Put identifiable patient information only into AI tools covered by a signed agreement that bars training on your data, limit who can use them, strip out identifiers wherever the task doesn't need them, set retention and history settings deliberately, and keep a register of every tool. The checklist below takes a small practice about two hours to work through the first time.
The most common leak isn't the carefully chosen scribe. It's a receptionist pasting a referral letter into a free chatbot on her phone to get a quick summary, because nobody told her what to use instead. So about half of this checklist is about contracts and settings, and the other half is about people: what they're allowed to use, where, and what to do when they slip.
A. The contract, before any patient data goes in
- A signed agreement that covers health information. Why: without it, the vendor's standard consumer terms apply. Verify: you hold a data-processing agreement, or the health-specific equivalent your law requires, signed for your organisation.
- No training on your data. Why: patient information shouldn't improve someone else's model. Verify: the contract says so, not only a marketing page. Business plans from the main vendors don't train on business content by default, but check your plan's terms.
- Health-data terms available on your plan. Why: "no training" isn't the same as "suitable for patient records". Some vendors only offer health-data terms on specialist or larger plans. OpenAI, for example, doesn't offer them on ChatGPT Business; it reserves them for its healthcare product and its API. Verify: ask the vendor in writing.
- Sub-processors listed. Why: your data may pass to cloud and AI providers behind the vendor. Verify: a published list, and a promise to tell you about changes.
- Where the data is processed and stored. Why: some rules restrict where health data may go. Verify: the region is named in the contract.
- Breach notification and deletion on exit. Why: you need to know fast if something goes wrong, and to get your data back or deleted if you leave. Verify: time limits written into the agreement. Independent security reports help here; what SOC 2 and ISO 27001 tell you about a vendor explains what to ask for.
Reading the sub-processor list takes ten minutes and often raises the best question of the whole exercise. Take an illustrative scribe vendor whose list names three companies: a cloud host, a speech-to-text provider and a large-language-model provider. The contract names one region for processing, but the list shows the language-model provider's location as "multiple regions". That isn't necessarily a problem, but it is a gap between two documents, so it goes to the vendor as one written question: "Your sub-processor list shows [provider] processing in multiple regions. Does patient data from our account ever leave [the contracted region], and which part of our agreement covers that?" File the answer with the contract.
B. Which tools may see what
Staff need a simple rule, not a policy document. A traffic-light list works well:
| Colour | Meaning | Typical examples |
|---|---|---|
| Green | Identifiable patient information allowed | An AI scribe under your signed health-data agreement; AI features inside your practice management system covered by your existing contract |
| Amber | De-identified information only | Business chat plans that don't train on your content but haven't signed health-data terms with you |
| Red | Never any patient information | Free chatbots, personal accounts, browser extensions, AI keyboards and transcription apps on personal phones |
- Every tool staff use is on the list. Verify: ask each person which AI tools they've used in the last month. Include the ones on their phones.
- Each tool has a colour. Verify: the list is pinned where staff work and in the staff handbook.
- Staff have a green or amber alternative for common jobs. Why: a ban without an alternative produces workarounds. Verify: for summarising letters, drafting replies and writing patient information, there's a named approved tool. Stopping staff pasting client data into free tools covers the people side in more depth.
C. Accounts and access
- Practice accounts only, never personal ones. Verify: every login uses a practice email address.
- Multi-factor authentication switched on. Verify: check the admin console, not staff memory.
- No shared logins. Why: you can't tell who did what. Verify: one account per person.
- Leavers removed the day they leave. Verify: the leaver checklist includes every AI tool on the register.
- Admin rights held by as few people as possible. Verify: list who can change settings; usually the practice manager and one deputy.
D. Settings inside each tool
- Chat history and retention set deliberately. Why: defaults often keep everything indefinitely. Verify: the setting is recorded in the register with the date checked.
- Memory features reviewed. Why: a tool that remembers across conversations may carry one patient's details into another chat. Verify: switched off for accounts that handle patient information, unless you've decided otherwise.
- Sharing links controlled. Why: a shared chat link can expose a conversation to anyone who has it. Verify: link sharing is restricted to your organisation, or off.
- Connected apps reviewed. Why: chat tools can now connect to email, calendars and file storage. ChatGPT calls these apps, and admins enable them on business plans. Verify: only the connections you've approved are on.
- File permissions tidied before AI search is switched on. Why: assistants built into office software can find anything the user can open, including that old folder of scanned letters. Verify: sensitive folders restricted before rollout.
Sharing links are the setting most often left open, and the slip is easy to miss. Suppose that at a quarterly review the practice manager opens the business chat tool's list of shared links and finds six active ones. Five are harmless leaflet drafts. The sixth is a chat in which a clinician worked through a de-identified but unusual case, sent to a colleague through a messaging group, and set so that anyone holding the link could open it. Nothing suggests it went further, but the fix is the same either way: delete the link, restrict sharing to the organisation, and add "shared links checked" to the quarterly review.
E. Recordings and scribes
- Patients told and asked before recording. Verify: the process is written down and the answer is recorded in the notes by the clinician.
- Audio deletion confirmed. Why: "we delete audio" should be tested, not assumed. Verify: check the vendor's documentation and your settings; test with a dummy session.
- Transcript retention set to the shortest period that works. Verify: recorded in the register.
- Devices that record are locked and encrypted. Verify: phones and tablets used for scribing have a passcode and automatic lock.
