> ## Documentation Index
> Fetch the complete documentation index at: https://sitegpt.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Use SiteGPT with protected health information (HIPAA)

> How to get a Business Associate Agreement, what changes in a HIPAA workspace, and what you must do to keep PHI in scope.

This page is for healthcare organizations whose chatbot visitors may share protected health information (PHI). This includes covered entities (providers, health plans, clearinghouses) and their business associates (agencies, vendors, platforms).

To handle PHI in SiteGPT, you need a signed Business Associate Agreement (BAA). BAAs are available on the Enterprise plan only. Your signed BAA controls. [sitegpt.ai/hipaa](https://sitegpt.ai/hipaa) and the [standard BAA](https://sitegpt.ai/legal/baa) describe the standard terms. This page explains how that works in the product.

<Warning>
  Do not put PHI into SiteGPT until SiteGPT confirms in writing that HIPAA processing is on for your account. This includes content, test conversations, uploaded files, and lead forms. The [Terms and Conditions](https://sitegpt.ai/legal/terms) and the BAA both require this.
</Warning>

You can use SiteGPT without a BAA for content that has no PHI, for example public FAQs, scheduling guidance, and service information.

## Get a BAA

SiteGPT signs BAAs as part of Enterprise onboarding. It signs its own standard BAA, and it can change that BAA to fit your needs. For example, it can change retention windows, breach notice timelines, notice contacts, and scope.

<Steps>
  <Step title="Send a request">
    Email [bhanu@sitegpt.ai](mailto:bhanu@sitegpt.ai). Give a short description of your organization and your use case.
  </Step>

  <Step title="Agree on the scope">
    SiteGPT reviews your deployment with you. This includes which content sources and features will carry PHI. If your account already has chatbot content or connected chat integrations, SiteGPT plans the move with you. See [Existing accounts](#existing-accounts).
  </Step>

  <Step title="Review the BAA">
    Your legal team reviews the standard BAA at [sitegpt.ai/legal/baa](https://sitegpt.ai/legal/baa). On that page, you can download a copy with your organization's details filled in. Send SiteGPT the specific changes you need.
  </Step>

  <Step title="Sign">
    Both parties sign. SiteGPT signs only after every vendor that touches PHI in your deployment has signed a BAA with SiteGPT. The BAA is binding only when both parties have signed it.
  </Step>

  <Step title="Wait for the written confirmation">
    SiteGPT turns on HIPAA processing for your account and confirms it to you in writing. Add chatbot content only after you get this confirmation. Start to send PHI only after you get it too.
  </Step>
</Steps>

### Check that it works

After the confirmation, open your chatbot on your website. The bottom of the chat shows "Responses are AI-generated". Only chatbots in HIPAA workspaces show this line.

### Existing accounts

If you already use SiteGPT, tell SiteGPT before HIPAA processing is turned on:

* **Chatbot content.** Turning on HIPAA processing does not move the content you added before. Contact SiteGPT to plan the move of your content before enablement.
* **Chat integrations.** Turning on HIPAA processing does not disconnect chat integrations that are already connected. Work with SiteGPT to disconnect them before enablement. After enablement, the **Integrations** page is not available, so contact [support@sitegpt.ai](mailto:support@sitegpt.ai) to disconnect one. Disconnecting does not delete copies that the other service already holds.

## Where PHI is allowed

After enablement, PHI is allowed in one place only: **conversations between your visitors and your chatbot, in the chat on a HIPAA-enabled account.** Patients and visitors can share PHI in the chat. That conversation data is covered by the BAA.

PHI is not allowed in:

* **Chatbot content.** This means website pages, uploaded files, text snippets, and custom responses. Everything your chatbot learns from must be free of PHI.
* **Lead forms.** Lead records are not redacted. See [Retention and redaction](#retention-and-redaction).
* **Support requests to SiteGPT.** Never send PHI by email, chat, or any other support channel. Remove identifying details from conversation text before you share it with support.
* **SiteGPT's free public tools.**
* **Beta or preview features**, unless SiteGPT tells you in writing that they are covered.
* **Any account that has no BAA**, or that has no written enablement confirmation.

Keeping PHI out of chatbot content keeps the list of vendors that receive PHI short.

## What changes in a HIPAA workspace

HIPAA mode applies to every chatbot that the BAA account owns. It is not a setting. Only SiteGPT can turn it on or off.

### AI processing

* PHI goes only to three subprocessors: Convex (database), OpenAI (answers and embeddings, on zero-data-retention endpoints only), and Pinecone (vector search). Each one has signed a BAA with SiteGPT. See the PHI section of the [subprocessor list](https://sitegpt.ai/legal/subprocessors).
* SiteGPT does not use PHI to train AI models, and does not let its subprocessors do so.
* Chatbot content in HIPAA workspaces is indexed and searched in a separate namespace and index from standard accounts. HIPAA workspaces share this index. It is not a dedicated environment for each customer.

### The chat widget

* The chat always shows the line "Responses are AI-generated". You cannot turn it off. It stays when you remove SiteGPT branding.

