Security · Compliance

Security your compliance team can sign off on.

ChatGPT Clinician was built for clinical data from the first line of code. Here is how we protect the chat, the dictation, and the note.

  • Voice is never stored

    Dictation audio is processed in real time and discarded. The only things kept are the transcript and the notes you approve.

  • Encrypted end to end

    Data is encrypted in transit (TLS) and at rest. Your transcripts and notes are protected the whole way.

  • HIPAA compliant, BAA included

    ChatGPT Clinician is built for HIPAA-compliant use, and a signed Business Associate Agreement is included with paid plans rather than gated behind an enterprise tier. Self-serve trial usage is not represented as BAA-covered.

  • Least-privilege access

    Role-based access and authentication on every session. Only you reach your patients' data.

  • Never used for training

    We collect the minimum needed to draft your notes. We do not sell data, and patient content is never used to train AI models, ours or any third party's.

  • Audited infrastructure

    Runs on hardened cloud infrastructure with continuous monitoring and automated backups.

  • Logging & monitoring

    Access to clinical data is logged and monitored for anomalies, so nothing happens in the dark.

  • Incident response

    A documented incident response plan with breach notification aligned to HIPAA timelines.

Read the brief, then decide.