This came up more than once at our team onsite, and we wanted to talk about it: agencies using ChatGPT to help with coding are very likely creating a HIPAA violation every time they do it, often without realizing it's happening.
Here's why, and what responsible AI actually looks like instead.
What actually makes this a violation
HIPAA doesn't care how good your intentions are. It cares about two things: whether Protected Health Information is involved, and whether the tool handling it has a signed Business Associate Agreement in place. PHI is broader than most people assume. Under HHS's Privacy Rule, any of 18 specific identifiers, a name, a date of birth, a medical record number, becomes PHI the moment it's paired with health information. A first name next to a diagnosis is enough to cross that line. A patient's initials next to a functional status note is enough too.
The standard, free, Plus, and Team versions of ChatGPT, the ones most people actually have on their laptop or phone, don't come with a BAA. OpenAI has been clear about this: those consumer tiers use conversation data in ways that aren't HIPAA-eligible, and there's no version of "we use it carefully" that changes that. The moment a coder pastes chart details into a personal or standard ChatGPT account to get help with a diagnosis code, that's PHI sitting inside a tool with no contractual protection behind it, and that's a violation regardless of how the tool was used afterward.
Where it gets more nuanced
OpenAI does offer HIPAA-eligible options, ChatGPT Enterprise, ChatGPT for Healthcare, and certain API tiers configured with modified data retention, but only through a sales-managed process that most individual coders and clinicians never go through. And even when an organization has actually signed that BAA, it doesn't automatically make the whole workflow compliant. HIPAA operates on a shared responsibility model: the BAA covers the vendor's obligations, but access controls, staff training, and minimum-necessary-use practices are still the agency's job. A signed BAA with sloppy internal habits is still a real risk.
In practice, this means the honest answer for most agencies is simple. Unless your organization has specifically gone through enterprise procurement and signed a BAA with OpenAI, any coder or clinician typing patient information into ChatGPT, even the paid personal version, is creating exposure your agency probably doesn't know about yet.
Why this keeps happening anyway
Nobody's doing this to cut corners maliciously. Coding volume is real, ambiguous charts are real, and a fast, confident-sounding answer from a free AI tool feels like it's just saving time on a routine question. The problem is that pasting a chart excerpt into a general-purpose chat tool doesn't feel like "sharing patient data with a third party," even though that's exactly what it is. The convenience is real. The risk usually isn't visible until an audit or a breach investigation makes it visible the hard way.
The accuracy problem underneath the compliance problem
There's a second risk here that's easy to miss because it's less obvious than a HIPAA violation. A general-purpose AI chatbot, whether it's ChatGPT, Claude, or anything else built to answer broad questions, will hand back a diagnosis code with the same confident, polished tone whether that code is right or wrong. These tools are built to sound helpful and complete, not to flag their own uncertainty, so a coder asking "what's the code for this" gets a clean, specific-looking answer every time, even when the underlying reasoning doesn't actually hold up against the documentation.
There's no confidence score attached to that answer, no citation back to the source chart, and no second reviewer checking it against what the record actually supports. That's a different problem than the compliance issue, but it compounds it. An agency that's already exposed on the HIPAA side is also leaning on an answer from a tool that was never trained or validated specifically against home health coding rules in the first place. It's built to be broadly helpful across every subject, not to know the difference between a defensible code and one that just sounds plausible, and that gap between sounding right and being right is exactly the kind of thing that turns into a real problem months later.
What responsible AI in home health actually requires
A compliant AI tool starts with a signed BAA, full stop, not a general privacy policy or a reassuring line on a website. Beyond that, it means PHI staying inside systems built and contracted specifically to handle it, audit logging so you can show exactly what happened with a chart if you're ever asked, and a workflow that doesn't rely on individual staff members making judgment calls about what's safe to paste into a chat window. These are the same kinds of questions worth asking any AI vendor before they touch a patient chart, and HIPAA compliance sits right at the top of that list for good reason.
Make sure your agency is actually covered
We'd like to walk through your current AI usage and help you understand where your agency might be exposed, and what a genuinely compliant setup should look like instead.
HIPAA, compliance, PHI protection, responsible coding







