Yes, conditionally — the line runs straight through the middle of the product. OpenAI's HIPAA Implementation and Configuration Guide, part of the BAA, covers "Codex Local" — clearly the Codex CLI and the Codex IDE extension — but only on a HIPAA-eligible ChatGPT account whose Codex Local workplace setting reads HIPAA-eligible, which an Account Director switches on. Codex Cloud is excluded outright, the Codex Desktop app sits on a boundary the contract leaves unclear, and covered Codex Local still excludes web search, connectors and MCP servers.
| Fact | Value |
|---|---|
| Tool | Openai |
| Verdict | Yes, with conditions |
| Sources checked | August 2026 |
| Typical range | $13,000–$25,000 |
| Typical timeline | 6–10 weeks |
| Last updated | August 2026 |
Which Codex surfaces the BAA actually reaches
"Covered" here means named as covered in OpenAI's HIPAA Implementation and Configuration Guide, the document whose header states it "is part of the Business Associate and Healthcare Addendum and (the \"BAA\") between Customer and OpenAI." That guide outranks the help centre because it is contract text. There are two guides, both dated 9 July 2026, and they split by product tier: the one that covers Codex Local applies to customers whose BAA includes ChatGPT for Healthcare, ChatGPT for Clinicians, ChatGPT Enterprise or Education with the Regulated Workspace, or any other ChatGPT service; the general one, for everyone else, lists Codex under Unsupported Features. Read alone, that first applicability clause looks wide — it ends "or any other ChatGPT service" — so what actually makes the split operative is the other guide scoping itself out: "Please note this HIPAA Guide does not apply if you are using ChatGPT for Healthcare or ChatGPT Enterprise or Edu with the Regulated Workspace." Every row below assumes a signed BAA — without one, none of this applies.
Your PHI
Your Openai app
Inside the agreement — PHI may live here
- Compliance API audit records (ChatGPT-authenticated usage)
- Codex Local — Codex CLI, on a HIPAA-eligible ChatGPT account· conditional
- Codex Local — Codex IDE extension, on a HIPAA-eligible ChatGPT account· conditional
- Codex Local driven by a customer-provided OpenAI API key· conditional
Outside it — PHI here is a gap
- Codex Local — Codex Desktop app (the ChatGPT desktop app), on a HIPAA-eligible ChatGPT account
- Codex Cloud (including cloud-hosted task execution)
- Codex on a workspace without the Healthcare, Clinicians or Regulated Workspace tier
- Web search from inside Codex Local
- MCP servers and connectors reached from a Codex session
- Plugins in the Codex Desktop app and Codex CLI
- Execution of the Codex Local Client on your own machines
- ChatGPT Business
- Event-triggered scheduled tasks in connected apps
- API endpoints outside the HIPAA-Eligible Endpoints list, or an API account without Modified Retention
| Service | Under the BAA | Condition |
|---|---|---|
| Codex Local — Codex CLI, on a HIPAA-eligible ChatGPT account | Conditional | Covered for data OpenAI receives, but only once the Codex Local workplace setting indicates HIPAA-eligible and an Account Director has enabled HIPAA coverage. Until then the switch is off, whatever the plan says. |
| Codex Local — Codex IDE extension, on a HIPAA-eligible ChatGPT account | Conditional | Same gating as the CLI. This is the one local client where plugins are not available at all, which narrows its third-party surface relative to the other two. |
| Codex Local — Codex Desktop app (the ChatGPT desktop app), on a HIPAA-eligible ChatGPT account | Unconfirmed | One surface, two readings, and we are flagging rather than resolving it. Section 4.3 lists Codex Desktop among the covered Local Clients, and OpenAI's Codex configuration guide describes Codex Local as including the ChatGPT desktop app alongside the IDE extension and the CLI. But the contract's definition of Codex Cloud in section 4.1 also reaches "any Codex functionality accessed via ChatGPT Enterprise via the web or applications", and the boundary is not clear on the face of the document. The CLI gating applies here too — workplace setting plus Account Director — and on top of it, ask your Account Director to put the Local-versus-Cloud line for the desktop app in writing before you route PHI through it. |
| Codex Cloud (including cloud-hosted task execution) | Not covered | Excluded by name: "Codex Cloud is not an Eligible Service and is not covered by the BAA, Customer may not upload, transmit, or process PHI using Codex Cloud." The configuration guide repeats it in bold. |
| Codex on a workspace without the Healthcare, Clinicians or Regulated Workspace tier | Not covered | The general HIPAA Guide lists Codex under "Unsupported Features" — features that "have not been evaluated by OpenAI for HIPAA compliance at this time and may not be used with PHI" — and names both the "Codex Local" and "Codex Cloud" toggles as the way to disable it. |
