Skip to main content
ForensicShield(go to home page)

Can you use ChatGPT to review a forensic report? A forensic psychologist’s compliance guide.

The direct answer: pasting a forensic evaluation into consumer ChatGPT — the Free, Go, Plus, or Pro tiers — means disclosing protected health information to a service that offers no Business Associate Agreement. That is a HIPAA problem regardless of how good the output is. OpenAI’s enterprise and clinician tiers change the compliance math, but they don’t close the forensic-workflow gaps: verified citations, jurisdiction calibration, and output built for expert work product. Here is the full analysis — with the current penalty figures and the case law.

Zero-Exposure ArchitecturePHI never leaves AWS Bedrock
Encrypted at Every LayerAES-256-GCM with AWS KMS envelope keys
Tamper-Proof Audit TrailAppend-only logs, 7-year retention
BAA RequiredSigned before any PHI upload

Where ChatGPT actually stands with HIPAA.

A forensic evaluation is saturated with protected health information: the evaluee’s name, dates, diagnoses, test data, history, and the factual record of the case. Sending that document to any third-party service makes the service part of your compliance picture, and HIPAA’s mechanism for that is the Business Associate Agreement — a signed contract obligating the vendor to safeguard PHI. No BAA, no permissible disclosure.

OpenAI documents its own position clearly, and it deserves a fair reading. Per OpenAI’s official Help Center (as of July 2026), BAAs are available for the API (requested through baa@openai.com), for sales-managed ChatGPT Enterprise and Edu accounts, and for ChatGPT for Clinicians through an in-product BAA flow. OpenAI explicitly does not offer a BAA for ChatGPT Business, and the consumer Free and Plus tiers are not listed as eligible at all. OpenAI has also launched an OpenAI for Healthcare offering in which PHI remains under organizational control, with data residency, audit logs, customer-managed encryption keys, and BAA support — and content shared with it is not used to train models. Those are real, well-engineered products for the organizations they target. The point is narrower: none of that applies to the ChatGPT window most practitioners have open.

Training defaults follow the same tier line. OpenAI’s data-usage documentation states that consumer ChatGPT improves by training on the conversations people have with it unless the user opts out (Settings > Data Controls), while business products — ChatGPT Business, Enterprise, and the API — are not trained on by default. Anthropic’s consumer Claude takes a different default: chats are used for model training only if the user chooses to allow it (with five-year retention if enabled, 30 days if not), and commercial products — the API, Amazon Bedrock, Claude for Work — are excluded entirely. Either way, the category conclusion is the same: no consumer chatbot tier, from either company, comes with a BAA.

The stakes are set by statute and adjusted for inflation every year — which is why the “ 45 CFR 102.3, reflecting the annual inflation adjustment published January 28, 2026 (figures current as of July 2026), HIPAA civil monetary penalties run:

  • Tier 1 — did not know (and could not reasonably have known):
  • Tier 2 — reasonable cause, not willful neglect:
  • Tier 3 — willful neglect, corrected within 30 days:
  • Tier 4 — willful neglect, not corrected: $73,011 minimum per violation.
  • Calendar-year cap for identical violations: $2,190,294.

Even the lowest tier — the one for a practitioner who genuinely didn’t know — starts at

Why “I’ll just remove the name” doesn’t hold.

The tempting workaround is to strip identifiers before pasting. HIPAA has a precise standard for that: the Safe Harbor method at 45 CFR 164.514(b)(2) requires removing eighteen categories of identifiers — names, all elements of dates (other than year) directly related to the individual, geographic subdivisions smaller than a state, record and case numbers, and “any other unique identifying number, characteristic, or code” among them — plus no actual knowledge that what remains could identify the person.

