Prescriber.io
All posts
AI in practice

ChatGPT for doctors: what it can and cannot do at the point of care

ChatGPT is useful to physicians for drafting and thinking, and wrong for a point-of-care drug decision. Which tiers are covered by a HIPAA business associate agreement, why interaction checking fails quietly, and a workable policy for a practice.

By the Prescriber.io team

August 2026 · 8 min read

The Monograph Desk

Press Run check to see the interaction, contraindication, and dosing decision-support card for this scenario.

Not in this sample

This on-page demo only ships with five illustrative scenarios and never invents clinical output, so it will not fake a card for this pair.

The full Prescriber.io desk checks any regimen against interactions, contraindications, and renal or hepatic dosing, with cited sources for you to verify.

Illustrative sample · decision-support only · verify against official sources

Interaction

Contraindication / allergy check

Dosing guidance (renal / hepatic)

Guideline-based alternatives

Sources

Illustrative sample · not real clinical advice · you verify and decide

Checked in · you review & sign

Decision support for licensed clinicians. Prescriber.io does not diagnose or prescribe and is not a substitute for professional clinical judgment.

In short

ChatGPT is genuinely useful to physicians for drafting, summarizing and stress-testing reasoning, and it is the wrong tool for a point-of-care drug or dosing decision. Two things decide this. It has no versioned source of truth you can audit or reproduce, and most ChatGPT tiers carry no HIPAA business associate agreement: Free, Plus, Pro, Team and self-serve Business are not BAA-eligible, while sales-managed Enterprise and Edu accounts and the API platform are covered under separate agreements that do not extend to one another. Use it for language work, keep clinical lookups on a cited reference, and never enter patient identifiers on a tier without a BAA.

The short answer: ChatGPT is genuinely useful to physicians for drafting, summarizing and thinking out loud, and it is the wrong tool for a point-of-care drug or dosing decision. Two things decide this. It has no fixed source of truth you can audit, and most ChatGPT tiers are not covered by a HIPAA business associate agreement, which means putting patient identifiers into them is a compliance problem before it is a clinical one.

The gap between "this is impressive" and "I can use this on a patient" is where most clinicians get stuck. It is worth being precise about where the line actually sits, because the honest answer is not "never" and it is not "sure, why not".

Is ChatGPT HIPAA compliant?

Not by default, and the tier you are on decides it. A HIPAA business associate agreement is the contract that makes a vendor legally responsible for protected health information. Without one in place, entering PHI into a service is a disclosure your practice cannot account for.

OpenAI does sign BAAs, but only for specific products, and the eligibility does not follow price. Paying $200 a month for a Pro subscription buys you a faster model, not a BAA.

TierBAA availablePractical meaning
Free, Plus, ProNoConsumer accounts. No PHI, at any price point.
Team and self-serve BusinessNoThe common trap. Buying a business plan feels like the compliant choice and is not.
Enterprise and EduYes, on requestSales-managed accounts only. The BAA is requested, not automatic.
API platformYes, separatelyCovered under its own agreement, which does not extend to the chat products.

The detail that catches organizations out is that these agreements do not travel. A BAA covering the API does not cover ChatGPT Business or Team, and a BAA covering ChatGPT Enterprise does not cover your developers' API keys. Two separate contracts, two separate scopes. Confirm your own coverage with the vendor and your privacy officer rather than assuming an enterprise logo on the login page means you are covered, and treat anything you read online about tier eligibility as something to verify, since these terms change.

There is a second layer people forget. Vendor compliance and employer permission are different things. A tool can be fully HIPAA-capable and your health system can still forbid it, which is exactly what has happened at some US systems with other AI clinical tools. Your organization's policy is the binding one.

Can ChatGPT check drug interactions?

It will answer, fluently, and that is the problem. A general-purpose model produces a plausible response whether or not it has current, correct data behind it, and for interaction checking the failure mode is quiet. You do not get an error message. You get a confident paragraph that omits the interaction that mattered.

