Using ChatGPT With Patient Data: Risks and De-identification

Pasting clinical notes into ChatGPT raises confidentiality and legal questions. What HIPAA, Gulf laws and OpenAI's own terms say, and how to de-identify.

Using ChatGPT With Patient Data: Risks and De-identification

Large language models such as ChatGPT, Gemini or Claude are remarkably good at summarizing a referral letter, drafting a patient explanation or restructuring a messy report. It is tempting to paste a full clinical note and ask for help. Before doing so, every clinician should understand where that text goes, which rules apply and how to strip the identifiers that turn a useful prompt into a confidentiality breach.

This article does not give legal advice. It sets out the main principles and the questions to ask.

Where does the text go?

When you type into a chatbot, the text is sent to the provider's servers, processed there and usually stored for some time. What happens next depends on the product and the contract, not on the model:

  • Consumer accounts (free or individual paid plans) are governed by general terms of use. They are not designed for protected health information.
  • Enterprise and API offerings can come with contractual commitments on retention, training use and security.

OpenAI's own HIPAA implementation guide, published in March 2026, states plainly that without a Business Associate Agreement (BAA) with OpenAI, customers may not use its services with protected health information. OpenAI offers BAAs for API use, limited to endpoints eligible for zero data retention, and for certain sales-managed ChatGPT Enterprise and Edu accounts. Other business plans are not eligible. A BAA is a US legal instrument. It does not by itself satisfy the laws of Saudi Arabia, the UAE, Morocco or any other country, and it does not replace the security measures the healthcare organization remains responsible for.

Which laws apply in the region?

Rules differ by country, but the trend is towards stricter protection of health data:

  • Saudi Arabia. The Personal Data Protection Law (PDPL) came into force on 14 September 2023 and became fully enforceable on 14 September 2024, after a one-year grace period, under the supervision of the Saudi Data & Artificial Intelligence Authority (SDAIA). Its implementing regulations add extra controls for health data. Penalties include fines of up to SAR 5 million, and disclosing sensitive data with intent to harm or for personal gain can lead to imprisonment.
  • United Arab Emirates. Federal Law No. 2 of 2019 on the use of ICT in health fields restricts storing, processing or transferring health data related to services provided in the UAE to outside the country, except in cases defined by the health authorities. Sending identifiable patient text to a foreign cloud service therefore needs careful review.
  • Other countries. Most countries in North Africa and the Middle East have personal data protection laws that treat health data as sensitive, and medical secrecy obligations apply regardless of technology.

The safest working assumption is simple: identifiable patient information should not be sent to a general-purpose AI service unless your institution has a compliant contract and a documented legal basis.

What de-identification actually means

The best-known framework comes from the US HIPAA Privacy Rule, which recognizes two methods.

Safe Harbor

Remove 18 categories of identifiers. They include names, geographic subdivisions smaller than a state, all elements of dates (except the year) related to an individual, phone numbers, email addresses, medical record numbers, account and device identifiers, full-face photographs and any other unique identifying number or code. Further conditions apply:

  • Dates more specific than the year must go: admission, discharge, birth and death dates.
  • The first three digits of a postcode may only be kept if that area contains more than 20,000 people.
  • The organization must have no actual knowledge that the remaining data could identify the person.

Expert determination

A qualified expert assesses the data and documents that the risk of re-identification is very small. This method can retain more detail but requires formal expertise.

Practical de-identification for a clinical prompt

For everyday use, such as asking an AI to rephrase or structure a report, a disciplined routine goes a long way:

  1. Remove direct identifiers: name, ID or file numbers, phone, address, email, insurance number.
  2. Generalize dates to relative time ("day 3 after admission") or the year only.
  3. Remove rare details that can identify someone in a small community: an unusual job, a named village, a rare disease combined with age and town.
  4. Strip free-text traps: names of relatives, referring doctors, the clinic name in a header.
  5. Re-read the prompt before sending. Then re-insert identifiers locally in the final document.

Automated tools can help, and some software now performs this replacement on the user's computer before any text is sent, but no automatic method is perfect. Free text is where identifiers hide.

Accuracy is a separate risk

Even de-identified, an AI output can be wrong: invented references, incorrect doses, a reversed laterality. Language models are not validated medical devices for diagnosis or treatment decisions. Treat any output as a draft that you verify, and never let it replace your clinical judgment.

Key takeaways

  • Do not paste identifiable patient data into consumer chatbot accounts.
  • A US Business Associate Agreement does not settle compliance with Saudi, Emirati or other national laws.
  • Use Safe Harbor-style de-identification: names, numbers, exact dates, small-area locations and rare details.
  • Prefer tools that de-identify on your own computer before any data leaves it, or AI models that run fully offline.
  • Verify every AI output; the signing clinician remains responsible.

Frequently asked questions

Can doctors put patient information into ChatGPT?

Not identifiable information through a consumer account. OpenAI's own guide says its services may not be used with protected health information without a Business Associate Agreement, and national laws may impose further limits.

What are the 18 HIPAA identifiers?

They include names, small-area geography, dates other than year, phone and fax numbers, emails, record and account numbers, device identifiers, biometric data, full-face photos and any other unique identifier.

Is de-identified data completely safe to share?

Risk is reduced, not eliminated. Rare details in free text can still identify a patient, so review every prompt before sending it.

Sources

  1. OpenAI — HIPAA implementation and configuration guide (2026)
  2. Hunton Andrews Kurth — HHS publishes guidance on how to de-identify protected health information
  3. Clyde & Co — Saudi Arabia's Personal Data Protection Law becomes enforceable (2024)
  4. Al Tamimi & Co — The Federal Law regulating the use of ICT in the UAE healthcare sector
Dictate your reports, nothing leaves your computer

Nabady Whisper transcribes your voice offline in English, French or Arabic, with report templates for every specialty.

General information, checked at the publication date; it is neither medical nor legal advice.

Share LinkedIn WhatsApp X