There is no such thing as HIPAA-certified software. The federal office that enforces the rule does not certify, pre-clear, or endorse any product, and it has said plainly that private "certifications" do not reduce a covered entity's legal obligations. That fact is the floor under this entire page: what follows is about architecture — where your records physically live and who can reach them — because architecture is the part of compliance a system builder can honestly affect. The rest belongs to your counsel or compliance officer, and nothing here replaces them.
Where your data goes is a legal fact, not a technical detail
The consumer tier of a public chatbot and the business tier of the same product are different legal objects. Consumer tiers commonly share conversations for model training by default and retain them under terms the vendor can change. Business and API tiers typically exclude training by default, and formal agreements — such as the business associate agreement a medical or dental practice must have before any vendor touches patient information — are generally available only at those tiers, if at all.
Your staff do not read tier distinctions. Studies of workplace AI use keep finding the same pattern: employees paste real business data into personal accounts because the tab is already open. Which tier of which tool your practice's information flows through is not an IT preference. It is the fact a regulator or opposing counsel will ask about first.
A federal court has already drawn the line
In February 2026, a federal judge in the Southern District of New York ruled that roughly thirty documents a defendant had created using the consumer tier of an AI chatbot — analyses of his own legal exposure, later shared with his lawyers — were protected by neither attorney-client privilege nor the work-product doctrine. The reasoning turned on the platform's terms: data collection, retention, and possible disclosure to third parties negated any reasonable expectation of confidentiality. The judge suggested that counsel-directed use of a tool with contractual data protections might come out differently.
Read that carefully, because it is the whole argument in miniature. The court did not say AI destroys privilege. It said this tier, under these terms, at nobody's direction, destroyed it. The question was architectural.
Someone else's lawsuit can override your retention schedule
In May 2025, a magistrate judge in a copyright case ordered a major AI vendor to preserve conversation logs that would otherwise have been deleted — including conversations users had deleted themselves. The vendor was later ordered to produce twenty million de-identified conversation logs to the plaintiffs.
Sit with what that means for a practice with a records policy. A law firm's destruction schedule, a dental office's retention policy, an adviser's books-and-records program — all of it runs downstream of the vendor's litigation, in a lawsuit the practice is not a party to and cannot influence. No contract you sign with a vendor prevents a court order against that vendor. The only records reliably governed by your policy are the ones on infrastructure your policy actually controls.
What a private deployment changes — and the sentence that must follow it
The private systems we design run the model, the document index, and the logs on infrastructure the client controls — a machine in the office or a private environment in the client's own name. When a staff member asks the system a question about a patient, a client matter, or a return, the question and the answer do not travel to a third-party processor. That removes a specific category of exposure: there is no outside vendor to paper with agreements for that data flow, no training default to audit, no third party whose subpoena becomes your discovery problem.
Here is the sentence that must always follow: keeping records on infrastructure you control is the starting point for a compliance conversation, not a substitute for one. We will say that in writing, before any engagement, because the vendors who say otherwise are the problem this page exists to name.
Each profession's rules already answer the question
The obligations predate the technology; the tool just has to fit inside them. A healthcare vendor that creates, receives, maintains, or transmits patient information is a business associate requiring a signed agreement — full stop. The American Bar Association's Formal Opinion 512, issued in July 2024, requires a lawyer to obtain informed client consent before putting information about a representation into a self-learning AI tool, and says boilerplate engagement-letter language is not sufficient. For tax preparers, federal law makes knowing or reckless disclosure of return information outside preparing the return a crime absent the client's written consent. For broker-dealers and advisers, business communications are records with multi-year retention requirements — which makes an uncaptured chatbot session about a client an off-channel communication problem, a category regulators have fined heavily in recent years.
What architecture cannot make you
A private deployment does not make you compliant. Compliance lives in your risk assessments, your written policies, your staff training, your incident-response plan, your record-keeping — none of which a system builder can do for you. A machine in your office can be misconfigured, left unpatched, unencrypted, or unlogged; on-premise is a posture, not a guarantee, and it has to be maintained like one. A system that never sends data anywhere can still show the wrong record to the wrong employee. And be wary of anyone in this industry who claims otherwise about their own product: the SEC's first enforcement actions for overstated AI claims came in March 2024, against two investment advisers, with about four hundred thousand dollars in combined penalties. Overclaiming is not just tacky. It is an enforcement category. Hold us to that standard too — ask for our claims in writing and take them to your counsel.
Where to start
Make a one-page inventory of every place client or patient information currently touches a third party — practice-management software, transcription tools, and the free chatbot tabs your staff already have open. Do not fix anything yet. Bring the list to your counsel or compliance officer and ask which of those flows they can defend. That inventory is the first document any serious compliance conversation needs, and it costs one honest hour to produce.