Guardrails
Use AI without creating a privacy or trust problem. These are the practical boundaries: what must stay out, what needs approval, and what is lower risk to use.
The reason to take this seriously is simple. One bad paste can damage trust and trigger an incident response. Clear boundaries protect the people whose information you handle and make responsible use easier to support.
The rules are short and easier to follow when the organization makes approved tools, prohibited data and escalation contacts explicit.
Keep out by default
Use sensitive material only in an explicitly approved workflow. Passwords and access keys never belong in a prompt.
- Patient information
- Do not paste identifiable clinical information into a general AI tool. A HIPAA-regulated organization may use ePHI only in a specifically approved configuration with the required agreements and safeguards.
- Anyone’s 360 or performance review content
- It was given to you under a promise of confidence. That promise didn’t have an exception for software.
- Evaluation comments with names still in them
- Open text boxes routinely name faculty, colleagues and occasionally patients. Take the names out first, every time.
- A client’s internal documents
- If you consult, your engagement terms almost certainly cover this. Check before you assume they don’t.
- Faculty disclosures before they are public
- Treat declared financial relationships as sensitive until your organization’s policy says they may be used. ACCME requires relevant relationships to be disclosed to learners before the education, but that does not make an AI tool an approved place to process them.
- Anything in an active grievance, investigation or legal matter
- Different rules apply and they aren’t yours to interpret. Talk to HR or your legal contact first.
- Logins and passwords, of any kind
- Passwords, portal logins, access keys, registration system credentials. Never, in any tool, for any reason.
Check first
Potentially usable, with a condition attached. Know the condition.
- Aggregate evaluation data
- Lower risk, not automatically safe. Small groups, rare combinations and attached free text can still identify a respondent.
- Unpublished program materials
- Fine in a tool your organization has approved. Ask before putting anything unreleased into a personal account.
- Draft grant or funding narratives
- Check whether the funder has anything to say about AI-assisted preparation. Some now do, and it’s easy to comply with if you know in advance.
- QI and chart review findings
- Use only under your organization’s approved workflow. Small cells, case detail and clinician-level findings can remain identifiable even when names are removed.
- Anything you wouldn’t email outside your organization
- A good rule of thumb that takes no thought. If it would need a second look before leaving in an email, it needs one here.
Go ahead
Where most of the useful work actually happens.
- Your own writing
- Drafts, notes, half-finished paragraphs, your sent folder as writing samples.
- Published guidelines and public literature
- Use links or short excerpts, and follow copyright, licensing and your organization’s policy.
- Your objectives, agendas and templates
- The reusable scaffolding of your work.
- Made-up scenarios you built yourself
- A composite case describing a behavior rather than a person.
- Public marketing copy
- Yours or anyone else’s, once it’s out in the world.
Can I paste this?
Four questions, in order. Stop at the first one that gives you an answer.
-
Could a colleague read this and work out who it's about?
Not "is there a name in it". Could they work it out? One patient with an unusual presentation on a small unit is identifiable with no name attached. So is "the only person in our department who does X".
Yes: use your organization’s approved de-identification process or keep it out. Removing names alone may not be enough.
-
Did someone give me this in confidence?
360 feedback, an anonymous evaluation, something a participant told you in a coaching session, a colleague's disclosure. The promise was yours to keep.
Yes: stop. Do this part by hand.
-
Does it belong to somebody else?
A client's documents, a vendor's unreleased materials, a licensed instrument, another organization's curriculum. Your engagement terms probably say something about this.
Yes: check the agreement first, not afterwards.
-
Am I in a tool my organization has approved?
This is the question people skip. The same text may be permitted in one account and prohibited in another. Contracts, administrative controls, retention settings and internal policy all matter.
Not sure: that's the thing to go and find out, once. It takes one email and it settles hundreds of future decisions.
If all four come back clean
Use the minimum material needed and follow your organization’s policy. Regulated or confidential material belongs only in a workflow explicitly approved for that use.
Removing identifying details before you work
This practical routine reduces risk in open text feedback. It is not one of the formal HIPAA de-identification methods, and removing direct identifiers does not guarantee that a person cannot be recognized from context.
- Work on a copy. Save the export as a separate working file. Never edit the original.
- Swap names for placeholders. Use find and replace to change each
faculty name to
[FACULTY A],[FACULTY B]and so on. Store any key separately in an approved location, or do not keep one if you do not need to reconnect the comments to people. - Search for the near misses. Search for "Dr", "the nurse", "my manager", "she", "he", department names, room and unit names. That's where the identifiers you missed are hiding.
- Remove clinical specifics. Any comment describing a particular patient encounter: take out the detail or set the comment aside.
- Hold back what won't survive it. A few comments can't be anonymized without losing their meaning. Set those aside and read them yourself. There will only ever be a handful.
- Review the working file. When the stakes are high, check the entire file. A spot-check may find obvious misses, but it is not formal de-identification.
Which account you're using matters more than which tool
The same product may carry different terms and controls in a personal account and an employer-managed workspace. Check what the vendor may do with your text, how long it is retained, whether it can be used to improve the service, which administrators can control it, and whether the vendor has agreed to handle regulated data on your organization’s behalf.
In US healthcare, a cloud vendor that creates, receives, maintains or transmits ePHI on behalf of a covered entity is generally a business associate. A compliant business associate agreement is required in that relationship, but the agreement is not enough by itself: the covered entity still needs risk analysis, appropriate safeguards and an approved use. Not every consumer product or feature is eligible.
So find out three things, once:
- Which AI tools your organization has licensed and approved for work.
- Whether any of them is cleared for information that counts as confidential or regulated, and if so, which kinds.
- Who to ask when you're unsure. A name, so the question is easy next time.
Your privacy officer, compliance lead or IT security contact can answer all three in one reply. Ask by email so you have it in writing, and share the answer with your team. You won't be the only person who wanted to know.
Terms change. Check the date.
How these products keep data, what they do with it by default, and what controls administrators get have all changed repeatedly and will change again. Treat anything you read about a specific tool's data handling, including on this page, as something to confirm rather than something to remember.
Four things specific to this field
The responsibility stays with you
You remain accountable for whether the content you put in front of learners is sound. A tool that drafted an objective isn't the author of it, and there's no version of "the AI wrote it" that moves that accountability anywhere else. That's the whole reason the checking steps in each recipe are written as routines rather than suggestions.
Do not accept a citation you have not verified
Research has documented fabricated and erroneous references in language-model output. Find the source yourself, open it, confirm that it exists and supports the claim, then let the tool help you work with material you have verified.
Requirements come from your accreditor, not the tool
It can paraphrase accreditation standards fluently and get the substance slightly wrong: a criterion half remembered, a requirement from a different accreditor mixed in, wording from a version that's been replaced. Check requirements against the source every single time, and use the tool to draft against a requirement you've already confirmed.
ACCME now recommends disclosure for substantive AI use
ACCME guidance published in January 2026 recommends disclosure when AI is used to create or develop educational content, especially when it generates, modifies or analyzes materials. It suggests naming the tool, version or date, and purpose. Routine spelling and grammar support generally does not need disclosure. Keep human oversight, screen for commercial bias, and follow any stricter local policy.
Follow your incident procedure immediately.
If you paste something you should not have, contact whoever handles privacy or security at your organization and follow its reporting procedure. Delete the conversation if instructed, but do not assume deletion resolves the incident.
Prompt reporting gives the appropriate team the best chance to assess retention, access, notification duties and next steps.