Get a BAA
SiteGPT signs BAAs as part of Enterprise onboarding. It signs its own standard BAA, and it can change that BAA to fit your needs. For example, it can change retention windows, breach notice timelines, notice contacts, and scope.1
Send a request
Email bhanu@sitegpt.ai. Give a short description of your organization and your use case.
2
Agree on the scope
SiteGPT reviews your deployment with you. This includes which content sources and features will carry PHI. If your account already has chatbot content or connected chat integrations, SiteGPT plans the move with you. See Existing accounts.
3
Review the BAA
Your legal team reviews the standard BAA at sitegpt.ai/legal/baa. On that page, you can download a copy with your organization’s details filled in. Send SiteGPT the specific changes you need.
4
Sign
Both parties sign. SiteGPT signs only after every vendor that touches PHI in your deployment has signed a BAA with SiteGPT. The BAA is binding only when both parties have signed it.
5
Wait for the written confirmation
SiteGPT turns on HIPAA processing for your account and confirms it to you in writing. Add chatbot content only after you get this confirmation. Start to send PHI only after you get it too.
Check that it works
After the confirmation, open your chatbot on your website. The bottom of the chat shows “Responses are AI-generated”. Only chatbots in HIPAA workspaces show this line.Existing accounts
If you already use SiteGPT, tell SiteGPT before HIPAA processing is turned on:- Chatbot content. Turning on HIPAA processing does not move the content you added before. Contact SiteGPT to plan the move of your content before enablement.
- Chat integrations. Turning on HIPAA processing does not disconnect chat integrations that are already connected. Work with SiteGPT to disconnect them before enablement. After enablement, the Integrations page is not available, so contact support@sitegpt.ai to disconnect one. Disconnecting does not delete copies that the other service already holds.
Where PHI is allowed
After enablement, PHI is allowed in one place only: conversations between your visitors and your chatbot, in the chat on a HIPAA-enabled account. Patients and visitors can share PHI in the chat. That conversation data is covered by the BAA. PHI is not allowed in:- Chatbot content. This means website pages, uploaded files, text snippets, and custom responses. Everything your chatbot learns from must be free of PHI.
- Lead forms. Lead records are not redacted. See Retention and redaction.
- Support requests to SiteGPT. Never send PHI by email, chat, or any other support channel. Remove identifying details from conversation text before you share it with support.
- SiteGPT’s free public tools.
- Beta or preview features, unless SiteGPT tells you in writing that they are covered.
- Any account that has no BAA, or that has no written enablement confirmation.
What changes in a HIPAA workspace
HIPAA mode applies to every chatbot that the BAA account owns. It is not a setting. Only SiteGPT can turn it on or off.AI processing
- PHI goes only to three subprocessors: Convex (database), OpenAI (answers and embeddings, on zero-data-retention endpoints only), and Pinecone (vector search). Each one has signed a BAA with SiteGPT. See the PHI section of the subprocessor list.
- SiteGPT does not use PHI to train AI models, and does not let its subprocessors do so.
- Chatbot content in HIPAA workspaces is indexed and searched in a separate namespace and index from standard accounts. HIPAA workspaces share this index. It is not a dedicated environment for each customer.
The chat widget
- The chat always shows the line “Responses are AI-generated”. You cannot turn it off. It stays when you remove SiteGPT branding.
Content
- Cloud file connectors are not supported for HIPAA use. The dashboard does not offer Notion, Google Drive, Dropbox, OneDrive, Box, or GitHub. API v2, the CLI, the SDKs, and MCP also refuse to create, change, authorize, or import from any cloud file connector, including SharePoint and Confluence. They return
403 HIPAA_CONNECTORS_DISABLED. If SiteGPT cannot check the HIPAA status, they return503 HIPAA_CHECK_UNAVAILABLE. Try again later. If your account had connectors before enablement, their scheduled syncs are turned off at enablement. You can still list and revoke existing connections through API v2. You can also ask support@sitegpt.ai to revoke them. Add content with website links, file uploads, and text snippets instead. - File uploads show a reminder. You can upload any supported file type. Files are parsed under zero data retention. The upload window reminds you never to upload files that contain PHI.
