Check retention beyond “not used for training”
Training, storage, deletion and zero data retention describe different things. Verify the exact service and feature.
Ask four separate questions
Is content used for training? How long are prompts, files, outputs and logs retained? Who can access them? What happens when you delete a conversation, file or account? Record the answers for the actual account, product, feature and agreement you will use.
Do not treat “not used for training” as “nothing is stored.” Include conversation history, uploaded files, application state, safety logs, backups and connected services in the review. Ask which deletion and retention settings your organization can control.
Zero data retention is feature-specific
OpenAI’s API documentation distinguishes abuse-monitoring logs from application state. Default abuse-monitoring logs may remain for up to 30 days; approved retention controls have eligibility requirements and feature-specific limits. Zero data retention is not a blanket property of every OpenAI product or API feature.
Check the current endpoint table and your approved configuration. Connected third-party services have their own handling policies. A provider’s retention promise does not automatically cover every downstream service or your own stored outputs.
Keep an intentional record, not accidental copies
Decide where the reviewed clinical result belongs and who can access it. Set an appropriate cleanup process for draft exports and teaching workspaces without deleting records your practice must retain. Assign an owner to verify that cleanup and access revocation work.
Recheck these settings when a feature or plan changes. Keep a dated configuration record rather than relying on a vendor logo or a broad “HIPAA-ready” label.
Compare the actual provider route
For Claude, use the API feature table and the separate BAA guidance for Claude Code or Enterprise. API HIPAA readiness and ZDR are different arrangements. Eligible local Claude Code configurations have additional ZDR requirements; consumer and remote surfaces do not inherit that coverage.
For Amazon Bedrock, inspect the selected model’s allowed retention mode and account settings. For Microsoft Foundry, distinguish Models sold by Azure from other provider-operated models and from Microsoft 365/Copilot. Read the documentation for the route you are actually using, including feature storage and abuse-monitoring controls.