Skip to main content
Guide

Is ChatGPT HIPAA Compliant? A Marketing Data Verdict

Consumer ChatGPT has no BAA, so it is not HIPAA compliant for healthcare marketing data. What an analytics export really contains, and the fix.

11 min read

Consumer ChatGPT is not HIPAA compliant, and pasting your practice's marketing analytics into it is a disclosure you cannot take back. Even where a BAA can be signed through an enterprise or API arrangement, the workflow is the exposure: you are exporting a patient-shaped funnel to a tool that sits outside the place where the data was collected. Curve built Analyst so the question gets asked where the data already lives, under a BAA, with nothing leaving.

TL;DR

  • Consumer ChatGPT (Free and Plus) is not covered by a BAA, and conversations may be used for training unless you opt out. Opting out does not create a BAA.
  • A "harmless" analytics export usually carries page paths that name conditions, campaign names that name treatments, conversion events, and session data with timestamps, locations, and device identifiers. Together that is health information attached to identifiers.
  • "We anonymized it" rarely survives contact with a small practice's data, because the population is small enough to pick a person out of the rows you left in.
  • An enterprise or API BAA covers the vendor's handling of what you send. It does not cover the CSV on a laptop, the copy in a shared doc, or the fact that the data left at all.
  • The fix is to ask the question inside the system that already holds the data under a BAA. Curve Analyst does that: Claude through Amazon Bedrock, read-only, no export, no training on your data.

What is actually in a "harmless" analytics export?

The export you were about to paste is a table of people who visited a healthcare website, what they looked at, and whether they booked. It does not have a column called "diagnosis". It has something more useful to an attacker and more embarrassing in a breach notice: a column called "page path".

Take a standard weekly pull for a practice that treats a few specific conditions.

  • Page paths. A URL like /conditions/low-testosterone/book or /ketamine-therapy/pricing says what the visitor was researching. Nobody lands on the pricing page for a treatment by accident.
  • Campaign and UTM names. Marketers name campaigns after the thing being sold, so utm_campaign reads like a treatment menu. The ad group name often narrows it further to a city or an age bracket.
  • Conversion events. A goal called consult_booked on a page about a specific procedure is not a neutral count. It marks the moment a visitor became a prospective patient for that procedure.
  • Session data. Timestamps, city and region, device model, browser, referrer, and whatever client or user identifier the tool assigns. An IP address if you exported at the raw level.

Any one of those fields on its own might be defensible. Stacked in one row, they describe a person with a probable condition, in a known city, on a known device, at a known minute. HIPAA's identifier list is wider than name and date of birth. It reaches dates, geographic detail below the state level, device identifiers, IP addresses, URLs, and any other unique number that can point at a person. A client ID is a unique number that points at a person. That is its whole job.

This feels harmless because nobody in marketing reads a row as a patient. The regulator does not share that habit. If you want the longer version of the argument, read why you cannot paste a patient funnel into ChatGPT.

Why consumer ChatGPT fails the test

There are two problems with the Free and Plus tiers, and either one is enough.

No BAA

Under HIPAA, a vendor that handles PHI on a covered entity's behalf is a business associate and needs a signed BAA before it touches the data. Consumer ChatGPT is not covered by one. So the moment PHI lands in a consumer chat, you have disclosed it to a party that has no contractual obligation to safeguard it, report a breach to you, or limit how it is used. It does not matter whether you deleted the chat afterward or whether anyone at OpenAI ever looks at it.

The same applies to consumer Claude.ai on the Free and Pro plans, so this is a consumer-product problem rather than an OpenAI problem.

Training is the default

Consumer ChatGPT may use conversations to train models unless the user opts out. Most people on a marketing team have not opted out, and the ones who have cannot prove that the colleague who pasted the export last Tuesday had.

A quieter problem: the paste is a copy. Your analytics tool has retention settings, access controls, and an audit log. The chat window has a scrollback. Whoever shares that account, and whoever inherits that laptop, now has your funnel.

Does "we anonymized it first" hold up?

For a hospital system with enormous traffic, aggregating to the campaign level can genuinely blur individuals. For a dermatology clinic with two locations, it usually cannot, and the argument is worth walking through because your team will make it.

What most marketers mean by "anonymized" is that they deleted the email column. The client ID, IP address, timestamp, city, and page path are still there, because those are the columns that make the report useful. Those are also the columns that do the identifying.

The deeper issue is cell size. HIPAA recognizes formal de-identification methods, and both of them are built around the idea that a row should not be traceable back to a single person. A small practice's weekly export of one landing page, broken down by city and by hour, with a conversion flag, is a lineup rather than a crowd. If a competitor or an employer already knows that someone lives in that town and visited that afternoon, the "anonymous" row confirms the visit and names the treatment. Your compliance officer can tell you whether your export has been through either of them. It almost never has.

One more thing that catches cash-pay and direct-to-consumer clinics off guard. The FTC has pursued health-data disclosures to ad platforms (the Hims & Hers complaint, 2026) on unfairness grounds. That theory rests on consumers not expecting their health information to be shared with an outside party, and it does not depend on whether you are a HIPAA covered entity. Read the complaint with counsel before assuming your practice is outside the rules because it does not bill insurance.

What a BAA does and does not cover

OpenAI and Anthropic make BAAs available for certain API and enterprise arrangements. Confirm the current terms with the vendor, because plans and coverage change, and the marketing page is not the contract. Assume for a moment you have one signed. What did you actually get?

What it covers

A BAA binds the vendor. It commits them to safeguards, breach notification, permitted uses, and limits on further disclosure. It is a contract about their side of the fence. If you send PHI to any AI vendor, you need it.