| Codex Local driven by a customer-provided OpenAI API key | Conditional | Covered only if your BAA, in the contract's wording, "includes the API Services as an Eligible Service" — and, as a separate condition stated in the guide's API section and repeated by OpenAI's help centre, only once OpenAI has provisioned that API organisation with Modified Retention. With API-key sign-in the ChatGPT workspace controls stop applying — retention, data-sharing and admin settings follow the API organisation instead. |
| Web search from inside Codex Local | Not covered | Excluded by definition: "Codex Local excludes Codex Cloud, cloud-hosted task execution, web search, connectors, MCP servers, and any Third-Party Services." Note the asymmetry — ChatGPT's own Web Search and Deep Research are listed as covered functionality, served from OpenAI's index rather than a third-party search provider. That does not carry over into the definition of Codex Local. |
| MCP servers and connectors reached from a Codex session | Not covered | Excluded by the same definition, and restated as customer responsibility: OpenAI's BAA "doesn't make another vendor a HIPAA-compliant destination." Each MCP server, connector, GitHub integration or browser destination needs its own agreement. |
| Plugins in the Codex Desktop app and Codex CLI | Unconfirmed | OpenAI's configuration guide states that the Codex Desktop app and the Codex CLI support plugins, which can include connectors and skills, and that plugins are not available in the IDE extension. The connector portion is excluded by the contract's own definition, which carves out "connectors, MCP servers, and any Third-Party Services" from Codex Local. On skills specifically we found no OpenAI document that addresses them either way — so the row splits: treat connector-style plugins as outside the BAA, and treat skills as an open question rather than a cleared one. |
| Execution of the Codex Local Client on your own machines | Not covered | Stated plainly: the BAA "does not apply to the execution of the Codex Local Client on Customer's client machines". Local history files, session transcripts, logs and caches are yours to control. |
| ChatGPT Business | Not covered | "Please note that we don't offer a BAA for ChatGPT Business." Enterprise and Edu qualify only on sales-managed accounts. |
| Event-triggered scheduled tasks in connected apps | Not covered | Off by default in ChatGPT for Healthcare, and admins can switch it on for eligible roles. OpenAI's instruction is not to use it with PHI. |
| API endpoints outside the HIPAA-Eligible Endpoints list, or an API account without Modified Retention | Not covered | Eligibility is per-endpoint and per-organisation. An endpoint that is not on the published list is not eligible, whatever the BAA says. |
| Compliance API audit records (ChatGPT-authenticated usage) | Covered | Listed among covered functionality. OpenAI keeps audit records for up to 30 days for retrieval through it. |
This table reflects two OpenAI PDFs stamped "Posted: July 9, 2026" and help-centre pages read on 26 August 2026. Treat it as having a short shelf life: the help-centre article that carries this material was renamed from "ChatGPT Healthcare and Regulated Workspace functionality" to "HIPAA Eligible Products and Functionality" within roughly the week before we read it, and it visibly changed its position on Codex in that window. The help centre prints only relative stamps such as "Updated: 2 days ago", so cite the dated PDFs and re-read them yourself before you rely on any row here.
Why half the internet says Codex is excluded
What secondary sources say
That Codex is "Non-Included Functionality" on a Regulated Workspace — a coding assistant that, if enabled by a workspace admin, "has the ability to perform tasks on the open Internet where it can be subject to increased security risks, including prompt injection attacks, malware and data exfiltration." That text is real. It is printed in OpenAI's own PDF specification of ChatGPT for Healthcare and Regulated Workspace features, under the heading "Access to Non-Included Functionality".
- OpenAI's own retired PDF, "ChatGPT for Healthcare and ChatGPT Regulated Workspace Features", still served at cdn.openai.com with its no-longer-maintained notice attached.
- The Portuguese localisation of help-centre article 20001069, which was still serving the superseded "Access to Non-Included Functionality" text when we read it on 26 August 2026.
- The Spanish localisation of the same article, serving an intermediate revision that had already flipped Codex Local to covered but under the article's old title.
