HIPAA and AI: What You Can Safely Put Into ChatGPT, Claude, or Gemini (And What You Absolutely Cannot)

Posted by
on
July 23, 2026
in

*Editor’s note: This piece was reviewed by Dr. Heather Signorelli, DO, as physician-reviewed operational guidance. It is not medical, legal, or compliance advice, and NatRevMD does not endorse any specific AI vendor. Verify any workflow against your own HIPAA and payer obligations.*

Here is the scenario that keeps compliance officers up at night. A well-meaning biller is fighting a denial at 4:45 on a Friday, opens ChatGPT, and pastes the whole EOB in, patient name and member ID included, to ask why the claim bounced. It saves her ten minutes. It also may have just sent protected health information to a third party your practice has no agreement with. Nobody meant to do anything wrong. That is exactly how HIPAA problems happen.

AI is genuinely useful in a billing office. But the line between useful and reportable is a signed piece of paper and a habit of de-identifying. Let us make both of those concrete so your team can use these tools without flinching.

First, what actually counts as PHI

Protected health information is not just a diagnosis. Under HIPAA, PHI is health information tied to something that identifies a patient. The identifiers that trip up AI use most often are names, dates of birth, medical record numbers, health plan member IDs, addresses, phone and email, full dates of service, and account numbers. There are eighteen identifier categories in total, and the practical rule is simpler than memorizing them: if a stranger reading your prompt could figure out which human it is about, it is PHI.

The trap is thinking you need a full chart to cross the line. You do not. A name plus “denied for a colonoscopy” is PHI. A member ID by itself, tied to a claim, is PHI. Assume more counts than you think, and you will rarely be wrong.

The rule that governs everything: the BAA

HIPAA lets you share PHI with a vendor only when that vendor has signed a Business Associate Agreement, a contract in which they accept legal responsibility for protecting the data. This is the single fact that determines whether a given AI tool is safe for PHI.

The free, consumer versions of the major AI tools generally do not come with a BAA. That does not make them evil. It makes them the wrong container for patient data. Some vendors offer enterprise or business tiers that will sign a BAA and turn off training on your inputs, and those tiers are a different animal entirely. But, and this matters, the terms change, the tiers change their names, and a blog post from last quarter is not a compliance decision. If you are going to route PHI through any AI product, get the current BAA in writing and have someone qualified read it. Do not take our word, or anyone’s marketing, as the answer.

What you can safely put in, right now

The good news is that most of the value in a billing office does not require PHI at all. You can put all of this into a consumer AI tool today without a BAA:

  • Denial reason codes, CARC and RARC codes, with no patient attached.
  • Public payer policies, bulletins, and prior-authorization criteria.
  • CPT, HCPCS, and ICD-10 codes discussed in the abstract, not tied to a person.
  • Generic clinical scenarios: “a middle-aged patient with a chronic respiratory condition,” not a real one.
  • Your own SOPs, training material, phone scripts, and template letters with placeholders.
  • Aggregate, de-identified denial counts by reason code.

Nearly every prompt worth running fits in that list. The AI does not need to know the patient’s name to explain a denial code or draft an appeal skeleton. It needs the shape of the problem.

What you cannot put in without a BAA

Just as concrete, here is the “absolutely not” list for any consumer tool lacking a BAA:

  • Patient names, initials tied to a case, or nicknames.
  • Dates of birth, and full dates of service or admission.
  • Member IDs, subscriber IDs, MRNs, account numbers.
  • Full EOBs, claim forms, or chart notes pasted as-is.
  • Addresses, phone numbers, emails, anything that pins down the person.
  • Photos, documents, or screenshots that contain any of the above.

If a task seems to require one of these, the answer is almost never “paste it anyway.” The answer is de-identify first.

De-identification, the practical version

You do not need to be a lawyer to de-identify a billing task. You need a habit. Before you prompt, scrub the identifiers and replace them with neutral stand-ins. “John Smith, DOB 3/4/1968, member ID X” becomes “the patient.” “Denied 6/12/2025” becomes “denied recently.” “Aetna policy #12345 for Mr. Smith” becomes “Payer A’s policy for this service.”

The output comes back just as useful, and then you fill the real details back in yourself, inside your own secure systems, by hand. The AI drafted the letter. You, in your EHR or billing platform, personalized it. The PHI never left the building.

Screenshots deserve a special warning. It is easy to paste an image to save typing and forget that the corner of it shows a patient banner. Crop and check every image, or better, do not upload images of clinical or claims screens at all.

Build the guardrail into the workflow, not the person

Willpower is not a compliance program. The practices that use AI safely bake the rules into how work gets done: a short written AI-use policy, a de-identification step that is part of the standard operating procedure rather than an afterthought, a named tool the team is allowed to use, and a clear “when in doubt, do not paste it” default. Train it once, post it by the workstations, and revisit it when a vendor changes its terms.

When there is genuine uncertainty, err toward caution. The downside of de-identifying an extra field is a few seconds. The downside of a breach is a very different kind of afternoon.

We built a HIPAA-aware AI Kit for exactly this reason, with de-identified prompt templates and a simple use policy your team can adopt. It is the same discipline our own billers work under every day. If you want the guardrails and the prompts in one place, start there.

We apply this same HIPAA-safe discipline across our revenue cycle management services and our use of AI in medical billing.

Get the AI Kit → https://eligibility.natrevmd.com/natrevmd-ai-kit-tool

Related Posts