OpenAI says AI products for healthcare sector to be compliant with US’ HIPAA requirements. Here’s why this is important

Artificial intelligence (AI) specialist and ChatGPT maker OpenAI on January 8 announced its “OpenAI for Healthcare” suite of products aimed at helping organizations “deliver more consistent, high-quality care to patients while supporting HIPAA compliance requirements.”
The products include two offerings: ChatGPT and OpenAI API for Healthcare. Notably, the company claims that both of its offerings are compliant with the United States Health Insurance Portability and Accountability Act (HIPAA) of 1996, which provides privacy and disclosure protections to patients.
“Advances in models have significantly improved AI’s ability to support real-world clinical and administrative work, such as helping clinicians personalize care using the latest evidence. OpenAI for Healthcare helps close this gap by providing organizations with a secure, enterprise-grade foundation for AI so teams can use the same tools to deliver better, more reliable care while supporting HIPAA compliance,” he said.
What is HIPAA? Why is it important?
According to the official website of the US Centers for Disease Control and Prevention (CDC), HIPAA establishes federal standards that prevent the disclosure of sensitive health information without the patient’s consent.
In addition, the law also covers health insurance coverage for workers, national standards for electronic health transactions, guidelines for pre-tax medical expense accounts, guidelines for group health plans, and governs company-owned life insurance policies.
It was stated that the HIPAA Privacy Rule and HIPAA Security Rule rules were published by the US Department of Health and Human Services (US HHS) to protect patient information in accordance with HIPAA requirements.
What are the exceptions to HIPAA compliance?
According to the US CDC, the law allows disclosure without a person’s consent in the following situations:
How does OpenAI ensure HIPAA compliance of its AI products?
OpenAI said in its announcement blog post that its products allow customers to access management and governance through a central workspace with role-based access controls and organization-wide user management. “This gives healthcare organizations the governance and visibility they need to deploy AI across clinical, administrative and research teams,” he said.
Additionally, in terms of data control and HIPAA compliance support, the company said patient data and PHI remain under an organization’s control “with data residency options, audit logs, customer-managed encryption keys, and a Business Associate Agreement (BAA) with OpenAI to support HIPAA-compliant use.”
“Content shared with ChatGPT for Healthcare is not used to train models,” he added.




