Is ChatGPT HIPAA compliant? Using AI tools with rider details in a NEMT office
Overview
Not on the plans most offices use. OpenAI signs a business associate agreement only for ChatGPT for Healthcare, ChatGPT Enterprise with a regulated workspace, ChatGPT FedRAMP, ChatGPT for Clinicians, and its API with modified retention. Free, Plus, Pro, and Business plans get none, so rider names, addresses, trip dates, and Medicaid IDs stay out of them unless every HIPAA identifier is removed first.
On this page
ChatGPT is not HIPAA compliant on the plans most small offices pay for. OpenAI signs a business associate agreement only for a short list of products set up for health care and other regulated work, and Free, Plus, Pro, and Business are not on it. Without that agreement, pasting a rider’s name, pickup address, or appointment date into the chat window hands protected health information to a vendor your company has no HIPAA contract with.
None of this means a NEMT office has to avoid AI. It means picking a tool that comes with an agreement for any work that touches riders, and stripping rider details out of everything else. Whether HIPAA covers your company at all is answered first in our HIPAA guide for NEMT providers. What AI does well in dispatch, booking, and billing is covered in AI in NEMT, and email raises the same agreement question, covered in is Gmail HIPAA compliant.
Which AI products come with a business associate agreement
OpenAI, Microsoft, and Google each offer an agreement for some AI products and not others. OpenAI’s help center lists six products eligible for its Business Associate and Healthcare Addendum, and says separately that it does not offer one for ChatGPT Business. Microsoft and Google cover their AI tools through the same agreement as their business email.
| Product | Agreement available | What it takes |
|---|---|---|
| ChatGPT Free, Plus, Pro | No | Individual plans are not on OpenAI’s eligible list |
| ChatGPT Business | No | OpenAI says it does not offer one for this plan |
| ChatGPT for Healthcare, or Enterprise with a regulated workspace | Yes | A sales-managed account arranged through OpenAI’s sales team |
| ChatGPT for Clinicians | Yes, for one person | Free, for verified US clinicians with an NPI |
| OpenAI API | Yes | Modified retention on the account, accepted in API settings or by email |
| Microsoft Copilot and Copilot Chat | Yes | Organization use under Microsoft’s Data Protection Addendum; web searches excluded |
| Gemini in Google Workspace | Yes | Workspace agreement accepted; not Gemini in Chrome |
A few details change what these rows mean in practice:
- ChatGPT for Healthcare launched on January 8, 2026. OpenAI says it offers data residency options, audit logs, customer-managed encryption keys, and an agreement, and that content shared with it is not used to train models.
- Even an eligible workspace has uncovered features. OpenAI lists functions outside its agreement, among them improved memory, event-triggered scheduled tasks, Codex in the cloud, and Sites. OpenAI says features outside the agreement are disabled by default, and rider details should never go into them if an administrator turns them on.
- The API agreement is now self-serve for organizations with an established history of API usage, accepted under organization settings. OpenAI warns that once HIPAA support is switched on for an organization, it cannot be switched off there.
- Microsoft now calls Microsoft 365 Copilot simply Microsoft Copilot. It says Copilot supports HIPAA compliance for properly configured implementations, but web search queries sent to Bing fall outside its data protection terms and its agreement.
- Google’s covered list, as of August 31, 2026, includes the Gemini app and Gemini in Workspace, but not Gemini in Chrome. Its implementation guide adds that the Gemini app turned on as an “Additional Product” is not covered either, so administrators should only enable it as a core Workspace service.
Turning off training is not the same as having an agreement
Turning off model training protects your data from one use. It does not satisfy HIPAA. OpenAI may train on conversations from its individual plans unless the user turns off “Improve the model for everyone” in data controls, and it does not train on ChatGPT Business, Enterprise, or API data by default. That is a privacy setting, not a contract.
HIPAA’s question is different: is a vendor creating, receiving, maintaining, or transmitting rider information for you? HHS’s cloud computing guidance says a company that has a cloud provider maintain its health information without a business associate agreement is violating the HIPAA rules, even if the provider never looks at the data. An AI chat service that stores your prompts and its answers fits that description. So a ChatGPT Business subscription, which OpenAI does not train on by default, is still the wrong place for a manifest, because no agreement is available for it.
What HHS expects when your office uses AI
HHS has said how the Security Rule applies to AI. In its January 6, 2025 proposal to update the rule, HHS wrote that health information in AI training data, prediction models, and algorithm data held by a regulated company is protected by HIPAA. It said it expects a company that uses AI tools to include them in its risk analysis, looking at the type and amount of health information the tool can reach, who receives that information, and who receives the output.
As of October 2026 the update is still a proposal; the Federal Register lists no final rule. But the risk analysis it describes is already required, and an AI tool is one more place rider information can go. Add every AI tool your staff use to the list in your HIPAA risk analysis, approved or not.
Broker contracts can add their own limits. Modivcare’s 2025 compliance attestation, for example, has providers certify that no one views, processes, or stores member health information outside the United States. Before any rider information goes into an AI tool, ask the vendor where it processes and stores data; the other questions worth asking an AI vendor are in AI in NEMT.
