← All articles

Is It Safe to Put Patient Records in ChatGPT? What Every Vet Team Should Know

By Dr. Pelton, DVM ·

If you’re reading this because you already pasted a record into ChatGPT and got a little nervous afterward, start here. You aren’t in trouble, and you’re asking exactly the right question. Most of the profession hasn’t thought about it at all.

Let me give you the honest version, because the internet has two camps on this and both are wrong. One camp says veterinary records aren’t HIPAA so do whatever you want. The other says AI is a privacy disaster so never touch it. Neither is true.

The mechanism: what actually happens when you paste

When you paste text into a chatbot, that text leaves your building and lands on a company’s servers. Two things can happen to it there. It gets processed to answer you, which is the point. And, depending on the product and its settings, it may get retained and used to improve the model.

That second part is the whole ballgame. If your input can be used for training, a fragment of what you pasted can, in principle, influence what the model says to someone else later. Not your file handed to a stranger, nothing that dramatic. But your data has left your control, and control is the thing that matters.

HIPAA is a red herring, and that trips people up

Here’s the fact that gives vets false comfort. Veterinary records aren’t covered by HIPAA. HIPAA is for human medicine.

The instinct behind the relief is understandable. But not-HIPAA doesn’t mean not-sensitive. Your records still hold client names, phone numbers, addresses, and payment details. You’re still bound by your state veterinary practice act, by your own privacy policy, and by the plain professional duty of confidentiality that existed long before any of this. The absence of one federal law doesn’t remove the other three obligations.

No spam. Unsubscribe anytime. Your email goes nowhere else.

The rule that solves most of it

Here’s the part that will actually change how your team works, and it’s simple.

Strip the identifiers before anything gets pasted. No client name. No pet name. No phone, address, or account number. What the model needs to help you is the clinical picture: species, age, weight, findings, history, plan. A ten-year-old cat with these labs isn’t identifying. “Mrs. Chen’s cat Biscuit at 4501 Oak” is.

Train the whole team on that one line and you’ve removed the large majority of the risk for the large majority of the day. It costs nothing and it slows no one down.

When you need to use real records

Stripping identifiers works for quick drafting. But some tools need the real data to do their job, and for those you need real controls. There are three clean paths, and they remove different pieces of the risk.

Use a business or API tier with training turned off and a data processing agreement in place. That closes the training door contractually.

Use a tool built for clinical data, one whose entire job is handling this correctly, rather than a general consumer chatbot.

Or self-host a model, so the data is processed on a machine in your own building and never leaves at all. This is the one I lean toward for the sensitive work, for the same reason I own my phone system instead of renting it. Remove the dependency, remove the risk.

Where I land

I’m not a lawyer, and this isn’t legal advice. Check the current terms for the exact product your team uses, because they change, and if you’ve real exposure, ask someone who does this for a living.

But the practical version isn’t complicated. Strip identifiers for the everyday drafting. Use controlled tools for anything that needs the real record. Never assume a consumer chatbot is private just because your records aren’t HIPAA.

If you want the drafting side done right without pasting anything you shouldn’t, start with ChatGPT Prompts for Veterinarians That Actually Work. And if you want to see how I moved the sensitive work onto tools I control, that’s the whole journey.

Questions I get asked

Are veterinary records covered by HIPAA?
No. HIPAA covers human health information. Veterinary records aren't HIPAA-protected. But they still contain client personal information and are covered by your state's veterinary practice act, your privacy obligations, and plain professional confidentiality. Not-HIPAA doesn't mean not-sensitive.
Does ChatGPT train on what I paste into it?
It depends on the tier. Consumer accounts have historically been able to use your inputs to improve the model unless you opt out, and settings change over time. Business and API tiers generally don't train on your data by default. Always check the current terms for the exact product you're using, because they move.
What is the simplest safe rule for my team?
Strip identifying details before anything gets pasted. No client name, no pet name, no phone number, no address, no account number. The clinical picture is what the model needs, and the clinical picture isn't identifying on its own.
Is there a way to use AI on real records safely?
Yes. Use a business or API tier with training turned off and a data agreement in place, use a tool built for clinical data, or self-host a model so the data never leaves your building. Each removes a different piece of the risk.

Get the playbook

Every build, every prompt, every thing I got wrong. Sent as I write it. No spam.

No spam. Unsubscribe anytime. Your email goes nowhere else.