stackofpaperwork

Can We Put PHI Into ChatGPT or Another AI Tool?

Artificial intelligence tools like ChatGPT can be incredibly useful. They can help draft emails, summarize policies, brainstorm patient communication ideas, simplify complex topics, and save time on administrative work.

But for healthcare organizations, there is one very important question:

Can we put protected health information, or PHI, into ChatGPT or another AI tool?

The safest answer is: not unless the tool has been properly approved, configured, and covered by a signed Business Associate Agreement.

For medical practices in Nashville, Montgomery, and across the Southeast, this is not just a technology question. It is a HIPAA, security, workflow, and risk management question.

What Counts as PHI?

PHI is health information that can identify a patient. That includes obvious details like names, dates of birth, Social Security numbers, medical record numbers, addresses, phone numbers, and insurance information.

It can also include less obvious information, such as appointment notes, diagnoses, lab results, prescriptions, billing details, provider names, visit dates, or unique circumstances that could point back to a specific patient.

A good rule of thumb: if the information could reasonably identify a patient, treat it as PHI.

Why AI Tools Create Risk

Many healthcare teams are tempted to use AI for practical reasons:

  • “Can you rewrite this patient letter?”
  • “Can you summarize this referral note?”
  • “Can you help respond to this complaint?”
  • “Can you explain these discharge instructions in simpler language?”

Those may be valid use cases, but the risk starts when real patient information is copied into a public or unapproved AI tool.

Under HIPAA, covered entities and business associates must protect electronic PHI and use appropriate safeguards for confidentiality, integrity, and availability. HHS also makes clear that when a cloud service creates, receives, maintains, or transmits ePHI on behalf of a covered entity, a HIPAA-compliant Business Associate Agreement is generally required.
That matters because an AI platform may store, process, log, review, or retain information depending on the product, plan, settings, and contract.

So, Is ChatGPT HIPAA-Compliant?

Not automatically.

OpenAI states that certain HIPAA-eligible products and functionality are available with a Business Associate Agreement, and that API HIPAA eligibility depends on specific account provisioning and retention settings. OpenAI also notes that it offers a Business Associate Agreement for ChatGPT for Healthcare and API healthcare customers to support HIPAA compliance requirements.

That does not mean every version of ChatGPT is appropriate for PHI.

A free, personal, or unapproved AI account should not be treated as safe for patient data. The organization needs the right contract, the right configuration, the right access controls, and clear internal policies before PHI is entered.

What Healthcare Practices Should Do Instead

For most practices, the best starting policy is simple:

Do not enter PHI into any AI tool unless it has been formally approved for PHI use.

That does not mean your team cannot use AI. It means they should use it carefully.

For example, staff can often use AI to help with:

  • Drafting general patient education content
  • Creating internal training outlines
  • Rewriting non-patient-specific messages
  • Brainstorming phone scripts
  • Improving website FAQs
  • Summarizing public regulations or vendor documentation
  • Creating templates with placeholder information

Instead of pasting real patient information, use generic examples:

“Write a reminder message for a patient who missed an appointment” is safer than including the patient’s name, condition, appointment date, and provider.

“Summarize this general billing policy” is safer than uploading a patient’s claim details.

Why This Matters for Small and Mid-Sized Practices

Many physician-owned and specialty practices operate with lean staffing, limited internal IT resources, and high reliance on EHR, practice management, imaging, and secure communication systems. Their priorities often include HIPAA compliance, secure communication, EHR access, uptime, and business continuity.

That is exactly why AI policies need to be practical. A policy that simply says “don’t use AI” may be ignored. A better policy explains:

  • Which AI tools are approved
  • Whether PHI is allowed
  • What staff can use AI for
  • What information must never be entered
  • Who reviews new tools
  • What to do if PHI is accidentally shared

A Practical AI Policy for PHI

Healthcare practices should consider creating an AI use policy that includes these rules:

1. No PHI in unapproved AI tools.
Staff should not paste patient names, records, notes, images, billing details, or identifiers into public AI tools.

2. Approved tools only.
Any AI tool used with PHI should go through security, compliance, and vendor review.

3. Confirm the BAA.
If the vendor will create, receive, maintain, or transmit PHI on your behalf, confirm whether a HIPAA-compliant Business Associate Agreement is required and in place.

4. Limit access.
Only authorized users should have access, and accounts should be protected with strong authentication.

5. Train staff with real examples.
Show the difference between safe prompts and risky prompts.

6. Review settings and retention.
Understand how the AI platform stores, logs, uses, and deletes data.

The Bottom Line

AI can be helpful for healthcare organizations, but PHI should never be casually copied into ChatGPT or any other AI tool.

Before using AI with patient information, confirm that the tool is approved, properly configured, covered by the right agreements, and supported by clear staff training.

For practice administrators, office managers, and managing physicians, the goal is not to avoid innovation. The goal is to use AI in a way that protects patients, supports staff, and keeps the practice aligned with HIPAA expectations.

 

Schedule A Discovery Call

Let's discuss how we can help your business achieve seamless and worry-free IT!
Schedule A Discovery Call