01 Aug Can Your Dental Practice Use ChatGPT Without Breaking HIPAA and PHIPA? A 2026 Compliance Guide
Somewhere in your practice right now, a team member may be pasting a patient’s chart note into ChatGPT to turn it into a polite recall message, or dropping a radiograph into an AI tool to ask “does this look like decay?” It feels harmless, even efficient. But the moment identifiable patient information enters a consumer AI tool, your practice has almost certainly made a disclosure of protected health information — and under both U.S. HIPAA and Ontario’s PHIPA, that disclosure can be a reportable privacy breach. The good news, updated for 2026, is that AI is not off-limits for dental practices. It just has to be used deliberately. Here is how to tell the safe path from the reportable one.
Why Pasting Patient Data Into ChatGPT Is a Disclosure
Protected health information is not just a Social Insurance Number or a full medical history. Under HIPAA, PHI is any health information tied to an identifier — a name, a date of birth, an address, a photo, or a treatment detail specific enough to single someone out. Ontario’s PHIPA uses a parallel concept, personal health information, and it is just as broad. A patient’s name beside a treatment note qualifies. So does an intraoral photo, a chart entry, or a panoramic radiograph, because imaging is identifiable health information about a specific person.
When a staff member types or uploads any of that into a public AI service, the data leaves your network and travels to a third-party company’s servers. In legal terms, you have disclosed PHI to an outside party. Whether that disclosure is permitted depends entirely on the contract you have — or, in most cases, do not have — with the AI vendor.

The Missing Piece: There Is No BAA on Consumer AI
HIPAA allows a covered entity like a dental practice to share PHI with a service provider only when a Business Associate Agreement (BAA) is in place. A BAA is a binding contract in which the vendor agrees to safeguard the data, restrict how it is used, report breaches, and accept liability. Without a signed BAA, sharing PHI with that vendor is a violation, full stop.
According to The HIPAA Journal’s 2026 analysis, generic ChatGPT services are not HIPAA compliant, because OpenAI will not sign a BAA for the Free, Plus, Team, or standard Enterprise consumer products. The same holds for the everyday consumer versions of Google Gemini and Microsoft Copilot’s free tiers. Sign in with a personal account, paste in a chart note, and there is no contract protecting that patient — and no lawful basis for the disclosure.
There is a second, quieter problem: training on your inputs. Consumer AI services may use what users type to improve their models unless the user has explicitly opted out or is on a paid tier with different data-use terms. That means a patient’s information could end up influencing a model that answers strangers’ questions. For a custodian of health records, that is precisely the loss of control the privacy laws exist to prevent.
Which AI Tiers Can Actually Be Covered
This is where 2026 is genuinely different from a couple of years ago. AI can be made compliant — on the right tier, with the right paperwork.
OpenAI’s API platform. OpenAI’s own help documentation confirms that any covered entity can request a BAA to process PHI through its API. You email the vendor with your company and use case, they review it case-by-case, and most requests are approved within a few business days. Software built on that covered API — including some dental practice-management and scribe products — can be used with PHI once the BAA is in place.
Sales-managed enterprise and healthcare tiers. OpenAI now offers a dedicated healthcare-oriented product and BAA-eligible enterprise accounts procured through its sales team. Microsoft and Google offer comparable HIPAA-eligible arrangements for their enterprise cloud and Copilot products under a signed agreement. The consistent thread: a BAA is available only on paid, contracted, business-grade tiers — never the free app your team already has open in a browser tab.

The PHIPA Angle for Ontario Practices
If your practice is in Ontario, HIPAA may not even apply to you — but PHIPA absolutely does, and the logic is the same. Under the Personal Health Information Protection Act, 2004, a dental practice is a health information custodian responsible for the personal health information it holds. Custodians must take reasonable steps to protect that information against unauthorized use or disclosure, and PHIPA requires notifying both the affected individual and Ontario’s Information and Privacy Commissioner when PHI is used or disclosed without authority, or stolen.
Feeding patient data into a consumer AI with no agreement and no control over how it is stored or reused is difficult to square with a custodian’s duty of reasonable safeguards. PHIPA does not name ChatGPT, but a regulator assessing a complaint will ask a simple question: did you retain control of the information, and could you account for where it went? With consumer AI, the honest answer is no.
The Real-World Cost of Getting It Wrong
The consequences are not theoretical. A disclosure without a BAA can trigger breach-notification obligations — letters to patients, a report to the regulator, and in serious cases financial penalties. But for a dental practice, the quieter damage is often worse: patient trust. Patients share sensitive information because they assume it stays between them and their care team. A local practice explaining why a patient’s records ended up in a public chatbot is a conversation no owner wants to have, and reputational harm in a community-based practice does not resolve with a form letter.

How to Let Your Team Use AI Safely
The goal is not to ban AI — it is to channel it. A few practical rules cover almost every situation:
- De-identify before you type. Strip names, dates of birth, contact details, and any specifics that could single out a patient. “Draft a friendly six-month recall reminder” is safe; the same request with a real patient attached is not. Remember that a radiograph or clinical photo is itself an identifier, so uploading images to a consumer tool is not de-identification.
- Use covered tiers for anything touching PHI. If AI genuinely needs real patient data — clinical documentation, an AI scribe, imaging assistance — run it only through a vendor that has signed a BAA (or, in Ontario, a written agreement meeting PHIPA’s safeguards) on an appropriate enterprise, healthcare, or API-based tier.
- Keep consumer AI to non-PHI work. Marketing copy, blog drafts, website FAQs, staff scheduling templates, policy wording, and general “how do I…” questions are perfectly fine on a standard account, because no patient is in the prompt.
- Turn off training where you can. On paid tiers, disable the option to use your inputs for model training as a baseline hygiene step.
- Write it down. A one-page AI usage policy — what tools are approved, what may never be entered, and who to ask — turns an invisible habit into a governed, defensible workflow, and gives you something concrete to point to if a regulator asks.

Where Compudent Systems Fits In
Compudent Systems works with dental practices across the GTA and Ontario, so we understand both sides of this: the clinical and administrative workflows your team is trying to speed up with AI, and the HIPAA and PHIPA obligations that govern the patient data behind them. We can help you inventory where AI is already being used in your practice, identify which tasks are safe on consumer tools and which require a covered tier, put a plain-language AI usage policy in front of your staff, and confirm the tools handling patient information are properly contracted and configured.
If you are not certain whether your team is quietly pasting patient details into public AI — or you want to adopt AI the right way before a mistake forces the conversation — that uncertainty is worth resolving now. Contact Compudent Systems to arrange an AI and privacy assessment for your practice.
Sources & further reading:
- The HIPAA Journal — Is ChatGPT HIPAA Compliant? Updated for 2026
- OpenAI Help Center — How can I get a Business Associate Agreement (BAA) with OpenAI for the API Services?
- Government of Ontario — Personal Health Information Protection Act, 2004 (PHIPA)