AI & compliance
Your staff are already using AI. You just can't see what they've typed into it.
Nobody asked permission. Someone had a long day, pasted a patient summary or a draft agreement into a free chatbot, and it worked — so they did it again. That's the single most common AI problem in a small business, and it doesn't show up on any dashboard.
The answer isn't to ban it. It's to give people a version that's covered by an agreement, and to close the door on the rest.
Book an AI exposure reviewWhat's actually at risk
Patient information
Pasting a chart, a claim or an appointment list into a tool with no BAA is a disclosure to a vendor you have no agreement with — which starts a breach assessment, not a conversation about productivity.
Privileged and client material
Draft pleadings, case facts and client emails pasted into a consumer chatbot are handed to a third party under terms that may permit training on them.
Customer and employee data
Names, addresses, payment details and HR records carry obligations of their own, whether or not you're in healthcare or law.
Your own trade secrets
Pricing models, bid sheets, vendor terms and customer lists leave the building the moment they're pasted in, and there's no getting them back.
Which AI tools can sign a BAA
A Business Associate Agreement is the contract that lets a vendor handle protected health information. Without one, the vendor isn't allowed to hold it and you aren't allowed to send it. Price tier decides this — not the model, and not how careful the person typing is being.
| Tool and tier | Can cover PHI | What it takes |
|---|---|---|
| ChatGPT Free, Plus, Pro, Team, self-serve Business | No | Not eligible for a BAA at any price. PHI here is a disclosure. |
| ChatGPT Enterprise or Edu (sales-managed) | Yes | BAA signed through OpenAI sales, on a managed account. |
| OpenAI API | Yes | BAA on request, and only on zero-data-retention endpoints. |
| Claude Free, Pro, Max, Cowork | No | No BAA option on any consumer tier. |
| Claude Enterprise | Yes | Covered only after the account owner switches HIPAA mode on and accepts the BAA. Easy step to miss. |
| Anthropic API | Yes | BAA on request, first-party API or via AWS Bedrock. |
| Gemini in paid Google Workspace | Yes | Under the Workspace BAA. Excludes Gemini in Chrome and browser extensions. |
| gemini.google.com (personal account) | No | Outside the Workspace agreement entirely. |
| Perplexity consumer, Pro, and API | No | Their own terms prohibit PHI without an executed BAA. |
| Perplexity Enterprise | Yes | Possible, but only with a BAA negotiated through enterprise sales. |
Read from the vendors' own documentation in September 2026. These terms change; we re-check them every quarter. This is a summary to help you ask the right questions, not legal advice — and no tool is “HIPAA compliant” by itself. The agreement plus your configuration is what makes it so.
Blocking it outright doesn't work
Block the websites and the work moves to personal phones, where you can't see it, can't log it and can't prove anything to an auditor. A ban with no sanctioned alternative doesn't remove the risk. It removes your view of it.
Give people something approved that's genuinely better than the workaround, and the workaround dies on its own.
What we put in place
Four things, usually inside a couple of weeks, and included in managed plans.
One sanctioned tool, properly papered
We pick a tool that can be covered for the work you actually do, get the agreement signed and the retention settings right, and give your staff a version that's better than the one they were sneaking.
A written policy that says what's allowed
Short enough to be read: what can go in, what can't, who to ask. Regulators and cyber insurers both expect this to exist, and most businesses don't have it yet.
Twenty minutes of training
Most exposure isn't malice, it's a receptionist trying to save time. People follow the rule once they understand what the tool does with what they type.
Controls on the network
Consumer AI endpoints blocked on managed devices, with logging that shows what's being used — so the policy is enforced rather than merely published.
What this should cost
Most quotes start with enterprise chat licences, and that's where the sticker shock comes from. It's also usually the wrong product for the job.
Sold by the seat
Enterprise chat plans
Priced per person per month, and the plans that can actually sign a BAA usually carry a minimum seat count and an annual commitment. That's how a forty-person clinic ends up quoted for a hundred and fifty seats — most of them for people who'd open it twice a week.
Billed by what you use
Tools built on the platform
The same models, reached directly and covered by the same kind of agreement, charged by the work done rather than by headcount. A report that takes a minute to generate costs cents. Nobody pays for a seat they don't open.
So the first question isn't which licence to buy. It's which of your work is a workflow to be built — quoting, reporting, intake, triage — and which genuinely needs a person typing into a chat window. The first is nearly all of the value and bills by the job. The second is usually a handful of people, not the whole company.
And before anyone buys anything: we check what you already own. If you're on a paid Microsoft or Google plan, some of this may already be covered by an agreement you signed years ago.
Then it starts earning
Compliance is the floor, not the point. Once there's a sanctioned tool your staff can use without anyone holding their breath, the same technology goes to work on quoting, scheduling, email triage and reporting — the repetitive load that eats your team's day.
Cutting headcount is a one-time discount. Cost cutting has a floor. Growth doesn't have a ceiling. That argument in full.
Find out what's already gone out the door
A short review: which AI tools are in use on your network, what your exposure looks like, and what it would take to make it defensible. No charge, and no obligation to hire us.
Book an AI exposure reviewOr call 323-213-9765.