MedVersify
MedVersify

MedVersify

Healthcare operations support for revenue, compliance, and patient flow.

Free Practice AuditNo obligation · 24-hr reply
Compliance12 min readOctober 9, 2026

Can Your Staff Paste Patient Data Into ChatGPT? A 2026 HIPAA Guide to Generative AI for Medical Practices

Your front desk, coders, and billers are already using AI chatbots — the question is whether patient data is going with them. This guide explains when an AI tool becomes a HIPAA business associate, why de-identifying clinical text is harder than it looks, where the long-delayed Security Rule overhaul stands, and the 12 questions to ask any AI vendor (including your billing company) before PHI touches their system.

MedVersify Editorial

Compliance & Data Security Specialists

Key Takeaways

What you will learn in this article

  • 1Sending PHI to an AI vendor is a disclosure to a business associate. Without a signed business associate agreement (BAA), pasting a patient note into a chatbot is an impermissible disclosure — however secure the vendor is.
  • 2Several major AI vendors now offer HIPAA-eligible enterprise tiers under a BAA, but often with features excluded. Consumer and free versions generally aren’t covered.
  • 3De-identification is the other legal route, and it is harder than deleting the name: HIPAA’s Safe Harbor method removes 18 identifier types, and clinical free text hides them everywhere.
  • 4The HIPAA Security Rule overhaul proposed in January 2025 — encryption, MFA, asset inventories, and AI inside the risk analysis — is still not final. The current rule applies, and OCR is expanding enforcement on risk analysis and risk management plans.
  • 5The fewer companies that touch PHI, the smaller the risk. Map every vendor, model provider, and sub-processor in the chain before patient data flows.

Somewhere in your practice, someone has used an AI chatbot this week to draft an appeal letter, summarize a payer policy, or rewrite a patient message. Most of that is harmless and genuinely useful. The risk sits in a single habit: copying patient information into a tool the practice hasn’t vetted. HIPAA doesn’t have a special chapter for AI. It doesn’t need one — the rules that already govern every vendor that touches PHI apply in full.

When an AI Tool Becomes a Business Associate

Under HIPAA, a business associate is any outside party that creates, receives, maintains, or transmits PHI on your behalf. An AI vendor that receives a clinical note, a claim, or a patient message to process it fits that definition. HHS made a closely related point years ago about cloud services: a provider that stores ePHI is a business associate even if the data is encrypted and the provider can’t view it. The practical consequence is simple — no BAA, no PHI.

Use casePHI involved?What’s required
Drafting a generic appeal template or summarizing a public payer policyNoAn acceptable-use policy. No BAA needed if no PHI is entered.
Pasting a patient’s note into a free consumer chatbotYesNot permitted without a BAA — this is an impermissible disclosure.
Coding or documentation tool from a vendor with a signed BAAYesBAA covering every sub-processor, minimum-necessary access, documented in your risk analysis.
Ambient scribe recording the visitYes (audio + PHI)BAA, patient consent per state recording law, clear audio retention terms.
Analytics on properly de-identified dataNo (if truly de-identified)Safe Harbor or Expert Determination de-identification, documented.
AI that runs entirely inside your own (or your BA’s) environmentYes, but containedCovered under existing safeguards and BAAs; no new third party in the chain.

General guidance, not legal advice. Your risk analysis and counsel decide what’s permitted in your practice.

A BAA is necessary, not sufficient. It gives permission to share; it doesn’t configure access controls, logging, or retention for you. Those stay your responsibility — and your business associate’s.

The chain problem

Many AI products don’t run their own models. They call a large language model owned by someone else, sometimes through more than one intermediary. Each company that touches PHI along the way needs to be covered by a BAA or subcontractor agreement. When a vendor says it is “HIPAA compliant”, the follow-up question is: which model providers and sub-processors see our data, and is each one under a BAA?

Third-party AI chain

Your PHI passes through several companies

  • Practice → AI app vendor → model provider → model host (cloud)
  • A BAA or subcontractor agreement needed at every link
  • Retention, logging, and training terms set by each company
  • Terms can change with a vendor’s product updates

Short chain

Fewer companies touch your PHI

  • Vendor hosts its own models, or every model provider is named in the contract
  • One BAA chain you can actually trace and document
  • Retention and training terms set out in writing, in one place
  • Easier to audit and to describe in your risk analysis

De-Identification Is Harder Than Deleting the Name

Data that is properly de-identified isn’t PHI, and HIPAA no longer applies to it. HIPAA allows two methods: Safe Harbor, which removes 18 specified types of identifiers, and Expert Determination, where a qualified expert documents that the risk of re-identification is very small. With structured data, Safe Harbor is manageable. With clinical free text, it isn’t simple.

  • Dates hide everywhere. All elements of dates more specific than the year (except year) must go — admission, discharge, service, and birth dates, often scattered through a narrative.
  • Small geography counts. Street addresses, cities, and most ZIP code detail are identifiers.
  • Free text carries surprises. Phone numbers in a callback note, an employer’s name, a relative’s name, a device serial number, a record number pasted into a message.
  • Ages over 89 must be aggregated into a single “90 or older” category.
  • Actual knowledge still matters. Even with identifiers removed, if you know the remaining information could identify the person, it isn’t de-identified.

