Skip to main content
SiteGPT supports healthcare organizations whose chatbot visitors may share Protected Health Information (PHI). Coverage runs under a Business Associate Agreement (BAA), available on the Enterprise plan. This page explains how a covered workspace works: what you can do, what to keep out of the chatbot, and what changes in the dashboard once your account is covered.
Every Enterprise deployment is scoped individually. If anything on this page looks like a blocker for your rollout, email us: most terms are set per deployment, and a short call is usually the fastest way to sort it out.
For BAA availability and the onboarding process, the authoritative source is sitegpt.ai/hipaa. Our standard BAA is published at sitegpt.ai/legal/baa, and audit reports and the current subprocessor list live on the trust portal at trust.sitegpt.ai.

How coverage works

  1. Request a BAA. Email bhanu@sitegpt.ai with a short note about your organization and use case.
  2. Scoping. We walk through your deployment together and confirm the Enterprise order form.
  3. Legal review. Your counsel reviews our standard BAA and sends the specific provisions your organization needs; we tailor our document during onboarding.
  4. Execution and provisioning. Both parties sign, and we provision your workspace in our HIPAA environment.
  5. Written enablement confirmation. We confirm in writing that your workspace is ready. This email is the green light.
Do not submit PHI through SiteGPT until you have received the written enablement confirmation. That includes training content, test conversations, uploaded files, and lead capture. This is a contractual condition, in both our Terms and the BAA.

The one rule

PHI belongs in end-user conversations, and nowhere else. Once your workspace is enabled, patients and visitors can freely share PHI while chatting with your bot, and that conversation data is protected under the BAA. Everything you put into the chatbot must stay PHI-free. For nearly every healthcare chatbot this is the natural shape of the deployment: the knowledge base is your public service information, and PHI only ever arrives in the conversation.

What you can do

  • Let visitors share PHI in the chat widget. Symptoms, conditions, care questions: the conversation channel is what the BAA covers.
  • Review conversations in the dashboard. Chat history, takeover via human support, and chat modes all work normally.
  • Train on your website and documents. Website links, file uploads, text snippets, and custom responses are all available, as long as the content itself contains no PHI. Uploaded files are parsed under zero-data-retention agreements.
  • Collect leads. Lead collection works, with guardrails described below. Lead records are yours and are never deleted on our schedule.
  • Remove SiteGPT branding. White-label is part of Enterprise. One element stays regardless: the “Responses are AI-generated” disclosure is pinned on HIPAA workspaces, required under our own obligations to our AI providers.

What to keep out of the chatbot

  • No PHI in training content. Website pages, uploaded files, snippets, Q&A entries, chatbot instructions, and custom responses must not contain patient information. Keeping the knowledge base PHI-free is what keeps the PHI vendor chain minimal.
  • No PHI in lead forms. Keep lead fields to basic contact details. Avoid free-text fields that invite people to describe a condition, and delete any lead that turns out to contain PHI.
  • No PHI in support emails to us. When you need help with a specific conversation, share the dashboard link, never the content.

What changes in your dashboard

A few features work differently on HIPAA workspaces, always in the direction of keeping PHI inside the covered channel. If one of these would get in the way of your rollout, say so during scoping:
  • Connected apps are unavailable. Notion, Google Drive, Dropbox, OneDrive, Box, GitHub, and other connected-app sources cannot be linked, because they would sync content through vendors outside the covered chain. If you sign a BAA on an account that already has connections, their syncs are switched off as part of enablement. Website links, file uploads, and snippets remain the supported content paths.
  • Chat integrations are unavailable. Helpdesk and messaging integrations (Zendesk, Slack, Crisp, and the rest) are off, because conversations must stay in the HIPAA-covered chat channel rather than flow into third-party chat tools.
  • Lead settings are stricter. Industry form templates are hidden so every field is a deliberate choice, and the form builder warns you when you add a free-text field.
  • AI insights are constrained. Topic analytics classify only against labels your team defines, and conversation text never feeds retained analytics.
  • Notifications are content-free. Email notifications from SiteGPT never include conversation content or visitor contact details; they link you to the dashboard instead.

Retention and deletion

  • Conversation content is redacted 7 days after a conversation’s last activity (the default; the window is configurable in your order form). Redaction replaces the message text; conversation counts and analytics aggregates remain so your reporting keeps working.
  • Leads persist until you delete them. A lead is a contact record someone deliberately submitted so your team would follow up: a referral, not a transcript. Deleting those on a schedule of ours could destroy records you are required to retain, so managing them is your call. You can export leads to CSV and delete them from the dashboard at any time.
  • You can delete anything yourself: individual conversations, trained content, leads, or the whole chatbot.

Behind the scenes

  • Your HIPAA workspace runs in a dedicated processing environment, separate from standard accounts, and every vendor that touches PHI in your deployment operates under a signed BAA before we execute yours.
  • Your data is never used to train AI models, by us or by our AI subprocessors.
  • Operational logs contain no conversation content.
  • The current subprocessor list is published at sitegpt.ai/legal/subprocessors.

If your deployment needs something different

Every Enterprise deployment is scoped individually, and the order form is where per-deployment terms live: the conversation retention window, quotas and volumes, white-label, and anything else specific to your rollout. If a rule on this page looks like a blocker for your deployment, mention it when we talk and we will tell you which terms can be adjusted. The BAA is tailorable too. During onboarding we adjust our standard BAA to your organization’s requirements: retention windows, breach notice timelines, notice contacts, and scoping. Have your counsel review our draft and send the specific provisions you need, and we will work them into our document wherever we can.

Questions

Email bhanu@sitegpt.ai to request a BAA, or support@sitegpt.ai for anything else. For vendor reviews, start at trust.sitegpt.ai.