What it does not cover

The export itself. The CSV sitting in Downloads, the copy someone attached to a Slack thread to ask a question, the version in a shared Drive folder called "reporting", and the paste into a personal login because the enterprise account was slow that day. A BAA with the AI vendor says nothing about any of those. Nor does it answer the minimum-necessary question, which is whether the marketing team needed to move the full row-level funnel out of the analytics system at all to answer "which campaign worked".

It also does not fix the upstream. If your analytics tool is Google Analytics 4, Google does not sign a BAA for it, and any AI feature inside GA4 inherits that status. The export was a problem before it reached ChatGPT. We have written about that separately in is Google Analytics 4 HIPAA compliant. The same logic applies to "chat with your data" products: most require your data to be loaded into their platform first, and whether a BAA exists varies by vendor and plan. Verify before you load anything.

So even in the best case, an enterprise BAA turns one exposure (an unprotected vendor) into several (every hop the data takes to reach the protected vendor). Exporting the funnel is the thing to stop doing. The tooling question is how to stop without giving up the answers.

The alternative: ask the question where the data already lives

The CSV you were going to paste was never the point. It was a proxy for a question: which channel is worth the money, where does the funnel leak, is anything new showing up, and what did the ad platform claim versus what actually booked. If the system that already holds the data can answer it, the export has no reason to exist.

That is what Curve Analyst is. It is an AI chat inside the Curve dashboard. You type a question, it queries your account's own data, and it answers with text plus charts: trends as line charts, ranked lists as tables, totals as stat cards, funnels as step charts. It runs on Claude through Amazon Bedrock, which is a HIPAA-eligible AWS service, inside infrastructure covered by Curve's BAA with AWS. Your data is not exported to a separate AI product and is not used to train models. Curve signs a BAA with every customer on every plan, so the chain from pixel to answer is covered end to end.

Because the data is already inside Curve, the collection side is handled too. Events go server-side to Curve's US-hosted infrastructure first, Curve strips what should not leave, and only then are conversions forwarded to Google Ads, Meta, TikTok, Microsoft, LinkedIn, and the rest. Analyst reads from that same store.

What it can answer

  • Website analytics: visitors, sessions, pageviews, bounce rate, top pages, sources and channels, UTM breakdowns, devices, browsers, locations, custom events, and realtime visitors. Referrals from AI assistants such as ChatGPT and Perplexity show up as their own rows in the sources report.
  • Goals and funnels: how many times each configured goal fired, period comparisons, and step-by-step drop-off.
  • Campaign reporting: spend, conversions, cost per acquisition, ROAS, revenue, clicks, impressions, and CTR by platform, campaign, or ad group, plus trends, automatically computed insights, and a reconciliation view showing what Curve sent to Google or Meta next to what the platform credited. When those differ, it is usually the platform's attribution window still being open rather than under-reporting, and Analyst says which number it is quoting.

What we deliberately left out

We built it to read and nothing else. It cannot change tracking or edit destinations, and it takes no actions in your account. It does not look up individuals and will not answer person-level questions, which is the line that keeps a marketing analytics tool from turning into a patient lookup tool. It keeps the date range and filters of the screen you opened it from.

It also has honesty rules that most dashboards lack. Every number comes from a query against your account. It never estimates. If a metric is empty it says so. If the data is stale, partial, a sample, or still syncing, it says so before the number. It treats "unknown" and "zero" as different things, which anyone who has explained a flat chart to a practice owner will appreciate.

It does not access session recordings or heatmaps, and it does not write SQL. Questions about tracking configuration or connector health are not covered yet; that is planned. If you want the full feature walkthrough, start with what is Curve Analyst. If the person you need to convince is the compliance officer, reports your compliance officer will sign off on is the piece to forward.

What to ask Curve Analyst

Open Analyst from the report you are already looking at, so it inherits the date range and filters, and type the question the way you would ask a colleague. These three replace the exports most teams were pasting into a chatbot.

  • "Which channel drove the most attributed conversions this month, and what did each one cost per acquisition?"
  • "Show me the consult booking funnel step by step. Where are we losing the most people compared with last month?"
  • "How much traffic came from AI assistants like ChatGPT and Perplexity this month, and did any of it convert?"

More examples and the launch details are in the Curve Analyst announcement.

Frequently asked questions

Is ChatGPT HIPAA compliant if I turn off training?

No. Opting out of training changes what happens to a conversation after it arrives. It does not create a BAA, and without a BAA the disclosure to an uncontracted vendor has already happened at the moment of the paste.

Is ChatGPT Enterprise or the OpenAI API HIPAA compliant?

OpenAI makes BAAs available for certain API and enterprise arrangements, so confirm current terms with them. A signed BAA covers the vendor's handling of the data. It does not cover the export on your laptop or the copy in a shared folder.

Can I paste aggregate totals, like conversions by month, into ChatGPT?

Totals with no identifiers attached are a much smaller risk than raw rows. In practice the export rarely stays that clean; the moment a campaign name, a page path, a city, or a date column comes along for context, you are back to information that describes people. The simplest policy that a compliance officer will sign off on is that marketing data does not leave the system that holds it.

Is Claude HIPAA compliant?

Consumer Claude.ai (Free and Pro) is not covered by a BAA, same as consumer ChatGPT. Anthropic makes BAAs available for certain API and enterprise arrangements; confirm with them. Curve Analyst uses Claude through Amazon Bedrock, inside Curve's BAA with AWS, which is a different arrangement from a consumer subscription.

Does Curve Analyst see patient records?

No. It reads the marketing analytics, goals, and campaign data already in your Curve account, it cannot look up individuals, and it cannot take actions.

If your team has been answering "what worked this month" by exporting a funnel to a chatbot, the fix is a demo away. Book a demo of Curve and ask Analyst the question yourself, inside the account, with nothing leaving.

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.

Book a free tracking audit