Cybersecurity: 24/7/365

Blog

How to Write an AI Policy for Your Practice
by 4MEDNET Team
April 9, 2026
AI & Automation

A medical assistant at a four-provider clinic needs to draft a referral letter. She pastes the patient's chart note into a free chatbot, gets a clean paragraph back, and moves on. It took ninety seconds. It also sent protected health information to a company with no business associate agreement, no deletion guarantee, and every right to train on what it received.

Nobody told her not to. That is the actual problem in most practices right now. Staff adopted artificial intelligence faster than anyone wrote down the rules, and the gap between what people do and what the practice has approved keeps widening.

An AI policy closes that gap. It does not have to be long. It has to be specific about which AI tools are approved, what may never be pasted into one, and who decides.

Is it a HIPAA violation to use AI in healthcare?

Using AI is not a violation by itself. Sending protected health information to a vendor without a signed business associate agreement is.

That single distinction drives most of your policy. If an AI system will touch PHI, the vendor is a business associate and needs a BAA before anyone uses it. Our guide to business associate agreements covers what that contract has to say.

Consumer chatbots are the trap. The free tier of a general-purpose AI tool almost never comes with a BAA, and its terms often permit training on your inputs. The paid enterprise tier of the same product frequently does offer one. Same brand, different contract, completely different compliance answer. We go deeper on that split in whether AI can be HIPAA compliant.

What regulations actually apply to AI in a US medical practice

There is no single federal AI law covering medical practices. Instead, four existing regulatory frameworks reach different parts of AI use, and digital health tools can fall under more than one at once.

  • HIPAA. The Privacy and Security Rules apply to PHI regardless of what technology processes it. An AI tool handling patient data sits inside your existing risk analysis.
  • FDA. Software that diagnoses, treats, or drives a clinical decision may be regulated as a medical device. Most administrative AI is not. Clinical decision support can be, depending on whether the clinician can independently review the basis for the recommendation.
  • ONC certification. Certified electronic health record technology must disclose information about predictive algorithms it ships. If your EHR includes AI-enabled features, that transparency information is available to you.
  • State law. A growing number of states regulate AI in health care directly, including disclosure requirements when generative AI produces clinical communications to patients. Some state statutes split duties between the developers who build a system and the deployers who put it to work — as the customer of a vendor tool, your practice is usually the deployer. Check your own state before you write the policy.

Note that the EU AI Act, which dominates most published AI governance writing, does not apply to a US practice treating US patients. Do not build your framework around it.

What to include in an AI policy

Keep it to two pages. A policy nobody reads governs nothing.

1. Scope: which AI tools this covers

State plainly that the policy covers any AI system used for practice work, on any device, including personal accounts. Staff often assume a personal ChatGPT login on a personal phone falls outside practice rules. Say that it does not.

2. An approved list

Name the specific AI tools staff may use, and for what. An ambient documentation tool with a signed BAA might be approved for clinical notes. A general chatbot might be approved for marketing copy and staff scheduling drafts only. Anything not on the list requires approval before use.

3. A hard line on PHI

This is the sentence that prevents the referral-letter incident. Write it as a rule, not a suggestion: no patient name, date of birth, medical record number, diagnosis, or chart text goes into any AI tool that is not on the approved list.

4. Human review before anything reaches a patient or chart

Generative AI produces fluent text that is sometimes wrong. Require that a person reads and approves every AI-drafted clinical note, patient message, or letter before it is sent or filed. Name who holds that responsibility for each workflow.

5. Disclosure to patients

Decide when you tell patients AI was involved. Some states now require it for certain communications. Even where it is optional, deciding in advance beats improvising when a patient asks.

6. Who owns oversight

Name a person, not a committee. In a small practice this is usually the practice manager or the privacy officer. That person approves new AI tools, keeps the approved list current, and reviews the policy at least annually.

7. How to report a problem

Give staff a way to flag an AI output that was wrong, or a mistake like the pasted chart note, without fear of discipline for admitting it. You cannot fix incidents you never hear about.

How to evaluate a new AI tool before deployment

Evaluate every request the same way. Six questions is enough for a practice of your size:

  • Will this AI system touch protected health information? If yes, is there a signed BAA?
  • Does the vendor train its models on our data, and can we turn that off?
  • Where is data stored, and how long is it retained after we delete it?
  • Does this feature make or influence a clinical decision? If so, can the clinician see the basis for it?
  • What happens to patient care if the tool is unavailable for a day?
  • Who at our practice is accountable for checking its output?

Document the answers. When an auditor asks how you vetted an AI-enabled feature, that record is your answer. It also belongs in your HIPAA risk assessment, since a new tool handling PHI changes your risk picture.

If you want an external reference to point at, the National Institute of Standards and Technology publishes an AI Risk Management Framework that larger health systems build their governance on. You do not need to adopt it wholesale. Borrowing its four functions — govern, map, measure, manage — gives a small practice a defensible structure without the overhead.

Accuracy, bias, and patient safety

Two risks of artificial intelligence deserve their own paragraph in the policy, because they are the ones a compliance checklist tends to miss.

The first is fabrication. Generative AI will invent a plausible medication dose or a referral detail that was never in the source. In clinical settings that is a patient safety issue, not a quality-of-writing issue, which is why the human review rule above is the most important line in the document.

The second is algorithmic bias. Models trained on data that underrepresents your patient population can perform worse for the people it underrepresents. A small practice cannot audit a vendor's training data. It can ask the vendor what populations the system was validated on, and it can watch for outputs that look consistently off for a subset of patients. Write down that healthcare professionals are expected to report that pattern when they see it.

Rolling it out so staff actually follow it

Policies fail at adoption, not at drafting. Three things move the needle.

Give people an approved option. A blanket ban pushes AI use underground, onto personal phones where you have no visibility. Approving one good tool for the tasks staff care about is more protective than prohibiting everything.

Fold it into the training you already run. Your annual HIPAA training is the natural home for a ten-minute AI segment, and it puts the acknowledgment in the same file as everything else. A little AI literacy goes further than a signature: staff who understand why a chatbot invents a citation are the ones who catch it.

Revisit it on a schedule. The tools change every few months. An AI governance framework reviewed once and filed away describes a practice that no longer exists. Put a date on the calendar.

Start with the two-page version

Practices stall on this because they picture a formal governance program. You do not need one. AI policies safeguard a practice when they are short enough to remember: an approved list of health AI tools, a hard rule about PHI, a named owner, and a review date.

Write those four things down this week. You can add detail as your use of AI grows, and you will have closed the gap that let a chart note walk out the door in ninety seconds.

The tool most practices approve first is ambient documentation. Our guide to AI medical scribes and HIPAA covers the vendor questions and the state recording-law trap that HIPAA does not cover.

Ready to take the next step? Explore our healthcare IT services, book a free consultation, or compare our plans.

Tags:
Share:
HIPAACybersecurityManaged ITRansomwareComplianceEHRData BreachAI AutomationBackup & DR
4MEDNET
Contact Us
Ready to secure your practice?
Schedule a free IT assessment today
Book Your Free IT Assessment