Skip to main content

Practice & Policy · 27 min read · Field Notes

How to Set Up AI in a Therapy Practice: HIPAA-Eligible Guide

2026-07-25 Matthew Sexton, LCSW, NATC All Field Notes

Quick answer Federal regulation at 45 CFR 164.502(e) only requires a business associate agreement when a vendor creates, receives, maintains, or transmits PHI on your behalf. Design your office in two lanes, a PHI lane and a no-PHI lane, and keep general-purpose AI in the no-PHI lane. Where AI does touch PHI, get the BAA and read the vendor's covered-services list, because every major vendor carves out named exclusions: Google excludes Gemini in Chrome and all third-party add-ons, OpenAI's documentation, as of an April 4, 2026 snapshot, excluded ChatGPT Business from BAA eligibility, and Anthropic excludes Console, Workbench, Cowork, and beta features while requiring 30-day retention. No certification exists that would substitute for any of this. — Matthew Sexton, LCSW, NATC

Matthew Sexton, LCSW, NATC — licensed clinical social worker in private practice. VibeCheck.luxury was built around the two-lane discipline described below.

Typographic banner reading $144,878,972 across 152 OCR settlements and civil money penalties, as of October 31, 2024, with the line "Not one turned on a vendor badge. None exists to buy."

As of October 31, 2024, the HHS Office for Civil Rights had settled or imposed a civil money penalty in 152 cases, for a total of $144,878,972 (OCR Enforcement Highlights, content last reviewed November 21, 2024). None of those resolutions turned on whether a practice had purchased a HIPAA certification, because there is no such credential to purchase. HHS says in its own FAQ that it "does not endorse or otherwise recognize private organizations' 'certifications'" regarding the Security Rule, and that such certifications "do not absolve covered entities of their legal obligations" (HHS OCR FAQ #2003). For a solo or small practice, the answerable question is which tasks in your office involve protected health information, and whether you can route AI at everything else.

Here is how to build that, in five steps you can finish in an afternoon.

Four things to hold onto. The legal trigger is PHI handling rather than software category. No HHS-approved certification exists, so a vendor badge tells you nothing. The riskiest AI-adjacent surface in most practices is the website. And you always owe yourself a written evaluation.

Step 1: How to set up AI in a therapy practice under HIPAA starts with the PHI line

Start with the regulation, because it is shorter and clearer than most of what has been written about it. 45 CFR 164.502(e)(1)(i) reads: "A covered entity may disclose protected health information to a business associate and may allow a business associate to create, receive, maintain, or transmit protected health information on its behalf, if the covered entity obtains satisfactory assurance that the business associate will appropriately safeguard the information." Paragraph (e)(2) adds that those assurances "must be documented through a written contract or other written agreement" meeting the requirements of § 164.504(e) (45 CFR 164.502, GPO authenticated text, 2024 edition).

Read that again with a pen. The rule turns on one condition. If a vendor handles PHI for you, the written agreement comes first. That leaves a small practice a large design lever. You get to decide how many of your vendors ever touch PHI at all.

So spend twenty minutes listing what you actually do in a week. Not the idealized version. Then sort every task into one of two lanes.

PHI lane. Session content. Progress notes. Treatment plans. Intake forms. Anything with a client name attached to the fact that they are a client. Appointment times tied to a person. Claims and billing records. Correspondence with a prescriber. Any recording or transcript of a session.

No-PHI lane. Your website copy. Blog drafts. Your fee schedule. Social posts. Superbill and consent-form templates. Your CE tracking. Insurance panel research. Policy language for your practice handbook. Vendor comparison spreadsheets. The email you have rewritten four times to a landlord. The de-identified clinical question you would ask a colleague at consultation, phrased exactly the way you would phrase it there.

For most solo practices the second list is longer than the first, and it is where the hours go. That is the useful news. A general-purpose AI assistant pointed only at the no-PHI lane is doing real work on real friction, and the BAA question never arises, because nothing meeting the definition of PHI ever leaves your hands. If you want a starting point for what to put in that lane, we keep a running list of the AI tools therapists in private practice are actually using.

