HIPAA Compliant GPT

Technical brief · HIPAA-compliant API

The model call is one line. The compliance boundary is the entire system.

Build the contract, data map, PHI controls, identity, retention, output review, and incident process around the API before production data arrives.

Document status

Audience
Healthtech and clinical teams
Unit of review
End-to-end request path
Production gate
BAA, controls, testing

01

A HIPAA API is an architecture decision

A healthcare application can use generative AI with ePHI only when every relevant service and data path is addressed. The API endpoint is one part of the system; authentication, application hosting, logs, databases, queues, monitoring, support, integrations, and downstream storage can all receive sensitive information.

Start by defining the intended workflow and drawing the complete data path before choosing a model or writing integration code.

02

Contractual coverage has to match the endpoint and configuration

Confirm that the API provider will sign an appropriate BAA and that the exact account, endpoint, model, retention configuration, and features are eligible. OpenAI currently ties HIPAA eligibility for its API to specified Modified Retention conditions. Anthropic uses a HIPAA-ready API organization with a published feature-coverage table.

A BAA with the model provider does not cover an application vendor's unrelated subprocessors. Maintain a complete list of every service that creates, receives, maintains, or transmits ePHI.

03

Put PHI controls before the model call

A purpose-built gateway can authenticate the caller, validate the permitted workflow, minimize input, detect or tokenize identifiers, enforce model and feature policy, and create appropriate audit evidence before a request reaches an LLM.

The response path needs equivalent controls. Restore tokens only inside the approved boundary, validate the output format, prevent unsafe disclosure, and require human review where the result affects a clinical or administrative decision.

04

What developers should record for each request path

A useful technical inventory includes more than an endpoint URL.

  • Purpose, data classification, and permitted users.
  • Input sources, PHI categories, files, audio, and metadata.
  • Model provider, endpoint, model, feature flags, and region.
  • Retention in the application, provider, logs, queues, caches, and backups.
  • Subprocessors, external tools, web access, and connector destinations.
  • Authentication, authorization, secrets, rate limits, and tenant isolation.
  • Output validation, clinical review, export destinations, and incident ownership.

05

Redaction and tokenization need failure tests

Automated PHI handling should be tested against realistic notes, scanned referrals, abbreviations, misspellings, dates, record numbers, and mixed identifiers. Measure both missed identifiers and excessive removal that changes clinical meaning.

Document what happens when the detector is uncertain or unavailable. A safe design should fail visibly and prevent an unreviewed request from silently bypassing the control.

06

Operational readiness after launch

HIPAA readiness is not finished when the integration passes a demo. Monitor access, model and feature changes, data retention, incidents, output quality, and use outside the approved purpose. Reassess whenever a vendor changes terms, the application adds a connector, or the workflow begins handling a new data source.

CompliantChatGPT offers a healthcare-oriented API path and PHI redaction capability. Confirm current service coverage, implementation requirements, BAA terms, and pricing directly before production use.

Primary sources

CompliantChatGPT API →OpenAI HIPAA-eligible products and functionality →Anthropic BAA coverage for commercial customers →HHS guidance on HIPAA and cloud computing →