This page provides an overview of OpenAI HIPAA eligible products and functionality. For details on the use and configuration of these products see the HIPAA Guide referenced in your BAA.
HIPAA Eligible Products
OpenAI makes the following HIPAA eligible products available with a Business Associates Agreement (BAA):
ChatGPT for Healthcare
ChatGPT for Enterprise with Regulated Workspace
ChatGPT FedRAMP
ChatGPT for Clinicians
API with Modified Retention
API FedRAMP with Modified Retention
ChatGPT functionality covered under BAA
HIPAA Eligible ChatGPT products include the following functionality that support HIPAA compliance and are covered by the OpenAI Business Associate and Healthcare Addendum (the “BAA”):
The functionality below is covered when it is used from an eligible ChatGPT workspace and is enabled for the member's role.
A feature’s availability does not, by itself, determine whether a particular use or connected third-party service is covered by your BAA.
Chat
Chat in Chat and Work
Files/Library
Search the web and Run deep research (See below for details)
Create and manage projects
Share projects
Share projects via workspace links
Browse and run workspace agents
Build workspace agents
Share workspace agents
Publish workspace agents
Create and manage GPTs
Publish GPTs to workspace
Publish GPTs externally
Allow all third party GPTs
Allow owner-approved GPTs only
Use Voice
Share screen and video in Voice
Reference Library files automatically
Use ChatGPT Record
Run code in Canvas and code blocks
Share chats and scheduled tasks in the workspace
Study Mode (Available in ChatGPT for Edu only)
Enable Trusted clinical search (Available ChatGPT for Healthcare only)
Chat extensions
Use ChatGPT for PowerPoint
Use ChatGPT for Excel and Sheets
Work
Locally on the ChatGPT desktop app
In the cloud on ChatGPT web, mobile, and desktop
Codex
Use Codex locally on the ChatGPT desktop app, IDE, or CLI (See below for details)
Discover and control devices remotely
Use Windows computer-use
Enable device code authentication for Codex CLI
Administer Codex
Workspace capabilities
Admin features
SSO
Compliance API
Use plugins, including apps and connectors available to the workspace
Create skills
Upload skills
Share skills
Publish skills to workspace
Use shared memory
Create personal access tokens
View workspace members and groups
Codex Local (Sign-in with ChatGPT)
Codex Local involves the installation of Codex Local Client on a local workstation. The HIPAA eligible local clients include CLI, IDE and Desktop App when signed in with a HIPAA eligible ChatGPT account. When the Codex Local Client transmits PHI to OpenAI for processing, OpenAI will protect the Customer PHI consistent with the BAA.
The OpenAI BAA does not apply to the execution of the Codex Local Client on Customer’s client machines or to any Third-Party Services accessed by the Codex Local Client due to Customer’s use or instructions. Customer is responsible for evaluating the Codex Local Client installation, its operating environment, and establishing a managed configuration that meets their requirements for use with PHI.
For more information on deploying Codex in your organization see the Admin rollout guide.
For Codex Local configuration options see Managed Configuration and the Codex HIPAA Implementation Guide.
Web Search & Deep Research
OpenAI configures HIPAA eligible ChatGPT workspaces to use OpenAI's search index. When users enable the Web Search or Deep Research tool or when the model retrieves information from the web, it uses information in OpenAI's index. OpenAI does not send queries to third-party search providers (e.g., Bing) when using a HIPAA eligible workspace.
ChatGPT functionality not covered under BAA
The functionality below is not covered under the BAA. PHI should not be entered when using this functionality. Features not listed here are not automatically covered under the BAA. Refer to the list above for covered features. Recently added functionality may not yet be listed on this page.
Chat
Share workspace agents with agent-owned connections
Allow internet access in Canvas and code blocks
Work
Allow browser use for Work in the cloud
Allow network access for Work in the cloud
Allow event-triggered scheduled tasks
Codex
Enable Computer History
Use Codex in the cloud
Administer Codex Security
Workspace capabilities
Use Sites
Use improved memory
Access to ChatGPT Functionality not covered under BAA
A customer may, in its sole discretion, enable access to additional ChatGPT functionality that is not covered under BAA. These additional features are disabled by default. Workplace administrators can enable access to these features through RBAC groups; see this article for more information on how to configure RBAC roles and groups. This access is intended only for uses that do not involve transmission, storage, or processing of PHI.
Improved memory
Improved memory can use context from a member’s past chats to keep its memory current. In ChatGPT for Healthcare and ChatGPT Enterprise with Regulated Workspace, improved memory is disabled by default.
Workspace owners and admins can enable Use improved memory for the default workspace role or eligible custom roles in Permissions & roles. Before enabling it, review which members will receive access and communicate the restriction below to those members.
This feature is not covered under your BAA. PHI should not be entered when using this feature.
For details about feature behavior, see: Memory FAQ. For role-based access settings, see: Role Based Access Controls for ChatGPT Enterprise.
Event-triggered scheduled tasks
Event-triggered scheduled tasks that respond to activity in connected apps are not covered under a Business Associate Agreement (BAA). This functionality is turned off by default in ChatGPT for Healthcare. Admins can enable Allow event-triggered scheduled tasks for eligible workspace roles. Do not use event-triggered tasks to transmit, store, or process protected health information (PHI).
For more information, see: Scheduled tasks in ChatGPT.
API Functionality covered under BAA
HIPAA eligibility for the OpenAI API is contingent on Customer’s account being provisioned with Modified Retention, unless otherwise specified by OpenAI. Once your org ID is provisioned with Modified Retention, the endpoints listed below can be used for processing PHI, even if data is retained, upon execution of the OpenAI BAA.
HIPAA-Eligible Endpoints
/v1/chat/completions
/v1/responses
/v1/assistants
/v1/threads
/v1/threads/messages
/v1/threads/runs
/v1/vector_stores
/v1/threads/runs/steps
/v1/images/generations
/v1/images/edits
/v1/images/variations
/v1/embeddings
/v1/audio/transcriptions
/v1/audio/translations
/v1/audio/speech
/v1/files
/v1/fine_tuning/jobs
/v1/batches
/v1/moderations
/v1/completions
/v1/realtime
Codex Local (API Key)
Use of Codex Local with a Customer-provided OpenAI API key for the OpenAI API Services will be covered by the BAA for data processed by OpenAI only if Customer has entered into a BAA with OpenAI that includes the API Services with Modified Retention as an Eligible Service. See the Codex Local (Sign-In with ChatGPT) section above for more information on BAA coverage and Customer Responsibilities.
