Read-Only and BAA-Backed Doesn't Automatically Mean HIPAA-Compliant
OpenAI's pitch rests on the connection being strictly read-only - ChatGPT can pull notes, labs, medications and specialist documentation out of Epic, but nothing writes back into the patient chart [1]. The enterprise package layers role-based access, single sign-on, audit logging and an optional Business Associate Agreement on top of that read-only boundary, which is how OpenAI frames the product as ready for HIPAA-governed use [1]. Karan Singhal, OpenAI's healthcare lead, personally posted the launch announcement, framing it as bringing ChatGPT closer to the systems, information and workflows healthcare teams already rely on; a separate account from inside OpenAI describes months spent pitching UCSF leadership before the feature - internally nicknamed 'ChartGPT' - actually shipped. Compliance-focused discussion elsewhere pushes back on how settled that picture really is: a BAA plus role-based access, SSO and audit logs establish the legal preconditions for compliant use, the argument goes, but don't by themselves answer what patient information ends up in a prompt, whether those chats and logs get retained, which vendors or subprocessors might touch that data, whether access genuinely reflects a user's actual role, or how a privacy incident involving the tool would even be detected.



