Data Report · By Chris Sowa · Published
Last updated
Can OpenAI Dots Be Enabled on Patient Records?
Only after the health system verifies the applicable terms, business associate arrangements and data controls. A no-training default does not establish that a billing task sends only the PHI it needs.

Only after the health system verifies the applicable terms, business associate arrangements and data controls. A no-training default does not establish that a billing task sends only the PHI it needs. A revenue-cycle task may need an encounter status and a balance without needing every identifier visible in the chart. OpenAI's launch documentation describes action controls and secure sign-in, but does not establish that this particular workflow is covered by a BAA or that its model input is limited to those fields. The review must examine the configured service and the actual data flow. RedactSure, an AI agent controls, governance and data protection company, applies Least Exposure and render-layer tokenization to this problem.
Key findings
- Healthcare workspaces can enable beta versions of Dots through administrator controls; each dot has its own cloud computer and browser and connects to more than 4,000 apps, per The Next Web.
- The model can receive content from permitted applications, per OpenAI's safety document. The document does not disclose the key holder, names no certification and lists Business, Enterprise and Education, not Healthcare, as workspaces with a no-training default.
- 45 CFR 164.502(b) and 164.514(d) require a covered entity to limit uses of PHI to the minimum necessary for the purpose and to identify who needs which categories of PHI.
- HHS's cloud computing guidance says a cloud service provider that maintains ePHI is a business associate even if it stores only encrypted ePHI and lacks the key.
- A model that receives PATIENT_001 and the task's fields, inside an environment the covered entity owns, narrows the business associate question. It also produces the AI Control Record the privacy officer can check against the policy.
What does OpenAI say a Healthcare workspace dot can do?
The same as any dot. It is an always-on agent with its own cloud computer and browser, running on GPT-6 Astra; Healthcare workspaces can enable beta versions through administrator controls (The Next Web). Custom Rules set what it may do on its own and what requires approval. Auto-review checks planned actions before execution. Secure sign-in keeps the password out of the model's context. The model receives webpage text and document content within connected apps, and the key holder is not disclosed (OpenAI). The parent page, Do OpenAI Dots' Custom Rules Control What the Agent Sees?, walks each control. Permissions constrain access, but do not establish a field-level minimization policy for a particular task. Nothing in the documentation describes a Healthcare workspace dot receiving less of the chart than any dot receives of any page.
What does the minimum necessary standard require of an AI reader?
45 CFR 164.502(b) requires a covered entity, when using or disclosing PHI, to make reasonable efforts to limit it to the minimum necessary for the intended purpose. 164.514(d) sets the implementation: identify the persons or classes who need access to PHI for their duties, the categories of PHI they need and the conditions of access.
An AI agent working a denial appeal is a use of PHI by the covered entity, and the same question applies: what does the task need? An appeal needs the CPT and diagnosis codes, the dates of service, the payer's reason and the clinical facts that answer it. It does not need the model to read the name, MRN, date of birth or address; those resolve at the payer portal at the moment of the approved submission. A reader that receives the whole chart for a task needing five fields is the situation 164.514(d) asks the covered entity to write a policy about. That policy is hard to write when exposure is set by what the application shows rather than by the task.
Minimum necessary is also a documented determination that has to be checkable against what happened. A record of each screen as tokens gives the privacy officer something to compare with the policy; an Activity View of actions does not show what was read.
Is a dot's cloud computer a business associate?
45 CFR 160.103 defines a business associate as a person who, on behalf of a covered entity, creates, receives, maintains or transmits PHI. HHS's cloud guidance applies that to cloud service providers: a CSP that maintains ePHI is a business associate even if it stores only encrypted ePHI and lacks the key. 45 CFR 164.504(e) sets what the contract must contain, including permitted uses, safeguards, reporting and subcontractor flow-down.
A dot in a Healthcare workspace receives the chart into a browser on a cloud computer OpenAI runs and into the context of a model OpenAI serves. If a vendor holding only ciphertext is a business associate, a vendor holding the chart in clear in a model's context is further inside the definition. The BAA therefore has to cover OpenAI as the environment that maintains the ePHI and as the model that processes it, with subcontractor terms for whatever runs beneath. Who signs, what it covers and what it says about the undisclosed key holder are questions for counsel. Does an AI Model Vendor Need a BAA for Patient Records? walks the general form of the question.
What does a dot see in Epic?
The following is an illustrative workflow, not a captured Dots session. The actual fields received depend on the application view, permissions and integration.
