The AI tool HIPAA compliance directory
Every entry answers three questions from the vendor's own documents: is there a BAA, on which tier, and does the tool train on your data. Sourced, dated, and updated as terms change.
How to Use This Directory
Every verdict below comes from the vendor's own trust center, privacy policy, or terms, with the source linked and the access date recorded in each tool's full entry. Where a vendor's documentation could not confirm a claim, the entry says UNVERIFIED instead of guessing.
Two patterns to watch as you read. A BAA does not mean the tool skips training on your data; some vendors offer both a BAA and a default right to train. And "HIPAA compliant" badges without published BAA terms are marketing until the paper exists.
| Tool | BAA | Tier required | Trains on your data | Verdict |
|---|---|---|---|---|
| ChatGPT | Yes | Enterprise / eligible API | Consumer tiers: yes by default | Enterprise tier only |
| Microsoft Copilot | Yes | M365 agreement scope | No | Yes, with tenant controls in place |
| Claude | Yes | Enterprise/API paths | Confirm per tier | Confirm per tier |
| Gemini | Yes | Workspace/Cloud paths | Confirm per tier | Confirm per tier |
| Otter.ai | Yes | Enterprise only | Yes by default below Enterprise | Enterprise only |
| Zoom AI Companion | Yes | All paid plans | No | Yes, strongest posture among meeting tools |
| Fireflies.ai | Yes | Enterprise + Private Storage | No by default | Both switches required, not one |
| Read AI | Yes | Enterprise+ annual, 5 seats | Off by default | Enterprise+ annual only |
| BastionGPT | Yes | All paid plans, no enterprise gate | No | Yes, and a cleaner BAA posture than most; certifications are inherited |
| Hathr.AI | Yes | Plan coverage not stated | No | Yes, confirm which plans the 24-hour BAA covers |
| CompliantChatGPT | Yes | All four plans, Starter upward | No | Yes, no third-party attestation claimed |
| Plaud | No: HIPAA Validation Report and Team-plan DPA only, no BAA (verified 2026-08-05) | n/a: no tier adds a BAA; Team adds a DPA | No (opt-in only) | Never for PHI |
| Freed | Yes (in ToS) | All plans | De-identified notes only | Cleanest BAA posture in this directory |
| Heidi Health | Yes | Tier unspecified | No | Yes, get the BAA attached to your plan |
| Retell AI | Yes | All plans | Yes by default (negotiate no-training) | BAA yes, read the training default |
| Krisp | Yes | Enterprise, 100+ seats | No | Enterprise only, 100-seat minimum |
| Adobe Acrobat AI Assistant | No: absent from Adobe's HIPAA-Ready list (May 2026) | n/a | No (moot for PHI) | Never for PHI |
| Google Vertex AI | Yes (Cloud BAA) | Product-enumerated | No | Match your workload to a named covered product |
| Blueprint | Yes (in ToS) | All plans | No | One of the cleanest postures in this directory |
| Nabla | Yes (ToS appendix) | All plans | De-identified use reserved | Mandatory BAA appendix |
| Doximity GPT | Member-level | Free (verified clinicians) | UNVERIFIED | Individual yes, organizational coverage needs enterprise BAA |
The Three Lessons the Table Teaches
What changes once you read past the BAA column
The training column matters more than the BAA column
Two tools in this directory sign BAAs while their terms permit model training on customer data by default. Read both columns before any PHI decision.
Tier gates put compliance out of reach quietly
Enterprise-only BAAs, seat minimums, and annual-plan requirements mean the version your staff downloaded is almost never the version the vendor's compliance page describes.
Your staff did not check this table
Every tool here was found in real healthcare workplaces. If the sanctioned answer does not exist yet, the unsanctioned usage already does. That is a governance decision, not a procurement one. See how HIPAA applies to AI tools.
Full Answers, Tool by Tool
Each entry below sources its verdict from the vendor's own trust center, privacy policy, or terms
Is ChatGPT HIPAA Compliant?
No consumer tier includes a BAA. The tier-by-tier reality and what a compliant deployment requires.
Read article → Compliance AnswerIs Copilot HIPAA Compliant?
Eight Microsoft products carry the name. Three sit inside the BAA, and the risk is tenant permission sprawl, not the model.
Read article → Compliance AnswerIs Microsoft Copilot HIPAA Compliant?
The personal-account product has no BAA. The work product does. Which name means which.
Read article → Compliance AnswerIs Claude HIPAA Compliant?
The BAA chain, path by path, and where a neutral answer beats the wrapper vendors selling their own take.
Read article → Compliance AnswerIs Gemini HIPAA Compliant?
The path-by-path answer, and the human-review risk that sits underneath the BAA question.
