Published June 22, 2026 · Updated September 18, 2026
The short answer: no — standard ChatGPT is not HIPAA compliant. HIPAA requires any vendor that processes protected health information (PHI) to sign a Business Associate Agreement (BAA), and OpenAI doesn't sign one for the consumer ChatGPT plans (Free, Plus, Pro, or Team). Pasting identifiable client information into them is a compliance violation regardless of whether anything ever leaks. BAAs exist only for a narrow set of OpenAI's enterprise products, and for everyone else, the practical rule is simpler: keep PHI out of the prompt entirely, and use AI on de-identified material with a privacy-focused setup. This guide covers both the compliance line and the day-to-day habits.
The Main Reason for Clinicians and Coaches: an AI Council That Cross-Checks the Answer You Rely On
Compliance is what sends most practitioners looking for a different tool. The AI Council is the reason to keep using one: you ask once, several top models answer the same question in parallel, and a referee model then compares their answers claim by claim and shows exactly where they contradict each other. The full panel is ChatGPT, Claude, Gemini and Grok: one from each company, each running its own live web search; a lighter two-model panel runs within the daily free quota and answers without search. For clinical and ethical questions that's the difference that matters. A single chatbot states a screening cut-off, a medication question or a reporting obligation with exactly the same fluent confidence whether it's right or wrong. Four models from four different companies splitting on it tells you, before you act on it, that this is the claim to take to a human: a supervisor for a practice question, the client's prescriber or a pharmacist for anything about medication, and the controlling law in your jurisdiction plus your regulator's or professional body's own guidance for a reporting duty. None of those is a question a panel of models can settle for you.
Two limits, up front. Agreement is evidence, not proof (models are trained on overlapping data and can be wrong together), and none of this is clinical, legal or compliance advice. None of it belongs anywhere near an urgent risk situation either: a client in crisis needs your own emergency protocol, not a panel of chatbots. And a council sends your question to every model on the panel, so it widens where your text travels rather than narrowing it: everything below about keeping identifiable client information out of the prompt applies with more force, not less.
The HIPAA Facts, Stated Precisely
- The BAA is the gate for a business associate. Where a vendor performs a function involving PHI on your behalf, HIPAA requires a signed Business Associate Agreement before you disclose. Not every disclosure creates that relationship — provider-to-provider treatment disclosures, disclosures a patient directs, and true conduits sit outside it — but a generative-AI tool processing your client material is the paradigm case that does. An impermissible disclosure is presumed to be a breach, subject to the four-factor risk assessment and the exceptions, rather than being automatically a reportable one in any subsequent breach.
- Consumer ChatGPT has no BAA — with one carve-out that probably is not you. OpenAI's HIPAA-eligible list covers ChatGPT for Healthcare, Enterprise with a Regulated Workspace, its FedRAMP offerings, and API with Modified Retention. Since April 2026 it also covers ChatGPT for Clinicians, which is free and offers verified individuals a self-serve BAA, but eligibility is limited to physicians (MD/DO), nurse practitioners, physician assistants and pharmacists. Psychologists, psychotherapists, licensed counsellors, clinical social workers, marriage and family therapists and coaches aren't on that list, so for this article's audience the answer is unchanged unless you also hold one of those four credentials. It remains true that no BAA attaches to the ordinary ChatGPT plans a solo practitioner would normally use. The same pattern holds across consumer Claude, Gemini, and Copilot.
- Know whether you are actually a covered entity. The test is narrower than "works in health care": covered entities are health plans, clearinghouses, and health-care providers (psychologists and other therapists included) who transmit health information electronically in connection with a HIPAA standard transaction. Many coaches fall outside it entirely, though a coach doing work for a covered entity can become a business associate. Outside HIPAA the statute may not bind you, but professional ethics, state privacy law, contracts and your clients' trust impose the same practical rule.
- De-identified information is not PHI — but "de-identified" is a legal standard, not a vibe. HIPAA recognises exactly two routes: Safe Harbor, which requires removing all 18 identifier categories for the individual and their relatives, employers and household members, with no actual knowledge that what remains could identify them; or Expert Determination, a documented finding by a qualified expert that the re-identification risk is very small. Deleting a name and a city doesn't meet either. Dates, record numbers, contact details, device identifiers, biometrics and photographs all count, and a distinctive clinical narrative can re-identify on its own. Treat redaction-first workflows (below) as risk reduction rather than as a legal safe harbour, which is why they're the sustainable way for practitioners to use AI at all.
