← Back to Ask Ellen
Prior Authorization2026-04-106 min read

Why ChatGPT Is Not an Option for Prior Auth Letters (And What Is)

Why ChatGPT Is Not an Option for Prior Auth Letters (And What Is)

Audience: Physicians, PA coordinators, practice administrators

Published: 2026-04-01

Category: Compliance, Practice Management

Why ChatGPT Is Not an Option for Prior Auth Letters (And What Is)

5 minute read

Prior authorization letters are time-consuming to write. AI writing tools have become capable enough that they can produce credible clinical correspondence in minutes. The combination of a difficult, repetitive task and a tool that appears to solve it has led many PA coordinators and physicians to use ChatGPT, Google Gemini, or similar general-purpose AI assistants to draft PA letters, LMNs, and appeal correspondence.

This practice has two distinct problems: one is a legal compliance issue that creates institutional liability, and the other is a clinical quality issue that reduces the letter's chance of approval. Both are worth understanding in detail.

The HIPAA Problem

HIPAA's Privacy Rule requires that protected health information (PHI) be disclosed only to covered entities and their business associates, and only in ways that are expressly permitted under the rule. When a PA coordinator opens ChatGPT and types "write a prior authorization letter for a 54-year-old patient with rheumatoid arthritis requesting Rinvoq through Aetna," any information about that patient that is included in the prompt constitutes PHI being transmitted to a third party.

OpenAI, Google, and Microsoft are not HIPAA-covered entities. They are not business associates of your practice in the legal sense, because they do not sign Business Associate Agreements (BAAs) for their standard consumer and professional tier products. As of this writing, OpenAI's standard ChatGPT and ChatGPT Plus plans explicitly state that they are not HIPAA-compliant and are not intended for healthcare use involving PHI.¹

This matters because the HIPAA Security Rule and Privacy Rule do not require that a breach actually occur before a violation exists. The act of transmitting PHI to a system without a BAA is itself a potential violation of 45 CFR 164.502, regardless of what the receiving system does with that data.²

The specific risk for prior authorization letters:

PA letters almost always contain:

  • Patient name
  • Date of birth
  • Diagnosis codes
  • Medication names and dosages
  • Lab values and clinical history
  • Insurance member ID
  • Every piece of that information is PHI. A coordinator who pastes any of it into ChatGPT to draft a letter has transmitted PHI to a non-HIPAA-covered system. At scale, across a practice with 40 to 60 PA submissions per week, this exposure compounds rapidly.

    What about Microsoft Copilot or ChatGPT Enterprise?

    Microsoft has HIPAA-compliant versions of its AI tools available through its enterprise healthcare agreements, and OpenAI has begun offering enterprise agreements with BAA provisions. These are not the tools most coordinators are using when they open ChatGPT on their phone or browser. If your practice intends to use any AI tool for PA drafting that involves PHI, the compliance analysis must start with a signed BAA, not with whether the output looks useful.

    The Clinical Quality Problem

    Even setting aside the compliance issue, general-purpose AI tools produce prior authorization letters that fail at a fundamental task: matching the specific criteria your payer requires for the specific drug being requested.

    Here is what that means in practice.

    Payer criteria are not generic. Aetna's coverage criteria for ustekinumab for psoriatic arthritis differ from Cigna's criteria for the same drug and the same indication. The criteria are documented in each payer's medical policy, updated periodically, and enforced by reviewers who are looking for specific documentation. A letter that does not address Aetna's specific requirements, in Aetna's preferred structure, leaves openings that experienced reviewers will use to justify a denial.

    ChatGPT does not know your payer's policy. General-purpose AI tools are trained on publicly available text, which includes some payer policy documents. But their training data has a cutoff date, payer policies change, and the model has no mechanism to verify whether it is producing language that matches the current coverage criteria for your specific payer. When asked to write a PA letter for Humira for rheumatoid arthritis, ChatGPT will produce a plausible-sounding letter. It will not produce a letter that addresses the exact step therapy documentation, the exact lab value thresholds, and the exact clinical rationale that your payer's current medical policy requires for approval.

    Generic output is identifiable. Experienced payer reviewers read hundreds of letters per week. Letters that are generic, well-formatted but vague about payer-specific criteria, and that do not directly address the specific coverage policy for the drug in question are recognizable as low-effort submissions. Payers are not required to tell you that they are denying because the letter was generic, but the pattern shows up in denial rates.

    Off-label cases require specific evidence. For off-label denials, the appeal letter must cite the NCCN Compendium entry, the relevant published clinical literature, and any applicable CMS or specialty society guidance. ChatGPT may produce a letter that mentions clinical evidence, but it cannot reliably identify the current NCCN listing for a specific drug-indication combination, verify the publication status of the most relevant trials, or match the evidence to the stated reason for denial in the way a system built for this purpose can.

    The Standard Your Letters Need to Meet

    A prior authorization letter that succeeds does three things:

    1. It addresses the specific coverage criteria in the payer's current medical policy. Not the general criteria for the drug class. The specific criteria for this drug, this indication, at this payer. That requires knowing what those criteria are before drafting.

    2. It documents the patient's clinical course in a way that directly maps to those criteria. Not a general clinical narrative. A narrative that demonstrates, point by point, why this patient meets the payer's authorization requirements.

    3. For appeals, it addresses the specific reason for denial with the specific clinical evidence that counters it. A generic "the medication is medically necessary" appeal fails because it does not engage with the reason the claim was denied. Payer reviewers are evaluating whether you have addressed their stated objection. Generic language does not do that.

    What HIPAA-Compliant, Payer-Specific Looks Like

    The alternative to general-purpose AI tools for PA drafting is a purpose-built tool that has been designed for healthcare use, executes under HIPAA compliance, and has indexed actual payer policy criteria.

    Ellen is one such tool. It has indexed coverage criteria for 507 drugs across 61 insurers. It signs a BAA for practices that require one. Patient data entered into Ellen is not used to train models. When you build a letter for a specific drug and payer, Ellen draws on that payer's current coverage criteria for that drug, building the letter around the language and requirements the payer actually enforces.

    The compliance baseline and the clinical quality problem are both addressed by the same design decision: a system built for healthcare use, with actual payer policy data, rather than a general-purpose text generator trained on public internet data.

    Ellen is free to start at ellenrx.com/providers. No EHR integration required.

    Sources:

  • OpenAI. "ChatGPT and HIPAA compliance." OpenAI Help Center, 2024. OpenAI's standard consumer and Plus tiers do not offer BAAs and are not designated HIPAA-compliant.
  • U.S. Department of Health and Human Services. "Business Associate Contracts." HHS.gov, 2023. 45 CFR 164.502(e) and 164.504(e).
  • American Medical Association. "Artificial Intelligence in Health Care: Privacy and Compliance Considerations." AMA, 2023.
  • Office for Civil Rights. "HIPAA Enforcement." HHS.gov, 2024. Enforcement actions for improper disclosure of PHI to third parties.
  • Need Help with Your Appeal?

    Ellen can help you decode your denial and generate a personalized appeal letter with the right legal citations and medical language.

    Start Your Appeal