Whether or not your organization has approved it, some of your staff are probably using a generative AI chatbot. They use it to draft an email to a family member, summarize a long document, polish a policy or figure out a spreadsheet formula. Most are trying to save time. The risk is that, in a busy moment, someone pastes in a resident's name and diagnosis to get a better answer, and protected health information has just left your control.
A short written policy, backed by a few practical controls, handles this better than a ban that everyone quietly ignores.
When you type or paste text into a public AI tool, it is sent to an outside company. Depending on the service and its settings, that text may be stored, reviewed by staff of the provider or used to improve models. Under HIPAA, disclosing protected health information to a vendor that handles it on your behalf generally requires a business associate agreement and appropriate safeguards. A free consumer chatbot typically offers neither. So the safe default is simple: do not put PHI into any AI tool your organization has not specifically approved for that purpose.
People often assume PHI means a name and a medical record number. It is broader. Information can identify a resident through combinations of details, such as:
Name, initials, room number, dates of birth or admission
Diagnoses combined with age, location or unusual circumstances
Photos, voice recordings or screenshots from the clinical system
Insurance or account numbers
Details of an incident that make the person recognizable
Removing a name is not always enough if the remaining story points to one person in a small facility.
Your policy can fit on one page. Consider covering:
Use approved AI tools for general tasks that contain no resident, family or employee information, such as drafting a generic policy outline, brainstorming activity ideas or explaining a software feature
Ask for help with wording using fictional or fully generic examples
Review every AI output for accuracy before using it, since tools can state wrong information confidently
Enter any PHI, including names, dates, diagnoses or identifiable descriptions, into an AI tool that has not been approved and covered by an appropriate agreement
Paste login credentials, internal network details or confidential business and financial data
Upload resident documents, care plans, incident reports or screenshots
Use AI output as a clinical decision, order or final documentation without clinician review
Install AI browser extensions or apps on work devices without approval
Name a person who handles requests for new tools, and promise a quick answer. People go around the rules when approval is slow.
Policy alone is not enough. Consider:
Approved tools. If AI is useful for your team, evaluate a business-grade option with proper contract terms, and confirm what it does with your data.
Device and browser controls. Block or limit unapproved AI sites and extensions on work computers where appropriate.
Data loss prevention. Some security tools can warn when sensitive patterns are pasted into websites.
Training. Show real examples of a risky prompt and a safe rewrite. Staff remember concrete examples.
Instead of pasting, "Write a note to the daughter of Mrs. Jones in Room 12 about her fall on Tuesday and her hip fracture," a staff member can ask the tool for "a compassionate template letter to a family member after a resident has had a fall," and then fill in the details privately.
Tell staff to report accidental disclosures right away, without fear of punishment. Your privacy officer can then assess whether it is a reportable event under your HIPAA breach procedures. Early reporting beats concealment.
AI tools change quickly. Revisit the policy at least twice a year, and update your HIPAA training to include it.
We help healthcare and senior-living organizations in Oklahoma, Texas and Arkansas write practical AI-use policies and apply the technical controls behind them.
An outsourced IT department with proactive maintenance and one number to call.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172