Insights
Is it safe to put patient information into AI?
Sometimes yes, and the thing that decides it is almost never the thing people worry about. It is not whether the model is smart, or new, or expensive. It is whether the company behind it has signed a document agreeing to be legally responsible for your patient's information, and whether the exact account your team is logged into is the one that document covers. That is the whole answer. Everything below is why it matters and how to find out.
Follow the sentence you just typed
It is 6:40 in the evening. The building is quiet, your last patient left an hour ago, and there is one more letter to write. So you open the assistant you use for everything else, and you type the situation out the way you would say it to a colleague — the name, the age, what you found, what you are worried about — and you ask it to help you say this kindly. Ten seconds later you have something good. Better than what you would have written tired. You paste it, you send it, you go home. Here is what happened while you were doing that. Those sentences left your building. They traveled to a data center that belongs to someone else, where they were processed and then held for some period of time in logs you cannot see, under a retention policy you never read. Depending on which account you were signed into, a human reviewer may be permitted to look at them, and the content may or may not be eligible to help train a future version of the model. Your patient's name went with it. Their age went with it. The fact of their diagnosis went with it. And nothing bad happened. That is genuinely the hardest part of this. Nothing visibly bad happens, not the first time and not the hundredth, which is exactly why it becomes a habit before anyone thinks to ask about it.
From the field
We were asked by a practice to look at their AI use, and we started the way we always do, by asking people what they were actually doing rather than what the policy said. The honest answer was a handful of personal accounts, opened by good people on their own initiative. One of them had been pasting visit details in for months to draft patient letters. She was, by a distance, the warmest writer on the team, and she was doing it because the letters that went out sounded like a form and she thought patients deserved better. That is not a discipline problem. That is someone doing the right thing through the wrong door. The tradeoff was real and we will not pretend it wasn't: switching everyone to a covered tool took about three weeks, cost money the practice had not budgeted, and the covered version was, at first, a little clumsier than what she had been using. She kept her workflow. They kept her judgment. Nobody got written up.
The two words that decide this are "business associate"
Under HIPAA, your practice is a covered entity. Anyone outside your walls who handles patient information on your behalf — your billing company, your shredding service, your cloud storage, and yes, an AI vendor — is a business associate, and a Business Associate Agreement is the signed contract that puts them legally on the hook alongside you. It is the difference between a locksmith who has a contract with your building and a stranger you handed a key to because he seemed competent. Without that signature, sending patient information to a vendor is not a gray area or a judgment call. It is a disclosure you were not permitted to make. The practical shape of this is simpler than it sounds. Most of the major AI providers will sign one, but generally on their business, enterprise, or developer plans, and generally not on the free or personal paid accounts that a well-meaning team member signs up for on a Tuesday with a work email. So the question is not "is this tool HIPAA compliant," which is marketing language and means very little on its own. The question is "will you sign a BAA covering the specific plan we are on, and can I have it in writing." That is one email. You do not need to understand a single thing about how the model works to send it. And this is not a fringe concern anymore: in the AMA's 2026 physician survey, 81 percent of physicians reported using AI in practice, more than double the 38 percent who said so in 2023, and 86 percent named data privacy as critical to adopting it more widely. Nearly everyone is already in the water. Most of them are asking the same question you are.
20.1 million
People whose protected health information was exposed in reported healthcare breaches in the first four months of 2026, according to the HIPAA Journal's April 2026 breach report — and that is actually good news, a 25.5 percent drop from the same period in 2025. Almost none of it involved AI. Hacking and IT incidents caused 76.6 percent of April's large breaches, nearly all of them on network servers. We are not telling you AI is the danger. We are telling you that you are adding a new door to a building where the existing doors are already being tried every night.
What to ask before anyone types a patient's name
Four questions will get you most of the way, and none of them are technical. Ask whether they will sign a BAA for the exact plan you are on, not for some other tier of the product. Ask whether your data is used to train or improve their models, and whether you can turn that off in writing rather than in a settings menu that a future update might quietly reset. Ask how long they keep what you send, and who inside their company is permitted to read it. And ask what happens to all of it on the day you leave — whether it is deleted, when, and how you would know. A vendor who answers those four plainly and in writing is a vendor you can work with. A vendor who sends you a marketing page with a shield icon on it has told you something too, just not what they meant to. It is worth knowing that the ground itself is still moving underneath all of this. The federal rule that governs how you protect electronic health information is in the middle of its first serious rewrite in twenty years, proposed in January 2025 with new expectations around encryption, multi-factor authentication, and asset inventories. It has not been finalized. The target date has slipped to 2027. So do not build your practice's approach around waiting for a regulator to hand you the answer, because on this timeline the answer is going to arrive well after your team has already decided what it does on Tuesday afternoons.
If it has already happened, you are not in trouble yet
Most practices we talk to discover this the same way: someone says something at lunch, and a small cold feeling arrives. If that is you, the useful move is not an investigation. It is a conversation, held without a hammer in your hand, where you ask your team what they are using and genuinely mean it when you say nobody is in trouble. You will learn more in fifteen honest minutes than in a month of monitoring, and you will learn the thing that actually matters, which is what problem they were solving when they reached for it. Then get them a covered version of that same capability, write one page in plain language about what may and may not be typed where, and — this is the part people skip — tell them why. Not the regulation. The reason. Because people route around rules they experience as pure friction, and a policy that costs a nurse twenty minutes a day without ever explaining itself is a policy that will be quietly ignored by the most dedicated person on your staff, who will be ignoring it in order to take better care of someone.
None of this is really about software. Somebody sat in a room with you and said a true thing out loud that they have not said to their spouse, or their manager, or their kids. They did that because the room felt safe and because you were fully there with them. Every tool we bring into a practice either protects that or spends it, and the tools are getting good enough now that it is easy to spend it without ever noticing. So ask the unglamorous questions. Get the signature. Do the boring work in the quiet part of the week, so that the next time someone tells you something hard, the only thing in the room is the two of you.