Confidentiality isn't a feature of therapy and coaching; it's the foundation the work stands on. A client opens up only because they trust that what they say stays between the two of you. That trust is exactly why AI sits in an awkward spot for practitioners. A model could draft progress notes, tidy a session summary, or help you prepare psychoeducation handouts in a fraction of the usual time. But the raw material of that work (a client's struggles, diagnoses, relationships, fears) is among the most sensitive information a person ever shares.
Here's the plain truth up front: putting client material into any cloud AI tool involves risk, and no product can honestly claim to erase it; this one included. What a privacy-minded setup can do is make the work safer than typing notes into a default consumer chatbot. The decision about what is appropriate to share, and the duty to protect the person who confided in you, stay with you. Below is where the real risk comes from, what "safer" genuinely offers, and the habits that keep your clients protected.
This is general information, not legal, clinical, or ethics advice. Follow your licensing board's rules, your professional code of ethics, and — where it applies to you — your obligations for protected health information. When in doubt, check with your supervisor or professional body.
Psychotherapy Notes Are a Separate Category, and They Are the Ones You Are Tempted to Paste
HIPAA singles out psychotherapy notes for stronger protection than the rest of the record, and any article written for therapists that skips this is missing the part that bites hardest.
The term is narrow and specific: notes recording or analysing the contents of a counselling session, kept separately from the rest of the file. It excludes what most people think of as the clinical record — diagnosis, treatment plan, medication, symptoms, prognosis, progress to date, session times and frequency. Those are ordinary PHI.
What makes the distinction matter here's the consent rule. Psychotherapy notes generally require the client's specific authorisation to disclose — even to another treating provider, and even in situations where ordinary PHI could be shared without it. A general consent to treatment doesn't cover them, and neither does a BAA: a BAA lets a vendor process PHI on your behalf, it doesn't supply an authorisation you never obtained.
So the material most likely to be dropped into a chatbot ("help me make sense of what came up in today's session") is precisely the material HIPAA guards most closely. If you're going to use AI anywhere in this work, this is the category to keep out of it.
Why Therapy and Coaching Notes Are at the Far End of Sensitive
Mental-health and personal-development records aren't ordinary documents. They can contain diagnoses, medication details, trauma histories, family conflicts, and disclosures a client might never repeat to anyone else. If that material surfaced where it shouldn't, the harm is rarely abstract; it can affect a client's job, relationships, custody arrangements, insurance, or sense of safety. The vulnerability is the whole point of the relationship, and it raises the stakes of any tool you let near it.
When notes go into a typical consumer chatbot, a few realities usually follow:
- The conversation is retained. Many tools keep your chats, tied to an account, sometimes for long periods.
- It may feed model training or human review. Unless you opt out, free tools often reserve the right to learn from what you type, and some allow staff to review samples.
- It is linked to your identity. A standard account connects sensitive prompts to a real, verified person (you) along with the time and device behind each request.
For licensed therapists there's an added layer: client information is frequently treated as protected health information under privacy law, with strict rules about who may process it and under what agreement. Coaches are usually outside that regime, but the ethical duty of confidentiality doesn't depend on a statute. Either way, the safe assumption is that anything you feed an AI tool should be treated as if it could be seen by someone other than you.
The Word Is "Safer," Not "Safe", and the Gap Matters
It helps to be exact about what a privacy-focused tool can and can't do, and to put the limits before the benefits.
What it improves: less of your material accumulating in a cloud account, fewer threads tying your prompts to your real identity, and clearer handling of a conversation once you're done with it. Against a default chatbot, that's a real drop in exposure.
What it doesn't improve: to answer you, the model must read what you send. With a multi-model cloud service like this one, your text is forwarded to whichever provider you pick (the company behind GPT, Claude, Gemini, Grok, or Perplexity), so it can generate a reply, and to each provider on the panel when you run an AI Council. The content is processed off your computer by an external company. This is cloud AI, not on-device AI, and it isn't encrypted in a way that hides the content from the model provider. A privacy tool narrows specific risks; it doesn't turn a cloud assistant into a private filing cabinet, and it doesn't move your duty of confidentiality onto the software.
One point worth stating clearly for clinicians: Secret Chat isn't a substitute for a formal compliance arrangement, and it doesn't, on its own, satisfy the legal requirements that govern protected health information. If your obligations require a signed agreement with any vendor that processes client data, a general-purpose AI gateway won't meet that bar. The most dependable protection in that situation is to keep identifiable client information out of the prompt entirely.
What Secret Chat AI Changes for the Better
Secret Chat AI is a private AI assistant and multi-model gateway built around privacy-conscious defaults. At its core it's an anonymizer: it builds no profile of you and never associates your prompts with your identity (the email you sign up with is used only for account access and payment), so even where a provider retains data, it isn't linked to you. It won't make cloud AI confidential, but it removes several of the habits that make mainstream chatbots a poor place for sensitive notes.