Read article → Compliance AnswerIs Zoom AI Companion HIPAA Compliant?
The strongest posture among meeting tools, with one feature-availability caveat for BAA accounts.
Read article → Compliance AnswerIs Fireflies.ai HIPAA Compliant?
Compliance requires two switches thrown together, the BAA and Private Storage. One without the other does not count.
Read article → Compliance AnswerIs Read AI HIPAA Compliant?
Yes, but only on Enterprise+ annual with five licenses, SAML SSO, and domain capture. The vendor warns ePHI must stay out of meeting titles.
Read article → Compliance AnswerIs Krisp HIPAA Compliant?
Yes, on Enterprise only, behind a 100-seat minimum. Below that there is no BAA path at all.
Read article → Compliance AnswerIs Otter.ai HIPAA Compliant?
HIPAA compliant only on Enterprise. Below that tier, the training default is the sharpest shadow AI exposure in this directory.
Read article → Compliance AnswerIs Plaud HIPAA Compliant?
No published BAA. Plaud publishes a HIPAA Validation Report and a Team-plan DPA. Neither is the contract HIPAA requires before PHI.
Read article → Compliance AnswerIs Freed HIPAA Compliant?
Yes. BAA in the Terms of Use on every plan including the trial, and Freed still trains on de-identified notes with no opt-out.
Read article → Compliance AnswerIs Blueprint HIPAA Compliant?
Compliant on all plans, BAA automatic in the Terms of Service, no training on client data. The published documentation stops short of group practices.
Read article → Compliance AnswerIs Nabla HIPAA Compliant?
Yes, with the BAA as a mandatory Terms of Service appendix on all plans. One clause reserves broad rights over de-identified patient data.
Read article → Compliance AnswerIs Heidi Health HIPAA Compliant?
Compliant, no training on your data. No vendor page names the tier with the BAA, so pin it to your order form.
Read article → Compliance AnswerIs Doximity GPT HIPAA Compliant?
Yes for the individual clinician, through a member-level BAA at registration. Organizational coverage needs the enterprise BAA. No page states the training policy.
Read article → Compliance AnswerIs Adobe Acrobat AI Assistant HIPAA Compliant?
No, on any tier. Acrobat AI Assistant is absent from Adobe's HIPAA-Ready Services list, and the button sits inside a tool IT already approved.
Read article → Compliance AnswerIs Google Vertex AI HIPAA Compliant?
Conditional. Google Cloud signs a self-serve BAA, but coverage is product-enumerated and Vertex AI by that name is not on the current list.
Read article → Compliance AnswerIs Retell AI HIPAA Compliant?
Yes, a free BAA on every plan, with a privacy policy that claims training rights by default.
Read article → Compliance AnswerIs BastionGPT HIPAA Compliant?
Yes, with a BAA on every paid plan, which is cleaner than most. Read the HITRUST and SOC 2 claims carefully; they are infrastructure-level.
Read article → Compliance AnswerIs Hathr.AI HIPAA Compliant?
Yes, with a 24-hour BAA on HHS-approved GovCloud. The FedRAMP High claim describes the hosting, not a Hathr authorization.
Read article → Compliance AnswerIs CompliantChatGPT HIPAA Compliant?
Yes, BAA on all four tiers including entry. It de-identifies before the model instead of covering the pipeline, which moves where the risk sits.
Read article → Regulatory GuideHIPAA & AI Compliance
How HIPAA applies to AI tools, what OCR expects, and how to achieve compliance without blocking innovation.
Read article → Platform GuideBest HIPAA-Compliant AI Platforms
How the governed-platform category compares to signing BAAs with individual point tools one at a time.
Read article →Directory FAQ
What is a BAA and why does every entry start with it?
A Business Associate Agreement is the HIPAA-required contract before any vendor handles PHI on your behalf. No BAA, no PHI, no exceptions. It is the binary gate; everything else in each entry is about what the BAA does not cover.
A tool says "HIPAA compliant" on its website. Is that enough?
No. HIPAA has no official certification. The claim is real only when the vendor will sign a BAA for your tier and their data-handling terms hold up. That is what each entry verifies.
How current is this directory?
Each full entry carries the date its sources were checked. Vendor terms change quarterly; treat any entry older than six months as a prompt to re-verify before contracting.
Our staff already use one of the "never for PHI" tools. Now what?
Assess what was exposed, then give staff a sanctioned alternative before removing the unsanctioned one. Bans without alternatives produce invisible usage rather than compliant usage.
Turn the Table Into Policy
The directory tells you which tools can be sanctioned. Your acceptable use policy is where that decision becomes enforceable. Generate a healthcare-ready draft in minutes.