIPAA guide says PHI may not be uploaded. Your organization’s policy may be stricter than both.

Is ChatGPT HIPAA compliant?

No product is HIPAA compliant by itself, and HHS certifies none. OpenAI’s HIPAA guide says the consumer plans (Free, Plus, Pro) and ChatGPT Business are not eligible services and may not be used with PHI. It lists ChatGPT for Clinicians, ChatGPT for Healthcare, and ChatGPT Enterprise or Edu with the Regulated Workspace among the services a BAA can include.

Does turning off chat history or model training make it acceptable?

No setting creates a BAA. Turning off training changes what the vendor does with your text, not whether it received it, and a vendor that receives or keeps PHI on your behalf is a business associate.

The vendor’s website says “HIPAA compliant”. Is that enough?

No. HHS does not certify products, and it does not recognize private certifications regarding the Security Rule. What matters is a signed BAA between your organization and the vendor that covers the plan and features you use.

Is de-identified health information still PHI?

De-identified health information, meaning information de-identified under 45 CFR 164.514, is not individually identifiable health information, so the Privacy Rule does not apply to it. There are two routes. Under Safe Harbor, the work is all eighteen identifiers for the patient and their relatives, employers and household members, and no actual knowledge that the rest could identify them. The other route is a documented expert determination under 164.514(b)(1).

Do I have to remove the doctors’ and nurses’ names?

Not as a listed identifier. HHS says only the names of the patient and of their relatives, employers and household members must be removed, but that the covered entity would need to consider whether other names in the note should come out to meet the actual knowledge condition. Your organization may want them out regardless.

The Safe Harbor checklist, the note skeletons and the firewall cards are in the Clinician Suite, $99 once.

Sources

Regulations read on eCFR, title 45 current to 6 October 2026. HHS pages read on 8 October 2026 from copies archived between 3 and 6 October; vendor pages read on 8 October 2026. The stress test and the scribe test used synthetic patients only; no real patient appears anywhere on this page.

Corrections go to support@theattending.net, and every correction is dated on this page.

Corrected 8 October 2026, the day of publishing: the built-in self-test masks 63 of 67 identifiers fully and one in part; we first wrote 64 of 67. No other number changed.