Two cautions on the sorting, because this is where people get sloppy.

De-identification is a technical standard with a test attached. Stripping a first name out of a paragraph that still contains an occupation, a town, a diagnosis, and a referral source has not de-identified anything. If you would recognize the client from it, so would someone else.

And "just this once" is how the line erodes. The lane holds only if it holds on a Thursday at 7:40 p.m. when you are tired and the note is not written. Decide the rule now, while you are calm, and make the tool in front of you the one that matches the lane you are standing in.

Step 2: There is no certification, so stop shopping for one

Vendors know clinicians are nervous, and the market has responded with badges. Here is what the two most authoritative sources say.

HHS OCR, answering whether a covered entity must "certify" compliance with the Security Rule: "No, there is no standard or implementation specification that requires a covered entity to 'certify' compliance." The FAQ continues that HHS "does not endorse or otherwise recognize private organizations' 'certifications' regarding the Security Rule, and such certifications do not absolve covered entities of their legal obligations under the Security Rule" (HHS OCR FAQ #2003, content last reviewed July 26, 2013). That answer is old, and it has not changed.

Microsoft says the same thing in commercial language on its own compliance page: "There's currently no certification standard that the Department of Health and Human Services approves to demonstrate compliance with HIPAA or the HITECH Act by a business associate" (Microsoft Learn, article date July 29, 2025, updated June 2, 2026). Asked directly whether holding a BAA with Microsoft is enough to satisfy your obligations, Microsoft's answer begins with a flat no, then explains that the agreement supports your program while your organization remains responsible for adequate internal processes. That is a vendor telling you, in writing, that its own paperwork does not do the work for you.

This is also why the careful phrase is HIPAA-eligible rather than the confident-sounding alternative. A service can be eligible to handle PHI under an executed BAA. A practice can be meeting its obligations. Neither state is a certificate anybody issues, and OpenAI's own help center titles its coverage article "HIPAA Eligible Products and Functionality," which suggests the industry's lawyers landed in the same place.

Step 3: Read the vendor's covered-services list, line by line

Every major AI vendor will sign a BAA. Every one of them then excludes specific products from it. Those exclusions are the part practitioners get wrong, and they usually sit one click away from the page that says "we sign BAAs."

Where each vendor draws the line

Google Workspace. Google's HIPAA Included Functionality terms name the covered services precisely (one item elided here as irrelevant to a practice; the full list is at the link): "AppSheet, Apps Script, Cloud Identity Management, Gemini app (excluding Gemini in Chrome), Gemini Mac App, Gemini in Workspace, Gmail, Google Calendar, Google Chat, … Google Drive (including Google Docs, Google Forms, Google Sheets, Google Slides, and Google Vids), Google Groups, Google Keep, Google Meet, Google Sites, Google Tasks, Google Vault (if applicable) and Google Voice (managed users only)." Customers subject to HIPAA who want to use those services must enter a Business Associate Amendment with Google. And then the sentence that belongs taped to your monitor: "Third-party applications including add-ons are not included in the Included Functionality covered by the BAA" (Google HIPAA Included Functionality, effective May 14, 2026).

Sit with what that excludes. Gemini in Workspace is in, Gemini in Chrome is out, the scheduling add-on you installed from the Marketplace three years ago is out, and Google Voice is in for managed users only. If your mental model was "we're on Google, we signed the thing, we're covered," the document says otherwise in three separate places.

OpenAI. As captured in an Internet Archive snapshot dated April 4, 2026, OpenAI's help-center article on BAAs stated that using the API platform with PHI requires a BAA first, that requests go to a dedicated BAA email address with a stated one-to-two business day response, that most API services are covered with a short list of exceptions, and that an enterprise agreement is not required in order to sign a BAA for the API. The same snapshot stated that only ChatGPT Enterprise or Edu customers with a sales-managed account were eligible for a BAA for ChatGPT, and that OpenAI did not offer a BAA for ChatGPT Business (OpenAI Help Center, archived April 4, 2026). Treat that as a dated snapshot rather than today's policy. Vendor coverage terms change without announcement, so confirm current terms with OpenAI directly before you route anything.

