How do I know if my dental or medical practice is HIPAA-safe when using AI?
The short answer: an AI tool is HIPAA-safe for your practice only if it has a signed Business Associate Agreement (BAA), documented HIPAA-compliant security controls, no training-on-your-data clauses, and role-based access with audit logs. Consumer ChatGPT, Claude, and Perplexity meet none of these criteria. HIPAA-compliant AI exists, but it is a specific subset of the AI market — not the default.
This page explains the four criteria that determine HIPAA-safety, the most common mistakes practices make, what a HIPAA-safe AI stack actually looks like, and the five questions every vendor needs to answer in writing before PHI touches their tool.
The four criteria that determine HIPAA-safe AI
If the tool does not meet all four, it is not HIPAA-safe for protected health information regardless of marketing language.
Signed Business Associate Agreement (BAA)
The vendor has signed a BAA with your practice, covering the specific product/service you are using. "The vendor offers BAAs" is not sufficient — you need the signed document in your files.
HIPAA Security Rule controls in place
Encryption in transit and at rest. Access controls. Integrity controls. Audit logging. Usually documented by SOC 2 Type II certification covering the specific service (not the company broadly).
No training-on-your-data clause
The vendor contractually agrees not to use your data (including PHI) to train their underlying AI models. Without this, PHI could theoretically leak into future model weights — a breach.
Role-based access + audit logs
Only authorized staff can access PHI within the tool, tied to roles. Every access is logged and exportable. Necessary for HIPAA breach investigation and annual audit readiness.
The four most common mistakes
Every one of these is a HIPAA breach under the Breach Notification Rule. Each has shown up in every practice we have looked at.
❌ Staff pasting patient information into consumer ChatGPT
The most common mistake, happening daily in most practices. A hygienist pastes a chart note to "rewrite for the insurance submission." A front desk employee drops appointment history to "check if this patient has been difficult." Every paste is a disclosure of PHI to OpenAI without a BAA. Remediation: block consumer ChatGPT at the network level or replace with an enterprise HIPAA-covered alternative.
❌ Using AI tools for appointment reminders without a BAA
Appointment reminders identify the patient-to-practice relationship, which is PHI under HIPAA. Any AI platform drafting or sending reminders must have a BAA. Consumer-grade scheduling tools with AI features (plain Calendly, plain ChatGPT drafting) are not HIPAA-safe for this workflow. Remediation: use a practice-management-integrated scheduling platform with BAA in place.
❌ Assuming "enterprise AI" automatically equals HIPAA-safe
Enterprise tiers sometimes include BAA eligibility and sometimes do not. ChatGPT Team has different HIPAA status than ChatGPT Enterprise. Claude for Work has different status than Claude via AWS Bedrock. Remediation: never assume — always get the specific BAA for your specific product tier in writing.
❌ Sharing AI-generated output externally without sanitization
A HIPAA-safe tool generates an output that includes patient identifiers. The staff then emails that output to a non-BAA-covered party — an ad agency, a generic project management tool, a personal email. Even if the AI tool was compliant, the downstream disclosure is the breach. Remediation: document which downstream tools are BAA-covered and require sanitization before external sharing.
What a HIPAA-safe AI stack looks like
Described at the category level — specific vendors change frequently. Caidance playbooks for healthcare name the current best-in-class tools in each category with pricing and BAA status.
HIPAA-compliant large language model (LLM) API
For custom AI workflows handling PHI: an enterprise-tier LLM API with a signed BAA. Examples include Anthropic Claude via AWS Bedrock (AWS signs a BAA covering Bedrock), Azure OpenAI Service (Microsoft signs a BAA covering Azure), and OpenAI API with a Zero Data Retention agreement + BAA.
HIPAA-compliant AI scheduling + reminders
Practice-management-grade AI scheduling integrated with your PMS (Dentrix, Eaglesoft, Epic, Athena) and covered by a BAA. These platforms handle PHI through encrypted channels and never transmit identifying information to general-purpose LLMs without BAA coverage.
HIPAA-compliant clinical scribe / transcription
For dental / medical notes transcription: AI scribe platforms specifically designed for healthcare with BAA, PHI-safe processing, and SOC 2 Type II. Often integrated with electronic health records to prevent data escape to general tools.
HIPAA-compliant chatbot / virtual assistant platforms
For patient-facing AI interactions: healthcare-specific chatbot platforms with BAA. These typically route PHI through the BAA-covered LLM infrastructure described above and never to consumer APIs.
What this stack deliberately excludes
Consumer ChatGPT (chat.openai.com), consumer Claude (claude.ai), consumer Perplexity, consumer Gemini — all unsafe for PHI without an enterprise BAA. Also excluded: plain Calendly, plain Google Workspace (without a BAA add-on), Slack (unless on a BAA-covered plan), and any general-purpose SaaS without documented healthcare compliance.
Five questions to ask every AI vendor before signing
Get each answer in writing. Hesitation or vague responses on any of these is disqualifying.
