Key takeaways
- The entire question is whether the vendor will sign a business associate agreement. Everything else follows.
- There is a large body of genuinely useful work in a practice that never touches patient information, and it can start today.
- Deleting the patient's name is not de-identification and should not be relied on.
- Your front desk is almost certainly already using a consumer tool. That is the exposure to address first.
Medical and dental practices approach this differently from other businesses, and correctly so. A law firm that mishandles client information has a professional problem. A practice that mishandles patient information has a regulatory one with defined penalties and a breach notification obligation attached. That changes the sequence: in healthcare you settle the compliance question first and then decide what is useful, rather than the other way round.
The good news is that the compliance question has a clear answer, and that a large amount of the available benefit sits outside it entirely.
The business associate agreement is the gate
Under HIPAA, any vendor that creates, receives, maintains or transmits protected health information on your behalf is a business associate, and you need a business associate agreement with them before that happens. This is not a formality and it is not satisfied by a vendor's privacy policy, a security page, or an assurance that data is encrypted.
Applied to AI tools, the position is straightforward:
- Consumer tiers generally will not sign a business associate agreement. Their terms usually say so explicitly. Protected health information must not go into them, regardless of how carefully an individual staff member thinks they are being.
- Some enterprise offerings will, either directly or through a cloud platform arrangement. Where a signed agreement is in place and the configuration matches it, the analysis becomes the same one you already applied to your practice management system and your cloud backup.
- Purpose-built clinical documentation tools are a separate category, sold into healthcare, designed around this requirement, and generally willing to sign. They are also a different product from a general-purpose assistant and should be evaluated separately.
So the first action for any practice is not a policy or a training session. It is finding out, in writing, what your intended vendor will sign. That single answer determines the scope of everything that follows.
The exposure most practices have right now: a front desk coordinator or billing specialist using a personal consumer account to reword a patient message, draft an appeal letter, or summarise a call. That is a disclosure to a vendor with no agreement in place, made by a workforce member, and the practice is responsible for it. It is worth finding out before you do anything else.
Start with the work that has no patient in it
Practices often assume that HIPAA makes AI mostly unavailable to them. It does not. It makes one category unavailable without an agreement, and leaves a substantial category untouched. The second category is where every practice should begin, because it requires no legal work at all.
| Task | Involves PHI | Can start |
|---|---|---|
| Policy, procedure and compliance documentation | No | Immediately |
| Staff training material and onboarding guides | No | Immediately |
| Job descriptions, interview questions, hiring correspondence | No | Immediately |
| Patient education handouts on conditions and procedures | No | Immediately, with clinical review |
| Website copy, newsletters and recall campaign content | No | Immediately |
| Front desk phone scripts and objection handling | No | Immediately |
| Explaining a payer policy or billing code rule internally | No | Immediately, verify against the source |
| Drafting an appeal letter for a specific patient | Yes | Only with a signed agreement |
| Summarising a patient message or call | Yes | Only with a signed agreement |
| Anything involving a chart, a claim or an identifiable person | Yes | Only with a signed agreement |
| Clinical documentation and notes | Yes | Purpose-built tooling, evaluated separately |
The top seven rows are not trivial work. A practice manager who is currently writing policy documents, rewriting the new hire guide, producing patient education material and drafting recall campaigns in the gaps between everything else will recover real hours, and none of it requires a lawyer's involvement to begin.
Why informal de-identification does not work
The idea that occurs to everyone is to strip the patient's name and proceed. It is worth understanding why this fails, because otherwise someone in your practice will do it.
HIPAA's safe harbour method requires removing eighteen categories of identifier, and they are broader than people expect. Not just names and record numbers, but all elements of dates other than year, geographic subdivisions smaller than a state, contact details, device identifiers, and any other unique characteristic or code. The alternative expert determination method requires a qualified person to assess and document the re-identification risk formally.
Beyond the technical requirements there is the practical one. In a small community, a description containing an unusual condition, an approximate age and a treatment date can identify someone to anyone who knows them, no name required. That is exactly the material that gets typed into a chat window when someone is trying to word a difficult letter.
The workable position for a practice is not to attempt de-identification informally at all. Either you have an agreement in place and can handle protected information within its terms, or you keep patient material out of the tool entirely. Half measures create the appearance of care without the substance of it.
Make this concrete in training: the rule staff can remember is that if you could work out who it is, it counts. That is not the legal standard but it produces the right behaviour, and a rule people apply beats a rule people can recite.
What the rollout looks like in a practice
Practices are small, busy, and have no IT function, so the sequence needs to be short.
- Find out who is already using something. Ask without consequences attached. You will get honest answers and a clear picture of where the risk is.
- Get the vendor position in writing. Will they sign a business associate agreement, on which tier, and at what cost. This determines your scope.
- Open one practice account on a business tier, with everyone on it and administrator-managed access, so the personal accounts have no reason to continue.
- Configure it. Training on inputs disabled, retention set, spending ceiling in place, access tied to employment.
- Write the one-page rule. What can go in, what cannot, and who to ask when unsure. One page, on the wall, not a binder.
- Train by role. Front desk, billing, practice manager and clinical staff have four different task lists, and generic training produces generic non-use.
That is a fortnight of part-time effort for most practices and it converts an ambient compliance risk into a documented arrangement.
Frequently asked questions
Is any AI tool HIPAA compliant?
No tool is compliant on its own. It depends on whether the vendor signs a business associate agreement covering your use and whether you configure and use it accordingly. Consumer tiers generally will not sign one. Some enterprise offerings will. Ask for the answer in writing before anything else.
What can we do without a business associate agreement?
Anything with no identifiable patient in it: policies and procedures, staff training and onboarding, hiring material, patient education content, website and recall copy, phone scripts, and internal questions about payer rules. That is a substantial amount of a practice manager's week and it can start today.
Can we just remove the patient's name?
No. De-identification requires removing eighteen identifier categories including dates and geographic detail, and unusual clinical detail can still identify someone in a small community. Informal redaction gives the appearance of care without the substance. Either work under a signed agreement or keep patient material out entirely.
What about AI scribes for clinical notes?
Those are a separate product category built for healthcare and generally willing to sign a business associate agreement. Evaluate them on their own terms, separately from the general-purpose assistant your administrative team uses. The two decisions are unrelated and mixing them slows both down.
Get your practice using AI on the safe side of the line
We establish what your provider will sign, configure the account and retention properly, cap the spend, tie access to employment, and write the one-page rule plus task guidance for front desk, billing and practice management. Fixed price, live in 30 days or less.