A practical rule for what belongs in a consumer AI tool, what requires a BAA, and what to do about staff already using AI on their phones.
Most of the AI-and-HIPAA questions I get from hospital executives boil down to one thing: someone on staff is already using a consumer AI tool, and leadership found out after the fact. The question is never really "should we allow AI." It is "what do we do about the fact that people are already doing this."
Protected health information is any individually identifiable health information handled by a covered entity or its business associate. That includes the obvious fields, like name and medical record number, and it includes anything that can be combined with other available information to re-identify a patient. A clinical note with the name stripped out is not automatically de-identified. If a date of service, a rare diagnosis, and a zip code are still in there, that can be enough to narrow a patient down to one person in a small community.
De-identification under HIPAA is a specific standard, not a vibe. It means either an expert determines the risk of re-identification is very small, or you strip a defined list of identifiers under the safe harbor method. Staff pasting a note into a chat window and deleting the name themselves is not de-identification. It is staff hoping.
A business associate agreement is the contract that lets a vendor touch PHI on a covered entity's behalf and assigns HIPAA obligations to that vendor. If a tool will not sign one, PHI does not go into that tool. That is the whole test. It does not matter how good the tool is, how senior the person using it is, or how obviously helpful the output would be. No BAA means no PHI, full stop.
Several AI vendors now offer a BAA on their enterprise or business tier. That is a necessary condition for using the tool with PHI. It is not sufficient on its own. You still need to read what the BAA actually covers, confirm which product tier it applies to, and confirm that the specific way your staff wants to use the tool falls inside that coverage.
The free or personal version of a chat tool and the enterprise version of the same product are different products from a compliance standpoint, even when the underlying model is similar. The consumer tier typically has no BAA available, and depending on account settings, conversations may be used to improve the model or retained for a period for abuse monitoring. The enterprise tier is where a BAA, admin controls, and contractual data handling terms usually live.
"Zero data retention" is a specific contractual commitment, not a feature toggle you found in a settings menu. It means the vendor has agreed, in writing, not to retain the input or output beyond what is needed to return the response, and not to use it for training. If you cannot point to that commitment in a signed agreement, do not assume it applies. A setting in a personal account that says "do not use my chats for training" is a privacy preference, not zero data retention, and it is not a substitute for a BAA.
The rule I give clients is short enough to fit on a badge card: if what you are about to paste could identify a specific patient, either directly or by combination with other details, it does not go into any tool that has not signed a BAA covering that use. If you are not sure whether it is de-identified, treat it as PHI. When in doubt, do not paste, ask first.
Assume it is already happening before you have a policy, because it usually is. The fastest way to reduce risk is not a memo threatening discipline. It is naming an approved tool with a BAA in place, making it as easy to reach as the unapproved one, and giving staff a short, specific example of what belongs in it and what does not. Pair that with a brief acknowledgment that this is about protecting patients and the organization, not about distrust of the people asking for help getting their work done.
If you want a second set of eyes on where your organization stands on this, that is the kind of conversation I have with hospital and health system leadership. See the contact page to set up a call.
This article is general information, not legal advice. Talk to your privacy officer or counsel about your specific situation.