Section 5.4 prohibits Customer from processing Protected Health Information through any OpenAI service unless a separate Healthcare Addendum and Business Associate Agreement has been signed, and further states that even with a Healthcare Addendum, certain OpenAI services are not designed for PHI processing and may not be used for that purpose.
This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision creates a direct HIPAA compliance obligation on Customer by prohibiting PHI processing through non-designated services, and requires execution of a separate Healthcare Addendum before any PHI workflows can be enabled, creating an operational prerequisite for healthcare sector deployments.
The agreement prohibits Customer from processing Protected Health Information through OpenAI services without a signed Healthcare Addendum, and states that some OpenAI services are not designed for PHI processing and cannot be used for that purpose regardless of any addendum. Healthcare and adjacent sector customers must execute the Healthcare Addendum before deploying any PHI-involving workflows.
Cross-platform context
See how other platforms handle HIPAA Prohibition Without Healthcare Addendum and similar clauses.
Compare across platforms →"Customer agrees not to use the Services to create, receive, maintain, transmit, or otherwise process Protected Health Information, unless it has signed the Healthcare Addendum. NOTWITHSTANDING THE FOREGOING, NOT ALL SERVICES OFFERED BY OPENAI ARE DESIGNED FOR PROCESSING PROTECTED HEALTH INFORMATION. IF CUSTOMER USES A SERVICE THAT IS NOT DESIGNED FOR PROCESSING PROTECTED HEALTH INFORMATION, CUSTOMER MAY NOT USE THE SERVICES TO STORE, TRANSMIT, OR PROCESS THIS INFORMATION.Excerpt from OpenAI's Business Terms
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision creates a direct HIPAA compliance obligation on Customer by prohibiting PHI processing through non-designated services, and requires execution of a separate Healthcare Addendum before any PHI workflows can be enabled, creating an operational prerequisite for healthcare sector deployments.
The agreement prohibits Customer from processing Protected Health Information through OpenAI services without a signed Healthcare Addendum, and states that some OpenAI services are not designed for PHI processing and cannot be used for that purpose regardless of any addendum. Healthcare and adjacent sector customers must execute the Healthcare Addendum before deploying any PHI-involving workflows.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.