Where the HIPAA Security Rule Overhaul Stands

In January 2025, HHS proposed the first major update to the HIPAA Security Rule since 2013. As of fall 2026 it is still a proposal: an earlier target to finalize in 2026 passed without a final rule, and the regulatory agenda now points to 2027. Nothing in the proposal is binding until it is finalized — but it shows clearly where regulators think the baseline should be.

  1. January 6, 2025

    Proposed rule published

    HHS OCR publishes the Security Rule NPRM in the Federal Register.

  2. March 7, 2025

    Comment period closes

    Thousands of comments; many provider groups object to cost and burden.

  3. February 16, 2026

    Privacy notices updated

    Separate, already-final deadline: Notices of Privacy Practices updated for the Part 2 alignment rule.

  4. 2026Now

    Target date passes

    OCR’s earlier target for final action passes without a final rule.

  5. 2027 (projected)

    Possible final rule

    Per the regulatory agenda — not a binding date. Compliance would follow months later.

01

Encryption and MFA

Encryption of ePHI at rest and in transit, and multi-factor authentication for systems that access ePHI, with limited exceptions.

02

Written inventories

A technology asset inventory and a network map — the proposal discussion also brings AI software that touches ePHI into the risk analysis.

03

Testing on a schedule

Vulnerability scans at least every six months and annual penetration testing.

04

Recovery in 72 hours

Procedures to restore critical systems within 72 hours, and business associates notifying covered entities within 24 hours of activating a contingency plan.

05

No more “addressable”

Most implementation specifications would become required, removing the flexibility many small practices rely on today.

What applies right now

The current Security Rule — and OCR’s enforcement focus

Until a final rule is published, the current Security Rule governs: a documented risk analysis, risk management, access controls, audit controls, workforce training, and BAAs. At the April 2026 National HIPAA Summit, OCR said its risk-analysis enforcement initiative is expanding to cover detailed risk management plans. If you add an AI tool that touches ePHI, it belongs in your next risk analysis.

12 Questions to Ask Any AI Vendor — Including Your Billing Company

  1. 1Will you sign a BAA, and does it cover the specific product and features we’ll use?
  2. 2Which model providers and sub-processors receive our data? Is each covered by a BAA or subcontractor agreement?
  3. 3Where is our data processed and stored, and does it ever leave the U.S.?
  4. 4Is our data — prompts, documents, audio, outputs — used to train or improve any model?
  5. 5How long is each kind of data retained, and can we require deletion?
  6. 6Is data encrypted in transit and at rest?
  7. 7Who at your company can access our data, and is that access logged?
  8. 8Do you support single sign-on and multi-factor authentication?
  9. 9How do you notify us of a security incident, and how quickly?
  10. 10Which features are excluded from your HIPAA coverage?
  11. 11How do you measure and report error or hallucination rates for outputs we rely on?
  12. 12Can a human review every AI output before it reaches a claim, a chart, or a patient?

One more governance point: if an AI tool influences clinical decisions, separate federal rules may apply. HHS’s Section 1557 regulation requires covered entities to make reasonable efforts to identify and mitigate discrimination risks in patient care decision support tools, including AI. And in MIPS, the new 2026 improvement activity for patient safety in AI use (IA_PSPA_34) gives practices credit for building exactly this kind of governance — see our ambient scribe rollout guide for a practical starting point.

Free tool · No signupCost-to-Collect CalculatorWeighing an AI billing platform against a billing partner? Compare what in-house billing really costs first.Run the numbers
Is ChatGPT HIPAA compliant?+

No tool is compliant on its own. Consumer and free versions of AI chatbots generally aren’t covered by a BAA, so entering PHI into them is an impermissible disclosure. Some vendors offer enterprise or API tiers that are HIPAA-eligible under a signed BAA, often with specific features excluded — check the current terms for the exact product you use.

Can staff use AI if they remove the patient’s name?+

Removing the name isn’t de-identification. HIPAA’s Safe Harbor method requires removing 18 types of identifiers, including dates and small geographic details, and clinical text often contains them in unexpected places. Without a BAA, the safest policy is no patient information at all.

Is the new HIPAA Security Rule in effect?+

No. It was proposed in January 2025 and, as of fall 2026, hasn’t been finalized. The current Security Rule remains the law. If finalized, the proposal would add a compliance period of several months.

Do we need to list AI tools in our HIPAA risk analysis?+

Under the current rule, any system that creates, receives, maintains, or transmits ePHI belongs in your risk analysis — AI tools included. The proposed rule would make that inventory explicit.

What should be in an AI acceptable-use policy?+

Which tools are approved, what data may never be entered into unapproved tools, who approves new tools, how outputs are reviewed before use, and how staff report a mistake. Train on it, and revisit it as tools change.

Ready to act on this?

Our Services

MedVersify manages billing, credentialing, MIPS, and scheduling — all within HIPAA-aligned workflows.

Tags

HIPAAAI in HealthcareData SecurityGenerative AIBusiness Associate AgreementCompliance

Share this article

Written by

MedVersify Editorial

Compliance & Data Security Specialists

MedVersify helps independent practices reclaim revenue through billing, MIPS, credentialing, and scheduling — so clinicians can focus on care.

MedVersify Newsletter

Billing & compliance insights, straight to your inbox.

Practical guides on billing, MIPS, credentialing, and scheduling for independent practices.

Actionable guidesNo spam, everUnsubscribe anytime
Call now(507) 312-9282