HIPAA compliant chatbot: what it takes and how to check
A chatbot is not HIPAA compliant by itself: HIPAA applies to covered entities (such as clinics that send insurance claims electronically) and their business associates, so what makes a chatbot usable under HIPAA is the clinic signing a business associate agreement (BAA) with the vendor, the vendor holding BAAs with every subcontractor that touches patient data (including the AI model provider), and the Security Rule safeguards being in place. There is no official HIPAA certification: HHS says it does not recognize private "certifications," and that a business associate cannot self-certify instead of signing a contract with the clinic.
This is general information, not legal advice: your compliance officer or lawyer should make the final call.
Is there such a thing as a "HIPAA certified" chatbot?
No. HHS answers this in two FAQs:
- On certification: "there is no standard or implementation specification that requires a covered entity to 'certify' compliance," and "HHS does not endorse or otherwise recognize private organizations' 'certifications' regarding the Security Rule" (HHS FAQ). HHS adds that a third-party certification "does not preclude HHS from subsequently finding a security violation."
- On vendors: asked whether a business associate can self-certify or be certified by a third party instead of signing a contract, HHS answers "No" (HHS FAQ).
Google Cloud agrees that "there is no certification recognized by the US HHS for HIPAA compliance," and Microsoft says using its services "doesn't on its own achieve HIPAA compliance." So a vendor's "HIPAA compliant" label is a claim about its own practices. It does not make your use of the tool compliant or replace a signed BAA.
Does HIPAA apply to your clinic?
HIPAA applies to covered entities: health plans, health care clearinghouses, and health care providers such as doctors, clinics and dentists, "but only if they transmit any information in an electronic form in connection with a transaction for which HHS has adopted a standard." The Privacy Rule summary says these transactions include claims, benefit eligibility inquiries and referral authorization requests, that this applies to every provider "regardless of size," and that using email alone does not make a provider a covered entity. An entity that is neither a covered entity nor a business associate "does not have to comply with the HIPAA Rules," though other laws may still apply.
What HIPAA protects is protected health information (PHI). The HHS summary of the Privacy Rule defines individually identifiable health information as information, including demographic data, that relates to a person's physical or mental health, "the provision of health care to the individual," or payment for it, and that identifies the person (or could reasonably be used to). Because the provision of care counts, a patient's name together with an appointment request can be PHI, even with no diagnosis in the message. HHS also notes there are no restrictions on de-identified information.
Outside the US, HIPAA does not apply, but health data is still protected. Under the EU GDPR, "data concerning health" is a special category (Article 9), and a processor must work under a contract (Article 28(3)); the UK ICO explains special category data and processor contracts. There, ask a chatbot vendor for a data processing agreement, not a BAA. Other countries have their own laws: check with your regulator or lawyer.
When is a chatbot vendor a business associate?
HHS defines a business associate as a person or organization that creates, receives, maintains or transmits PHI on behalf of a covered entity (HHS: Business Associates). Its list of examples now names this case directly: a "third-party vendor Artificial Intelligence (AI) chatbot on a provider's patient portal that provides services involving the patient's PHI such as symptom assessment, medical reminders, and appointment scheduling."
Three more HHS points decide most chatbot cases:
- Hosting counts. A software company that "hosts the software containing patient information on its own server" is a business associate (HHS FAQ). A chatbot that keeps conversation transcripts on the vendor's servers fits that description.
- Encryption does not exempt the vendor. HHS's cloud computing guidance says a cloud provider that stores ePHI is a business associate "even if the CSP processes or stores only encrypted ePHI and lacks an encryption key for the data."
- The "conduit" exception is narrow. It covers only transmission services, like the postal service and "their electronic equivalents," with at most temporary storage. HHS says "Entities that access PHI on a regular or frequent basis to perform a service on behalf of a covered entity are not conduits." By that test, a chatbot that reads and answers messages is not a conduit.
What must the BAA say?
According to HHS, the agreement must contain the elements at 45 CFR 164.504(e). In particular it must describe the permitted and required uses and disclosures of PHI, and provide that the vendor will not use or further disclose PHI except as the BAA permits or the law requires. Under the Security Rule, the BAA must also require the vendor to comply with the Security Rule, to have its own subcontractors sign BAAs, and to report security incidents, including breaches of unsecured PHI (HHS: Summary of the Security Rule). HHS publishes sample BAA provisions you can compare a vendor's contract against.
The chain matters. HHS says a business associate "must establish a BAA with its subcontractor before disclosing PHI to the subcontractor," and that all downstream subcontractors are also business associates. Your clinic does not need to sign directly with the vendor's subcontractors, but the chain has to be unbroken.
Which Security Rule safeguards matter for a chatbot?
