Doctors who use ChatGPT to summarize patient charts, interpret test results or work with medical images can violate HIPAA when identifiable health information is sent to a service without the agreements and safeguards required by federal privacy law.
The concern is becoming more immediate as artificial intelligence moves rapidly into everyday medical practice. An American Medical Association survey released in March found that 81% of physicians reported using AI professionally, more than double the 38% reported in 2023. Doctors said they were using AI to create care plans and progress notes, document medical charts, and generate chart summaries.
OpenAI offers ChatGPT products that can operate inside regulated clinical environments, while ordinary consumer ChatGPT operates under a different privacy framework. That distinction can determine how a patient’s medical information is handled.
HIPAA generally requires a health care provider to enter into a Business Associate Agreement, or BAA, when an outside company creates, receives, maintains, or transmits protected health information on the provider’s behalf. The Department of Health and Human Services specifically identifies a third-party AI chatbot handling a patient’s protected health information, or PHI, for a provider as a potential business associate.
HHS also says a provider that uses a cloud service to process or store electronic PHI without the required agreement can violate HIPAA. Patient authorization does not replace those business associate requirements when an outside service is performing work for the provider.
Properly de-identified health information is treated differently. Once information has been de-identified under HIPAA standards, it is no longer considered PHI under the Privacy Rule.
When Doctors Can Use ChatGPT With Patient Information
Doctors can use ChatGPT with identifiable patient information when the product and the provider’s use satisfy HIPAA requirements, including a Business Associate Agreement when one is required.
OpenAI currently lists several products and configurations as eligible for use under a BAA, including ChatGPT for Healthcare, ChatGPT Enterprise with Regulated Workspace, ChatGPT FedRAMP, ChatGPT for Clinicians and certain API configurations.
ChatGPT for Healthcare includes security, governance and data-retention controls designed for regulated clinical environments. OpenAI says health care organizations can use the product for tasks such as summarizing patient information and preparing discharge instructions when the required safeguards are in place.
The key distinction is the environment in which the information is handled. A regulated clinical workspace covered by a BAA carries different privacy protections than an ordinary consumer ChatGPT account.
Consumer ChatGPT operates under a different framework. OpenAI’s Health feature allows eligible users to connect their own medical records for personal use, but OpenAI does not position that product as a HIPAA-regulated clinical workspace for health care organizations.
A physician who copies identifiable patient information into an ordinary consumer account can expose PHI to a service that may fall outside the safeguards required for the provider’s clinical use.
OpenAI expanded its health care offerings on September 1, 2026, with an integration between ChatGPT for Healthcare and Epic. The system can bring authorized information from electronic health records into a governed workspace, allowing clinicians to work with laboratory results, medications, specialist notes, and other patient information.
The integration illustrates the practical divide in medical AI. AI used inside a system built around clinical privacy controls can be governed very differently from the same information copied into a personal consumer account.
Patients Who Upload Their Own Records Face Different Rules
Patients are in a different legal position when they choose to use AI with their own medical records.
HIPAA primarily governs covered health care entities and their business associates. A patient who obtains a copy of a medical chart generally can choose to enter that information into a consumer application.
HHS has also said that when a patient directs a medical provider to send information to an unaffiliated app acting on the patient’s behalf, HIPAA generally stops governing the information after the app receives it. The data can still be subject to other federal and state privacy protections, as well as the company’s own privacy practices.
The legal framework changes when an AI service is performing work for a doctor, hospital or other covered provider. In that setting, HIPAA’s business associate requirements can require a contract and additional protections for the patient’s information.
The same laboratory result or medical note can be treated differently depending on who sends it to the AI service, which product receives it, and whether the technology company is working for the patient or the health care provider.
HIPAA Is Only One Part of Medical AI Regulation
Privacy is one part of the expanding legal framework around artificial intelligence in medicine.
The Food and Drug Administration regulates AI systems when they qualify as medical devices, including certain software used for diagnosis, treatment, or other medical purposes. Oversight depends on what the product is designed to do and the risks associated with its use.
On August 18, the FDA opened a public docket seeking input on how its rules should apply to generative AI-enabled medical devices. The agency is asking for feedback on issues including risk assessment, review before products reach patients, and monitoring after they enter the market. Comments are due October 19.
HIPAA governs protected health information, FDA rules can apply to certain medical-device functions, and state laws can add their own privacy, security, and professional requirements.
AI can help doctors summarize complicated records, reduce paperwork, and organize clinical information. Those benefits make the choice of system increasingly important when identifiable patient data is involved.
Patients share some of the most personal details of their lives with doctors, often with the expectation that the information will remain within a protected clinical setting. As AI becomes more deeply woven into medical practice, understanding where that information goes and which privacy rules follow it will become an increasingly important part of responsible patient care.