Stripping identifiers before anything goes into an AI chat
If a task does not need rider details, take them out first and use whatever tool you like. Under the safe harbor method in HIPAA’s de-identification rule (45 CFR 164.514(b)(2)), information counts as de-identified once 18 types of identifiers are gone, covering the rider and any relatives, employers, or people in the same household. The company also must not actually know of a way the rest could single the person out.
Trip data is full of these identifiers, several of them easy to miss:
- Places. Street addresses, cities, counties, and ZIP codes. Only the first three digits of a ZIP code may stay, and only when that three-digit area holds more than 20,000 people.
- Dates. Every part of a date tied to the rider except the year: pickup dates, appointment dates, admission and discharge dates, and birth dates. Ages over 89 may only appear as a single “90 or older” group.
- Numbers. Phone and fax numbers, email addresses, Social Security numbers, medical record numbers, health plan beneficiary numbers such as Medicaid IDs, account numbers, and license numbers.
- Anything else unique. Treat broker trip numbers and authorization numbers as covered by the catch-all for any other unique identifying number, characteristic, or code.
- Images and voices. Full-face photos and voice prints.
Here is an example with a made-up rider. A dispatcher wants help answering a complaint and starts with: “Rose Alvarez, Medicaid ID 9876543210, picked up 10/03 at 412 Pine St., Tampa, for dialysis at the kidney center on Fowler Avenue, says the driver came 40 minutes late.” Stripped, it becomes: “A rider says a pickup for a recurring treatment ran 40 minutes late. Draft a short apology and explain how we will prevent it.” The second version gets the same help and contains nothing that points to her.
The actual-knowledge test matters in a small town. If your service area has one rider who uses a stretcher and attends a particular clinic, describing those two facts may identify her even with every listed identifier gone.
A one-page AI rule for the office
Write the rule down and train on it, the same way you handle texting and email.
- Approved tools only. List the AI tools the company has an agreement for, and the uses allowed in each.
- No rider details anywhere else. Names, addresses, dates, phone numbers, Medicaid IDs, and trip numbers never go into an unapproved tool, personal accounts included.
- Work accounts only. Staff sign in to approved tools with company accounts, so access ends when they leave.
- Uncovered features stay off. Turn off every function the vendor lists outside its agreement for anyone who handles rider information, such as improved memory in an eligible OpenAI workspace or web search in Microsoft Copilot.
- A person checks every answer. AI drafts get read before they go to a rider, a facility, or a broker, and nobody sends an AI-written message about a specific rider’s trip without checking it against the record.
- AI tools go in the risk analysis. Review the list when you add a tool or change a plan.
- Slips get reported the same day. A pasted manifest is handled like a misdirected email: contain it, assess it, and notify if required.
Keep it with your other policies and procedures, and cover phishing messages written with AI in your cybersecurity training, since HHS’s proposal also names phishing built with generative AI as a threat to health information.
Using Ryder AI inside HealthRide
Ryder AI works inside HealthRide, so a dispatcher can ask about tomorrow’s trips without copying a manifest into a separate chatbot. It answers questions and also books, assigns, and cancels trips with your approval. HealthRide is HIPAA compliant, signs business associate agreements with its providers, and shows each person only what their role allows.
Frequently asked questions
- Is ChatGPT Plus HIPAA compliant if I turn off model training?
- No. Turning off "Improve the model for everyone" stops OpenAI from training on your new conversations. It creates no business associate agreement, which HIPAA demands of every vendor that stores or processes rider information for you. OpenAI does not offer that agreement for Plus or the other individual plans.
- Can a NEMT office use ChatGPT for Clinicians?
- Not for office staff. ChatGPT for Clinicians is free, but only for verified clinicians in the United States: physicians, nurse practitioners, physician assistants, and pharmacists, each confirmed through their NPI. Its agreement covers one person. OpenAI points organizations that need an agreement for several users to ChatGPT for Healthcare.
- Is Microsoft Copilot covered by Microsoft's HIPAA agreement?
- When it is used through your organization's Microsoft 365 account, yes. Microsoft lists Microsoft Copilot and Copilot Chat among the services covered by its HIPAA business associate agreement, which comes through its Data Protection Addendum. Microsoft also says web search queries Copilot sends to Bing are not covered, so rider details should never end up in a prompt that searches the web.
- Can I paste a rider complaint into an AI tool if I delete the name?
- Only if you remove much more than the name. HIPAA's safe harbor method lists 18 identifiers to strip, including street addresses, cities, ZIP codes in most cases, every part of a date except the year, phone numbers, and Medicaid or member ID numbers. Broker trip numbers count as unique identifying numbers too. If what remains could still point to one rider, it is not de-identified.
- Does using AI for marketing or policy writing need a business associate agreement?
- No, as long as no rider information goes in. Drafting a flyer, a job ad, or a section of your driver handbook involves no protected health information, so HIPAA does not require an agreement for that use. The risk starts when someone pastes in a manifest, a complaint, or an email thread to save time.
- Someone pasted a manifest into a free AI chatbot. What now?
- Handle it as a suspected breach. Delete the conversation, write down what was pasted and when, and run the four-factor assessment in 45 CFR 164.402. Unless that assessment shows a low probability the details were compromised, notice is due. For a broker's members, you report to the broker on the schedule your agreement sets. For riders you serve as a covered entity, each one gets a notice no later than 60 days after discovery.