The Security Rule is "flexible, scalable, and technology neutral," so it does not prescribe specific tools. It requires administrative, physical and technical safeguards, starting with a risk analysis that should include the chatbot. HHS has proposed changes; its summary covers the rule in effect. The standards below come from it; the questions are our suggestions.
| Security Rule standard (HHS summary) | What to ask about a chatbot |
|---|---|
| Risk analysis and risk management | Has the vendor shared enough about how it stores and processes messages for you to include it in your risk analysis? |
| Access control | Who at the vendor and at your clinic can read transcripts? Does each staff member have their own login? |
| Audit controls | Is there a log of who viewed or exported conversations? |
| Authentication | How does the system verify who is asking before it shows details of an appointment or record? |
| Transmission security | Are messages protected in transit between the patient, the vendor and the AI model? |
| Integrity | Can transcripts be altered or deleted without a trace? |
| Security incident procedures | How fast will the vendor tell you about an incident, and is that written into the BAA? |
| Contingency plan | Are conversations backed up, and what happens if the service goes down? |
| Business associate contracts | Is there a signed BAA with the vendor, and does the vendor have BAAs with its AI and hosting providers? |
The AI layer: does the model provider sign a BAA?
If a chatbot sends patient messages containing PHI to a large language model run by another company, the model provider is a subcontractor and needs a BAA with the chatbot vendor. Here is what each major provider's own page says (read September 24, 2026). Each limits coverage to specific services or settings, so ask the vendor which service, under which BAA, with which configuration.
| Provider | What its official page says | Conditions it states |
|---|---|---|
| OpenAI (API) | "To use our API platform with PHI, you'll first need a BAA with OpenAI." Requests go to baa@openai.com and are reviewed case by case (OpenAI Help Center). | API eligibility is "contingent on Customer's account being provisioned with Modified Retention" (HIPAA eligible products). OpenAI says it does not offer a BAA for ChatGPT Business. |
| Microsoft Azure (Azure OpenAI) | The HIPAA BAA is available "by default" through the Microsoft Product Terms to customers that are covered entities or business associates, for in-scope Azure services (Azure HIPAA). | The in-scope list is kept in a separate compliance document. Azure OpenAI is not named on the Microsoft HIPAA pages we read, so confirm it is on the in-scope list. |
| Google Cloud (Vertex AI) | "Google will enter into Business Associate Agreements with customers as necessary under HIPAA." Covered products include "Generative AI on Gemini Enterprise Agent Platform" (Google Cloud HIPAA), Google's current name for the platform "formerly Vertex AI" (product page). | Do not use products outside the covered list, or pre-GA offerings, with PHI unless expressly noted. |
| Anthropic (Claude API) | "Anthropic provides a BAA covering our HIPAA-ready services, such as use of our first-party API or Enterprise plans" (Anthropic Privacy Center). | For the API, the organization signs the BAA and then contacts Anthropic to turn it on. Not all API features are covered. Covered models require 30-day data retention and are not available with zero data retention. |
| AWS (Amazon Bedrock) | Amazon Bedrock is on the list of HIPAA eligible services (AWS, last updated September 3, 2026). | Covered entities and business associates agree not to use these services with PHI "without first entering into an AWS business associate agreement." |
AI tools your staff sign up for on their own are not covered by your chatbot vendor's BAA, and not every plan offers one: OpenAI says "we don't offer a BAA for ChatGPT Business."
SMS, web chat or WhatsApp: does the channel matter?
Yes: every company that stores or processes the messages for you is part of the chain.
- Web chat on your site or patient portal. HHS's own AI chatbot example is a chatbot on a patient portal: the chat vendor is a business associate if it handles PHI. HHS's online tracking guidance also says tracking technology vendors are business associates if they create, receive, maintain or transmit PHI on your behalf. HHS notes that a federal court vacated part of that guidance in June 2024.
- SMS. The texting or chatbot platform that stores and processes messages for you is a business associate under the same HHS definition, so it needs a BAA. The closest HHS guidance we found is about email: providers may communicate electronically with patients "provided they apply reasonable safeguards," and a patient warned of the risks of unencrypted email may choose to continue (HHS FAQ).
- WhatsApp. Meta's terms for the WhatsApp Business Platform (section 4.2) say "Meta is not a Business Associate or Subcontractor" under HIPAA "and that the WhatsApp Business Platform is not HIPAA compliant." Meta's Business Messaging Policy adds: "Don't use WhatsApp for telemedicine or to send or request any health related information, if applicable regulations prohibit distribution of such information to systems that do not meet heightened requirements to handle health related information." Any chatbot on WhatsApp inherits these limits, whatever the chatbot vendor signs. More detail in our WhatsApp for clinics guide.
When a chatbot is not the right choice
- Patients need to discuss clinical details. A secure patient portal from your EHR or practice-management vendor may be the simpler route, especially if that vendor already has a BAA with you.