The ChatGPT Business exclusion is worth naming anyway, because "Business" is exactly the tier a growing group practice would upgrade to on the assumption that the word means what it sounds like it means.

Anthropic. BAA coverage for Claude is opt-in, organization-scoped, and feature-scoped. A BAA is available for Claude Enterprise and the first-party API, and for Claude Enterprise the organization's Primary Owner has to activate HIPAA settings under "Data and privacy" and accept the agreement. A standard Enterprise plan is not covered until somebody performs that step. Excluded from coverage: "Workbench, Claude Console, Claude Cowork, or features currently in beta such as Claude in Office and Claude Design," plus the Batch API, Files API, Skills API, Code Execution, Computer Use, and Web Fetch, along with third-party data flows through MCP connectors, Enterprise Search, and Claude in Chrome (Anthropic Help Center, accessed July 25, 2026; the page exposes only a relative update timestamp, so the access date is the only reliable one).

One detail here reverses most clinicians' instincts. Covered models "require 30-day data retention and aren't available with zero data retention (ZDR) enabled." Everyone assumes zero retention is the safest possible setting. Under this BAA it is disallowed, because the covered configuration needs a window in which a security event can be investigated.

Governance runs on evidence. A system that keeps nothing also proves nothing, which is roughly why your clinical record exists at all.

— Matthew Sexton, LCSW, NATC

Microsoft. The BAA is available by default through the Microsoft Online Services Data Protection Addendum to customers who are covered entities or business associates, and Microsoft publishes an in-scope list rather than a blanket promise. The Office 365 Commercial table names Microsoft 365 Copilot and Microsoft 365 Copilot Chat alongside Exchange Online, Teams, OneDrive for Business, SharePoint Online, Forms, and Planner (Microsoft Learn).

The four vendors side by side

VendorBAA available forExplicitly excludedThe gotcha
Google Workspace (terms effective May 14, 2026)Gemini in Workspace, Gmail, Drive, Calendar, Chat, Meet, Sites, Tasks, Vault, and Google Voice for managed users onlyGemini in Chrome; third-party applications including add-onsSigning the Business Associate Amendment does not reach the Marketplace add-on somebody installed three years ago.
Microsoft (page updated June 2, 2026)Microsoft 365 Copilot and Microsoft 365 Copilot Chat, Exchange Online, Teams, OneDrive for Business, SharePoint Online, Forms, PlannerAnything absent from the published in-scope tableThe agreement arrives by default through the Data Protection Addendum, which makes coverage feel blanket. Microsoft says in writing that its own paperwork does not do the work for you.
OpenAI (as stated in an Internet Archive snapshot dated April 4, 2026 — confirm current terms)The API platform once a BAA is executed; ChatGPT for Enterprise or Edu customers with a sales-managed accountChatGPT Business, for which no BAA was offered"Business" is exactly the tier a growing group practice would upgrade to on the assumption that the word means what it sounds like.
Anthropic (accessed July 25, 2026)Claude Enterprise, once the Primary Owner activates HIPAA settings under "Data and privacy"; plus the first-party APIWorkbench, Claude Console, Claude Cowork, beta features such as Claude in Office and Claude Design; Batch API, Files API, Skills API, Code Execution, Computer Use, Web FetchCovered models require 30-day data retention and are not available with zero data retention enabled. The safest-sounding setting is the disallowed one.
Four-row comparison of AI vendor business associate agreement coverage: Google Workspace covers Gemini in Workspace, Gmail, Drive, Calendar, Chat, Meet and Vault but excludes Gemini in Chrome and all third-party applications including add-ons; Microsoft covers Microsoft 365 Copilot and Copilot Chat, Teams, Exchange, OneDrive and SharePoint, with anything absent from the published in-scope table left uncovered; OpenAI, per an Internet Archive snapshot dated April 4, 2026, covered most API services and ChatGPT for Enterprise or Edu customers with a sales-managed account while offering no agreement for ChatGPT Business; Anthropic covers Claude Enterprise once the Primary Owner activates it plus the first-party API, and excludes Workbench, Console, Cowork and beta features while disallowing zero data retention.