What the vendor's own documentation says
The same PDF is stamped "Posted: May 8, 2026" and carries OpenAI's own retirement notice: "The version below was current as of May 8, 2026 and is no longer maintained." It points readers to the help-centre article that replaced it. In the current contractual guide, dated 9 July 2026, there is no Unsupported Features section at all and Codex appears only in an affirmative coverage section: "Codex Local involves installation of Codex Local Client on a local workstation. When the Codex Local Client transmits PHI to OpenAI for processing, OpenAI will protect the Customer PHI consistent with the BAA subject to the requirements below."
How we resolve it
Nobody is lying; the document moved. But the useful correction is not simply old-versus-new on a time axis. There are two contractual guides, both dated 9 July 2026, and they diverge by product tier. On the Healthcare, Clinicians and Regulated Workspace tier, Codex Local is covered. On every other tier, the general guide still lists Codex among features that "may not be used with PHI." So "Codex is excluded" and "Codex Local is covered" can both be true statements about different customers on the same day — which is why the unqualified version of either sentence is the one that gets somebody in trouble. Codex Cloud is excluded on both tiers, and that has not changed.
Where a pasted prompt actually goes
The prompt and the files Codex sends for inference
HighThis is the whole mechanism, stated by OpenAI: "Codex sends inputs, such as prompts and files, to OpenAI for inference, and OpenAI returns the outputs." A developer debugging a failing case pastes the row that fails — a name, a date of birth, a note field. That text leaves the workstation. Whether it lands inside the BAA depends entirely on which tier the workspace is on and whether the Codex Local switch was ever thrown.
How to check
Open the Codex Local setting in your ChatGPT workspace admin panel and read whether it says Codex Local is HIPAA-eligible. If it does not say so, everything pasted so far went to OpenAI outside the agreement.
A Codex Cloud task started from a repository with a real fixture in it
HighCodex Cloud is the surface OpenAI tells you not to use with PHI at all. The realistic path in is not a deliberate upload — it is a developer handing a cloud task a repo that contains a seed file, a test fixture or a support export somebody committed months ago, and the cloud agent reading it as context.
How to check
Look at whether the Codex Cloud toggle is on for your workspace. Then ask each developer whether they have ever started a cloud task and which repository it was pointed at, and search those repositories for a real surname.
MCP servers, connectors and GitHub integrations wired into a Codex session
HighCodex is useful because it reaches things. Each of those things is a separate recipient of whatever context gets passed to it, and each sits outside the definition of Codex Local. OpenAI puts it bluntly: its BAA "doesn't make another vendor a HIPAA-compliant destination." A Drive connector pulling a spreadsheet of appointments into a prompt is a disclosure to Google, not to OpenAI.
How to check
Open the Codex configuration file on one developer's machine and read the MCP server list. Then check which connectors the workspace enables and for which groups. For every entry, ask who holds the agreement with that vendor.
Web search and browser use from inside Codex
MediumThe contract excludes web search from the definition of Codex Local, and separately excludes third-party services. A model that decides to look something up, or to drive a browser, can carry the identifying detail out of the prompt and into a query. This is the surface people assume is covered because ChatGPT's own web search is listed as covered functionality on a HIPAA-eligible workspace — the definition of Codex Local does not inherit that.
How to check
Read your Codex configuration for whether computer use, browser use and in-app browser are set to false, and whether web search is restricted. If nobody has set them, they are not off.
What stays on the developer's own workstation
MediumOpenAI is explicit that the BAA "does not apply to the execution of the Codex Local Client on Customer's client machines", and that "Your users' workstations keep inputs and outputs from Codex Local." So the pasted record persists locally: history file, session transcripts, SQLite data, logs, caches. Turning history persistence off helps with one of those — OpenAI's own guidance notes it "Disables history.jsonl, not session transcripts, SQLite data, logs, or other local records."
How to check
On one laptop, search the Codex history and session files for a surname or a record-number prefix you know is real. One hit tells you the whole fleet is the same.
A developer signed in with the wrong account
HighThe covered path is a specific workspace. A personal API key, or a second ChatGPT workspace, is a different contract or no contract, and the client will happily use either. OpenAI's guidance is that pinning this requires machine-level enforcement — an allowed login method and an allowed workspace ID pushed through the system configuration file or MDM — and warns that "workspace restrictions alone don't block API key sign-in."
How to check
Ask one developer which account their Codex is signed in with, then check whether anything on the machine would have stopped them choosing a different one. If the answer is that nothing would have — you simply told everyone which account to use — that is your gap.
