For health-tech and healthcare teams, the first decision is not a checklist. It is who uses the system, where the workflow runs, what data crosses each boundary, and which OpenAI service your agreement actually covers.
Source review: Independent Ginylil guidance
Decision map
Start with the user and system boundary.
Managed healthcare workspace
ChatGPT for Healthcare
Choose this path when
Clinicians, administrators, or researchers need a governed ChatGPT workspace built for a healthcare organization.
Investigate before choosing
Which users, features, connectors, retention settings, and administrative controls your BAA and rollout cover.
Not a fit when
The AI capability must live inside your own application or product workflow.
Managed enterprise workspace
ChatGPT Enterprise with Regulated Workspace
Choose this path when
Employees need a governed general-purpose workspace with enterprise identity, roles, and administrative controls.
Investigate before choosing
Whether the required functions are enabled and covered, including any connector, search, sharing, or local-client use.
Not a fit when
The end user is a patient or customer interacting through your own product.
Custom application
API with Modified Retention
Choose this path when
Your organization must own the application experience, authorization, data flow, logging, human review, and operational controls.
Investigate before choosing
BAA execution, organization provisioning, endpoint eligibility, storage behavior, third-party tools, and the exact account and project configuration.
Not a fit when
You need a ready-made employee workspace rather than a product engineering program.
Local engineering client
Codex Local
Choose this path when
Authorized engineers need CLI, IDE, or desktop assistance and your organization can manage the workstation and repository environment.
Investigate before choosing
Authentication path, workspace eligibility, local retention, repositories, MCP servers, browser or computer use, secrets, and third-party services.
Not a fit when
You cannot enforce managed endpoint, identity, repository, and tool-use policy.
Five questions
The minimum useful discovery.
Who is the user?Employee, clinician, researcher, engineer, patient, or customer.
Where does the workflow live?OpenAI workspace, local developer tool, or your application.
What crosses the boundary?Data classes, files, prompts, outputs, metadata, and connected systems.
Which agreement applies?Product, BAA, eligible functions, retention controls, and account provisioning.
Who operates the controls?Identity, endpoint, application, logging, review, incident, and vendor owners.