- You want a person on every conversation. A medical answering service staffed by people is a reasonable alternative. If it handles PHI for you, it is a business associate too and needs a BAA.
- You only need hours, directions and "we'll call you back." An auto-reply, or a bot that answers general questions and never asks who the patient is, is simpler. PHI requires information that identifies the person; once a bot collects names or appointment details, you need the BAA.
- The vendor won't sign a BAA, or won't say which AI model it uses and under what agreement. For a covered entity handling PHI, that ends the evaluation.
Vendor checklist
- Will you sign a BAA with us, and can we review it against the HHS sample provisions?
- Which AI model provider processes our patients' messages, and do you have a BAA with it covering that exact service and configuration?
- Who else stores or processes our data (hosting, SMS carrier platform, analytics), and do they all have BAAs with you?
- Where are transcripts stored, for how long, and can we delete them?
- Are our patients' conversations used to train any model?
- How and how fast will you report a security incident or breach?
- What channel does the patient use, and does the channel's owner accept HIPAA obligations?
- What independent audit reports (for example SOC 2) can you share? Useful, but not a HIPAA certification.
What healthcare chatbot vendors say about HIPAA
What each vendor's own site says, read September 24, 2026. "Not stated" means we did not find it on the pages we read, not that the vendor refuses. Ask each vendor directly.
| Vendor | What it offers (its words) | What its site says about HIPAA and BAAs |
|---|---|---|
| Hyro | "HIPAA-compliant conversational AI, crafted for health systems" | "HIPAA-compliant" AI agents; its Responsible AI page lists "SOC II Compliant." BAA: not stated on the pages we read. |
| Luma Health | "Operational AI Platform" for health systems, hospitals and specialty practices | "All of Luma's software and company processes are fully HIPAA-compliant" (Security and Trust). Publishes its Business Associate Agreement (effective date March 1, 2015). |
| Artera | "AI Agents for Healthcare" automating calls, intake, scheduling and payments | Lists "SOC 2 Type 2," "HITRUST Certified" and "HIPAA Compliant," and says "We do not use identifiable PHI/PII to train our models." BAA: not stated on the page we read. |
| Weave | "All-in-one communication platform for small business," including an AI Receptionist | Publishes a Business Associate Addendum between Weave and its client as "Covered Entity" (last updated April 10, 2026). |
| Microsoft healthcare agent service | A cloud platform for healthcare organizations "to build and deploy compliant Generative AI healthcare copilots" | Described as "HIPAA-ready." Microsoft's HIPAA page lists "Microsoft Healthcare Bot Service" among services covered by its BAA; confirm the exact service name with Microsoft. |
| Intercom (Fin AI Agent) | "Intercom Helpdesk and Fin AI Agent" (general customer service, not healthcare-specific) | "Intercom and Fin hold SOC 2 Type II and HIPAA compliance." Its 2021 announcement says: "We can now enter into Business Associate Agreements with businesses in the healthcare industry." |
Disclosure: we make ClinicConvo. ClinicConvo answers a clinic's WhatsApp with AI, runs on WhatsApp (which Meta states is not HIPAA compliant) and does not claim HIPAA compliance, so it is not the right tool for a US covered entity that needs a BAA for patient messages; you can see it here.
Sources
- HHS. Are we required to "certify" our organization's compliance with the standards of the Security Rule?
- HHS. Can business associates self-certify or be certified by a third party?
- HHS. Covered Entities and Business Associates
- HHS. Summary of the HIPAA Privacy Rule
- HHS. Business Associates
- HHS. Is a software vendor a business associate of a covered entity?
- HHS. Guidance on HIPAA and Cloud Computing
- HHS. Sample Business Associate Agreement Provisions
- HHS. Summary of the HIPAA Security Rule
- HHS. Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates
- HHS. Does the HIPAA Privacy Rule permit health care providers to use e-mail to discuss health issues and treatment with their patients?
- EUR-Lex. General Data Protection Regulation (EU) 2016/679, Articles 9 and 28
- ICO. What is special category data? and What needs to be included in the contract?
- OpenAI. How can I get a Business Associate Agreement (BAA) with OpenAI for the API Services? and HIPAA eligible products and functionality
- Microsoft. HIPAA and HITECH Act and HIPAA: Azure Compliance
- Google Cloud. HIPAA Compliance on Google Cloud and Gemini Enterprise Agent Platform (formerly Vertex AI)
- Anthropic. Business Associate Agreements (BAA) for Commercial Customers
- AWS. HIPAA Eligible Services Reference
- Meta. Meta Terms for WhatsApp Business Platform (section 4.2) and WhatsApp Business Messaging Policy
- Vendor pages: Hyro, Hyro Responsible AI, Luma Health Security and Trust, Luma Health BAA, Artera, Weave, Weave BAA, Microsoft healthcare agent service, Intercom Security, Intercom HIPAA announcement (2021)