Sources: Google Included Functionality terms, effective May 14, 2026; Microsoft Learn, updated June 2, 2026; OpenAI Help Center read via an Internet Archive snapshot dated April 4, 2026; Anthropic Help Center, accessed July 25, 2026.

The pattern across all four

It is the same every time. The covered-services list is the contract. Ten minutes with the terms document tells you more than a week of roundups written by people who never opened it.

Step 4: Where AI does touch PHI, know what the agreement has to contain

If a task in your PHI lane genuinely needs AI, whether a scribe, a documentation assistant, or a tool wired into your record system, you are in the territory 45 CFR 164.504(e) governs, and the written agreement comes before the data. The paperwork is not the only question a scribe raises, either — there is also consent, and whose note it is.

The regulation sets the floor itself. Among other requirements, the contract must provide that the business associate will not use or disclose the information other than as permitted by the contract or required by law; will use appropriate safeguards and comply, where applicable, with subpart C for electronic PHI; will report to you any use or disclosure not provided for by the contract, including breaches of unsecured PHI under § 164.410; will ensure that any subcontractors handling PHI on its behalf agree to the same restrictions and conditions; and will, at termination, if feasible, return or destroy all PHI (45 CFR 164.504, GPO authenticated text, 2024 edition).

The subcontractor flow-down does quiet heavy lifting here, because AI vendors chain subprocessors in a way older software never did. Your scribe may sit on someone else's model, which sits on someone else's inference host, which sits on someone else's storage. The regulation says the chain carries the same restrictions all the way down. Ask for the chain.

For the vendor-facing version of this conversation, meaning the specific questions to send by email before anything gets signed and the answers that should end the conversation, we already wrote that list: the AI vendor BAA checklist. Lay out the office first, then use that checklist as your interrogation script.

Decide one more thing in advance rather than during a migration: what happens to your data when the vendor changes hands. Retention terms written under one owner get inherited by another, as in what a private-equity acquisition does to AI transcript retention.

Step 5: Fix the surface you forgot, which is your website

OCR has published guidance aimed squarely at the analytics code sitting on your practice website, and that guidance names therapy explicitly. Most clinicians have never read it, because the worry goes to the chatbot instead.

OCR's bulletin on online tracking technologies states: "The HIPAA Rules apply when the information that regulated entities collect through tracking technologies or disclose to tracking technology vendors includes protected health information (PHI)... Regulated entities are not permitted to use tracking technologies in a manner that would result in impermissible disclosures of PHI to tracking technology vendors or any other violations of the HIPAA Rules." Among the examples of sensitive information the bulletin lists are "diagnoses, frequency of visits to a therapist or other health care professionals, and where an individual seeks medical treatment" (HHS OCR, content last reviewed June 26, 2024).

A federal court did strike part of this guidance, and the confident versions circulating online get the scope wrong in both directions. On June 20, 2024, the U.S. District Court for the Northern District of Texas declared unlawful and vacated a portion of the bulletin in American Hospital Association v. Becerra, specifically the part providing that HIPAA obligations are triggered where an online technology connects an individual's IP address with a visit to an unauthenticated public webpage addressing specific health conditions or health care providers. OCR's page carries that notice at the top and states that HHS is evaluating its next steps.

The court struck the IP-address-on-a-public-page theory. The bulletin stands for everything else, and OCR still has it posted. Anyone telling you the tracking guidance is dead is reading a headline.

