October 7, 2026. OpenAI added a self-serve Business Associate Agreement to its API Platform on October 5, according to the API changelog. An admin of an eligible organization can now accept the standard BAA in the organization settings and switch on HIPAA compliance support, with no enterprise agreement required. Self-serve enrollment needs an established history of API usage, the switch cannot be turned off in settings afterwards, and protected health information has to stay on the 23 endpoints OpenAI lists as eligible, which include the Realtime voice endpoint. Here is what changed and what it means for anyone building an AI receptionist or intake agent for a medical practice.

What changed on October 5
- The BAA is a settings page, not a sales call. Per OpenAI's Help Center guide, an organization admin opens Settings, then Organization, then General, selects Enable under HIPAA compliance support, reviews the Business Associate and Healthcare Addendum and confirms the organization name and ID. The section then shows Active.
- Eligibility is usage-based. An enterprise agreement is not required, but self-serve enrollment requires an established history of API usage. An organization that does not meet the requirements sees Not eligible yet. The person accepting must be an admin with authority to sign for the organization.
- It is one-way. Once HIPAA compliance support is enabled, it cannot be disabled in the API Platform settings.
- Custom terms still go by email. Organizations that need a tailored BAA can write to [email protected], and agreements arranged outside the self-serve flow cannot be downloaded through the setting.
Which endpoints the BAA covers
OpenAI's list of HIPAA eligible products says API eligibility requires an executed BAA and, unless OpenAI specifies otherwise, an organization provisioned with Modified Retention. With both in place, PHI can go through 23 listed endpoints, including /v1/responses, /v1/chat/completions, the new /v1/decisions, /v1/audio/transcriptions, /v1/audio/speech, /v1/realtime and /v1/live/sessions. For a voice agent, that means the speech-to-speech leg on the Realtime API can sit under the BAA. Anything not on the list is outside it, so check new features against the page before you route patient data through them.
What it means for a medical AI receptionist
OpenAI's BAA covers the data OpenAI processes, and a phone agent touches more systems than the model. The US Department of Health and Human Services says a business associate includes any subcontractor that creates, receives, maintains or transmits PHI on behalf of another business associate, and the HIPAA rules require agreements between business associates and their subcontractors. So the phone carrier, any voice platform between the caller and the model, and the scheduling system or CRM that stores the appointment each need their own BAA. Our comparison of HIPAA compliant AI receptionists shows which voice platforms sign one and on which plan, and Anthropic made the same move for Claude in July with its self-serve HIPAA setup.
What to do before you send patient data
Check the BAA section first: Not eligible yet means your organization does not meet the self-serve requirements, and OpenAI's guide points organizations that need custom terms to [email protected]. Because the switch cannot be undone in settings, keep healthcare work in its own API organization rather than enabling HIPAA support on the one that runs everything else. Confirm the retention setting the eligibility page requires, keep PHI on the listed endpoints, and download the agreement once the status shows Active.
If the agent also places outbound calls, such as appointment reminders or recall campaigns, HIPAA is only half the compliance work: the consent rules in our TCPA-compliant AI calling setup apply too. We build AI receptionists for healthcare on this stack, with the BAA chain mapped before the first patient call.
Frequently Asked Questions
OpenAI offers HIPAA compliance support for the API under a Business Associate Agreement. Since October 5, 2026, eligible organizations can accept the standard BAA in their API organization settings. API eligibility also requires Modified Retention unless OpenAI specifies otherwise, and PHI is covered only on the endpoints OpenAI lists as HIPAA eligible.
No. OpenAI says an enterprise agreement is not required to sign a BAA for API services. Self-serve enrollment requires an established history of API usage, and organizations that do not qualify see Not eligible yet. Custom BAA terms can be requested at [email protected].
Yes, the /v1/realtime and /v1/live/sessions endpoints are on OpenAI's list of HIPAA eligible API endpoints, along with audio transcription, audio speech, the Responses API and Chat Completions. Other vendors in a phone agent's chain, such as the carrier and the voice platform, need their own BAAs.
Not in the API Platform settings. OpenAI's Help Center says that once HIPAA compliance support is enabled for an organization, it cannot be disabled there, so it is worth keeping healthcare workloads in a separate API organization.