See how AI medical-record review links every fact to the exact Bates page that proves it — click any citation and jump straight to the record.
See the 60-second demo →AI is transforming legal work. Personal injury attorneys are uploading medical records. Legal nurse consultants are using AI to build case chronologies. Medical malpractice firms are running depositions through language models to find admissions.
The problem: most of them have no idea whether the AI tool they're using is HIPAA-compliant — and the penalties for getting it wrong are severe.
This guide explains exactly what HIPAA compliance means for attorneys and LNCs using AI tools, what to look for before uploading a single medical record, and which protections are non-negotiable.
The short answer: it depends on the arrangement — but if you're receiving protected health information (PHI) from a covered entity (a hospital, physician practice, or health plan) to work on a legal matter involving that patient, you are likely a Business Associate under HIPAA.
A Business Associate is any person or entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity. Personal injury attorneys and LNCs who receive and analyze medical records on behalf of patients may qualify, and those who receive records from covered entities under formal referral arrangements almost certainly do.
Even if you conclude that strict HIPAA requirements don't technically apply to your firm as a matter of law (some argue attorneys are not Business Associates in litigation contexts), the ethical obligations under your state bar's rules of professional conduct and the practical reputational risk make HIPAA-aligned practices the only prudent choice.
HIPAA compliance for an AI platform isn't a single checkbox — it's a combination of contractual, technical, and operational requirements.
This is the most important document. A BAA is a written contract between you (or your firm) and any vendor who will receive or process PHI on your behalf. The BAA obligates the vendor to:
What this means in practice: Before uploading any client's medical records to an AI tool, ask the vendor whether they provide a BAA. If they say no, or if they say HIPAA doesn't apply to them, stop. Do not upload patient records to that platform.
OpenAI does not offer a standard BAA for ChatGPT. Google Workspace's AI features (Gemini) require an enterprise agreement with a BAA. Microsoft Azure OpenAI Service offers a BAA through its enterprise health offerings. Always verify before uploading.
All PHI must be encrypted both when it's stored (at rest) and when it's being transmitted (in transit). The HIPAA Security Rule doesn't mandate a specific encryption standard, but industry practice is AES-256 for stored data and TLS 1.2 or higher for data in transit.
When evaluating a vendor, ask: "What encryption standards do you use for stored data and data in transit?" If they can't answer, that's a red flag.
HIPAA requires that covered entities and their business associates implement:
This is where many general-purpose AI tools fail: they may use your uploaded data to train future models. Under HIPAA, PHI cannot be used for any purpose other than the treatment, payment, or operations purpose for which it was disclosed.
If your AI vendor's terms of service include any language about using uploaded content for model improvement, training, or development — and they haven't specifically carved out PHI from those terms in a BAA — you have a problem.
Always ask vendors explicitly: "Is our data used to train your models? Does that include PHI we upload? Does your BAA exclude uploaded PHI from model training?"
For firms with federal contracts or clients in certain regulated industries, where data is stored matters. Most major cloud providers (AWS, Azure, Google Cloud) can provide US-only data residency. If your vendor uses overseas data centers, verify this is acceptable for your practice.
