Cybersecurity: 24/7/365

A medical assistant at a four-provider clinic needs to draft a referral letter. She pastes the patient's chart note into a free chatbot, gets a clean paragraph back, and moves on. It took ninety seconds. It also sent protected health information to a company with no business associate agreement, no deletion guarantee, and every right to train on what it received.
Nobody told her not to. That is the actual problem in most practices right now. Staff adopted artificial intelligence faster than anyone wrote down the rules, and the gap between what people do and what the practice has approved keeps widening.
An AI policy closes that gap. It does not have to be long. It has to be specific about which AI tools are approved, what may never be pasted into one, and who decides.
Using AI is not a violation by itself. Sending protected health information to a vendor without a signed business associate agreement is.
That single distinction drives most of your policy. If an AI system will touch PHI, the vendor is a business associate and needs a BAA before anyone uses it. Our guide to business associate agreements covers what that contract has to say.
Consumer chatbots are the trap. The free tier of a general-purpose AI tool almost never comes with a BAA, and its terms often permit training on your inputs. The paid enterprise tier of the same product frequently does offer one. Same brand, different contract, completely different compliance answer. We go deeper on that split in whether AI can be HIPAA compliant.
There is no single federal AI law covering medical practices. Instead, four existing regulatory frameworks reach different parts of AI use, and digital health tools can fall under more than one at once.
Note that the EU AI Act, which dominates most published AI governance writing, does not apply to a US practice treating US patients. Do not build your framework around it.
Keep it to two pages. A policy nobody reads governs nothing.
State plainly that the policy covers any AI system used for practice work, on any device, including personal accounts. Staff often assume a personal ChatGPT login on a personal phone falls outside practice rules. Say that it does not.
Name the specific AI tools staff may use, and for what. An ambient documentation tool with a signed BAA might be approved for clinical notes. A general chatbot might be approved for marketing copy and staff scheduling drafts only. Anything not on the list requires approval before use.
This is the sentence that prevents the referral-letter incident. Write it as a rule, not a suggestion: no patient name, date of birth, medical record number, diagnosis, or chart text goes into any AI tool that is not on the approved list.
Generative AI produces fluent text that is sometimes wrong. Require that a person reads and approves every AI-drafted clinical note, patient message, or letter before it is sent or filed. Name who holds that responsibility for each workflow.
Decide when you tell patients AI was involved. Some states now require it for certain communications. Even where it is optional, deciding in advance beats improvising when a patient asks.
Name a person, not a committee. In a small practice this is usually the practice manager or the privacy officer. That person approves new AI tools, keeps the approved list current, and reviews the policy at least annually.
Give staff a way to flag an AI output that was wrong, or a mistake like the pasted chart note, without fear of discipline for admitting it. You cannot fix incidents you never hear about.
Evaluate every request the same way. Six questions is enough for a practice of your size:
Document the answers. When an auditor asks how you vetted an AI-enabled feature, that record is your answer. It also belongs in your HIPAA risk assessment, since a new tool handling PHI changes your risk picture.
If you want an external reference to point at, the National Institute of Standards and Technology publishes an AI Risk Management Framework that larger health systems build their governance on. You do not need to adopt it wholesale. Borrowing its four functions — govern, map, measure, manage — gives a small practice a defensible structure without the overhead.
Two risks of artificial intelligence deserve their own paragraph in the policy, because they are the ones a compliance checklist tends to miss.
The first is fabrication. Generative AI will invent a plausible medication dose or a referral detail that was never in the source. In clinical settings that is a patient safety issue, not a quality-of-writing issue, which is why the human review rule above is the most important line in the document.
The second is algorithmic bias. Models trained on data that underrepresents your patient population can perform worse for the people it underrepresents. A small practice cannot audit a vendor's training data. It can ask the vendor what populations the system was validated on, and it can watch for outputs that look consistently off for a subset of patients. Write down that healthcare professionals are expected to report that pattern when they see it.
Policies fail at adoption, not at drafting. Three things move the needle.
Give people an approved option. A blanket ban pushes AI use underground, onto personal phones where you have no visibility. Approving one good tool for the tasks staff care about is more protective than prohibiting everything.
Fold it into the training you already run. Your annual HIPAA training is the natural home for a ten-minute AI segment, and it puts the acknowledgment in the same file as everything else. A little AI literacy goes further than a signature: staff who understand why a chatbot invents a citation are the ones who catch it.
Revisit it on a schedule. The tools change every few months. An AI governance framework reviewed once and filed away describes a practice that no longer exists. Put a date on the calendar.
Practices stall on this because they picture a formal governance program. You do not need one. AI policies safeguard a practice when they are short enough to remember: an approved list of health AI tools, a hard rule about PHI, a named owner, and a review date.
Write those four things down this week. You can add detail as your use of AI grows, and you will have closed the gap that let a chart note walk out the door in ninety seconds.
The tool most practices approve first is ambient documentation. Our guide to AI medical scribes and HIPAA covers the vendor questions and the state recording-law trap that HIPAA does not cover.
Ready to take the next step? Explore our healthcare IT services, book a free consultation, or compare our plans.