- Will you sign a Business Associate Agreement (BAA) at no additional cost? — if BAA eligibility requires a premium tier, factor that into your pricing analysis
- Is your BAA HIPAA-compliant and can I see it in advance? — some BAAs are stricter than others; read before signing
- Do you have SOC 2 Type II certification covering the service I am using? — a company-level SOC 2 is not enough; the certification must cover the specific product
- Does your service use my data (including PHI) to train AI models? — the answer must be no in writing
- Can you provide audit logs of all PHI access from my account? — required for HIPAA breach investigation and annual audit readiness
Frequently asked questions about HIPAA-safe AI
What does HIPAA-safe AI actually mean?
HIPAA-safe AI means that any AI tool handling protected health information (PHI) on your behalf has (1) a signed Business Associate Agreement (BAA) with your practice, (2) documented security controls meeting HIPAA Security Rule standards, (3) no training-on-your-data clauses that would leak PHI into a general model, and (4) role-based access controls with audit logging. Consumer AI tools — ChatGPT, Claude, Perplexity, Gemini without enterprise BAAs — do not meet any of these criteria and are not HIPAA-safe for PHI workflows.
Is ChatGPT HIPAA compliant?
Consumer ChatGPT (chatgpt.com) is not HIPAA compliant. OpenAI does not sign Business Associate Agreements for consumer or standard ChatGPT Plus accounts. However, OpenAI does sign BAAs for specific Enterprise tiers (ChatGPT Enterprise and the OpenAI API with a Zero Data Retention agreement). Whether you can use ChatGPT with PHI depends entirely on which OpenAI product you have and whether a signed BAA is in place. The default assumption should be "no" unless you have documentation in writing.
Do I need a BAA with every AI tool I use in my practice?
You need a BAA with every tool that will touch PHI. If the AI tool is used exclusively for non-PHI tasks (writing marketing copy, drafting generic policy documents, summarizing a public research paper), a BAA is not required. The moment the tool processes patient names, health conditions, appointment details tied to individuals, insurance information, or any other PHI, the BAA requirement activates. A cleaner heuristic: if you would not be comfortable with the data appearing in a training dataset, you need a BAA.
What is the difference between PHI-safe and PHI-free workflows?
A PHI-safe workflow uses tools that CAN handle PHI legally (BAA + security controls in place). A PHI-free workflow is architected so PHI never reaches the AI tool at all — for example, a chatbot that collects general questions but hands off to a non-AI intake form for anything that would include health details. PHI-free is often simpler and cheaper than PHI-safe because you avoid enterprise tooling costs and BAA administration. Many practice workflows can be restructured to be PHI-free for 80% of AI use cases, reserving PHI-safe tooling only for the 20% that genuinely needs it.
Can my front desk use AI for patient scheduling?
Yes, with the right tool. The AI scheduling platform must have a signed BAA, handle PHI through encrypted channels, and not transmit patient data to any underlying language model without that data being covered by a BAA. Several practice-management-grade AI scheduling tools (integrated with PMS platforms like Dentrix, Eaglesoft, Epic, Athena) are HIPAA-compliant by design. Consumer scheduling tools (plain Calendly, plain Google Calendar booking) without BAAs are not HIPAA-safe for patient scheduling — they are for non-patient scheduling only.
What questions should I ask an AI vendor before signing?
Ask five questions: (1) Will you sign a Business Associate Agreement (BAA) at no additional cost? (2) Is your BAA HIPAA-compliant and can I see it in advance? (3) Do you have SOC 2 Type II certification covering the service I am using? (4) Does your service use my data (including PHI) to train AI models? (5) Can you provide audit logs of all PHI access from my account? If the vendor hesitates or refuses on any of these, they are not HIPAA-safe for your practice regardless of marketing claims.
What happens if a staff member accidentally pastes PHI into consumer ChatGPT?
This is a HIPAA breach. Under the HIPAA Breach Notification Rule, any unauthorized disclosure of PHI must be assessed and potentially reported to affected patients, HHS, and (for breaches over 500 individuals) the media. The practical consequences depend on scale and intent: a single accidental paste of one patient record, caught immediately and documented, typically warrants internal remediation and policy update. Repeated or large-scale pastes trigger formal breach assessment. Document the incident, lock the account immediately, review all PHI your staff has pasted, and consult your HIPAA Privacy Officer or attorney.
Do HIPAA rules apply to appointment reminders?
Yes. Appointment reminders that identify the patient and the practice (which implies the patient is receiving care) are PHI under HIPAA. Any AI tool generating, personalizing, or sending appointment reminders must have a BAA in place. Appointment reminders are one of the most common HIPAA-risk workflows because they feel mundane and are often automated with general-purpose tools. Caidance playbooks for healthcare explicitly name HIPAA-compliant reminder platforms as the only viable tools for this workflow.
Related Caidance references
- Healthcare & Dental industry page — the 10 AI-era fixes calibrated for medical and dental practices, each with a HIPAA-aware playbook
- Caidance Discovery Index (CDI) — the 0–60 readiness score measuring AI-era readiness for your practice
- The Caidance method — how the assess → fix → monitor cycle works in practice
- Free 5-minute assessment — get your practice's current CDI + top 3 priority fixes