> ## Documentation Index
> Fetch the complete documentation index at: https://sitegpt.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Using SiteGPT under HIPAA

> How HIPAA-covered deployments work on SiteGPT, from BAA to go-live.

SiteGPT supports healthcare organizations whose chatbot visitors may share
Protected Health Information (PHI). Coverage runs under a Business Associate
Agreement (BAA), available on the **Enterprise plan**. This page explains how
a covered workspace works: what you can do, what to keep out of the chatbot,
and what changes in the dashboard once your account is covered.

<Note>
  Every Enterprise deployment is scoped individually. If anything on this page
  looks like a blocker for your rollout, [email
  us](mailto:bhanu@sitegpt.ai): most terms are set per deployment, and a short
  call is usually the fastest way to sort it out.
</Note>

For BAA availability and the onboarding process, the authoritative source is
[sitegpt.ai/hipaa](https://sitegpt.ai/hipaa). Our standard BAA is published at
[sitegpt.ai/legal/baa](https://sitegpt.ai/legal/baa), and audit reports and the
current subprocessor list live on the trust portal at
[trust.sitegpt.ai](https://trust.sitegpt.ai).

## How coverage works

1. **Request a BAA.** Email [bhanu@sitegpt.ai](mailto:bhanu@sitegpt.ai) with a
   short note about your organization and use case.
2. **Scoping.** We walk through your deployment together and confirm the
   Enterprise order form.
3. **Legal review.** Your counsel reviews our standard BAA and sends the
   specific provisions your organization needs; we tailor our document
   during onboarding.
4. **Execution and provisioning.** Both parties sign, and we provision your
   workspace in our HIPAA environment.
5. **Written enablement confirmation.** We confirm in writing that your
   workspace is ready. This email is the green light.

<Warning>
  Do not submit PHI through SiteGPT until you have received the written
  enablement confirmation. That includes training content, test conversations,
  uploaded files, and lead capture. This is a contractual condition, in both
  our [Terms](https://sitegpt.ai/legal/terms) and the BAA.
</Warning>

## The one rule

**PHI belongs in end-user conversations, and nowhere else.** Once your
workspace is enabled, patients and visitors can freely share PHI while
chatting with your bot, and that conversation data is protected under the BAA.
Everything you put *into* the chatbot must stay PHI-free.

For nearly every healthcare chatbot this is the natural shape of the
deployment: the knowledge base is your public service information, and PHI
only ever arrives in the conversation.

## What you can do

* **Let visitors share PHI in the chat widget.** Symptoms, conditions, care
  questions: the conversation channel is what the BAA covers.
* **Review conversations in the dashboard.** [Chat
  history](/docs/navigating-your-chatbot/chat-history), takeover via [human
  support](/docs/features/human-support), and chat modes all work normally.
* **Train on your website and documents.** [Website
  links](/docs/content/website-links), [file uploads](/docs/content/files), [text
  snippets](/docs/features/text-snippets), and [custom
  responses](/docs/features/custom-responses) are all available, as long as the
  content itself contains no PHI. Uploaded files are parsed under
  zero-data-retention agreements.
* **Collect leads.** [Lead collection](/docs/features/lead-collection) works, with
  guardrails described below. Lead records are yours and are never deleted on
  our schedule.
* **Remove SiteGPT branding.** White-label is part of Enterprise. One element
  stays regardless: the "Responses are AI-generated" disclosure is pinned on
  HIPAA workspaces, required under our own obligations to our AI providers.

## What to keep out of the chatbot

* **No PHI in training content.** Website pages, uploaded files, snippets,
  Q\&A entries, chatbot instructions, and custom responses must not contain
  patient information. Keeping the knowledge base PHI-free is what keeps the
  PHI vendor chain minimal.
* **No PHI in lead forms.** Keep lead fields to basic contact details. Avoid
  free-text fields that invite people to describe a condition, and delete any
  lead that turns out to contain PHI.
* **No PHI in support emails to us.** When you need help with a specific
  conversation, share the dashboard link, never the content.

## What changes in your dashboard

A few features work differently on HIPAA workspaces, always in the direction
of keeping PHI inside the covered channel. If one of these would get in the
way of your rollout, say so during scoping:

* **Connected apps are unavailable.** Notion, Google Drive, Dropbox, OneDrive,
  Box, GitHub, and other connected-app sources cannot be linked, because they
  would sync content through vendors outside the covered chain. If you sign a
  BAA on an account that already has connections, their syncs are switched off
  as part of enablement. Website links, file uploads, and snippets remain the
  supported content paths.
* **Chat integrations are unavailable.** Helpdesk and messaging integrations
  (Zendesk, Slack, Crisp, and the rest) are off, because conversations must
  stay in the HIPAA-covered chat channel rather than flow into third-party
  chat tools.
* **Lead settings are stricter.** Industry form templates are hidden so every
  field is a deliberate choice, and the form builder warns you when you add a
  free-text field.
* **AI insights are constrained.** Topic analytics classify only against
  labels your team defines, and conversation text never feeds retained
  analytics.
* **Notifications are content-free.** Email notifications from SiteGPT never
  include conversation content or visitor contact details; they link you to
  the dashboard instead.

## Retention and deletion

* **Conversation content is redacted 7 days after a conversation's last
  activity** (the default; the window is configurable in your order form).
  Redaction replaces the message text; conversation counts and analytics
  aggregates remain so your reporting keeps working.
* **Leads persist until you delete them.** A lead is a contact record someone
  deliberately submitted so your team would follow up: a referral, not a
  transcript. Deleting those on a schedule of ours could destroy records you
  are required to retain, so managing them is your call. You can export leads
  to CSV and delete them from the dashboard at any time.
* **You can delete anything yourself**: individual conversations, trained
  content, leads, or the [whole
  chatbot](/docs/navigating-your-chatbot/delete-chatbot).

## Behind the scenes

* Your HIPAA workspace runs in a dedicated processing environment, separate
  from standard accounts, and every vendor that touches PHI in your deployment
  operates under a signed BAA before we execute yours.
* Your data is never used to train AI models, by us or by our AI
  subprocessors.
* Operational logs contain no conversation content.
* The current subprocessor list is published at
  [sitegpt.ai/legal/subprocessors](https://sitegpt.ai/legal/subprocessors).

## If your deployment needs something different

Every Enterprise deployment is scoped individually, and the order form is
where per-deployment terms live: the conversation retention window, quotas
and volumes, white-label, and anything else specific to your rollout. If a
rule on this page looks like a blocker for your deployment, mention it when
we talk and we will tell you which terms can be adjusted.

The BAA is tailorable too. During onboarding we adjust our standard BAA to
your organization's requirements: retention windows, breach notice
timelines, notice contacts, and scoping. Have your counsel review our draft
and send the specific provisions you need, and we will work them into our
document wherever we can.

## Questions

Email [bhanu@sitegpt.ai](mailto:bhanu@sitegpt.ai) to request a BAA, or
[support@sitegpt.ai](mailto:support@sitegpt.ai) for anything else. For vendor
reviews, start at [trust.sitegpt.ai](https://trust.sitegpt.ai).
