You are the clinician. You are also the scheduler, the biller, the note-writer, and the person who stays late when a client runs over. You have heard that ChatGPT can write a SOAP note in 30 seconds. You have probably tried it, or thought seriously about trying it. A Healthcare Brew survey of over 500 healthcare professionals published in February 2026 found that 57% had encountered or used unauthorized AI tools at work — with 20% admitting they use them regularly. The motivation, in 50% of cases: faster workflows.
That is the context. The problem is that the tools people reach for — ChatGPT, Gemini, consumer Claude — are not HIPAA-compliant in their standard form. And unlike most regulatory grey areas, this one has a clear line. Here are the six questions solo OTs, SLTs, and other allied health clinicians ask most often about AI and patient data — answered without hedging.
1. "Is it a HIPAA violation to use ChatGPT to write my clinical notes?"
Yes. The standard consumer version of ChatGPT does not qualify as HIPAA-compliant. OpenAI's default terms of service do not include a Business Associate Agreement (BAA) — the contractual requirement that any vendor handling your patients' Protected Health Information (PHI) must sign with you. Without a BAA, using a tool with PHI is a violation regardless of how good the tool is, how carefully you word the note, or how small your practice is.
The same applies to consumer Gemini, standard Claude, and any other general-purpose AI assistant not specifically configured for HIPAA-covered use. These platforms are built for general use. Their default terms typically allow data to be used for model improvement. That alone disqualifies them for clinical use involving patient information.
The direct recommendation: if you have been using ChatGPT for clinical notes, stop. The tools that can do the same job and are HIPAA-compliant exist, cost very little, and are covered in question six below.
2. "Do I need a Business Associate Agreement with my AI note tool?"
Yes, and this is not optional. Under HIPAA, any person or organization that creates, receives, maintains, or transmits PHI on behalf of a covered entity — which includes your solo practice — is a Business Associate. AI note tools that listen to your appointments and generate clinical documentation are definitionally business associates. A signed BAA must be in place before you enter any patient information.
In 2026, BAAs for AI tools have become more complex than the standard template. The U.S. Department of Health and Human Services issued a proposed update to the HIPAA Security Rule in January 2025 — its first major revision in 20 years — which removes the previous distinction between "required" and "addressable" safeguards and tightens expectations around encryption and access controls. Any BAA you sign for an AI tool should now specify: (a) whether the vendor may use your PHI to train its AI models, (b) where data is processed and stored, (c) how long audio, transcripts, and generated notes are retained after each session, and (d) what happens to your data if you cancel your subscription.
The training restriction clause is the one most practices overlook. If a vendor has trained its model on your patient data, deleting the source files does not remove that information — it may be embedded in the model weights. Your BAA must prohibit training on your PHI from the outset.
3. "What happens to my patient data when an AI scribe processes it?"
When you use an AI ambient scribe, your session audio or text is transmitted to the vendor's servers, transcribed, and processed to generate the clinical note. The data flow involves at minimum: your device, the vendor's cloud infrastructure, and in many cases third-party subprocessors for transcription or AI model inference.
The risks are in what happens after the note is generated. A June 2026 class action lawsuit filed against two major California health systems alleged that patients were not clearly informed their medical conversations were being recorded by an AI platform, transmitted outside the clinical setting, and processed by third-party systems. The vendors were named as co-defendants. As a solo clinician, you have the same exposure — and far less legal resource to defend it.
What to check before signing up for any AI scribe: does the vendor retain audio after the session ends? Are transcripts stored, and for how long? Is the generated note stored on the vendor's servers or only locally? The best tools — Heidi Health and Nabla among them — are explicit that audio is not retained after processing and that patient data is never used for model training. Verify this in the BAA, not just on the marketing page.
4. "Can I de-identify patient data before using an AI tool and stay HIPAA-safe?"
Partially, and this is where most clinicians underestimate the standard. HIPAA's Safe Harbor de-identification method requires the removal of all 18 listed identifiers — not just name, but also dates (including dates of service), geographic data smaller than a state, phone numbers, device identifiers, and any other information that could reasonably be used to identify the individual. In practice, a SOAP note with the patient's name removed but with their diagnosis, date of birth, and appointment date still present is not de-identified under HIPAA Safe Harbor.