Here is the structural problem, as a matter of reasoning rather than citation: a forensic report resists that standard by design. The referral question names the charge and the proceeding. The offense conduct is described with the specificity that cross-examination demands. Collateral records are quoted. Test dates anchor the timeline, and the fact pattern itself — a specific charge, in a specific county, in a specific month — can function as an identifier in any jurisdiction smaller than a metropolis. Strip all eighteen categories and what remains is no longer the report you needed reviewed; the reasoning you want scrutinized lives in exactly the details the standard removes. And a partially scrubbed report is not “de-identified” in the legal sense — it is simply a disclosure with fewer fields.

De-identification is a data-release standard, not a review workflow. The defensible path is not to make the report anonymous enough for a consumer chatbot — it is to review it inside an environment built to hold PHI in the first place.

Citations in expert work product.

Suppose the compliance question were fully solved — an Enterprise account under BAA, or the clinician tier. A general-purpose assistant still wasn’t designed for expert work product headed to court, and the documented failure mode is the confident, plausible, wrong citation.

  • Kohls v. Ellison, No. 24-cv-3754, 2025 WL 66514 (D. Minn. Jan. 10, 2025). An expert declaration on AI-generated media — filed by a Stanford professor — cited two articles that do not exist and misattributed a third, artifacts of drafting with GPT-4o. Judge Laura M. Provinzino excluded the declaration, writing that the citation of fake, AI-generated sources “shatters his credibility with this Court.” The order’s general warning is the part every expert should read: courts expect that attorneys and experts will not “abdicate their independent judgment and critical thinking skills in favor of ready-made, AI-generated answers.” Read the order (PDF).
  • Mata v. Avianca, Inc., 678 F. Supp. 3d 443 (S.D.N.Y. 2023). The first high-profile sanctions decision over ChatGPT-fabricated case law: Judge P. Kevin Castel sanctioned the attorneys $5,000 in June 2023 for filing briefs citing nonexistent opinions. Read the opinion.
  • Ferlito v. Harbor Freight Tools USA, Inc., No. CV 20-5615, 2025 WL 1181699 (E.D.N.Y. Apr. 23, 2025). The counterpoint: courts have not banned expert AI use. The court declined to exclude an expert who used ChatGPT only after authoring his report, to confirm findings he had already reached through his own methods. Case summary.

Read together, the line courts are drawing runs through method and candor, not the tool. Disclosure is becoming the differentiator. Texas Senate Bill 1188, effective September 1, 2025, requires healthcare practitioners to disclose their use of AI in diagnosis and treatment contexts; how far that logic extends into forensic evaluation is not yet settled, but the direction of regulation is unambiguous. And proposed Federal Rule of Evidence 707 — still proposed, with a public hearing held January 15, 2026 — would subject machine-generated evidence to the same kind of reliability scrutiny Rule 702 applies to expert testimony.

For a forensic psychologist, the practical version of this arrives in cross-examination: whether AI was used in preparing the report, which tool, what it received, and how its output was verified. Those questions deserve answers you are comfortable giving under oath.

Purpose-built review inside a HIPAA boundary.

Consider the difference in posture. ForensicShield exists for one job — pre-finalization review of forensic reports — and the architecture follows from the job:

HIPAA compliant, BAA first

ForensicShield is HIPAA compliant, and a Business Associate Agreement is signed before any PHI upload is possible. The compliance conversation happens before the first document, not after an incident.

PHI stays inside the boundary

Reports are protected with AES-256 encryption, and AI inference runs through HIPAA-eligible AWS Bedrock — PHI never leaves the AWS boundary.

Every citation verified

Every citation surfaced passes a verification pipeline against public court databases, with a link to the actual opinion and a verification badge. A citation that cannot be verified is flagged as unverified — never presented as settled.

Calibrated to your venue

Analysis is calibrated to the admissibility framework of 55 US jurisdictions — federal and state — so the review asks the questions your court will ask.

You remain the expert

Findings are framed as considerations for your judgment. The forensic psychologist is the author, the expert, and the signatory on every report — the AI assists, it never decides.

