Every Enterprise deployment is scoped individually. If anything on this page
looks like a blocker for your rollout, email
us: most terms are set per deployment, and a short
call is usually the fastest way to sort it out.
How coverage works
- Request a BAA. Email bhanu@sitegpt.ai with a short note about your organization and use case.
- Scoping. We walk through your deployment together and confirm the Enterprise order form.
- Legal review. Your counsel reviews our standard BAA and sends the specific provisions your organization needs; we tailor our document during onboarding.
- Execution and provisioning. Both parties sign, and we provision your workspace in our HIPAA environment.
- Written enablement confirmation. We confirm in writing that your workspace is ready. This email is the green light.
The one rule
PHI belongs in end-user conversations, and nowhere else. Once your workspace is enabled, patients and visitors can freely share PHI while chatting with your bot, and that conversation data is protected under the BAA. Everything you put into the chatbot must stay PHI-free. For nearly every healthcare chatbot this is the natural shape of the deployment: the knowledge base is your public service information, and PHI only ever arrives in the conversation.What you can do
- Let visitors share PHI in the chat widget. Symptoms, conditions, care questions: the conversation channel is what the BAA covers.
- Review conversations in the dashboard. Chat history, takeover via human support, and chat modes all work normally.
- Train on your website and documents. Website links, file uploads, text snippets, and custom responses are all available, as long as the content itself contains no PHI. Uploaded files are parsed under zero-data-retention agreements.
- Collect leads. Lead collection works, with guardrails described below. Lead records are yours and are never deleted on our schedule.
- Remove SiteGPT branding. White-label is part of Enterprise. One element stays regardless: the “Responses are AI-generated” disclosure is pinned on HIPAA workspaces, required under our own obligations to our AI providers.
What to keep out of the chatbot
- No PHI in training content. Website pages, uploaded files, snippets, Q&A entries, chatbot instructions, and custom responses must not contain patient information. Keeping the knowledge base PHI-free is what keeps the PHI vendor chain minimal.
- No PHI in lead forms. Keep lead fields to basic contact details. Avoid free-text fields that invite people to describe a condition, and delete any lead that turns out to contain PHI.
- No PHI in support emails to us. When you need help with a specific conversation, share the dashboard link, never the content.
What changes in your dashboard
A few features work differently on HIPAA workspaces, always in the direction of keeping PHI inside the covered channel. If one of these would get in the way of your rollout, say so during scoping:- Connected apps are unavailable. Notion, Google Drive, Dropbox, OneDrive, Box, GitHub, and other connected-app sources cannot be linked, because they would sync content through vendors outside the covered chain. If you sign a BAA on an account that already has connections, their syncs are switched off as part of enablement. Website links, file uploads, and snippets remain the supported content paths.
- Chat integrations are unavailable. Helpdesk and messaging integrations (Zendesk, Slack, Crisp, and the rest) are off, because conversations must stay in the HIPAA-covered chat channel rather than flow into third-party chat tools.
- Lead settings are stricter. Industry form templates are hidden so every field is a deliberate choice, and the form builder warns you when you add a free-text field.
- AI insights are constrained. Topic analytics classify only against labels your team defines, and conversation text never feeds retained analytics.
- Notifications are content-free. Email notifications from SiteGPT never include conversation content or visitor contact details; they link you to the dashboard instead.
Retention and deletion
- Conversation content is redacted 7 days after a conversation’s last activity (the default; the window is configurable in your order form). Redaction replaces the message text; conversation counts and analytics aggregates remain so your reporting keeps working.
- Leads persist until you delete them. A lead is a contact record someone deliberately submitted so your team would follow up: a referral, not a transcript. Deleting those on a schedule of ours could destroy records you are required to retain, so managing them is your call. You can export leads to CSV and delete them from the dashboard at any time.
- You can delete anything yourself: individual conversations, trained content, leads, or the whole chatbot.
Behind the scenes
- Your HIPAA workspace runs in a dedicated processing environment, separate from standard accounts, and every vendor that touches PHI in your deployment operates under a signed BAA before we execute yours.
- Your data is never used to train AI models, by us or by our AI subprocessors.
- Operational logs contain no conversation content.
- The current subprocessor list is published at sitegpt.ai/legal/subprocessors.