Medical and dental · Who's allowed to read it

Nobody signed anything

A consumer AI account is not a business associate. There is no agreement behind it, because there was never anything to sign. That one fact decides more about what your staff may do than any feature comparison.

We build software. We are not lawyers and this is not legal or compliance advice. Every rule quoted below is linked at the foot of the page so you can read it yourself, which is the only reason we are willing to quote any of it.

There is no approved list

People go looking for a government list of HIPAA-approved software and are surprised when there isn't one. There isn't one because the rule does not work by product. It works by function.

45 CFR 160.103 defines a business associate as a person who, on behalf of a covered entity, "creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter", and it lists examples — claims processing or administration, data analysis, processing or administration, utilization review, quality assurance, patient safety activities.

Nothing in that sentence is about software. A courier is a business associate under the right conditions. A model running in a data centre is one under the same conditions. What decides it is what the thing does with your patients' information, not what it is made of.

What the rule then requires, in one paragraph

45 CFR 164.502(e) says a covered entity may disclose protected health information to a business associate only if it obtains satisfactory assurances, in the form of a contract, that the associate will appropriately safeguard it. The Security Rule says the same thing about electronic PHI at 164.308(b)(1).

45 CFR 164.504(e)(2)(ii) says what that contract has to contain. The business associate must not use or further disclose the information other than as permitted by the contract or required by law; must use appropriate safeguards; must report any use or disclosure not provided for, including breaches; must bind its own subcontractors to the same restrictions; must return or destroy the information at termination where feasible; and the contract must let you terminate it on a material breach.

That is the whole apparatus. It is six promises and a termination clause.

Now the specific thing

Take the vendor we ourselves run on, because it is the one whose documentation we can quote without any incentive to shade it. Anthropic's own privacy documentation says its business associate agreement covers Claude Enterprise and the first-party API in HIPAA-ready configurations, and that it does not cover Claude Free, Pro or Max. It also names features excluded even inside a covered plan.

That is a clear, well-documented, entirely reasonable position. And it means the account most people in a practice would actually open — the free one, or the one they pay twenty dollars a month for themselves — has none of the six promises attached to it. Not because anyone refused. Because nobody was ever asked.

We wanted to quote the equivalent page from OpenAI in the same breath, and we could not. Both help.openai.com and openai.com returned HTTP 403 to this machine, twice. Summaries of that page were readily available and we have not used one — the previous post in this series is about an automated summary of a document getting every figure in it wrong. The URL is in the sources below. Read it yourself; we are not going to tell you what it says.

What the absence actually means, and what it doesn't

It does not mean the vendor is careless. Several of them will sign a business associate agreement on the right product and say so plainly on their own websites.

It does not mean anyone has broken a promise. There was no promise. That is the point of the phrase in the heading.

What it means is that the obligation is yours. The rule binds the covered entity. If a disclosure of protected health information happens to something that never gave satisfactory assurances, the party the rule is speaking to is the practice, not the model.

And here is the line that actually matters

If no protected health information goes in, none of the above applies.

A staff member asking a chatbot to tighten up the wording of a recall letter, with no patient anywhere in it, has put no patient information anywhere. The same staff member on the same afternoon, pasting in a chart note to "make this read better", plainly has — and whether that amounts to a disclosure the rule cares about is precisely the question your counsel exists to answer. Same tool, same person, same twenty minutes, two completely different questions.

The question is never "is this software allowed". It is "what did we put into it".

That distinction is where a written policy earns its keep, and it is also why buying a different product does not settle anything on its own. A tool with a signed agreement behind it still needs someone to have decided what goes in. A tool with nothing behind it is fine right up until the moment somebody pastes.

What we are not going to do

We are not going to tell you that your front desk using a consumer chatbot is a breach, and we are not going to quote you a penalty figure. We are not qualified to do the first and the second would be doing work that the argument should be doing on its own. If a claim needs a scary number to land, it was not a very good claim.

What to do

Take the list from the previous post and add two columns: does a business associate agreement exist, and does patient information go in. One sitting, one page, no software.

Most rows will be no and no. That is a fine answer and it is the most common one. The rows worth an hour of your time are the ones where the two columns disagree — and in our experience of this exercise, the surprising row is never the one people expect when they start.

It delegates cleanly. An office manager can fill the second column from what people actually do, and the first column is usually a search of the vendor's own site for the words "business associate". Ask for the filled-in grid back rather than a verdict on it; reading the grid is the part worth your own attention.

What skipping it costs is narrow and real. When somebody eventually asks which of your tools handle patient information — a payer, an insurer, a partner, an acquirer, your own new practice manager — the honest answer without the grid is a week of asking around. With it, the answer is an attachment.

Working out which product a given vendor agreement actually covers is genuinely fiddly, and it is a reasonable thing to want a hand with; that is work we do. The grid is worth building either way, and nothing about it requires us.

Sources

Want this running in your own practice? Let's talk.