For the type of content a solo clinician would want an AI tool to process — a session recording, a partial SOAP draft, a referral letter — full de-identification to the HIPAA standard is almost always impractical in real time. This means the BAA route is the correct one, not de-identification as a workaround.
There is a legitimate use case for de-identification: if you want to use a general AI tool to draft template letters or protocol documents that contain no patient information, that is lower-risk. The moment a real patient enters the picture, the BAA is the requirement.
5. "What are the actual HIPAA fines for using a non-compliant AI tool?"
OCR fines are tiered by culpability. At the lower end, an unknowing violation — where you were unaware the action was a breach — carries penalties of $100 to $50,000 per violation, capped at $25,000 per calendar year for identical violations. At the upper end, willful neglect that is not corrected within the required timeframe carries fines of up to $50,000 per violation, with an annual cap of $1.9 million for repeated identical violations.
The penalty that catches most solo clinicians off guard is that each patient record exposed is a separate violation. Using a non-compliant tool with 50 patient files is not one $100 fine — it is potentially 50 separate violations, each assessed at the applicable tier.
OCR has confirmed it settled or imposed civil monetary penalties in more than 50 HIPAA enforcement actions under its risk analysis initiative. Recent actions have consistently cited three failure modes: inadequate security risk analysis, insufficient access controls, and failure to sign BAAs with business associates. Using a non-compliant AI tool would tick all three boxes simultaneously.
Beyond regulatory fines, the IBM-tracked average cost of a healthcare data breach exceeded $10 million in 2026 when legal fees, notification costs, remediation, and reputational damage are included. For a solo clinician, a breach does not need to be large to be practice-ending.
6. "Which AI note tools are HIPAA-compliant for a solo OT or SLT in 2026?"
Three tools are worth evaluating for solo OT and SLT practices in 2026. All offer BAAs, maintain explicit data protection policies compatible with HIPAA, and have free or low-cost tiers that make them accessible without significant capital outlay.
Heidi Health offers a free tier that includes HIPAA-compliant note generation across specialties. OT and SLT templates are available, and the BAA is accessible on request. Audio is processed and not retained. The free tier is genuinely functional for a solo clinician's volume — up to a threshold of monthly sessions after which a paid plan applies.
Nabla is certified to HIPAA, SOC 2 Type II, and ISO 27001. It does not retain audio, does not train on patient data, and offers a BAA as standard. Nabla's note quality for allied health specialties is strong, and at $59–$99 per month, it sits in the accessible range for a solo practitioner generating consistent session volume.
SLPFlow is designed specifically for speech-language pathologists and includes HIPAA-compliant documentation tools. For SLTs, the specialty-specific template library is a material advantage over general-purpose scribes that require manual configuration.
For occupational therapists, Ambiki is a practice management platform built for OT, PT, and SLT workflows with HIPAA compliance across its documentation features. It is worth evaluating if you want note generation integrated into scheduling and billing rather than a standalone scribe.
The question to ask every vendor before entering any patient data is: "Will you sign a Business Associate Agreement with my practice, and does your BAA explicitly prohibit training AI models on my patients' data?" If the answer to either part is no, move on. If you are unsure which tool to start with for your specialty, book a 20-minute call and we will point you in the right direction.
The bottom line
Shadow AI use in healthcare is not a niche problem. A survey of over 500 healthcare professionals published in February 2026 found one in five routinely using unauthorized tools (Healthcare Brew, February 2026). The motivation is always the same: time. The exposure is always the same: a BAA that does not exist, a tool that should not have seen patient data, and fines that are assessed per record.
The practical answer is not to avoid AI — it is to use the right tools. For a solo OT or SLT, Heidi Health's free tier with a signed BAA is a 30-minute fix that eliminates the compliance risk and saves real time on documentation. The upside is genuine. The downside of getting it wrong is not worth testing.
For a broader look at what compliant AI adoption looks like for a sole practitioner, see 4 admin tasks a sole OT can automate for under $50 a month. For the cost reality of the tools available, see the real cost of AI for an independent practice.
The Clinical AI Briefing
One practical AI insight for healthcare practices every week. No hype. Evidence and outcomes only.
Related: 4 admin tasks a sole OT can automate for under $50 a month · The real cost of AI for an independent practice · AI note tools in therapy: the compliance rules that now apply
This article is for informational purposes only and does not constitute legal or compliance advice. Consult a HIPAA compliance officer or attorney before making decisions about your practice's data handling procedures.