Blog · Security

AI tools and HIPAA: do not paste patient details into a chatbot

Drafting letters with AI is fine. Dropping a name, DOB, and assessment into a consumer model is a disclosure you may not be able to unwind.

Patients are already asking whether their doctor uses AI. Staff are already pasting awkward letters into free chat tools. The compliance question is simple: did protected health information leave your designated record set for a vendor with no BAA?

Rules staff can remember

  • No names, dates of birth, member IDs, or unique clinical details in a consumer AI prompt.
  • No uploading visit notes, faxes, or form PDFs to a personal AI account.
  • If a vendor offers a healthcare AI feature, ask for the BAA and the training-data policy first.
  • Keep the official letter, fax, or form in your HIPAA system even if AI helped draft the wording.

Where HIPAA Companion fits

The product does not replace clinical judgment. It keeps the official send path (email, fax, and personalized forms) inside a stack that already has a BAA and an audit trail. Draft offline if you want. Transmit through the documented channel.

Write a one-page AI use policy. Put it next to the email and fax policy so it is not a separate mystery document.