All engagements conducted under NDA·Evidence preserved to technical chain-of-custody standards·Engagements limited to qualified organizations

Free scanThe studyForensic TriageForensic AuditAI VendorsResearch
Free scan · no install

The three AI tools most health organisations are running, and what their vendors actually say

Microsoft Teams, ChatGPT and Zoom AI Companion. What each vendor's own documentation states about BAA scope, training, retention and audit-log access, sourced line by line. No scoring, no verdict, no vendor rankings. What the documents say, and where they say nothing.

Verified September 2026 · Facts only — no scoring, no verdict

ChatGPT

ChatGPT (all tiers)
Does a BAA cover it?Not at the tier most organisations are onOpenAI publishes a list of HIPAA-eligible products — it names ChatGPT for Healthcare, ChatGPT for Enterprise with Regulated Workspace, ChatGPT FedRAMP, ChatGPT for Clinicians, API with Modified Retention, and API FedRAMP with Modified Retention. Standard "ChatGPT Enterprise" is not on that list, neither is Business, and neither is any consumer tier. Being on an eligible product is necessary, not sufficient — specific functionality sits outside BAA coverage even there: improved memory, event-triggered scheduled tasks, browser use in cloud Work, and cloud-based Codex.
Does it train on your data?Consumer tiers (Free, Go, Plus, Pro): yes, by default. Opt-out exists in the privacy portal and applies only to new conversations, so it is forward-only. Business and Enterprise: no, not by default.
What survives deletion?The data-usage help article does not state what happens to content already used in training.
Can the deployer export usage logs?Consumer accounts are individual, not workspace-managed, so there is no admin log path. Business and Enterprise have admin retention and workspace controls.

Microsoft Teams (transcription and recording)

Microsoft Teams
Does a BAA cover it?YesOffice 365 is on Microsoft's HIPAA in-scope services list, and Microsoft names Microsoft 365 Copilot and Microsoft 365 Copilot Chat on it directly — Microsoft is the clearest of the three on this point.
Is transcription on by default?Yesfor newly created meeting policies.
What survives deletion?Recordings and transcripts carry a 120-day default expiration, and they are stored in OneDrive and SharePoint. The part most people miss: Microsoft states that changing the expiration setting applies only to newly created recordings and transcripts. You cannot shorten retention on anything already captured.
Can the deployer export usage logs?YesTranscripts and recordings live in OneDrive and SharePoint under existing retention and eDiscovery tooling.
Commonly mistaken for

GitHub Copilot being covered by the same BAA. It does not appear on Microsoft's HIPAA in-scope services list — same vendor, different answer, and developers may be running it under the same assumption.

Zoom AI Companion

Zoom AI Companion
Does a BAA cover it?Not answeredZoom's HIPAA page states that Zoom "helps customers enable HIPAA compliant programs by executing a Business Associate Agreement (BAA) and safeguarding protected health information," then directs readers to a separate compliance guide for scope — AI Companion is not discussed on that page at all. So whether AI Companion summaries and transcripts fall inside an executed Zoom BAA is not stated in the public HIPAA documentation.
Does it train on your data?Noand Zoom's wording here is the most explicit of any vendor reviewed: Zoom does not use customer audio, video, chat, screen sharing, attachments or other communications-like customer content to train Zoom's or third-party AI models.
What survives deletion?AI Companion outputs are stored according to the customer's retention settings. Zoom states customers may choose the retention period for "some of the AI Companion outputs" — the scope of "some" is not defined.
Can the deployer export usage logs?Admins enable and manage features in the Admin Portal, and summaries are stored in the web portal under account, group or user retention settings. No dedicated audit-export path is specified on the AI Companion security page.
Third-party attestationSOC 2, and a HITRUST report referenced for healthcare customers.
Verified: September 2026Verified by: Adil — Shadow AI Forensics

Three things worth doing

  1. 1Check which ChatGPT product your contract actually names. If it says "Enterprise" without "Regulated Workspace," it is not on OpenAI's HIPAA-eligible list. This is a five-minute check against your order form and it is the highest-value one here.
  2. 2Accept that Teams recordings already captured are on their original clock. Setting a shorter expiration is worth doing, and it reaches nothing recorded before you set it. If you need those gone sooner, that is a manual exercise, not a policy change.
  3. 3Get Zoom to state AI Companion's BAA scope in writing. Their public documentation doesn't answer it. Ask your account team directly and keep the answer. "We assumed it was covered" is not a position you can defend later.
What this brief deliberately does not do

It reports what vendors publish. It does not score them, rank them, or tell you whether to use one.

It also cannot tell you whether your organisation is exposed. That depends on your tier, your executed contract, and what your people are actually putting into these tools, and none of that is in a vendor's public documentation.

Running something other than these three?
Email the tool name to adil@shadowaiforensics.com and I'll tell you what its documentation says. No charge.

Adil Ali, Shadow AI Forensics · shadowaiforensics.com
Verified September 2026

Need this on the record for one specific vendor?

This brief reports what vendors publish. It deliberately doesn't score them or give a verdict. The AI Vendor Risk Assessment does: one vendor, your regulatory context, three industry gates and nine scored criteria, a Go / Conditional Go / No-Go in 48 hours, plus the exact question to put to the vendor in writing.

$997. No call, no access to your systems.

See what's in it →