IN BRIEF

A plain-language map of data, agreements, and approved environments. Use this as a structured conversation starter, then apply qualified legal, privacy, security, clinical, or ethical review to the real workflow.

01

First decide whether HIPAA applies

HIPAA applies to covered entities and business associates, not to every health-related app or every piece of health information in every setting. A healthcare provider is a covered entity only in the circumstances defined by the rules, including certain standard electronic transactions.

The organization should identify its role and the information involved before relying on a vendor statement. When a service handles ePHI on behalf of a regulated entity, HHS guidance explains that a written business associate arrangement and appropriate safeguards are central requirements.

02

A BAA does not approve every feature

Confirm the exact services and functionality covered by the agreement. Consumer accounts, optional connectors, external actions, file tools, or retention modes may have different eligibility or configuration requirements.

OpenAI, for example, publishes a current list of HIPAA-eligible products and functionality and provides implementation guidance tied to its BAA. That nuance is why ‘Is ChatGPT HIPAA compliant?’ cannot be answered responsibly with a universal yes or no.

  • Exact plan and workspace
  • Covered features and connectors
  • Retention and training terms
  • Admin and access configuration
03

Compliance is a workflow, not a label

A product name, model name, or marketing page cannot make a healthcare workflow compliant by itself. The organization using the tool still has to determine whether HIPAA applies, understand what information enters the system, document permitted uses, configure access, train its workforce, and manage risk.

For a cloud service that creates, receives, maintains, or transmits electronic protected health information on behalf of a covered entity or business associate, HHS guidance centers the business associate agreement and the regulated organization’s own risk analysis. Those are operational responsibilities, not badges that can be inferred from a homepage.

  • Identify the data before selecting the tool
  • Confirm the contract and covered services
  • Document access, retention, review, and incident handling
04

Keep the human decision visible

Generative output can be fluent and still be incomplete, outdated, or wrong. A useful implementation names who reviews the output, what they compare it against, which changes they must make, and where the approved final record lives.

Human review should be proportionate to the consequence of error. A draft staff announcement and a patient-specific clinical recommendation do not belong in the same review lane. High-consequence decisions require qualified professional judgment and authoritative sources.

THE RULE WORTH KEEPING

A fluent draft is still a draft.

The accountable professional or organization remains responsible for verification, correction, final decisions, and the official record.

05

A review table for the team

QuestionEvidence to requestDecision owner
What data enters?Workflow and data-flow mapPrivacy / security
What is covered?Agreement plus exact feature listLegal / procurement
How is output checked?Test protocol and correction logClinical owner
What changes over time?Vendor notices and monitoring planGovernance owner
SOURCES & LIMITS

Read the current primary guidance.

This article is educational and cannot determine whether a specific organization, contract, product, or workflow complies with law or professional duties.