What counts
PHI is an identifier plus context.
PHI is health information that is individually identifiable — in practice, any of the eighteen Safe Harbor identifiers appearing together with health, treatment or payment context.
Two consequences people consistently get wrong.
Not legal advice. Compliance is a property of how a covered entity uses a tool, not an attribute the tool possesses. Your privacy officer and counsel own these determinations. Reviewer to be named
62-year-old male, admitted 3 March, MRN 4471102, presenting with…
Stripping the name is not de-identification. A date more specific than year, a medical record number, and an age. Still PHI. Invented data.
The eighteen Safe Harbor identifiers
- Names
- Geography below state
- Dates except year
- Phone
- Fax
- SSN
- Medical record number
- Health plan beneficiary number
- Account numbers
- Certificate & licence numbers
- Vehicle identifiers
- Device identifiers & serials
- URLs
- IP addresses
- Biometric identifiers
- Full-face photographs
- Any other unique code
Context is what makes an identifier PHI. A phone number in an email signature is not. The same number next to “discharge summary” is — which is why HIPAA severity fires only on co-occurrence with health context terms, and why that list is yours to edit.
The BAA question
Three things to confirm rather than assume.
A BAA makes a vendor a business associate and binds them to safeguard PHI. Without one, the provider is an unauthorised recipient and the submission is an impermissible disclosure — regardless of whether they train on it, retain it, or ever look at it.
Some providers will execute a BAA for specific enterprise or API offerings. Consumer tiers generally will not.
- 01
Is a BAA actually executed?
For the specific product and tier in use — not for the vendor in general.
- 02
Does it cover the interface your staff use?
Or only the API? These are frequently different agreements.
- 03
Are your staff using that tenant?
Or a personal account on the same site. This is the one that breaks in practice.
The second-disclosure trap
A monitoring tool can become the problem it was bought to solve.
There is an obvious trap here. A tool that inspects prompts by transmitting them to a vendor’s cloud has, for a covered entity, created a second PHI disclosure — to the security vendor. You would need a BAA with them too, and you have expanded the number of parties holding your patients’ data in the course of trying to protect it.
Itzal avoids this structurally. Detection runs on the endpoint, and what leaves is a redacted record: a type, a count, a confidence, a masked snippet, a destination, a risk score. The PHI never reaches Itzal’s servers, so there is nothing for a breach of those servers to expose.
If it has already happened
The categories are enough to run the assessment.
With a redact-then-report tool you will have the data categories and not the content — which is the point, and your assessment can proceed on categories.
- 01
Preserve what you know
Who, when, which tool, which account tier, approximately what categories.
- 02
Determine whether a BAA covered the destination
For that tier and that interface.
- 03
Run the four-factor risk assessment
Under the Breach Notification Rule.
- 04
Involve your privacy officer immediately
The determination is theirs, not the security team’s.
- 05
Ask the provider about deletion
Knowing that deletion from storage does not reverse a disclosure that has occurred.
Straight answers
Is ChatGPT HIPAA compliant?
The question is not well formed. Compliance is a property of how a covered entity uses a tool, not of the tool. Some providers will sign a BAA for specific enterprise or API offerings; consumer tiers generally will not. Without a BAA in place, submitting PHI is a disclosure to an unauthorised party.
Does removing the patient’s name make it safe?
Usually not. Safe Harbor de-identification requires removing all 18 identifier categories, which includes dates more specific than year, geography below state level, and any other unique identifying number. A name-stripped clinical note very often remains PHI.
Is a single paste a reportable breach?
It is an impermissible disclosure that triggers a risk assessment under the Breach Notification Rule. Whether notification is required depends on that assessment, and the determination belongs to your privacy officer and counsel.
Can staff use AI tools at all in a covered entity?
Yes, with a sanctioned tool under a BAA, a documented policy, and a technical control that stops PHI reaching anything else. Prohibition without a sanctioned alternative reliably produces unmonitored use on personal devices.