HIPAA Compliant GPT
← Back to blog

Published August 10, 2026· 6 min read

What actually makes an AI assistant HIPAA compliant

A clinical compliance dossier, checklist, key, and tablet arranged for review

Type "HIPAA compliant AI" into a search bar and you'll get dozens of tools claiming the same two words. Almost none of them explain what those words are supposed to guarantee. That gap matters, because "HIPAA compliant" isn't a certification a product earns once and keeps forever. It's a description of how a specific piece of software handles a specific kind of data, and it can be true in one part of a product and false in another.

"HIPAA compliant" isn't a single checkbox

HIPAA itself doesn't certify software. There's no government seal a vendor applies for and displays on a landing page. What actually exists is a set of legal obligations that a covered entity (a clinician or practice) and a business associate (a vendor handling PHI on their behalf) agree to in writing, backed by technical and administrative safeguards that make those obligations real rather than theoretical.

That means the honest version of "is this HIPAA compliant" is really three separate questions, and a vendor that only answers one of them hasn't actually answered it.

The three things that actually matter

Is there a signed Business Associate Agreement? This is the legal contract that makes a vendor responsible for protecting PHI the way HIPAA requires. Without one, a tool isn't "HIPAA compliant" no matter what its marketing page says, because there's no binding commitment behind the claim.

What happens to identifiable information before it reaches a model? A lot of AI products route your raw text straight to a third-party model provider. Others, including this one, tokenize identifying details before anything leaves your session, so the underlying model never sees a name, a date of birth, or a chart number in the clear. These are different architectures with different risk profiles, and the difference is worth asking about directly.

Who can access stored data, and for how long? Encryption and access controls matter, but so does the plain question of retention. If a vendor can't tell you how long your data sits somewhere or who can see it, that's a real gap, not a detail to skip past.

Questions worth asking before you trust a tool

  • Can I see the BAA before I sign up, not just after?
  • Is the BAA included by default, or sold as a separate add-on?
  • What specifically happens to identifiable information before it reaches a model?
  • Is trial or free-tier usage covered by the same protections as a paid plan?

If a vendor can't answer these plainly, that's information too.

Where we stand today

We publish our own answers to these questions on oursecurity ledger, row by row, with a status for each claim: confirmed, pending validation, or limited. We're not certified for SOC 2 Type II or HITRUST yet, and we say so directly instead of writing around it. A BAA is included by default once you move past the free trial. PHI is tokenized before it reaches a model on every plan, including the trial. Those are the specifics. If something you need isn't listed, ask usrather than assuming the answer is no.