Treat public AI tools as external systems
Do not enter patient-identifiable information into a public or personally managed AI service. A convenient text box is still an external data destination, and familiarity with a product is not evidence that it is approved for protected health information.
Use only services approved by your organization for the intended data and workflow. Confirm privacy, security, contracting, retention and access controls before clinical use.
Use the minimum information necessary
Even in an approved environment, share only what is needed for the task. Remove names, identifiers, exact dates and distinctive combinations of facts when they are unnecessary.
De-identification is contextual. A rare diagnosis, unusual event or small community may make a narrative identifiable even after obvious identifiers are removed.
- Prefer synthetic or fictional cases for learning and prompt development
- Remove unnecessary identifiers and unique narrative details
- Avoid copying entire charts when a limited factual summary is enough
- Follow organizational policy and applicable privacy law
Know how the provider handles data
Ask whether submitted data are retained, reviewed by people, used for product improvement or training, transferred across jurisdictions or accessible to subcontractors.
Settings can change, so governance should depend on written organizational approval and contractual safeguards—not an individual user’s interpretation of a product screen.
Review every output before use
Generative systems can omit facts, invent details and present uncertain conclusions confidently. A clinician remains responsible for checking the source record, clinical context and final communication.
Never allow generated text to enter a medical record, patient message, referral or order without appropriate human review. Preserve a clear distinction between drafting assistance and clinical judgment.
Create a safe team workflow
Organizations should publish an approved-use list, prohibited-use list, escalation route and incident-reporting process. Education should include privacy, bias, hallucination, consent and patient communication.
A safe default is simple: if the environment, data agreement or permitted use is unclear, do not submit patient information until an authorized privacy or security leader confirms the workflow.
