Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Section 5.4 prohibits Customer from processing Protected Health Information through any OpenAI service unless a separate Healthcare Addendum and Business Associate Agreement has been signed, and further states that even with a Healthcare Addendum, certain OpenAI services are not designed for PHI processing and may not be used for that purpose.
This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision creates a direct HIPAA compliance obligation on Customer by prohibiting PHI processing through non-designated services, and requires execution of a separate Healthcare Addendum before any PHI workflows can be enabled, creating an operational prerequisite for healthcare sector deployments.
The agreement prohibits Customer from processing Protected Health Information through OpenAI services without a signed Healthcare Addendum, and states that some OpenAI services are not designed for PHI processing and cannot be used for that purpose regardless of any addendum. Healthcare and adjacent sector customers must execute the Healthcare Addendum before deploying any PHI-involving workflows.
Cross-platform context
See how other platforms handle HIPAA Prohibition Without Healthcare Addendum and similar clauses.
Compare across platforms →Monitoring
OpenAI has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Customer agrees not to use the Services to create, receive, maintain, transmit, or otherwise process Protected Health Information, unless it has signed the Healthcare Addendum. NOTWITHSTANDING THE FOREGOING, NOT ALL SERVICES OFFERED BY OPENAI ARE DESIGNED FOR PROCESSING PROTECTED HEALTH INFORMATION. IF CUSTOMER USES A SERVICE THAT IS NOT DESIGNED FOR PROCESSING PROTECTED HEALTH INFORMATION, CUSTOMER MAY NOT USE THE SERVICES TO STORE, TRANSMIT, OR PROCESS THIS INFORMATION.Excerpt from OpenAI's Business Terms
1. REGULATORY LANDSCAPE: This provision directly engages HIPAA, enforced by HHS Office for Civil Rights. Under HIPAA, a covered entity or business associate that transmits PHI to a cloud service provider must have a Business Associate Agreement in place. The Healthcare Addendum serves as OpenAI's Business Associate Agreement mechanism. Failure to execute the Healthcare Addendum before processing PHI would constitute a HIPAA violation by the Customer and potentially by OpenAI as an unintended business associate. HHS OCR can impose civil monetary penalties for HIPAA violations. 2. GOVERNANCE EXPOSURE: High. Healthcare organizations, health plans, healthcare clearinghouses, and business associates of covered entities that use OpenAI APIs without a signed Healthcare Addendum face direct HIPAA exposure. The agreement's additional limitation that certain services are not designed for PHI even with the Healthcare Addendum means customers must confirm service eligibility before deployment. 3. JURISDICTION FLAGS: HIPAA applies to U.S.-based covered entities and their business associates. State health privacy laws, such as California's Confidentiality of Medical Information Act, may impose additional or broader obligations beyond HIPAA. International customers in the EEA processing health data are subject to GDPR Article 9 special category data requirements regardless of HIPAA applicability. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams in healthcare or adjacent sectors must confirm execution of the Healthcare Addendum as a prerequisite to any deployment. The agreement's statement that not all OpenAI services are designed for PHI processing means vendor assessments must include service-by-service PHI eligibility review, not just agreement-level BAA execution. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should conduct a mapping of all planned OpenAI API use cases to identify any PHI touchpoints. Healthcare Addendum execution and service eligibility confirmation should be documented prior to go-live. Ongoing monitoring of which OpenAI services are designated as PHI-eligible is warranted given OpenAI's right to update services periodically under Section 2.3.
This provision creates a direct HIPAA compliance obligation on Customer by prohibiting PHI processing through non-designated services, and requires execution of a separate Healthcare Addendum before any PHI workflows can be enabled, creating an operational prerequisite for healthcare sector deployments.
The agreement prohibits Customer from processing Protected Health Information through OpenAI services without a signed Healthcare Addendum, and states that some OpenAI services are not designed for PHI processing and cannot be used for that purpose regardless of any addendum. Healthcare and adjacent sector customers must execute the Healthcare Addendum before deploying any PHI-involving workflows.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.