Practically, that means two moves. Inventory what is actually loading on your pages, including tags you added years ago and tags a web developer added without mentioning it. This is the same site you are otherwise tuning for local search in your area, which is why the tags accumulate. Then treat anything behind a login, such as a client portal or a scheduling page that already knows who the person is, with more care than a public page, because authenticated surfaces are where the vacatur gives you nothing. If a marketing or analytics vendor receives data from those surfaces, that vendor sits in the same conversation as your scribe.

What this buys you

Enforcement should be the last of your reasons for doing any of this. The same OCR page reporting 152 penalty or settlement resolutions also reports 15,561 cases where investigation found no violation, and 67,873 where OCR intervened early and provided technical assistance (OCR Enforcement Highlights, figures stated as current through October 31, 2024). Most OCR contact with a practice ends in technical assistance.

A governed office buys you the ability to answer a question without a knot in your stomach. When a client asks whether a machine sees their notes, you know the answer and it is specific. When you want to try a new tool on Tuesday, a rule you already wrote decides it, so you are not relitigating your own ethics at the end of a long day.

The certification question points at one more obligation. HHS's FAQ, having said no certification is required, sends covered entities to the evaluation standard at § 164.308(a)(8), which calls for a periodic technical and non-technical evaluation. Nobody hands you a certificate. You write the evaluation yourself, date it, and keep it. A single page listing your tools, the lane each one sits in, which have executed BAAs, what your website loads, and when you last checked is worth more than any vendor badge.

We built VibeCheck.luxury around this lane discipline, because the person doing the sorting is the same person holding the license. If you want to walk your own tool list through the two lanes with someone who does this paperwork, book a call.

FAQ

Do I need a BAA to use AI in my therapy practice?

Only where the AI vendor creates, receives, maintains, or transmits protected health information on your behalf. That is the trigger written into 45 CFR 164.502(e). If you route general-purpose AI at tasks containing no PHI, such as website copy, templates, fee research, and admin drafting, the requirement is not engaged. Where AI does touch client data, the written agreement comes before the data.

Is there such a thing as HIPAA certification for an AI tool?

No. HHS OCR states there is no standard or implementation specification requiring a covered entity to certify compliance, that HHS does not endorse or recognize private organizations' certifications regarding the Security Rule, and that such certifications do not absolve you of your legal obligations. Microsoft's own documentation agrees from the vendor side: there is currently no certification standard that HHS approves for demonstrating compliance with HIPAA or the HITECH Act.

Does signing a BAA with Google or Microsoft cover everything in my account?

No, and this is the most common expensive misreading. Google's HIPAA Included Functionality terms list the covered services explicitly, state that third-party applications including add-ons are not covered, and exclude Gemini in Chrome while including Gemini in Workspace. Microsoft publishes an in-scope table for the same reason. Read the list, then compare it against what your practice actually uses.

Can I use ChatGPT with client information?

As of an April 4, 2026 archived snapshot, OpenAI's help center said a BAA is available for the API platform, that BAA eligibility for ChatGPT itself was limited to Enterprise or Edu customers with a sales-managed account, and that no BAA was offered for ChatGPT Business. That snapshot is months old and vendor terms change, so confirm the current position with OpenAI before relying on it. The safer default is keeping PHI out of general-purpose chat tools.

Why would a BAA require data retention instead of zero retention?

Anthropic's BAA documentation states that covered models require 30-day data retention and are not available with zero data retention enabled. The reasoning is auditability: a covered configuration needs a window in which a security event can be investigated. Zero retention feels safer and produces less evidence.

Does the OCR online tracking guidance still apply to my practice website?

Mostly yes. On June 20, 2024, a federal court in the Northern District of Texas vacated one portion of the bulletin, the part treating an IP address plus a visit to an unauthenticated public webpage about a condition or provider as a trigger for HIPAA obligations. The rest of the bulletin stands, HHS states it is evaluating next steps, and authenticated pages such as client portals were never covered by that ruling.

