# Is Codex HIPAA compliant? Codex Local only on a Regulated or Healthcare tier

- Tool: Compliance
- Last updated: August 2026

## TL;DR

Yes, conditionally — the line runs straight through the middle of the product. OpenAI's HIPAA Implementation and Configuration Guide, part of the BAA, covers "Codex Local" — clearly the Codex CLI and the Codex IDE extension — but only on a HIPAA-eligible ChatGPT account whose Codex Local workplace setting reads HIPAA-eligible, which an Account Director switches on. Codex Cloud is excluded outright, the Codex Desktop app sits on a boundary the contract leaves unclear, and covered Codex Local still excludes web search, connectors and MCP servers.

## Frequently asked questions

### We already have a BAA with OpenAI. Does that cover our team's Codex usage?

Not by itself. Two more things have to be true. Your BAA has to include the right Eligible Service — a HIPAA-eligible ChatGPT service if your developers sign in with ChatGPT, or, if they use an API key, the API Services as an Eligible Service with that API organisation provisioned for Modified Retention. And Codex Local has to be switched on for the workspace: the contract says coverage applies "only if the Codex Local workplace setting in Customer's ChatGPT account indicates that Codex Local is HIPAA-eligible", and that you must contact your Account Director to enable it. Check the setting before you assume anything.

### What is the actual difference between Codex Local and Codex Cloud here?

Codex Local is the client installed on a workstation — the CLI, the IDE extension and the Desktop app — talking to OpenAI for inference. That is what the BAA covers. Codex Cloud is cloud-hosted task execution, and the contract says it "is not an Eligible Service and is not covered by the BAA, Customer may not upload, transmit, or process PHI using Codex Cloud." One warning: the contract's definition of Codex Cloud also reaches "any Codex functionality accessed via ChatGPT Enterprise via the web or applications", while Codex Desktop is listed as a covered local client. That boundary is not clear on the face of the document, and it is worth getting in writing from your Account Director rather than guessing.

### We are on ChatGPT Business. Can we get there?

Not on that plan. OpenAI states "we don't offer a BAA for ChatGPT Business", and limits ChatGPT BAA eligibility to Enterprise or Edu customers on sales-managed accounts. The HIPAA-eligible ChatGPT services it names are ChatGPT for Healthcare, ChatGPT for Clinicians, ChatGPT Enterprise or Edu with the Regulated Workspace, and ChatGPT FedRAMP. There is also a separate in-product BAA flow for individual clinicians under ChatGPT for Clinicians, and the API is a different track — an enterprise agreement is not required to sign a BAA for the API Platform.

### Our developers run Codex against our own API key. Does that change anything?

It changes which contract governs and which settings apply. The contract says use of Codex Local with a customer-provided API key is covered "only if Customer has entered into a BAA with OpenAI that includes the API Services as an Eligible Service", and the API section adds that the account must be provisioned for Modified Retention. It also means your ChatGPT workspace controls stop applying — with API-key sign-in, retention, data-sharing and administrative settings follow the API organisation instead. That is also why workspace restrictions alone do not close the gap: they do not block API-key sign-in.

### Does Modified Retention mean OpenAI stops keeping our prompts?

No, and this one catches people. OpenAI's own wording is that once your organisation ID is provisioned, the eligible endpoints "can be used for processing PHI, even if data is retained". Modified Retention is not zero data retention. Separately, for ChatGPT-authenticated usage OpenAI keeps audit records for up to 30 days so you can pull them through the Compliance API, and it states that it does not train on ChatGPT Enterprise data or Codex Local data.

### Our Codex talks to a GitHub MCP server and a Drive connector. Are those covered?

No — and not as an oversight, but by definition. The contract defines Codex Local as excluding "Codex Cloud, cloud-hosted task execution, web search, connectors, MCP servers, and any Third-Party Services." OpenAI's configuration guide says the same thing in plain language: its BAA "doesn't make another vendor a HIPAA-compliant destination." Every MCP server, connector, plugin and browser destination is a separate recipient that needs its own agreement, or needs to come off the allowlist for anyone touching PHI.

### Is Codex HIPAA certified?

Nothing is. There is no government HIPAA certification for a product or a company — what exists is a signed Business Associate Agreement with each vendor that receives protected health information, plus the safeguards you implement and document on your side. In this case the agreement reaches some Codex surfaces and expressly does not reach others, which is why the useful question is never whether Codex is compliant, but which Codex surface, on which tier, with which switch thrown.

---

Source: https://www.rapidevelopers.com/compliance/is-codex-hipaa-compliant
© RapidDev — https://www.rapidevelopers.com/compliance/is-codex-hipaa-compliant
