What separates a HIPAA-safe ChatGPT prompt from a compliance landmine?
Three properties separate clinic-grade prompts from compliance landmines. **De-identification at the keyboard:** the eighteen HIPAA identifiers (name, MRN, DOB, address, phone, email, dates of service, and the rest of the 45 CFR 164.514 Safe Harbor list) never enter the prompt unless the endpoint is BAA-covered. **Scope discipline:** the prompt asks ChatGPT to draft, explain, or rewrite, not to diagnose, prescribe, or set firm policy. **Clinician read-back:** the dentist, hygienist, or office manager reviews every output before it reaches a patient, insurer, or regulator.
Per HHS OCR HIPAA AI guidance, a covered entity that routes PHI through a non-BAA AI vendor has executed an impermissible disclosure under the Privacy Rule. ChatGPT Enterprise and Team sign BAAs and disable training on submitted content; ChatGPT Free and Plus do not. The practical line: a solo GP on ChatGPT Plus should de-identify everything; a DSO-backed office on ChatGPT Enterprise with a signed BAA can use limited identifiers when clinical context requires it. When in doubt, strip identifiers.