Sep 26, 2026
News
Using Claude or ChatGPT in Your Practice Without Creating a HIPAA Problem


Your front desk staff is probably already using AI. Not because anyone approved it, because ChatGPT is free, it’s fast, and it’s very good at drafting a patient letter or summarizing a chart note in ten seconds. The question isn’t whether AI shows up in your practice. It’s whether it shows up in a way that’s actually compliant, or in a way that quietly creates a reportable breach. Here’s what’s actually true about using Claude and ChatGPT around patient data, not marketing claims, but what each company states in its own published terms.
The one fact that determines everything else
Neither Claude.ai (the consumer chat product) nor the free/Plus version of ChatGPT is covered by a Business Associate Agreement (BAA) by default. That single fact is the whole ballgame under HIPAA. Anthropic states plainly in its own trust and privacy materials that a customer must have an executed BAA in place before submitting any Protected Health Information (PHI) to Claude, and that BAAs are available only on Anthropic’s Team, Enterprise, and API plans, not on individual Free, Pro, or Max consumer accounts. OpenAI publishes the same structure: a BAA is available for API, ChatGPT Enterprise, ChatGPT Edu, and ChatGPT Business/Team workspaces, but explicitly not for ChatGPT Free, Plus, or Pro individual consumer accounts. In plain terms: if a staff member is pasting a patient’s chart note into the free version of ChatGPT on their personal account to clean it up, that’s very likely a HIPAA violation already in progress, regardless of how careful they’re being about not typing the patient’s name.
What’s actually allowed
This doesn’t mean AI is off-limits in a medical office. It means the account matters as much as the content. A practice can use Claude or ChatGPT for genuinely non-PHI tasks on any account tier: drafting a generic patient education handout, writing a job posting, summarizing publicly available research, drafting internal policy language. For anything that does touch PHI, clinical note drafting, chart summarization, patient message drafting referencing a specific case, the practice needs a business-tier account with an executed BAA actually signed and on file, not just technically available for purchase. Signing up for a business plan does not automatically create a BAA, both companies require it to be separately executed.
Where this actually breaks in a real office
The realistic failure mode isn’t a rogue employee trying to misuse AI. It’s a well-meaning staff member using their own personal ChatGPT account, the one they use at home, because the office never gave them an approved alternative, and it’s faster than typing the referral letter from scratch. That’s a policy and access-management problem before it’s a technology problem, which is exactly the kind of thing a HIPAA-focused IT company should be closing, not something you find out about during an audit.
What UpsiteGroup does with this for our clients
For practices we support, this isn’t a one-time policy memo, it’s ongoing management: confirming which AI tools are provisioned on business-tier accounts with an executed BAA before anyone uses them with patient data, setting access controls so PHI-adjacent AI use only happens through the approved covered account, keeping AI tool use inside the same audit-logging and access-review process we already run for the EHR itself, and training staff on the specific, concrete line between draft me a generic diabetes handout (fine, any account) and summarize this patient’s chart (business account with BAA, or don’t do it). AI isn’t something to bolt onto your practice’s IT and hope for the best. It’s another system that touches PHI, which means it gets the same governance as your EHR and your email.
Get expert clarity
Frequently asked questions
Can my staff use the free version of ChatGPT or Claude at work?
Yes, for tasks with no patient information at all, like drafting a generic handout or a job posting. Never for anything touching a patient’s chart or PHI, per both companies’ own consumer terms.
What is a BAA and why does it matter for AI tools?
A Business Associate Agreement is a signed contract required under HIPAA before any vendor can touch PHI on your behalf. Anthropic and OpenAI only offer BAAs on business-tier or API plans, and it must be separately executed, not assumed from a paid subscription.
Does paying for ChatGPT Plus or Claude Pro make it HIPAA-compliant?
No. Both companies state that even paid individual consumer accounts (Plus, Pro, Max) are not covered by a BAA and PHI should not be entered into them.
What should our practice do before letting staff use AI with patient information?
Confirm a business-tier account is provisioned with an executed BAA, set a written policy distinguishing PHI from non-PHI use cases, and fold AI access into your existing audit-logging and access-review process.
How does UpsiteGroup help with this?
We confirm which AI tools your staff can access, verify a BAA is actually on file (not just technically available), and manage AI access controls alongside your EHR’s existing security configuration.