Pay per report

$49 per report, with case packs bringing that as low as $39. The 14-day trial includes 2 reports. No subscription, and reports never expire.

One honest note on general-purpose AI: it has legitimate, PHI-free uses in a forensic practice — orienting yourself in unfamiliar literature, drafting administrative text, preparing teaching materials. For those uses, consider following the American Psychological Association’s Ethical Guidance for AI in the Professional Practice of Health Service Psychology (June 2025, updated December 2025), which addresses six areas: transparency and informed consent, bias mitigation, data privacy and security, accuracy, human oversight, and liability. The boundary to hold is simple: nothing that identifies an evaluee ever goes into a tool that isn’t under a BAA.

Common questions.

Is ChatGPT HIPAA compliant for psychologists?

The consumer tiers — ChatGPT Free, Go, Plus, and Pro — are not: no Business Associate Agreement is available for them, so uploading PHI is a disclosure HIPAA does not permit. OpenAI does offer BAAs for its API, for sales-managed ChatGPT Enterprise and Edu accounts, and for ChatGPT for Clinicians — and explicitly not for ChatGPT Business. A signed BAA is the entry ticket, not the whole compliance picture: encryption, access controls, audit logging, and your own safeguards still matter.

Does ChatGPT Enterprise fix the problem?

It changes the compliance math: a sales-managed Enterprise account can come with a BAA, and OpenAI does not train on business-tier content by default. What it doesn’t change is the forensic-workflow gap — no citation-verification pipeline against court databases, no jurisdiction calibration, no output designed for expert work product under cross-examination. Compliance and fitness-for-purpose are separate questions, and a forensic report review needs both answered.

Can courts find out I used ChatGPT?

Increasingly, yes. Fabricated citations surface the moment opposing counsel or the court checks them, as in Kohls v. Ellison. Cross-examination can probe how a report was prepared. Texas SB 1188 already requires practitioners to disclose AI use in diagnosis and treatment contexts, and proposed FRE 707 would bring machine-generated evidence under reliability scrutiny. The safer assumption is that AI use will be visible — and the case law suggests courts respond well to verified, disclosed use (Ferlito) and poorly to unverified reliance.

What about Claude — is it different?

On training defaults, yes: Anthropic’s consumer Claude uses chats for model training only if the user chooses to allow it, and its commercial products — the API and Amazon Bedrock — are excluded from training entirely. On the compliance category, no: consumer Claude, like consumer ChatGPT, comes with no BAA. ForensicShield runs Claude inside a HIPAA-eligible AWS Bedrock boundary under a signed BAA — a different deployment category from any consumer chatbot.

What should I use instead to review a forensic report?

Consider a platform built for the task and the data: ForensicShield signs a BAA before any PHI upload, encrypts reports with AES-256, keeps AI inference inside a HIPAA-eligible AWS Bedrock boundary, verifies every citation against public court databases with linked opinions, and calibrates the review to 55 US jurisdictions — at $49 per report with a 14-day, 2-report trial and no subscription. For PHI-free tasks where a general-purpose assistant genuinely helps, consider the APA’s June 2025 ethical guidance on AI in professional practice.

Go deeper.

For the longer treatment of the consumer-AI compliance problem, read why pasting your forensic report into ChatGPT could cost you $50,000 on our blog. Our HIPAA compliance page documents the BAA, encryption, and audit-trail architecture in detail, and the security page covers the full control set. To see what a purpose-built review actually checks, start with the forensic frameworks behind the analysis, the free Daubert self-audit checklist, and the sister comparison on manual checklists.

Review your next report inside the boundary.

A HIPAA-compliant review with a signed BAA, verified citations, and jurisdiction calibration. The 14-day trial includes 2 reports — $49 per report after, no subscription.

Start Free Trial →

14-day free trial · 2 reports included (1 sample + 1 of your own) · A payment method is collected for identity verification — your card will not be automatically charged when the trial ends · HIPAA compliant