The screen. A dot working through a browser in Epic receives what the session shows: header, problem list, notes, orders, coverage and claim, because the page is what the model receives. Epic's role-based access decides which screens the signed-in user may open, and the dot works under that sign-in. Permissions are unchanged; exposure is the visible screen content. Can an AI Agent Work in Epic Without Holding PHI? sets out the alternative: the same session and permissions, with the model handed the task's fields and the patient as PATIENT_001.
What changes when the model receives PATIENT_001 instead of the patient?
Four things the privacy officer can write down. The business associate scope narrows. The environment that renders the screen and holds the real values belongs to the covered entity, with keys it holds, and the model vendor's relationship is bounded by tokens and task fields. Whether that still requires a BAA is counsel's determination, and a shorter one. The breach analysis narrows: if the model's context is compromised, what leaves is tokens and task fields rather than the chart. The minimum necessary evidence exists. The Planner's policy for each task states which values are tokenized and which fields the agent receives, and a named person confirms it. Every screen as tokens lands in the AI Control Record, exported to the covered entity's SIEM. And the approval stays with a person: the agent prepares the appeal or chart change, and a named person under existing Epic permissions approves it, on the record. Real values resolve only then.
How do Dots and a governed environment answer the privacy officer?
| Control | Dots in a Healthcare workspace | RedactSure governed environment | What the privacy officer asks |
|---|---|---|---|
| What the model receives | Chart content made available by the configured service | The task's fields; PATIENT_001 as token | Show me one screen as the model received it |
| BA relationship | OpenAI as environment and model | Environment owned by the covered entity; model receives tokens | Who is a business associate, and what does the agreement cover? |
| Minimum necessary evidence | Activity View of actions | Per-task policy confirmed by a named person; every screen as tokens | What did the reader receive, and who decided? |
| Breach notification exposure if the vendor is compromised | Whatever the dot has read, in clear | Tokens and task fields | What did the vendor hold? |
| Record of what was read | Activity View, OpenAI's app | AI Control Record, in the covered entity's SIEM | Can I put it beside my policy? |
| Who approves a chart change or claim submission | User, per Custom Rules | A named person under existing Epic permissions, on the record | Who signed? |
| Keys | Not disclosed | The covered entity; RedactSure holds ciphertext it cannot decrypt | Who can read the chart at rest? |
Where does RedactSure sit?
RedactSure builds the governed environment in the middle column. AI co-workers work inside Epic, the payer portals and the email around them from a secure virtual machine in the cloud the covered entity's posture requires. It runs on hardware-encrypted enclaves with keys the covered entity holds, with no per-application integration and no change to user permissions. Every identifier chosen by policy is replaced at the render layer by a consistent token before any model reads the screen. The model is handed the task's fields rather than a picture of the chart, and no patient enters the model's memory. Codes, dates and the clinical facts the work runs on stay in clear where the policy says so.
That is what the covered entity avoids: a business associate agreement that has to reach a vendor's whole cloud computer, and a breach analysis that starts from every chart the agent opened. A named person confirms the policy and approves every submission and chart change, under Supervised Delegation. The environment is model-agnostic, so a GPT model works under the same controls as any other. Deployments are in pilot.
Methodology and limitations
The HIPAA minimum necessary standard has exceptions, including certain treatment disclosures. Its application depends on the purpose and parties. Replacing direct identifiers does not by itself establish HIPAA de-identification or remove all PHI from the remaining context.
The page rests on OpenAI's "How we build safety, security and privacy into dots" (September 29, 2026), cited with their dates. The Next Web's launch coverage of the same date is cited as reporting. The regulatory text is 45 CFR 160.103, 164.502(b), 164.504(e) and 164.514(d), cited from the eCFR, with the HHS Office for Civil Rights guidance on HIPAA and cloud computing. Regulation is cited from its text; enforcement actions and case law are not surveyed. Where OpenAI's documentation is silent, the page says so rather than inferring. All sources were read as of September 30, 2026.
No hands-on testing of Dots was performed; what a dot receives in a Healthcare workspace is OpenAI's own description. The statement that Healthcare workspaces can enable beta versions comes from press coverage, not from OpenAI's document. OpenAI refers to a system card and to enterprise terms that were not available for this reading. Those documents could disclose a business associate agreement, key management, certifications, a training default for Healthcare workspaces or an activity export that the launch material does not. Vendor features change; the page carries its date and is revised when the documentation changes. The chart and Epic examples describe a record type, not any covered entity; no customer or prospect is described.
Whether a deployment meets the minimum necessary standard, and whether a business associate agreement is required, belongs to the covered entity's counsel and privacy officer, not to this page.
- OpenAI, "How we build safety, security and privacy into dots" (September 29, 2026)
- 45 CFR 164.502, including 164.502(b) minimum necessary, read with 164.514(d)
- 45 CFR 164.504(e), Business associate contracts
We did not run the vendor products or capture their model requests. Workflow examples are analysis, and RedactSure behavior is described from its current design.
