Evidence ledger
Sources and review notes
The handbook was fact-checked against primary and official sources in July 2026. Product features and policies change, so open the linked source before making a compliance or purchasing decision.
The recipes also contain professional judgment: suggested prompts, review routines and workflow choices. Those are presented as practical guidance, not measured product rankings or legal, compliance, medical, or accreditation advice.
Editorial standard
How the handbook is reviewed
- Claims first. Privacy, accreditation, research, and product claims are checked against primary or official sources.
- Judgment labeled. Prompts, review routines, and workflow choices are practical recommendations, not measured product rankings.
- Dates visible. Product and policy guidance carries a review date because features, terms, and standards change.
- Responsibility stays local. Readers are directed back to their accreditor, organization, privacy lead, or other responsible authority.
Healthcare privacy
- HHS: HIPAA and cloud computing Business associate agreements, risk analysis and safeguards for ePHI.
- HHS: Business associates Required written assurances, permitted uses and safeguards.
- HHS: Guidance on de-identification The formal Safe Harbor and Expert Determination methods.
Accredited education and research
- ACCME: Guidance on AI Disclosure, human oversight and commercial-bias review, January 2026.
- ACCME: Identify, mitigate and disclose relevant financial relationships Disclosure to learners before the education.
- ACCME: Alert on AI in accredited continuing education Human and clinical oversight for validity, accuracy and bias.
- ICMJE: AI use by authors Disclosure, accountability and source verification.
- NIH: Confidentiality in peer review Prohibition on uploading confidential applications to generative AI.
- NSF: Generative AI and merit review Reviewer restrictions and disclosure guidance for proposers.
Product capabilities and data controls
- OpenAI: Projects in ChatGPT Files, chats, instructions, plan availability and workspace data treatment.
- OpenAI: Enterprise privacy Business data controls and training defaults.
- OpenAI: HIPAA-eligible products and functionality Eligible services and configurations, not a blanket claim for every plan.
- Anthropic: Claude Projects Paid-plan project knowledge and instructions.
- Anthropic: Commercial data roles Claude for Work data processing and consumer-product distinction.
- Microsoft: Data, privacy and security for Microsoft 365 Copilot Permission boundaries and foundation-model training treatment.
- Microsoft: How Copilot Notebooks works Reusable, source-grounded notebooks in supported Microsoft 365 plans.
Accuracy and citation risk
- NIST: Generative AI Profile Confabulation, false citations and other generative-AI risks.
- Scientific Reports: Fabricated and erroneous citations A primary study demonstrating citation errors in earlier model versions.