OpenAI · OpenAI Business Terms · View original document ↗

HIPAA Prohibition Without Healthcare Addendum

High severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time OpenAI changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity OpenAI recorded 24 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for OpenAI Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

Section 5.4 prohibits Customer from processing Protected Health Information through any OpenAI service unless a separate Healthcare Addendum and Business Associate Agreement has been signed, and further states that even with a Healthcare Addendum, certain OpenAI services are not designed for PHI processing and may not be used for that purpose.

This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision creates a direct HIPAA compliance obligation on Customer by prohibiting PHI processing through non-designated services, and requires execution of a separate Healthcare Addendum before any PHI workflows can be enabled, creating an operational prerequisite for healthcare sector deployments.

Consumer impact (what this means for users)

The agreement prohibits Customer from processing Protected Health Information through OpenAI services without a signed Healthcare Addendum, and states that some OpenAI services are not designed for PHI processing and cannot be used for that purpose regardless of any addendum. Healthcare and adjacent sector customers must execute the Healthcare Addendum before deploying any PHI-involving workflows.

Cross-platform context

See how other platforms handle HIPAA Prohibition Without Healthcare Addendum and similar clauses.

Compare across platforms →

Monitoring

OpenAI has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Customer agrees not to use the Services to create, receive, maintain, transmit, or otherwise process Protected Health Information, unless it has signed the Healthcare Addendum. NOTWITHSTANDING THE FOREGOING, NOT ALL SERVICES OFFERED BY OPENAI ARE DESIGNED FOR PROCESSING PROTECTED HEALTH INFORMATION. IF CUSTOMER USES A SERVICE THAT IS NOT DESIGNED FOR PROCESSING PROTECTED HEALTH INFORMATION, CUSTOMER MAY NOT USE THE SERVICES TO STORE, TRANSMIT, OR PROCESS THIS INFORMATION.

Excerpt from OpenAI's Business Terms

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision directly engages HIPAA, enforced by HHS Office for Civil Rights. Under HIPAA, a covered entity or business associate that transmits PHI to a cloud service provider must have a Business Associate Agreement in place. The Healthcare Addendum serves as OpenAI's Business Associate Agreement mechanism. Failure to execute the Healthcare Addendum before processing PHI would constitute a HIPAA violation by the Customer and potentially by OpenAI as an unintended business associate. HHS OCR can impose civil monetary penalties for HIPAA violations. 2. GOVERNANCE EXPOSURE: High. Healthcare organizations, health plans, healthcare clearinghouses, and business associates of covered entities that use OpenAI APIs without a signed Healthcare Addendum face direct HIPAA exposure. The agreement's additional limitation that certain services are not designed for PHI even with the Healthcare Addendum means customers must confirm service eligibility before deployment. 3. JURISDICTION FLAGS: HIPAA applies to U.S.-based covered entities and their business associates. State health privacy laws, such as California's Confidentiality of Medical Information Act, may impose additional or broader obligations beyond HIPAA. International customers in the EEA processing health data are subject to GDPR Article 9 special category data requirements regardless of HIPAA applicability. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams in healthcare or adjacent sectors must confirm execution of the Healthcare Addendum as a prerequisite to any deployment. The agreement's statement that not all OpenAI services are designed for PHI processing means vendor assessments must include service-by-service PHI eligibility review, not just agreement-level BAA execution. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should conduct a mapping of all planned OpenAI API use cases to identify any PHI touchpoints. Healthcare Addendum execution and service eligibility confirmation should be documented prior to go-live. Ongoing monitoring of which OpenAI services are designated as PHI-eligible is warranted given OpenAI's right to update services periodically under Section 2.3.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • Hhs Ocr
    HHS Office for Civil Rights enforces HIPAA and has jurisdiction over PHI processing violations, which this provision directly addresses
    File a complaint →

Provision details

Document information
Document
OpenAI Business Terms
Entity
OpenAI
Document last updated
May 11, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-013683
Document ID
CA-D-00755
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
d94c426a41263f7d81583f26a9f1dc6ca88a070174a55e9238c4e7d25a8f6604
Analysis generated
July 9, 2026 03:44 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: OpenAI
Document: OpenAI Business Terms
Record ID: CA-P-013683
Captured: 2026-07-09 03:44:03 UTC
SHA-256: d94c426a41263f7d…
URL: https://conductatlas.com/platform/openai/openai-business-terms/provision/CA-P-013683/hipaa-prohibition-without-healthcare-addendum/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does OpenAI's HIPAA Prohibition Without Healthcare Addendum clause do?

This provision creates a direct HIPAA compliance obligation on Customer by prohibiting PHI processing through non-designated services, and requires execution of a separate Healthcare Addendum before any PHI workflows can be enabled, creating an operational prerequisite for healthcare sector deployments.

How does this clause affect you?

The agreement prohibits Customer from processing Protected Health Information through OpenAI services without a signed Healthcare Addendum, and states that some OpenAI services are not designed for PHI processing and cannot be used for that purpose regardless of any addendum. Healthcare and adjacent sector customers must execute the Healthcare Addendum before deploying any PHI-involving workflows.

Is ConductAtlas affiliated with OpenAI?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.