### Content

* **Cloud file connectors are not supported for HIPAA use.** The dashboard does not offer Notion, Google Drive, Dropbox, OneDrive, Box, or GitHub. API v2, the CLI, the SDKs, and MCP also refuse to create, change, authorize, or import from any cloud file connector, including SharePoint and Confluence. They return `403 HIPAA_CONNECTORS_DISABLED`. If SiteGPT cannot check the HIPAA status, they return `503 HIPAA_CHECK_UNAVAILABLE`. Try again later. If your account had connectors before enablement, their scheduled syncs are turned off at enablement. You can still list and revoke existing connections through API v2. You can also ask [support@sitegpt.ai](mailto:support@sitegpt.ai) to revoke them. Add content with website links, file uploads, and text snippets instead.
* **File uploads show a reminder.** You can upload any supported file type. Files are parsed under zero data retention. The upload window reminds you never to upload files that contain PHI.
* If the upload window says the workspace accepts `.txt` files only, other file types are rejected. If it says uploads are unavailable, contact [support@sitegpt.ai](mailto:support@sitegpt.ai).
* **You cannot turn a conversation into a custom response.** The **Incorrect? Modify bot's answer!** link in **Chat History** is not shown. This keeps conversation text out of chatbot content. You can still add custom responses in **Custom Responses**. See [Custom responses](/docs/guides/answers/custom-responses).

### Integrations

* **Chat integrations are not available.** You cannot connect Zendesk, Slack, Messenger, Google Chat, Crisp, Freshdesk, or Zoho after enablement. **Integrations** does not show in the sidebar. Conversations stay in the chat on your website, which the BAA covers. See [Integrations](/docs/integrations/overview#hipaa-workspaces).

* Integrations that were connected before enablement are not disconnected automatically. See [Existing accounts](#existing-accounts).

### Notifications and webhooks

Notifications and webhooks carry no conversation content and no visitor contact details:

* **Emails to your team** (escalation, new lead, new conversation) leave out the visitor's name, email, phone, custom fields, and messages. The escalation email subject leaves out the visitor's name. The email links to the conversation in the dashboard.
* **iPhone push notifications** do not include visitor names or message text. See [Use the SiteGPT iPhone app](/docs/guides/human-support/iphone-app#get-push-notifications).
* **Reply emails to visitors** say only that there is a new response. They do not include your reply. See [Reply and take over](/docs/guides/human-support/reply-and-take-over).
* **Webhooks** send the event and IDs, without messages, sources, or contact details. See [Webhooks](/docs/developers/webhooks#hipaa-mode).
* **The weekly digest email** shows numbers only, with no topics or questions.

### Leads

* Industry templates for lead forms are not available. You choose each field yourself.
* **Leads Settings** shows a warning: "Leads are never auto-deleted. Conversations are redacted after 7 days. Lead records are not. Never collect PHI here."
* If you add a free-text field, the form builder warns you that free-text fields invite PHI.

See [Collect leads](/docs/guides/leads/collect-leads).

### Analytics

* **Conversation insights** are not turned on by a plan upgrade alone in a HIPAA workspace. To use them, contact [support@sitegpt.ai](mailto:support@sitegpt.ai).
* When insights are on, topics come only from your own topic list. Conversations that match none of your topics show as "other". If your list is empty, every conversation shows as "other". Use generic topic labels with no PHI.
* The **Frequently asked questions** grouping does not run.
* SiteGPT's own product analytics and session recording do not run in the dashboard for people who own or are members of a HIPAA workspace.

See [Analytics](/docs/guides/monitor/analytics).

### Chatbot transfers

* You cannot transfer a chatbot to or from an account that has a BAA. See [Manage chatbots](/docs/guides/account/manage-chatbots#transfer-a-chatbot-to-another-owner).

## Retention and redaction

**Conversation content is redacted 7 days after the conversation's last activity.** Your order form can set a different window. A conversation that is still active is not redacted.

What redaction does:

* Each message in the conversation is replaced with "\[Redacted under the HIPAA retention policy]".
* The conversation title, IP address, page URL, and answer sources are removed.
* The content is removed from the production database. You cannot get it back through SiteGPT.
* Counts and totals stay, so your analytics keep working. The link between the conversation and its topics is removed.
* If the visitor sends a new message after redaction, the new message is kept. The earlier messages stay redacted. The retention window starts again from the new message.

Automatic redaction does not delete these records. You must delete them separately:

* **Lead records.** A lead is a contact record that a visitor sent so your team would follow up. Leads stay until you delete them. Managing them is your responsibility.
* **Visitor identity records.** The visitor record that links a visitor's conversations is also kept. To delete it, use **Delete all visitor data** on the lead, or **Delete Visitor Data** in the conversation menu in **Chat History**. See [Manage leads](/docs/guides/leads/manage-leads).

You can delete data yourself at any time: a conversation, a lead, all data for one visitor, content, or a whole chatbot. See [What you can delete](/docs/account/security#what-you-can-delete).

## What you must do

The BAA sets duties for you. In practice:

* Do not send PHI before the written enablement confirmation.
* Keep all chatbot content free of PHI.
* Keep lead forms to basic contact details. Do not add free-text fields that invite people to describe a condition. Delete any lead that contains PHI.
* Use generic topic labels in analytics.
* Never put PHI in a support request.
* Test that the chatbot answers accurately for your use cases before you use it with PHI.
* Let only trained, qualified people use the chatbot and its output for healthcare work.
* Never tell anyone that the chatbot's answers were written by a person.
* Train your staff on their duties under the BAA.

## Limits

* SiteGPT and its answers do not replace the judgment of licensed professionals. The service is not for use as a medical device.
* Some state and federal laws are stricter than HIPAA. You are responsible for checking that your use complies with them.
* BAAs are available on the Enterprise plan only. They are not available on Starter, Growth, or Scale.
* The standard BAA also covers breach notification timelines, subcontractor obligations, and what happens to PHI when the agreement ends. Read the [standard BAA](https://sitegpt.ai/legal/baa) for the terms.

## Questions

Email [bhanu@sitegpt.ai](mailto:bhanu@sitegpt.ai) to request a BAA. Email [support@sitegpt.ai](mailto:support@sitegpt.ai) for other questions. For a vendor review, see [Security and data handling](/docs/account/security#documents-for-a-security-review).