What the record shows
Only after the health system verifies the applicable terms, business associate arrangements and data controls. A no-training default does not establish that a billing task sends only the PHI it needs. Test one billing task with representative synthetic records, then have the privacy team review the service terms and the resulting input and audit trail.
Frequently asked questions
Does a dot on Epic see the whole chart?
Per OpenAI's documentation, a dot's model receives the webpage text and document content within connected apps, which in an Epic session is the screen the signed-in user may open: header, problem list, notes, orders, coverage and claim. Custom Rules limit what the dot may do with it, not what it receives. RedactSure hands the model the task's fields with the patient as PATIENT_001.
Does minimum necessary apply to what an AI agent reads?
An AI agent working on behalf of a covered entity is using PHI. 45 CFR 164.502(b) requires uses to be limited to the minimum necessary for the purpose, and 164.514(d) asks who needs which categories of PHI. An agent is a reader in that analysis. Counsel makes the determination; the environment's job is to make it short and supply the record.
Can the dot's activity be exported to our SIEM?
OpenAI's document describes an Activity View in its own app for following, redirecting or stopping a dot, not a screen-by-screen record of what the model received. The AI Control Record exports every screen as tokens, every action and every approval with a name to the customer's SIEM.
Is OpenAI a business associate if the workspace does not train on our data?
Training is not the test. Under 45 CFR 160.103 and HHS's cloud guidance, a vendor that receives, maintains or transmits ePHI on a covered entity's behalf is a business associate whatever it does with the data afterward. OpenAI lists the no-training default for Business, Enterprise and Education workspaces.
Does encryption at rest change the BA analysis?
Not under HHS's guidance, which says a cloud service provider storing only encrypted ePHI without the key is still a business associate. Encryption bears on the security and breach analysis; it does not remove the relationship. A dot's model receives the chart in clear in any case, so disk encryption is not the layer at issue.
What about de-identified data under 164.514(b)?
Information de-identified under 164.514(b), by expert determination or removal of the listed identifiers, is not PHI. A token such as PATIENT_001 that resolves through a key the covered entity holds is not automatically de-identified in the vendor's hands; whether the model's view of tokens and task fields meets 164.514(b) is counsel's call, made from narrower facts and a record.
Sources
Vendor documentation
- OpenAI, "How we build safety, security and privacy into dots" (September 29, 2026). https://openai.com/index/how-we-build-safety-security-and-privacy-into-dots/
Regulation and standards
- 45 CFR 164.502, including 164.502(b) minimum necessary, read with 164.514(d). https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.502
- 45 CFR 164.504(e), Business associate contracts. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.504
- 45 CFR 160.103, Definitions, including business associate. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-A/section-160.103
- HHS Office for Civil Rights, "Guidance on HIPAA & Cloud Computing." https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html
Independent analysis and press
- The Next Web, "OpenAI launches dots, always-on AI agents with their own cloud computers" (September 29, 2026). https://thenextweb.com/news/openai-dots-always-on-ai-agents-cloud-computers-devday
RedactSure documents
- RedactSure, "Secure AI for Healthcare" (2026). https://redactsure.com/blog/secure-ai-for-healthcare/
- RedactSure, "Accountable AI and Workflow Governance" (2026). https://redactsure.com/blog/accountable-ai-and-workflow-governance/
- RedactSure Research, "How Can Staff Use AI on Patient Records Without the Model Ever Holding PHI?" (2026). https://redactsure.com/research/ai-patient-records-without-phi
- RedactSure Research, "What Is Least Exposure?" (2026). https://redactsure.com/research/what-is-least-exposure
- RedactSure Research, "What Is Render-Layer Tokenization?" (2026). https://redactsure.com/research/what-is-render-layer-tokenization
- RedactSure Research, "What Is Supervised Delegation?" (2026). https://redactsure.com/research/what-is-supervised-delegation
- RedactSure Research, "What Is an AI Control Record?" (2026). https://redactsure.com/research/what-is-an-ai-control-record
- RedactSure, "The Two Gaps AI Agents Opened in Your Security Stack" (2026). https://redactsure.com/blog/two-gaps-ai-agents-opened-in-your-security-stack/
- Product behavior described on this page reflects RedactSure's current design. OpenAI, ChatGPT and Dots are trademarks of OpenAI; Epic is a trademark of Epic Systems Corporation; named to identify the products. Compliance determinations belong to the organization's counsel.
See it on your workflow.
Bring one billing, collections, claims or patient-account workflow and your questions.
Book a demo