- If the upload window says the workspace accepts
.txtfiles only, other file types are rejected. If it says uploads are unavailable, contact support@sitegpt.ai. - You cannot turn a conversation into a custom response. The Incorrect? Modify bot’s answer! link in Chat History is not shown. This keeps conversation text out of chatbot content. You can still add custom responses in Custom Responses. See Custom responses.
Integrations
- Chat integrations are not available. You cannot connect Zendesk, Slack, Messenger, Google Chat, Crisp, Freshdesk, or Zoho after enablement. Integrations does not show in the sidebar. Conversations stay in the chat on your website, which the BAA covers. See Integrations.
- Integrations that were connected before enablement are not disconnected automatically. See Existing accounts.
Notifications and webhooks
Notifications and webhooks carry no conversation content and no visitor contact details:- Emails to your team (escalation, new lead, new conversation) leave out the visitor’s name, email, phone, custom fields, and messages. The escalation email subject leaves out the visitor’s name. The email links to the conversation in the dashboard.
- iPhone push notifications do not include visitor names or message text. See Use the SiteGPT iPhone app.
- Reply emails to visitors say only that there is a new response. They do not include your reply. See Reply and take over.
- Webhooks send the event and IDs, without messages, sources, or contact details. See Webhooks.
- The weekly digest email shows numbers only, with no topics or questions.
Leads
- Industry templates for lead forms are not available. You choose each field yourself.
- Leads Settings shows a warning: “Leads are never auto-deleted. Conversations are redacted after 7 days. Lead records are not. Never collect PHI here.”
- If you add a free-text field, the form builder warns you that free-text fields invite PHI.
Analytics
- Conversation insights are not turned on by a plan upgrade alone in a HIPAA workspace. To use them, contact support@sitegpt.ai.
- When insights are on, topics come only from your own topic list. Conversations that match none of your topics show as “other”. If your list is empty, every conversation shows as “other”. Use generic topic labels with no PHI.
- The Frequently asked questions grouping does not run.
- SiteGPT’s own product analytics and session recording do not run in the dashboard for people who own or are members of a HIPAA workspace.
Chatbot transfers
- You cannot transfer a chatbot to or from an account that has a BAA. See Manage chatbots.
Retention and redaction
Conversation content is redacted 7 days after the conversation’s last activity. Your order form can set a different window. A conversation that is still active is not redacted. What redaction does:- Each message in the conversation is replaced with “[Redacted under the HIPAA retention policy]”.
- The conversation title, IP address, page URL, and answer sources are removed.
- The content is removed from the production database. You cannot get it back through SiteGPT.
- Counts and totals stay, so your analytics keep working. The link between the conversation and its topics is removed.
- If the visitor sends a new message after redaction, the new message is kept. The earlier messages stay redacted. The retention window starts again from the new message.
- Lead records. A lead is a contact record that a visitor sent so your team would follow up. Leads stay until you delete them. Managing them is your responsibility.
- Visitor identity records. The visitor record that links a visitor’s conversations is also kept. To delete it, use Delete all visitor data on the lead, or Delete Visitor Data in the conversation menu in Chat History. See Manage leads.
What you must do
The BAA sets duties for you. In practice:- Do not send PHI before the written enablement confirmation.
- Keep all chatbot content free of PHI.
- Keep lead forms to basic contact details. Do not add free-text fields that invite people to describe a condition. Delete any lead that contains PHI.
- Use generic topic labels in analytics.
- Never put PHI in a support request.
- Test that the chatbot answers accurately for your use cases before you use it with PHI.
- Let only trained, qualified people use the chatbot and its output for healthcare work.
- Never tell anyone that the chatbot’s answers were written by a person.
- Train your staff on their duties under the BAA.
Limits
- SiteGPT and its answers do not replace the judgment of licensed professionals. The service is not for use as a medical device.
- Some state and federal laws are stricter than HIPAA. You are responsible for checking that your use complies with them.
- BAAs are available on the Enterprise plan only. They are not available on Starter, Growth, or Scale.
- The standard BAA also covers breach notification timelines, subcontractor obligations, and what happens to PHI when the agreement ends. Read the standard BAA for the terms.