Six checks before you talk to anyone
Each of these is a yes or no you can reach in about a minute if you have workspace admin and one developer laptop in front of you. Run them before you pay anybody, us included — the answers decide whether there is a project here at all.
01In your ChatGPT workspace admin settings, does the Codex Local setting indicate that Codex Local is HIPAA-eligible?
02Is your workspace ChatGPT Business, or an Enterprise or Edu account that is not sales-managed?
03Is the Codex Cloud toggle switched on for your workspace, and has anyone run a cloud task against a repository that contains real data?
04Does any developer's Codex configuration list MCP servers, or does the workspace enable connectors such as Google Drive or GitHub for the team using PHI?
05Is there anything on your developer machines — a managed system configuration or MDM policy — that forces Codex to sign in through the approved ChatGPT workspace?
06On one developer laptop, does searching the Codex history and session files for a real surname return a hit?
What we do about it
Typical range
$13,000–$25,000
Typical timeline
6–10 weeks
- 01
Surface and tier audit
3–5 daysA one-page map of how your team actually uses Codex — which clients, which sign-in method, which workspace, whether Codex Cloud has been used — with each surface marked against the HIPAA Guide and the date we read it printed on the page.
- 02
Getting onto the covered path
1–2 weeksThe gating conditions closed: the right ChatGPT service on a sales-managed account, the BAA naming the services you actually use, the Account Director request raised, and a screenshot of the Codex Local workplace setting reading HIPAA-eligible filed as evidence.
- 03
Managed client configuration
2–3 weeksA managed Codex configuration deployed to every developer machine: sign-in pinned to the approved workspace, Codex Cloud off, browser and computer use disabled, web search restricted, MCP allowlist empty by default, history persistence set to none — with a note of what that setting does not cover.
- 04
Third-party destination review
1–2 weeksAn inventory of every MCP server, connector, plugin and integration the team reaches from Codex, each one either removed, or documented with its data flow, its OAuth scopes and who holds the agreement with that vendor.
- 05
Historical exposure and workstation cleanup
1 weekA written account of what was sent before the covered path existed — what your developers can reconstruct about cloud tasks and the repositories those tasks were pointed at, plus the local history and transcripts we find on machines — and what was done about each.
- 06
Handover pack
3–5 daysOne document with the surface map, the configuration we deployed, the dated PDFs behind each decision, the re-verification schedule, and an explicit list of what remains your responsibility — the thing your auditor will ask for.
What moves the number
- How many developer machines are in scope, and whether you already have MDM — without it, pinning sign-in is the longest part of the work.
- Whether Codex Cloud has been used historically, because tracing which tasks read which repositories takes far longer than switching the toggle off.
- How many MCP servers, connectors and plugins the team has wired in, since each one is a separate vendor review.
- Whether you are on the ChatGPT sign-in path or a customer API key, which changes which settings govern retention and admin controls.
- Whether real records have reached repositories and fixtures, which turns a configuration job into a data-handling job.
When not to hire us
- You have no real PHI yet. If Codex only ever sees synthetic fixtures, none of this is urgent, and doing it before the product shape settles usually means doing it twice.
- All you actually need is the BAA and the Account Director switch. Those are conversations with OpenAI sales and your account team — paying an agency to have them for you is paying an agency to send an email.
- You are a small team already on ChatGPT for Healthcare or a Regulated Workspace with the Codex Local setting reading HIPAA-eligible, Codex Cloud off and no MCP servers. Then this is a checklist, not a project, and the self-check above is the whole audit.
- You are shopping for a compliance certificate. There is no government HIPAA certification, so nobody can sell you one — us included.
Worth knowing either way
There is no government HIPAA certification
No authority certifies software as HIPAA-compliant. What exists is a signed Business Associate Agreement with every vendor that touches protected health information, plus the administrative, physical and technical safeguards you implement and document yourself.
SOC 2 is not a substitute for a BAA
Supabase states it plainly in its own documentation: “SOC 2 does not cover, nor is it a substitute for, compliance with the Health Insurance Portability and Accountability Act (HIPAA).” The same holds for every vendor here.
An absence of documentation is not a vendor promise
Several answers here rest on what vendor documents do not say. We name which documents we read and when. A vendor that has never published a HIPAA position may still decline to sign, and one that publishes nothing today may publish something next quarter.
