Compliance Answer

Is Doximity GPT HIPAA Compliant?

Free, physician-verified, and covered for the individual, not the organization. The two are not the same question.

The Verdict: Is Doximity GPT HIPAA Compliant?

Is Doximity GPT HIPAA compliant? Unverified. Doximity attaches a BAA to every verified clinician at registration, but its BAA text does not name Doximity GPT among the covered tools.

No vendor page states whether prompts are used for model training. Individual coverage is real; organizational coverage needs the enterprise BAA.

Checked against Doximity's published BAA and product pages, 2026-07-12.

Fact table (sources checked 2026-07-12)
BAAMember-level at registration; enterprise BAA exists per support center (unverifiable by automated fetch)
Trains on your dataUNVERIFIED
Enterprise controlsIdentity verification gate; SSO, audit, and retention UNVERIFIED
Sourcesdoximity.com/baa, blog.doximity.com GPT articles; support articles 403-blocked

This is not legal advice, and your counsel makes the call for your organization.

The Catch

Doximity's own FAQ answers "Is Doximity Ask HIPAA compliant?" with an unqualified yes: "Users can securely include PHI in prompts, thanks to strict HIPAA-compliant protocols." That framing should give a compliance officer pause. HIPAA compliance is not a property a tool grants by assertion, it depends on whose BAA covers the disclosure and whether the clinician's employer authorized it.

A member-level BAA is real for the individual and useless for the organization, it does not add up to organizational compliance, visibility, or audit trails, and an employed clinician pasting PHI into a personal-membership tool may be making a disclosure their covered entity never sanctioned.

If Your Staff Use It

Likely your most widespread clinician AI tool because it is free and physician-verified. The org-level questions, training policy, enterprise BAA, logs, are exactly the ones only your organization can ask.

Free tools never generate an invoice, and an invoice is how most organizations find out a tool exists. Every verified clinician on your medical staff could be using this today with no purchase order, no vendor review, and a BAA your compliance team has never read. Clinician-owned AI accounts are the hardest category in this directory to count for exactly that reason, and a verdict on the vendor is not a headcount.

Doximity GPT and HIPAA: Common Questions

Does Doximity sign a BAA?

Unverified. Membership registration attaches a BAA to every verified clinician, but the published BAA text never names Doximity GPT among its covered tools. An enterprise BAA is described in support material we could not read.

Is this legal advice?

No. This is not legal advice, and your counsel makes the call for your organization.

The Policy Question Comes Before The Membership Question

Whether it is Doximity GPT or another clinician-membership tool, the first control is a policy your staff can follow. Generate a healthcare-ready draft in minutes, then decide which tools earn a place in it.