OpenAI claims to provide features that enable HIPAA compliance through its API services, but only under certain conditions.
The security & privacy section of the OpenAI website states that the company helps “customers meet regulatory, industry, and contractual requirements like HIPAA”; however, ChatGPT isn’t currently covered by OpenAI’s BAA.
According to OpenAI, only API services with “endpoints that are eligible for zero retention are covered” by its BAA. Customers do not have to be on an Enterprise plan to be eligible for OpenAI’s BAA.