The same question, for the other fifteen tools
Firebase
NoOnly the Google Cloud equivalents are covered — no Firebase-branded service is
Supabase
Yes, with conditionsBAA plus a paid HIPAA add-on, on the Team plan or above
v0 by Vercel
PartiallyVercel hosting is covered; v0 itself is contractually off-limits for PHI
Lovable
NoIts terms prohibit uploading protected health information
Bubble
NoIts own documentation says apps built on Bubble won't achieve compliance
Replit
NoIts Terms, Commercial Agreement and DPA carry no HIPAA or BAA terms
Bolt.new
NoNo BAA in the StackBlitz and Bolt documents we read; HIPAA is named only for self-hosted
FlutterFlow
NoIts terms bar processing HIPAA-protected data outright
Claude Code
Yes, with conditionsCovered only with zero data retention, on accounts Anthropic qualifies
Codex
Yes, with conditionsCodex Local on a Regulated or Healthcare tier; Codex Cloud is excluded
Cursor
Yes, with conditionsEnterprise only, with Privacy Mode locked organisation-wide
GitHub Copilot
NoNo BAA offered; the Data Protection Agreement tells customers not to send PHI
Devin
NoPHI is Prohibited Data under the acceptable-use policy
Hermes Agent
Not the right questionSelf-hosted — the agreement you need is with your model provider
OpenClaw
Not the right questionSelf-hosted — but the vendor-run router still receives prompts
Base44
NoNo BAA; its terms ask customers to keep PHI off the platform
Sources, quoted as printed
Every claim above traces to one of these. Quotes are reproduced as printed on the source document; where a document prints no date, we say so rather than guessing. The two HIPAA Guide PDFs are contract text and outrank the help centre where they differ — the third PDF cited here is a retired product specification, not contract text; the help-centre pages print only relative update stamps, which we captured on the date shown.
Codex Local is affirmatively covered by the BAA for Healthcare and Regulated Workspace customers, at contract level rather than only in a help article.
This portion of the HIPAA Guide applies to Customer's use of Codex Local through either the API or using their account for ChatGPT Eligible Services. Codex Local involves installation of Codex Local Client on a local workstation. When the Codex Local Client transmits PHI to OpenAI for processing, OpenAI will protect the Customer PHI consistent with the BAA subject to the requirements below.
OpenAI — HIPAA Implementation and Configuration Guide (Healthcare / Regulated customers), section "Codex Local"Source dated: Posted: July 9, 2026Checked: August 2026Codex Cloud is excluded by name, and the contractual definition of Codex Cloud is broader than the cloud product alone.
3. Exclusions. Codex Cloud is not an Eligible Service and is not covered by the BAA, Customer may not upload, transmit, or process PHI using Codex Cloud.
OpenAI — HIPAA Implementation and Configuration Guide, section 3Source dated: Posted: July 9, 2026Checked: August 2026The same exclusion is restated in OpenAI's first-party Codex configuration guide, in bold.
The BAA doesn't cover Codex cloud. Don't use Codex cloud with PHI.
OpenAI — Codex HIPAA configuration guideSource dated: The page prints no date of any kind; read 26 August 2026Checked: August 2026Even inside covered Codex Local, the contract's definition carves out web search, connectors, MCP servers and third-party services — narrower than the help centre implies.
"Codex Local" means the Codex Local Client used with the Codex SiWC Backend or the OpenAI API. Codex Local excludes Codex Cloud, cloud-hosted task execution, web search, connectors, MCP servers, and any Third-Party Services.
OpenAI — HIPAA Implementation and Configuration Guide, section 4.4Source dated: Posted: July 9, 2026Checked: August 2026Coverage is gated on a workplace setting plus an Account Director switch — it is not self-serve.
1.2. Codex Local and ChatGPT. Customer use of Codex Local with Codex SiWC will be covered by the BAA only if the Codex Local workplace setting in Customer's ChatGPT account indicates that Codex Local is HIPAA-eligible. Customer must contact their Account Director to enable HIPAA coverage for Codex Local via Codex SiWC.
OpenAI — HIPAA Implementation and Configuration Guide, section 1.2Source dated: Posted: July 9, 2026Checked: August 2026The API-key path has its own contractual precondition, and the contract states it as an Eligible Service test rather than a retention test.
1.1. API. Customer's use of Codex Local with a Customer-provided OpenAI API key for the OpenAI API Services will be covered by the BAA only if Customer has entered into a BAA with OpenAI that includes the API Services as an Eligible Service.
