Is Doximity GPT HIPAA Compliant?
Free, physician-verified, and covered for the individual, not the organization. The two are not the same question.
The Verdict: Is Doximity GPT HIPAA Compliant?
Is Doximity GPT HIPAA compliant? Unverified. Doximity attaches a BAA to every verified clinician at registration, but its BAA text does not name Doximity GPT among the covered tools.
No vendor page states whether prompts are used for model training. Individual coverage is real; organizational coverage needs the enterprise BAA.
Checked against Doximity's published BAA and product pages, 2026-07-12.
| BAA | Member-level at registration; enterprise BAA exists per support center (unverifiable by automated fetch) |
| Trains on your data | UNVERIFIED |
| Enterprise controls | Identity verification gate; SSO, audit, and retention UNVERIFIED |
| Sources | doximity.com/baa, blog.doximity.com GPT articles; support articles 403-blocked |
This is not legal advice, and your counsel makes the call for your organization.
The Catch
Doximity's own FAQ answers "Is Doximity Ask HIPAA compliant?" with an unqualified yes: "Users can securely include PHI in prompts, thanks to strict HIPAA-compliant protocols." That framing should give a compliance officer pause. HIPAA compliance is not a property a tool grants by assertion, it depends on whose BAA covers the disclosure and whether the clinician's employer authorized it.
A member-level BAA is real for the individual and useless for the organization, it does not add up to organizational compliance, visibility, or audit trails, and an employed clinician pasting PHI into a personal-membership tool may be making a disclosure their covered entity never sanctioned.
If Your Staff Use It
Likely your most widespread clinician AI tool because it is free and physician-verified. The org-level questions, training policy, enterprise BAA, logs, are exactly the ones only your organization can ask.
Free tools never generate an invoice, and an invoice is how most organizations find out a tool exists. Every verified clinician on your medical staff could be using this today with no purchase order, no vendor review, and a BAA your compliance team has never read. Clinician-owned AI accounts are the hardest category in this directory to count for exactly that reason, and a verdict on the vendor is not a headcount.
Doximity GPT and HIPAA: Common Questions
Does Doximity sign a BAA?
Unverified. Membership registration attaches a BAA to every verified clinician, but the published BAA text never names Doximity GPT among its covered tools. An enterprise BAA is described in support material we could not read.
Is this legal advice?
No. This is not legal advice, and your counsel makes the call for your organization.
Related Resources
Continue across the compliance directory and the core governance hubs
AI Tool HIPAA Compliance Directory
Every "is X HIPAA compliant" verdict in one sourced, dated directory
Read article →HIPAA & AI Compliance
How HIPAA applies to AI tools and what OCR expects in 2026
Read article →Healthcare Shadow AI Use Cases
Where shadow AI shows up across clinical and administrative workflows
Read article →Best HIPAA Compliant AI Platforms
An independent comparison of governed AI platforms for healthcare
Read article →The Policy Question Comes Before The Membership Question
Whether it is Doximity GPT or another clinician-membership tool, the first control is a policy your staff can follow. Generate a healthcare-ready draft in minutes, then decide which tools earn a place in it.