- Your history stays with you. Conversations are stored in your browser's local storage rather than a cloud archive on Secret Chat's servers, and uploaded files are held locally too. The ongoing record of your work lives on your own device.
- Registration asks for very little. An email address is all that's needed (no name, no phone number), so less about you is attached to your prompts.
- Your network is hidden from the provider. Requests are routed through Secret Chat's infrastructure, so the model provider doesn't see your IP address directly.
- Deletion is requested, and reported plainly. Where a provider supports it, Secret Chat asks for processed content to be deleted or not stored, and each message can produce a Session Privacy Report (PDF) showing what actually happened, including when a deletion step didn't succeed, instead of pretending otherwise.
- Several models, one workspace. You can choose the assistant that suits a task and compare results without scattering your work across multiple provider accounts.
On documents: uploads support images and PDFs, and since September 2026 also Word files, spreadsheets, PowerPoint decks, CSV, text and code files, and zip archives of them. Images and PDFs go to the model as files; notes or worksheets in a Word file are converted to text in your browser and only that text is sent, so the file itself never leaves your machine. The contents still reach the provider, so leave out anything that shouldn't travel before you attach — the app shows you the exact text it is about to send.
Those formats come back out as well. The model selector has a Generators group, eight of them, and each answers with the finished piece rather than text to copy out. Document writes a worksheet, a between-session handout or an informed-consent template as a .docx; Presentation builds the deck for a psychoeducation group or a workshop as a .pptx; Table makes an intake checklist or a mood-tracking sheet as a spreadsheet, and Chart draws a sheet like that — sleep by week, sessions by month — as a JPG or a PDF. Email drafts the practice announcement or the waiting-list reply in the tone you set (never a message about a named client — see below); Translator puts a handout into a client's language, any on its list; Article drafts the practice blog post and Social Post the version for the practice's page, within the network's limit. Attach the worksheet you already use and say what to change, and it comes back as a new file with your material kept — a fresh document, not tracked changes. When you supply the material the model works from that and doesn't look on the web for more unless you switch the web on. Two details are worth knowing. The Document generator leaves anything you didn't state as a [___] blank and offers no PDF: it's a template you finish in Word, so a client's name or history is typed there, never into the chat. And the file itself is assembled in your browser from the model's reply, never built or stored on a server; it's kept in the app's Library on your device, with an Edit button that reopens it on its generator. Whatever you attached still reached the model provider, exactly as a typed prompt would, so a worksheet is fine and a session note is not, for the same reasons as everywhere else in this article. The generators run on the paid models — ChatGPT, Claude, Gemini and Grok.
For the Most Sensitive Cases: Keeping AI In-House
When the material is so delicate that no outside party should ever touch it, the strongest option is to keep it off third-party servers altogether. A practice or organization can run AI on infrastructure it controls, or a practitioner can run an open-source model locally on their own machine. Nothing is transmitted, and there's no external provider to compel, breach, or rely on.
The honest cost is capability. The open-weight models you can self-host today tend to be clearly less capable than the flagship models the major labs offer only through their paid APIs — weaker at nuanced summarizing, reasoning, and drafting. A common compromise is to split the work: a local model for anything truly identifiable or high-risk, and a privacy-focused gateway to the stronger commercial models for general, de-identified tasks, with careful redaction applied regardless of which route a task takes. A small local model handles that first half perfectly well on an ordinary computer; our measured local-LLM comparison covers what it can and can't do, and why matching the frontier models locally is a different order of expense.
Habits That Protect Your Clients
The most powerful safeguard isn't a toggle; it's restraint about what you enter. Every identifying detail you leave out is one that can't be exposed, whatever happens after you hit send.
- De-identify before you type. Strip names, ages, locations, employers, and distinctive specifics. Refer to "the client," and keep any key linking that back to a real person offline and separate.
- Generalize the specifics. Many questions about technique, framing, or planning can be asked in the abstract, without a single client-identifying fact.
- Send the fragment, not the file. Paste the one passage or upload the single page you actually need help with, not an entire case file.
- Clean documents first. Before exporting to PDF, remove comments, tracked changes, and hidden details, and keep only the pages that matter.
- Check what comes back. Treat AI output as a draft to review, not guidance to follow blindly; models can be confidently wrong, and clinical or coaching judgment is yours alone.
- Fit the tool to the risk. For anything truly identifiable or high-stakes, fall back to offline or in-house options rather than any cloud service.
