التاليالدليل التالي
ChatGPT ونماذج اللغة الكبيرة
لغة الذكاء الاصطناعي
دليل المجتمع
Consumer ChatGPT, meaning the Free, Plus, Pro and other individual plans, is not suitable for protected health information under HIPAA, because OpenAI does not sign a business associate agreement (BAA) for those plans.
A HIPAA-covered organization can use an AI service with patient data only if the vendor signs a BAA and the service is set up to meet HIPAA's safeguards. OpenAI says it can offer BAAs for certain API and sales-managed business products after review, and several cloud AI services offer them too.
HIPAA applies to covered entities and their business associates. Covered entities are health plans, health care clearinghouses, and providers who conduct certain standard transactions electronically, such as billing. A business associate is a vendor that creates, receives, stores or transmits protected health information on a covered entity's behalf. Protected health information (PHI) is individually identifiable health information: anything linking a person to their health, their care or payment for it. Three rules matter most. The Privacy Rule limits how PHI can be used and disclosed. The Security Rule requires administrative, physical and technical safeguards for electronic PHI. The Breach Notification Rule requires notice when unsecured PHI is compromised. Before a covered entity shares PHI with a vendor, it needs a signed BAA in which the vendor agrees to protect the data and report incidents. So the honest answer to whether ChatGPT is HIPAA compliant is: it depends on which product, under what contract, configured how. Consumer ChatGPT plans come without a BAA, so clinicians and staff should never put PHI into them. OpenAI states that it can sign BAAs for some API and business customers after review. Large cloud platforms include certain AI model services in their HIPAA programs, and other AI vendors offer BAAs on business plans. Always check the vendor's current list of covered services, because coverage often excludes some features. Several misconceptions are common. There is no official government HIPAA certification, so a "HIPAA certified" badge is marketing. Turning off model training or deleting a chat does not create a BAA. Removing a name alone does not de-identify data. Under the Safe Harbor method, 18 kinds of identifiers must be removed, including dates more specific than the year and most geographic detail smaller than a state. The alternative is formal Expert Determination. Clinical free text often hides identifiers in dates, rare diagnoses or small-town references. Never paste names, dates of birth, medical record numbers, addresses, phone numbers, dates of service, full notes or identifiable images into an unapproved chatbot.
تعتمد الأضرار الكارثية واليومية التي يسببها الذكاء الاصطناعي على من يفهم المخاطر ومن يستطيع التصرف.
إن المعرفة العامة والمهنية تحدد ما إذا كانت سياسة السلامة القوية ممكنة من الناحية السياسية.
إن التفسيرات الواضحة تقلل من الاستيلاء على الضجيج والعلاقات العامة المعملية والمسرح الأخلاقي الغامض.
HHS proposed updates to the HIPAA Security Rule in early 2025, and organizations should check the rule's current status before relying on any particular requirement. AI vendors are adding health-specific offerings, and the list of services covered by BAAs changes often, so compliance teams need to re-check vendor documentation regularly. Staff using personal chatbots at work without approval remains a practical risk. Many organizations respond by offering an approved, BAA-covered tool so staff are not tempted to use personal accounts. Consumer health apps that fall outside HIPAA may instead be covered by FTC rules and state privacy laws.
A clinic manager pastes a patient's name, date of birth and diagnosis into a personal ChatGPT account to draft a referral letter. That discloses protected health information to a vendor without a BAA and is a potential HIPAA violation.
A hospital builds a discharge-summary drafting tool on a cloud AI service covered by its cloud provider's BAA, with access controls and logging configured. Set up that way, it can be a compliant arrangement.
A therapist asks a chatbot for general wording to explain sleep hygiene to anxious teenagers and includes no patient details. No protected health information is involved, so HIPAA is not implicated.
A patient pastes their own lab results into ChatGPT to get an explanation. HIPAA does not restrict what patients do with their own information, but the data is then governed by OpenAI's privacy terms, not by HIPAA.
التعامل مع المخاطر الوجودية باعتبارها خيالًا علميًا ومركبات القدرة.
الخلط بين سلامة المنتج السطحي والمحاذاة في ظل الاستقلالية العالية.
ترك الجماهير غير الإنجليزية وغير الخبراء مع مصادر منخفضة الجودة فقط.
فصل أضرار المنتج، وسوء الاستخدام، ومخاطر فقدان السيطرة/اختلال المحاذاة.
اسأل عن الأدلة التي من شأنها أن تغير وجهة نظرك بشأن الجداول الزمنية وشدتها.
تفضيل المصادر الأولية والتقييمات الملموسة على المطالبات التسويقية.
حدد مسار عمل واحد: المهنة، أو السياسة، أو التمويل، أو المهارات - وليس الوعي فقط.
Free newsletter
Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.
One email each weekday. Unsubscribe in one click. We never sell or share your address.
Test yourself
Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.
Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation
Consumer ChatGPT, meaning the Free, Plus, Pro and other individual plans, is not suitable for protected health information under HIPAA, because OpenAI does not sign a business associate agreement (BAA) for those plans. A HIPAA-covered organization can use an AI service with patient data only if the vendor signs a BAA and the service is set up to meet HIPAA's safeguards. OpenAI says it can offer BAAs for certain API and sales-managed business products after review, and several cloud AI services offer them too.
بدون اتفاقية BAA، لا يُسمح بمشاركة المعلومات الصحية المحمية (PHI) مع البائع للكيان المغطى، مهما كانت الميزات الأخرى للمنتج.
يتعامل شركاء العمل مع المعلومات الصحية المحمية للكيانات المشمولة ويجب عليهم التوقيع على اتفاقيات الأعمال. الخطة الصحية هي في حد ذاتها كيان مغطى.
HHS لا تصادق على المنتجات. يعتمد الامتثال على العقود والتكوين والممارسات.
يُلزم قانون HIPAA الكيانات المشمولة وشركاء الأعمال، وليس الأفراد الذين يتعاملون مع سجلاتهم الخاصة.
يسرد Safe Harbor 18 نوعًا من المعرفات التي يجب إزالتها. إزالة الاسم وحده لا يكفي.
استمر في التعلم
تم اختيار المزيد من الأدلة لهذا الموضوع
التاليالدليل التالي
ChatGPT ونماذج اللغة الكبيرة
لغة الذكاء الاصطناعي