01
A HIPAA API is an architecture decision
A healthcare application can use generative AI with ePHI only when every relevant service and data path is addressed. The API endpoint is one part of the system; authentication, application hosting, logs, databases, queues, monitoring, support, integrations, and downstream storage can all receive sensitive information.
Start by defining the intended workflow and drawing the complete data path before choosing a model or writing integration code.
02
Contractual coverage has to match the endpoint and configuration
Confirm that the API provider will sign an appropriate BAA and that the exact account, endpoint, model, retention configuration, and features are eligible. OpenAI currently ties HIPAA eligibility for its API to specified Modified Retention conditions. Anthropic uses a HIPAA-ready API organization with a published feature-coverage table.
A BAA with the model provider does not cover an application vendor's unrelated subprocessors. Maintain a complete list of every service that creates, receives, maintains, or transmits ePHI.
03
Put PHI controls before the model call
A purpose-built gateway can authenticate the caller, validate the permitted workflow, minimize input, detect or tokenize identifiers, enforce model and feature policy, and create appropriate audit evidence before a request reaches an LLM.
The response path needs equivalent controls. Restore tokens only inside the approved boundary, validate the output format, prevent unsafe disclosure, and require human review where the result affects a clinical or administrative decision.
04
What developers should record for each request path
A useful technical inventory includes more than an endpoint URL.
- Purpose, data classification, and permitted users.
- Input sources, PHI categories, files, audio, and metadata.
- Model provider, endpoint, model, feature flags, and region.
- Retention in the application, provider, logs, queues, caches, and backups.
- Subprocessors, external tools, web access, and connector destinations.
- Authentication, authorization, secrets, rate limits, and tenant isolation.
- Output validation, clinical review, export destinations, and incident ownership.
05
Redaction and tokenization need failure tests
Automated PHI handling should be tested against realistic notes, scanned referrals, abbreviations, misspellings, dates, record numbers, and mixed identifiers. Measure both missed identifiers and excessive removal that changes clinical meaning.
Document what happens when the detector is uncertain or unavailable. A safe design should fail visibly and prevent an unreviewed request from silently bypassing the control.
06
Operational readiness after launch
HIPAA readiness is not finished when the integration passes a demo. Monitor access, model and feature changes, data retention, incidents, output quality, and use outside the approved purpose. Reassess whenever a vendor changes terms, the application adds a connector, or the workflow begins handling a new data source.
CompliantChatGPT offers a healthcare-oriented API path and PHI redaction capability. Confirm current service coverage, implementation requirements, BAA terms, and pricing directly before production use.
Primary sources
CompliantChatGPT API →OpenAI HIPAA-eligible products and functionality →Anthropic BAA coverage for commercial customers →HHS guidance on HIPAA and cloud computing →