OpenAI — HIPAA Implementation and Configuration Guide, section 1.1Source dated: Posted: July 9, 2026Checked: August 2026For customers without the Healthcare, Clinicians or Regulated Workspace tier, a separate contractual guide of the same date still lists Codex as an Unsupported Feature.
5.1. Unsupported Features. The following features have not been evaluated by OpenAI for HIPAA compliance at this time and may not be used with PHI. It is recommended that Customer disable these functionalities. a. Codex - Customer can disable this functionality through the "Codex Local" and "Codex Cloud" toggles.
OpenAI — HIPAA Implementation and Configuration Guide (general), section 5.1Source dated: Posted: July 9, 2026Checked: August 2026The document that competitors quote to say Codex is excluded has been retired by OpenAI itself.
The version below was current as of May 8, 2026 and is no longer maintained.
OpenAI — ChatGPT for Healthcare and ChatGPT Regulated Workspace Features (superseded)Source dated: Posted: May 8, 2026Checked: August 2026The wording in that retired document, which is what the "Codex is excluded" claim is built on.
Codex - Codex is ChatGPT's AI's coding assistant. If enabled by a workspace admin, Codex has the ability to perform tasks on the open Internet where it can be subject to increased security risks, including prompt injection attacks, malware and data exfiltration.
OpenAI — ChatGPT for Healthcare and ChatGPT Regulated Workspace Features (superseded), under "Access to Non-Included Functionality"Source dated: Posted: May 8, 2026Checked: August 2026What happens to a prompt by default: where it goes, what is kept, and whether it trains a model.
ChatGPT Enterprise stores inputs and outputs in the OpenAI cloud. Your users' workstations keep inputs and outputs from Codex Local. Codex sends inputs, such as prompts and files, to OpenAI for inference, and OpenAI returns the outputs. For usage authenticated through ChatGPT, OpenAI keeps audit records for up to 30 days so you can retrieve them through the Compliance API. OpenAI doesn't train on ChatGPT Enterprise data or Codex Local data.
OpenAI — Codex HIPAA configuration guideSource dated: The page prints no date of any kind; read 26 August 2026Checked: August 2026The API path has its own precondition, and "Modified Retention" does not mean zero retention.
HIPAA eligibility for the OpenAI API is contingent on Customer's account being provisioned with Modified Retention, unless otherwise specified by OpenAI. Once your org ID is provisioned with Modified Retention, the endpoints listed below can be used for processing PHI, even if data is retained, upon execution of the OpenAI BAA.
OpenAI Help Center — HIPAA Eligible Products and FunctionalitySource dated: "Updated: 2 days ago" as printed when loaded on 26 August 2026; no absolute date printedChecked: August 2026ChatGPT Business is not BAA-eligible; Enterprise and Edu qualify only on sales-managed accounts, and individual clinicians have a separate route.
Only ChatGPT Enterprise or Edu customers that have a sales-managed account are eligible for a BAA for ChatGPT at this time. Please note that we don't offer a BAA for ChatGPT Business.
OpenAI Help Center — How can I get a Business Associate Agreement (BAA) with OpenAI?Source dated: "Updated: 3 days ago" as printed when loaded on 26 August 2026; no absolute date printedChecked: August 2026A signed OpenAI BAA does not extend to the other vendors Codex reaches.
OpenAI's BAA doesn't make another vendor a HIPAA-compliant destination.
OpenAI — Codex HIPAA configuration guideSource dated: The page prints no date of any kind; read 26 August 2026Checked: August 2026Pinning Codex to the approved workspace requires machine-level enforcement — workspace settings alone do not do it.
Cloud-managed requirements ignore both settings, and workspace restrictions alone don't block API key sign-in.
OpenAI — Codex HIPAA configuration guideSource dated: The page prints no date of any kind; read 26 August 2026Checked: August 2026Turning history persistence off removes one local record and leaves the others behind.
Disables history.jsonl, not session transcripts, SQLite data, logs, or other local records.
OpenAI — Codex HIPAA configuration guideSource dated: The page prints no date of any kind; read 26 August 2026Checked: August 2026Event-triggered scheduled tasks are outside BAA coverage even on a HIPAA-eligible workspace.