Sources

  1. U.S. Government Publishing Office / GovInfo — Code of Federal Regulations, Title 45, § 164.502 (disclosures to business associates; written-contract documentation), 2024 annual edition, revised as of October 1, 2024. govinfo.gov
  2. U.S. Government Publishing Office / GovInfo — Code of Federal Regulations, Title 45, § 164.504 (implementation specifications for business associate contracts, including subcontractor flow-down and return-or-destroy at termination), 2024 annual edition, revised as of October 1, 2024. govinfo.gov
  3. HHS Office for Civil Rights — FAQ #2003: Are we required to "certify" our organization's compliance with the standards of the Security Rule?, content last reviewed July 26, 2013; read via Internet Archive snapshot captured July 1, 2026. hhs.gov
  4. Microsoft Learn — Health Insurance Portability and Accountability Act (HIPAA) & HITECH Act — Microsoft Compliance (no HHS-approved certification standard; BAA available by default; in-scope services including Microsoft 365 Copilot), article date July 29, 2025, updated June 2, 2026. learn.microsoft.com
  5. Google — HIPAA Included Functionality terms (covered services list; Gemini in Chrome excluded; third-party applications and add-ons not covered), effective May 14, 2026. workspace.google.com
  6. OpenAI Help Center — How can I get a Business Associate Agreement (BAA) with OpenAI for the API Services?, read via Internet Archive snapshot captured April 4, 2026; live page not retrievable to automated fetch. Companion article HIPAA Eligible Products and Functionality referenced by title only, accessed July 2026. help.openai.com · companion article
  7. Anthropic — Business Associate Agreements (BAA) for Commercial Customers (Enterprise activation by the Primary Owner; excluded products and features; 30-day retention requirement), accessed July 25, 2026; page exposes no absolute publication date. support.claude.com · mirror
  8. HHS Office for Civil Rights — Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates, content last reviewed June 26, 2024, including the court notice regarding Am. Hosp. Ass'n v. Becerra, No. 4:23-cv-1110 (N.D. Tex. June 20, 2024); read via Internet Archive snapshot captured July 9, 2026. hhs.gov
  9. HHS Office for Civil Rights — Enforcement Highlights (152 settlements or civil money penalties totaling $144,878,972; 15,561 no-violation findings; 67,873 technical-assistance interventions), figures stated as current through October 31, 2024, page content last reviewed November 21, 2024; read via Internet Archive snapshot captured May 19, 2026. hhs.gov

Sources current as of July 25, 2026. HHS.gov and OpenAI help-center pages were not retrievable to automated fetch during research and were read through Internet Archive snapshots, with capture dates recorded above. Vendor coverage terms change without notice — verify the covered-services list with each vendor before routing anything.

About the author

Matthew Sexton, LCSW, NATC, is a practicing psychotherapist in private practice. He built VibeCheck.luxury, a HIPAA-eligible clinical support tool, for his own caseload — by a clinician who does this paperwork, for the clinician who's tired of it. It is not an AI therapist and not a replacement for the clinician.

Disclaimer

This article is for educational and informational purposes only. It does not constitute medical, clinical, legal, or therapeutic advice, and reading it does not create a therapist-client relationship with Matthew Sexton, LCSW or Mental Wealth Solutions PLLC. Although the author is a licensed clinical social worker, the content in this article is not clinical assessment, diagnosis, or treatment.

HIPAA obligations, business associate agreement requirements, vendor coverage terms, and federal guidance vary by practice, by state, by the services a practice actually uses, and over time, and may change after this article is published. Nothing here is legal advice or a substitute for reviewing your specific setup with a healthcare attorney or a qualified privacy professional, or for confirming current terms directly with each vendor. Practices and circumstances differ, and what is described here may not match your situation.

If you are in immediate emotional crisis, you can reach the 988 Suicide & Crisis Lifeline by calling or texting 988 (US). If you are experiencing domestic violence or are in physical danger, contact the National Domestic Violence Hotline at 1-800-799-7233 or visit thehotline.org. In a life-threatening emergency, call 911.

Built by a clinician who does this work too.

See VibeCheck.luxury → See pricing — $77.77/mo per seat →