Security · Compliance
Security your compliance team can sign off on.
ChatGPT Clinician was built for clinical data from the first line of code. Here is how we protect the chat, the dictation, and the note.
Voice is never stored
Dictation audio is processed in real time and discarded. The only things kept are the transcript and the notes you approve.
Encrypted end to end
Data is encrypted in transit (TLS) and at rest. Your transcripts and notes are protected the whole way.
HIPAA compliant, BAA included
ChatGPT Clinician is built for HIPAA-compliant use, and a signed Business Associate Agreement is included with paid plans rather than gated behind an enterprise tier. Self-serve trial usage is not represented as BAA-covered.
Least-privilege access
Role-based access and authentication on every session. Only you reach your patients' data.
Never used for training
We collect the minimum needed to draft your notes. We do not sell data, and patient content is never used to train AI models, ours or any third party's.
Audited infrastructure
Runs on hardened cloud infrastructure with continuous monitoring and automated backups.
Logging & monitoring
Access to clinical data is logged and monitored for anomalies, so nothing happens in the dark.
Incident response
A documented incident response plan with breach notification aligned to HIPAA timelines.