Three specific things break down:

  • No versioned source. A drug compendium tells you which labeling revision an entry reflects. A chat response cannot, so you cannot audit what it was drawing on or reproduce the answer later.
  • Silent staleness. Labeling changes constantly. Contraindications get added. A model trained before a revision does not know it is out of date, and neither do you.
  • No completeness guarantee. An interaction checker is built to enumerate every flagged pair in a list. A language model summarizes, and summarizing means leaving things out, chosen by relevance rather than by risk.

That last one matters most in polypharmacy. Ask about two drugs and you will usually get a reasonable answer. Paste a list of fourteen medications for an 82-year-old and the tool that enumerates systematically beats the tool that writes well, every time. This is the job a purpose-built drug interaction checker is designed for, and we go through the differences in detail in our piece on AI drug interaction checkers.

What ChatGPT is actually good at in clinical work

Plenty, as long as no patient identifiers are involved and no clinical fact goes unverified.

It is strong at language work: turning a rough dictation into a readable letter, rewriting discharge instructions at a sixth-grade reading level, drafting a prior authorization appeal, summarizing a paper you have already read, or reformatting a protocol into a checklist. It is good at helping you think, too. Asking it to argue the opposite side of a management decision, or to list what a differential might be missing, uses the model as a prompt for your own reasoning rather than as an authority.

The common thread is that in every one of those tasks, you already know the right answer and you are using the model to shape or stress-test it. The moment you would be accepting a clinical fact you cannot independently confirm, you have crossed the line.

What to use instead at the point of care

The purpose-built tools solve the auditability problem by construction: they cite a specific monograph, they carry an update date, and they are built to enumerate rather than summarize.

OpenEvidence has become the common answer among US clinicians because it is free to NPI-verified professionals and grounds its answers in the literature with citations, which is why we compared the two directly in OpenEvidence vs ChatGPT. The established references solve it differently, through editorial process: UpToDate, DynaMed and the drug compendia behind them. Those carry no published price, as we found when we checked what DynaMed and DynaMedex cost and again with UpToDate subscription pricing, because they are sold to institutions rather than to individuals.

Whatever you land on, the test is the same one: can you show, six months from now, what source supported the decision you documented today. A chat transcript does not pass that test. A cited monograph with a revision date does.

A workable policy for a practice

Most practices do not need to ban the tool. They need to write down three things and make them easy to follow.

First, name which tier is approved and confirm the BAA actually covers it, in writing, before anyone touches patient data. Second, define the de-identification rule in plain language, because "remove identifiers" is not specific enough to follow under time pressure: state that ages over 89, rare diagnoses, dates of service and free-text details that could identify someone in a small community all count. Third, require that any clinical fact taken from a model gets verified against a cited reference before it reaches the chart, and that the reference, not the chat, is what gets documented.

Writing the policy is the easy half. The harder half is showing an auditor that it was followed, which is the same problem regulated teams have with every new tool and the reason it helps to map each obligation to a specific control rather than keep the rules in a memo nobody reopens. Whichever way you handle it, put a review date on it. This category is moving fast enough that a policy written a year ago is probably wrong now.

The bottom line

Use it for words, not for facts you cannot check, and never with identifiers on a tier that has no BAA. That single sentence covers almost every situation a practicing clinician runs into.

The clinicians getting real value out of these tools are not the ones asking a chatbot for a dose. They are the ones who moved their documentation burden onto a general model, kept their clinical lookups on a cited reference, and were clear with themselves about which was which. Our buyer's guide to clinical decision support software covers what the purpose-built options do differently, and what each one costs.

See Prescriber.io check a prescription

The assistant surfaces interactions and contraindications for review, flags renal and hepatic dose adjustments, and suggests guideline-based alternatives with cited sources. You review, verify and sign every prescription.

Bring the check to your prescribing workflow

Prescriber.io surfaces interactions and contraindications, flags renal and hepatic dose adjustments, and suggests guideline-based alternatives with cited sources, in one calm card at the point of care. The responsible clinician reviews, verifies and signs every prescription.

Interactions · Contraindications · Dosing · You review & sign

Prescriber.io is a decision-support tool for licensed clinicians. It does not diagnose or prescribe, and it is not a substitute for professional clinical judgment. Verify against official sources.