| Tool | BAA Available? | Training on Data? | Verdict |
|---|---|---|---|
| ChatGPT (consumer) | ❌ No | May be used | 🔴 Do NOT use with PHI |
| ChatGPT Enterprise | ✅ Yes | No (by contract) | 🟡 Compliant if BAA signed |
| Google Gemini (consumer) | ❌ No | May be used | 🔴 Do NOT use with PHI |
| Google Workspace with AI (enterprise) | ✅ Yes (with HIPAA config) | No (by contract) | 🟡 Compliant if configured |
| Microsoft Copilot (consumer) | ❌ No | May be used | 🔴 Do NOT use with PHI |
| Microsoft Azure OpenAI (enterprise) | ✅ Yes | No (by contract) | 🟡 Compliant if BAA signed |
| MedLegal AI (medicalai.law) | ✅ Yes (all plans) | ❌ Never | 🟢 Built for this use case |
| Claude.ai (consumer) | ❌ No | May be used | 🔴 Do NOT use with PHI |
| Claude for Business (Anthropic) | ✅ Enterprise only | No (by contract) | 🟡 Compliant if BAA signed |
HIPAA violations aren't theoretical. The Office for Civil Rights (OCR) at HHS has collected over $150 million in civil monetary penalties since 2008. The penalty structure in 2026:
| Violation Category | Minimum Per Violation | Maximum Per Violation | Annual Cap |
|---|---|---|---|
| Unaware (reasonable diligence) | $100 | $50,000 | $25,000 |
| Reasonable cause | $1,000 | $50,000 | $100,000 |
| Willful neglect, corrected | $10,000 | $50,000 | $250,000 |
| Willful neglect, not corrected | $50,000 | $1.9 million | $1.9 million |
Beyond the financial penalty: state attorneys general can bring their own actions, and a HIPAA breach must be disclosed to the affected patients — which, for a law firm, means disclosing to clients that you mishandled their medical records. The reputational damage is often worse than the fine.
Make a list of every AI tool your firm currently uses. For each one, ask:
For any vendor where you upload PHI and no BAA exists: either stop using that vendor for PHI-related work immediately, or contact the vendor and request their HIPAA BAA. Most enterprise vendors have a standard template. If they don't have one or won't sign one, that's a disqualifier.
The most common source of HIPAA breaches isn't a hacker — it's a well-meaning paralegal who doesn't know the rules. If you have any staff who work with medical records, they need to understand:
The simplest way to ensure HIPAA compliance in your AI workflow is to use tools designed specifically for legal and healthcare work — tools where HIPAA compliance isn't an afterthought bolted onto a consumer product, but the core design requirement.
One area often overlooked: when you share a client's medical records with an expert witness, that sharing needs to be properly covered as well. Expert witnesses who receive PHI in connection with litigation are generally treated as Business Associates, and your engagement agreement with them should address how they'll protect that information.
Similarly, if you use an AI tool to help your expert prepare their report — and you're uploading the client's records into that tool to do so — your BAA with the AI vendor needs to cover that use.
AI in medical-legal work is no longer optional — the attorneys and LNCs who aren't using it are losing time and competitive edge to those who are. But using AI without proper HIPAA safeguards is a liability that can cost you your practice, your reputation, and your license.
The checklist is simple:
If your current AI setup doesn't check all five boxes, you're taking on unnecessary risk. And in a field where your clients have already been through medical trauma and are trusting you with their most private records, that's a risk you can't afford.
BAA included on every plan. Your records are never used for training. US-based infrastructure. Purpose-built for PI attorneys, LNCs, and medical expert witnesses.
Start Your Free 14-Day Trial →The question is genuinely unsettled in some respects, but the practical answer is: if you're receiving medical records from covered entities (hospitals, doctors) and processing them on behalf of patients, you should treat yourself as a Business Associate and conduct yourself accordingly. The ethical obligations under your bar's rules may independently require HIPAA-equivalent protections even if the statute doesn't directly apply.
Not without a BAA, and OpenAI doesn't provide a standard BAA for individual or small business ChatGPT accounts. If you upload medical records to the standard ChatGPT interface, you're potentially violating HIPAA and certainly violating good data stewardship practices. Use an enterprise solution with a signed BAA.
Properly de-identified information (under HIPAA's Safe Harbor or Expert Determination methods) is not PHI and isn't subject to HIPAA restrictions. The problem is that true de-identification is more rigorous than most people realize — removing names and dates isn't sufficient if other information in the record could re-identify the patient. If you're de-identifying records as a workaround, make sure you're following the full Safe Harbor standard, not just removing obvious identifiers.
"HIPAA-ready" is marketing language with no legal meaning. Compliance requires a signed BAA, actual implementation of required technical safeguards, and documented policies and procedures. Always ask for and review the BAA before using any vendor with client PHI.