HIPAA compliant AI is one of the biggest questions we field from our legal and engineering clients, and for good reason. Lawyers handle privileged documents and client confidentiality every day, and some deal with medical records that fall under HIPAA. Engineering firms sign NDAs, MSAs, and contracts that often prohibit the use of consumer grade software with client data. In both cases, one concern comes up again and again: how do we make sure an AI tool does not train on our confidential information, and which plans are actually approved for regulated data?
At SFV Cloud, we help businesses across Ventura County, the San Fernando Valley, and the greater Los Angeles area answer exactly these questions. Below, we break down where ChatGPT, Gemini, and Claude stand on data training and HIPAA, and what the approval process looks like for each.
The Line That Matters Most: Consumer vs Business Plans
Before comparing providers, understand the single most important distinction. Consumer tiers are not built for confidential or regulated data, and business or enterprise tiers are. As one 2026 industry review put it, no mainstream free AI tool offers a Business Associate Agreement, and free tiers from all three major providers explicitly exclude BAA eligibility. If your team is pasting client information into a personal ChatGPT, Gemini, or Claude account, you are almost certainly operating outside any compliant framework, no matter how careful you are.
That is why the first thing we tell clients is simple. Never use consumer AI accounts for confidential client work. The right plan is what makes protection possible.
Does the AI Train on Your Data?
For engineering and legal clients bound by NDAs, the no-training question is often the deciding factor.
With OpenAI, business data is not used to train its models by default across ChatGPT Enterprise, Business, Edu, Healthcare, and the API. Consumer tiers are the exception and require you to opt out of training.
With Anthropic, the company does not train on commercial API or Enterprise data by default, and its privacy terms state that retained API data is never used for training without your explicit permission. On consumer plans, Anthropic introduced an opt-in toggle, so training is off unless a user turns it on, and opting in can extend data retention significantly.
With Google, the split is sharp. Consumer Gemini may use your conversations to improve Google’s public models and can be reviewed by humans, so Google openly warns against entering sensitive information. Inside Google Workspace with a proper license, submissions are not used to train models and are not human reviewed.
The takeaway for confidential work is consistent across all three. The business and enterprise tiers keep your data out of training. The consumer tiers do not offer the same protection.
HIPAA Compliant AI: Which Plans Support a BAA
HIPAA compliance requires a Business Associate Agreement, or BAA, a contract in which the vendor agrees to protect any protected health information you handle. Here is where each provider stands in 2026.
For a HIPAA compliant AI setup with OpenAI, a BAA is available for ChatGPT Enterprise, the purpose-built ChatGPT for Healthcare, and the API. It is not available for Free, Plus, or Business (formerly Team) plans, which cannot be used with protected health information.
With Anthropic, a BAA covers its HIPAA-ready Enterprise plans and the first-party API. It does not cover Free, Pro, Max, or Team plans, the Console and Workbench, or beta features. Using consumer Claude with patient data falls outside any compliant path.
With Google, a BAA covers Gemini inside Google Workspace on qualifying plans, and Gemini accessed through Vertex AI on Google Cloud. Consumer Gemini and the free AI Studio playground are not covered.
In short, every provider can support HIPAA compliant AI, but only on specific paid tiers with a signed BAA, and only after the environment is properly configured.
What the HIPAA Approval Process Looks Like
Each company has its own path to a signed BAA, and knowing the steps saves time.
OpenAI handles this through its sales and API teams. For API use, you email OpenAI’s BAA team with your company and use case, and they typically review and respond within a couple of business days. For ChatGPT Enterprise, you work with a sales-managed account to execute the BAA.
Anthropic offers a streamlined route for eligible Enterprise organizations. An administrator can enable HIPAA configuration directly in the organization settings under Data and Privacy, where the BAA is presented as a click-to-accept agreement, so there is no separate document to mail back. For API use, an admin signs the BAA and coordinates with Anthropic to enable a HIPAA-configured organization. Note that this is a one-way setting once enabled.
Google uses an administrator-driven process inside the Workspace Admin console. A super administrator reviews and electronically accepts the BAA under the account’s Legal and Compliance settings, which carries the same legal weight as a paper contract. For Google Cloud, the BAA covers Vertex AI within your cloud project.
A BAA Is Only Half the Job
Here is the point we stress most to clients. Signing a BAA does not make your use of AI automatically compliant. Every provider says the same thing: the BAA covers how they handle your data, but the rest is your responsibility. That includes access controls, audit logging, staff training, and enforcing what information employees are actually allowed to enter into a prompt. In practice, most compliance failures happen not with the vendor, but with a staff member using a personal account or pasting in far more sensitive data than a task requires.
This is exactly where a proactive, client-first MSP earns its keep. We help you select the right plan, execute the correct BAA, configure the security controls HIPAA requires, and train your team so confidential data never ends up somewhere it should not be. For engineering firms, we also help document that you are using approved, business grade tools rather than consumer software, which matters when your own client contracts demand it.
Frequently Asked Questions
Is any free AI tool HIPAA compliant?
No. As of 2026, the free and consumer tiers of ChatGPT, Gemini, and Claude do not offer a BAA and should never be used with protected health information or confidential client data.
Which plans stop the AI from training on my documents?
The business and enterprise tiers of all three providers keep your data out of model training by default. Consumer Gemini trains on your data, OpenAI consumer plans require you to opt out, and Claude consumer plans are opt-in for training.
Does a signed BAA mean my AI use is automatically compliant?
No. A BAA covers the vendor’s obligations only. Your organization still needs access controls, audit logs, staff training, and clear policies, which is where SFV Cloud helps.
Ready to Use AI Without Risking Your Confidential Data?
HIPAA compliant AI is achievable, but only with the right plan, the right contract, and the right configuration. If your law firm or engineering business in Ventura County, the San Fernando Valley, or the greater Los Angeles area wants to adopt AI safely without violating an NDA or exposing client data, SFV Cloud is here to help. Reach out today and let us build an AI setup that keeps you productive and protected.

