Is It HIPAA-Compliant to Use ChatGPT in a Dental Office?
- Kyle Summerford

- Mar 24
- 3 min read

You're not crazy for wanting to use it. ChatGPT, Claude, Gemini, these tools can save you hours every week on everything from writing patient letters to drafting HR policies to preparing for difficult conversations with your doctor. The question isn't whether you should use them. It's whether you know how to use them without putting your practice at risk.
The Short Answer
General AI tools like the free or standard versions of ChatGPT, Claude, and Gemini are not covered entities under HIPAA. They do not automatically sign Business Associate Agreements (BAAs). That means if you type a patient's name, date of birth, insurance ID, or any identifying information into a standard AI window, you may be transmitting protected health information to an unprotected third-party system. That is a HIPAA violation regardless of your intent.
But here's what most people miss: you don't have to share any of that information to get value from these tools.
What PHI Actually Is
Protected Health Information (PHI) is any information that can be used to identify a patient and is connected to their health, treatment, or payment history. Under HIPAA, dental practices are required to protect this information at all times, including how and where it's stored, transmitted, or discussed.
PHI includes: patient names, dates of birth, Social Security numbers, addresses, phone numbers, email addresses, insurance ID numbers, account numbers, appointment dates tied to a named patient, clinical notes, treatment details, and X-ray or image data linked to a patient.
The Difference Between General AI Tools and HIPAA-Compliant Platforms
Dental-specific, HIPAA-compliant AI tools are built to handle PHI within a protected environment, with BAAs in place and encryption standards that meet federal requirements. General AI tools are not. Know which category your tool falls into before you decide what to put in it.
Some enterprise versions of general AI tools, including certain paid tiers of ChatGPT and Claude, do offer BAAs in specific configurations. If your practice has explored that route, confirm the BAA is in place and covers your actual use case before proceeding. When in doubt, ask your IT or compliance advisor.
What PHI-Safe Prompting Is
PHI-safe prompting is a practical method for getting the full value of AI tools in your dental practice without ever putting protected health information at risk. The core principle is simple: you give the AI the situation without giving it the patient.
Instead of writing: "Write a follow-up message for Jane Smith who missed her appointment on March 10th for a crown prep," you write: "Write a warm, professional follow-up message for a patient who missed an appointment and needs to reschedule. Keep it brief and friendly."
Same result. Zero PHI. That's the framework.
The Never-Type-This List for Your Team
Before you roll out any AI tool to your front desk team, build a short training session around these basics. Post a one-page reference guide at every workstation where team members might use AI. It should include what PHI is, what tools are and aren't approved for use, and how to rewrite any prompt to remove patient identifiers.
The items that should never go into a general AI tool: patient names, insurance ID numbers, treatment codes tied to a specific person, appointment dates with identifying details, clinical notes, and any image or document that includes patient information.
This Is a Training Issue, Not Just a Technology Issue
As the office manager, you set the standard for how AI is used in your practice. That means it's not enough for you to understand PHI-safe prompting. Your entire front desk team needs to understand it too. The most common AI-related HIPAA violations won't come from malicious intent. They'll come from someone moving fast, trying to be helpful, not thinking twice about what they typed.
The managers who are going to lead their practices into the next decade are the ones learning how to use these tools responsibly, confidently, and effectively right now. PHI-safe prompting is the foundation that makes all of that possible.
If you want to go deeper, PHI-safe prompting is one of the core frameworks inside the DOMA AI Certification. It covers every module, from vendor evaluation to team training to implementation leadership. Learn more at DentalAIStandard.com.




Comments