How HIPAA-compliant is ChatGPT Enterprise, really?
OpenAI signs a BAA. That's necessary but not sufficient. Here's what actually happens to PHI in ChatGPT Enterprise, and where the gaps that matter to a privacy officer hide.
Sanolith Blog
Engineering posts on PHI redaction, per-tenant fine-tuning, audit trails, and what actually goes into a clinical-grade AI workspace. No fluff. No "AI is transforming healthcare." Just the technical and operational details that matter to teams shipping this work.
OpenAI signs a BAA. That's necessary but not sufficient. Here's what actually happens to PHI in ChatGPT Enterprise, and where the gaps that matter to a privacy officer hide.
Most healthcare AI marketing says 'we have a redactor.' Few say what it catches, what happens when it errors, and why fail-closed is non-negotiable.
Shared models memorize training data. Per-tenant fine-tuning is the only way to specialize a model for your team without your data leaking to someone else's queries. Here's how it actually works.