The honest answer is: for some things, and not for the thing most people want it for. The line is not about AI. It is about who you are disclosing a client to, and whether they agreed to it.
This is general information, not legal advice. Your licensing board, your professional body and your own counsel outrank anything on this page.
The obligation does not transfer
HIPAA binds you. It does not bind a consumer chatbot, and nothing you type into one changes that. When protected health information moves from your notes into a service that has not signed a Business Associate Agreement, that is a disclosure — and the responsibility for it stays with you, because you are the covered entity.
This surprises people because the tool feels private. A chat window with no audience reads like a notebook. It is not a notebook. It is a request to somebody else’s server, kept under their retention policy, tied to your account, and — depending on the product and its settings — potentially reviewed by a human or used to improve a model.
A chat window with no audience feels like a notebook. It is a disclosure to a third party.
Identifying is broader than naming
Clinicians reach for “I removed the name, so it is de-identified.” Under HIPAA’s Safe Harbour method there are eighteen identifiers, and a name is one. Dates — including admission and discharge — are on the list. So is any geography finer than a state, any age over 89, and a catch-all for any other unique identifying characteristic.
The catch-all is the one that bites in practice. “A 34-year-old air traffic controller in a town of nine thousand, in her second marriage, whose brother died in March” carries no name and identifies one person. A caseload is small; the details that make a case worth writing about are the same details that make it findable.
What is usually fine
- •Your own writing. Tightening a paragraph of psycho- education, rewording a policy, drafting an intake form.
- •General clinical questions. Asking about an intervention, a diagnostic criterion, a body of research. No client appears in the question at all.
- •Practice admin. Marketing copy, a supervision agenda, a letter template with the blanks still blank.
- •Genuinely de-identified reasoning. A composite case, altered enough that it corresponds to nobody — which is a higher bar than changing the name and the town.
What is not
- •Pasting session notes to be summarised. The single most common use, and the one that discloses the most.
- •Uploading a recording or transcript. A voice is an identifier, and a transcript carries every detail the session did.
- •Asking for advice on a named or describable client. Including in the details that make the question answerable.
- •Drafting a letter to an insurer or a court with the real particulars in the prompt.
Two arrangements that hold
The first is contractual: use a tool whose vendor will sign a Business Associate Agreement. Several will, usually on enterprise plans. The agreement is what places them under HIPAA alongside you, and without a signed one the marketing word “compliant” means nothing.
The second is technical: never let the identifying details leave in the first place. This is the arrangement Secure AI is built on. Names, dates of birth, addresses, phone numbers, email addresses, record numbers and government identifiers are detected in your message and replaced with realistic stand-ins before it goes to a model. The model answers about the stand-ins; your real values are restored in the reply you read. What leaves is a coherent clinical question about somebody who does not exist.
Neither arrangement removes your judgement. A tool can stop a name leaving; it cannot decide whether a particular disclosure was appropriate, and it cannot tell you what your board expects. It narrows the failure to the one place a professional can actually stand: what you chose to write.
The question worth asking
Before you type, ask whether you could describe what you are about to do to the client in front of you. Not a lawyer — the client. “I paste our sessions into a chatbot to summarise them” is a sentence most clinicians would not want to say out loud, and that reaction is doing the same work as the regulation, faster.
Questions
Does turning off chat history make it compliant?
No. It may reduce retention and stop training on your inputs, which is worth doing, but the disclosure has already happened by the time the setting matters. Compliance turns on the agreement and on what left your machine, not on a toggle in the account that received it.
What about the AI note-takers built for therapists?
Several are legitimate and will sign a BAA. Ask for the signed agreement, ask where the audio is stored and for how long, and ask whether your data trains their models. A vendor who cannot answer those three in writing has answered them.
Is this different outside the United States?
The framework changes, the shape does not. Under UK and EU law you are the controller, the AI vendor is a processor, and a processor needs a contract and a lawful basis. The practical question is the same one: did identifying information about a client leave your control, and did they agree to it.

Try Secure AI free
Frontier AI chat — encrypted by default, with your identity stripped before any request reaches the provider.