Event-triggered scheduled tasks that respond to activity in connected apps are not covered under a Business Associate Agreement (BAA). This functionality is turned off by default in ChatGPT for Healthcare. Admins can enable Allow event-triggered scheduled tasks for eligible workspace roles. Do not use event-triggered tasks to transmit, store, or process protected health information (PHI).
OpenAI Help Center — HIPAA Eligible Products and FunctionalitySource dated: "Updated: 2 days ago" as printed when loaded on 26 August 2026; no absolute date printedChecked: August 2026
Frequently asked questions
We already have a BAA with OpenAI. Does that cover our team's Codex usage?
Not by itself. Two more things have to be true. Your BAA has to include the right Eligible Service — a HIPAA-eligible ChatGPT service if your developers sign in with ChatGPT, or, if they use an API key, the API Services as an Eligible Service with that API organisation provisioned for Modified Retention. And Codex Local has to be switched on for the workspace: the contract says coverage applies "only if the Codex Local workplace setting in Customer's ChatGPT account indicates that Codex Local is HIPAA-eligible", and that you must contact your Account Director to enable it. Check the setting before you assume anything.
What is the actual difference between Codex Local and Codex Cloud here?
Codex Local is the client installed on a workstation — the CLI, the IDE extension and the Desktop app — talking to OpenAI for inference. That is what the BAA covers. Codex Cloud is cloud-hosted task execution, and the contract says it "is not an Eligible Service and is not covered by the BAA, Customer may not upload, transmit, or process PHI using Codex Cloud." One warning: the contract's definition of Codex Cloud also reaches "any Codex functionality accessed via ChatGPT Enterprise via the web or applications", while Codex Desktop is listed as a covered local client. That boundary is not clear on the face of the document, and it is worth getting in writing from your Account Director rather than guessing.
We are on ChatGPT Business. Can we get there?
Not on that plan. OpenAI states "we don't offer a BAA for ChatGPT Business", and limits ChatGPT BAA eligibility to Enterprise or Edu customers on sales-managed accounts. The HIPAA-eligible ChatGPT services it names are ChatGPT for Healthcare, ChatGPT for Clinicians, ChatGPT Enterprise or Edu with the Regulated Workspace, and ChatGPT FedRAMP. There is also a separate in-product BAA flow for individual clinicians under ChatGPT for Clinicians, and the API is a different track — an enterprise agreement is not required to sign a BAA for the API Platform.
Our developers run Codex against our own API key. Does that change anything?
It changes which contract governs and which settings apply. The contract says use of Codex Local with a customer-provided API key is covered "only if Customer has entered into a BAA with OpenAI that includes the API Services as an Eligible Service", and the API section adds that the account must be provisioned for Modified Retention. It also means your ChatGPT workspace controls stop applying — with API-key sign-in, retention, data-sharing and administrative settings follow the API organisation instead. That is also why workspace restrictions alone do not close the gap: they do not block API-key sign-in.
Does Modified Retention mean OpenAI stops keeping our prompts?
No, and this one catches people. OpenAI's own wording is that once your organisation ID is provisioned, the eligible endpoints "can be used for processing PHI, even if data is retained". Modified Retention is not zero data retention. Separately, for ChatGPT-authenticated usage OpenAI keeps audit records for up to 30 days so you can pull them through the Compliance API, and it states that it does not train on ChatGPT Enterprise data or Codex Local data.
Our Codex talks to a GitHub MCP server and a Drive connector. Are those covered?
No — and not as an oversight, but by definition. The contract defines Codex Local as excluding "Codex Cloud, cloud-hosted task execution, web search, connectors, MCP servers, and any Third-Party Services." OpenAI's configuration guide says the same thing in plain language: its BAA "doesn't make another vendor a HIPAA-compliant destination." Every MCP server, connector, plugin and browser destination is a separate recipient that needs its own agreement, or needs to come off the allowlist for anyone touching PHI.
Is Codex HIPAA certified?
Nothing is. There is no government HIPAA certification for a product or a company — what exists is a signed Business Associate Agreement with each vendor that receives protected health information, plus the safeguards you implement and document on your side. In this case the agreement reaches some Codex surfaces and expressly does not reach others, which is why the useful question is never whether Codex is compliant, but which Codex surface, on which tier, with which switch thrown.
This page reports what OpenAI's published documents said on the dates shown and is technical information rather than legal advice; HIPAA compliance is a property of your whole system and the processes around it rather than of any single tool, and vendor terms change — this shelf changed twice between May and August 2026 — so verify the current terms with OpenAI before relying on anything here.