A way to put a model to work without revealing who your client is:
Act as a documentation assistant. I have removed every identifying detail and refer to the person only as "the client." Turn these rough session notes into a structured summary with presenting concerns, approaches used, and follow-up steps, and flag anything that looks unclear or incomplete. Here are the notes:
Where AI Genuinely Helps in Practice
With those habits in place, AI can take real weight off the parts of the work that don't require exposing anyone:
- Shaping de-identified notes into a clean summary, a structured plan, or a list of follow-up questions.
- Drafting psychoeducation material — explainers, worksheets, and between-session resources you then tailor and review.
- Summarizing a PDF such as a research article or a generic worksheet before you read it in full.
- Exploring approaches in the abstract by asking different models how they would frame an intervention, then comparing.
- Translating jargon into plain, warm language for clients, or simplifying your own reading.
- Getting the file, not the text — the worksheet as a .docx, the group session as a .pptx, the tracking sheet as a spreadsheet and a chart of it, the handout in a client's language — through the Generators described above, from material without client identifiers.
The split never changes: AI handles the mechanical drafting; you bring the clinical or coaching judgment, the ethics, and the protection of the person behind the notes.
Exploring approaches across several models is the one on that list that rarely survives a full day of sessions, because doing it by hand means opening each model in turn, asking again, waiting each time, and then reading several long answers against one another. The AI Council compresses both ends of that. The models are asked at the same moment rather than one after another, so a run takes about as long as its slowest member instead of the sum of the panel, and each answer opens as it arrives. The referee then reads them: the claims are pulled out, laid side by side model by model, and returned as a short synthesis of what at least two models arrived at independently, with anything still contested listed separately to weigh before you use it. In the ten minutes between clients, that's a ready conclusion and a short list of what to think about — less to read than a single model's reply, not several times more, with the full answers still there above it when one verdict looks off. The two limits in the note at the top of this article travel with it: the synthesis says what to check rather than having checked it, and it widens where your text goes.
The Takeaway
Therapists and coaches deserve modern tools without putting a client's trust on the line. The responsible framing is the measured one: a privacy-focused tool like Secret Chat makes AI use with sensitive notes safer — through on-device storage of chats and files, minimal-information sign-up, IP shielding, and transparent deletion handling, but never risk-free. The model provider still reads your prompt, and protecting client and personal data stays in your hands.
Keep identifiers out, verify what the model gives back, and reserve the most sensitive material for offline or in-house tools. Looking for a more private place to handle the lower-risk work? Try Secret Chat AI, and bring your own de-identification and review discipline with you.
Sources
- HHS — Covered entities and business associates
- HHS — Business associate guidance
- HHS — De-identification: Safe Harbor and Expert Determination
- HHS — Psychotherapy notes and mental health information
- OpenAI — ChatGPT for Clinicians (eligibility and self-serve BAA)
Frequently Asked Questions
- Is it safe to put therapy or coaching notes into AI?
No cloud AI tool is fully "safe" for client notes, because the model provider has to read your prompt to respond. A privacy-focused tool can be safer by reducing how much is stored and how directly it links back to you, but the duty of confidentiality stays with you. Keep identifying details out and share only what a task truly requires.
- Is Secret Chat compliant for protected health information?
No. Secret Chat is a privacy-focused gateway, not a formal compliance solution, and it doesn't by itself satisfy the legal requirements for protected health information or provide the kind of signed vendor agreement those rules often demand. If your obligations cover client health data, the safest approach is to keep identifiable information out of the prompt and consult your own compliance requirements.
- What documents can I upload?
Images, PDFs, Word files, spreadsheets, PowerPoint decks, CSV, text and code files, and zip archives of them. A Word file or spreadsheet is converted to text in your browser before being sent, and you can read that text in the app first; use that moment to drop anything that shouldn't be shared.
- Can it write or edit a worksheet as a Word file, or build a slide deck?
Yes. Choose Document or Presentation from the Generators group (Table, Chart, Email, Translator, Article and Social Post are there too), describe what you need or attach your existing file and say what to change, and the answer is a new .docx or .pptx assembled in your browser. A document leaves anything you didn't state as a
[___]blank and has no PDF option, on purpose — you complete it in Word, so client details never need to enter the chat. Whatever you attach reaches the model provider like any prompt, so keep it to material without client identifiers. The generators run on the paid models. - Does the tool automatically remove client names or identifying details?
No. Assume nothing is stripped for you. If you don't want a name, age, location, or other identifier processed, take it out before sending. Handling personal and sensitive data remains your responsibility.
- What should I use for the most sensitive material?
For information that no outside party should ever see, keep it off third-party servers, a practice-controlled deployment or an open-source model running locally and offline. The trade-off is that self-hosted open-weight models are generally less capable than the top-tier models available only through the providers' APIs, so many practitioners reserve local tools for the most sensitive work and use a privacy-focused gateway for everything else.