The dummy-session test in item 21 takes about ten minutes. A clinician records a three-minute scripted consultation with no real patient in it ("test patient, heel pain for two weeks, keen runner"). Straight afterwards, the practice manager looks through the account for any audio file or playback option; a week later, after the stated seven-day window, she checks that the transcript has gone too. The date and result go in the register. Plan for the patient who says no as well: the clinician writes the note as before, records "declined AI scribe", and doesn't ask again in the same appointment. A patient who feels pressed into agreeing hasn't really agreed.
F. What happens to the outputs
- AI drafts end up in the patient record, not in the chat tool. Why: the record is where you control access and retention. Verify: staff copy the checked output into the record and delete working chats in line with your settings.
- A person checks anything that goes to a patient. Verify: no automated sending of AI-written clinical content.
- AI-drafted letters don't carry more than they need. Why: a referral letter drafted by AI may pull in history the recipient doesn't need. Verify: spot-check five letters a month.
The spot-check in item 26 finds real problems. In an illustrative month at the podiatry practice below, two of five AI-drafted referral letters to a vascular clinic carried history the recipient didn't need: one mentioned a long-resolved alcohol problem from the patient's notes, the other a family dispute over transport to appointments. Both details were accurate, and neither belonged in a referral about circulation in the feet. The fix was one line added to the letter feature's instructions: "Include only history relevant to the reason for referral; list current medications in full." The following month's five letters were clean.
G. When something goes wrong
- Staff know to report a slip at once, without blame. Verify: the rule card says who to tell.
- Someone decides quickly whether it's a reportable breach. Why: some laws set short deadlines for reporting to a regulator. Verify: named person, and your data-protection adviser's contact details, on the incident sheet.
The deadline is what makes the named person matter. Under the GDPR, for example, a reportable breach must be notified to the regulator within 72 hours of the practice becoming aware of it. If the receptionist mentions her slip at 9am on a Tuesday, the decision and any report are due by 9am on Friday, and a manager's day off or a busy clinic can swallow most of that. Put the adviser's direct number on the incident sheet, and name a deputy for when the practice manager is away.
H. The paperwork
- A register of AI tools, with what each is used for, its colour, the contract status, the settings, and when it was last reviewed. The AI risk register template can be adapted.
- A risk assessment for any tool that processes patient data, and a privacy notice that mentions it. Data-protection law such as the GDPR often expects a formal impact assessment for new technology handling health data; what GDPR means for AI tools outlines when.
A filled-in register for a four-clinician podiatry practice
Here's an illustrative register, the kind of thing the practice manager keeps in a shared spreadsheet:
| Tool | Used for | Colour | Contract | Key settings | Last checked |
|---|---|---|---|---|---|
| AI scribe (vendor A) | Consultation notes, 3 clinicians | Green | Health-data agreement signed | Audio not stored; transcripts 7 days | Sep |
| Practice system's AI letter feature | Drafting GP and referral letters | Green | Covered by main contract addendum | Available to clinicians only | Sep |
| Claude Team | Patient leaflets, policies, marketing | Amber | Business terms; no health-data terms | Memory off; no connectors | Aug |
| Free chatbots, phone apps | Nothing | Red | None | n/a | n/a |
The register makes gaps obvious. If a clinician mentions using a transcription app for home visits and it isn't on the list, it's either added with a colour or stopped.
De-identifying a letter before it goes into an amber tool
Amber tools are for text with identifiers removed. Removing the name isn't enough; the combination of details can identify someone. An illustrative before and after:
Before: "Referral for [full name], 58, retired head teacher at the village primary school, diabetic, ulcer on left hallux, lives alone at [address], daughter is a nurse at the surgery."
After: "Adult patient in their fifties with diabetes. Ulcer on the left big toe. Lives alone. Please draft a plain-English explanation of home foot care for this situation."
The job, the local school and the daughter's workplace are gone, because together they would identify the patient to anyone in the area. The clinical details the task needs are kept. Redacting personal data from documents has more worked examples.
A realistic slip, and how the checklist handles it
A receptionist is asked to summarise a long scanned referral for a clinician in a hurry. She photographs it and asks a free chatbot app on her phone for a summary. She mentions it the next day, pleased with how well it worked.
What happens next matters more than the slip. The practice manager thanks her for saying so, asks her to delete the conversation, and notes what was shared. The manager and the practice's data-protection adviser then decide whether it needs reporting, using the free app's published retention and training terms. Finally, the practice fixes the cause: the green-listed practice system can summarise letters, but nobody had shown reception how. Items 9 and 27 did their work; item 9 also turned out to have a gap.
The staff rule card
Print this, adapt the tool names, and have every staff member read and sign it:
AI AND PATIENT INFORMATION: OUR RULES
GREEN - patient details allowed:
[scribe name], [practice system] AI features
AMBER - remove names and identifying details first:
[business chat tool]
RED - never any patient information:
free chatbots, personal accounts, phone apps,
browser extensions
Always:
- Use your practice login, never a personal account
- Check anything AI writes before it goes to a patient
- Save final versions in the patient record
If you slip up, tell [name] straight away.
You won't be in trouble for telling us.
Running the checklist without it becoming a chore
The first pass takes about two hours: an hour on sections A and B with the practice manager, half an hour on settings, half an hour on the register and rule card. After that, a 30-minute review each quarter is enough, plus a check whenever you add a tool, a vendor changes its terms, or someone leaves. For the broader habits that keep customer and patient data private across a team, keeping customer data private when your team uses AI is a useful companion.
A quarterly review note can be short. An illustrative one for the podiatry practice: "Q3, 35 minutes. Asked all seven staff which AI tools they'd used: one new, an AI keyboard on a reception phone, now red and switched off. Scribe vendor emailed in July about a new sub-processor: reviewed, accepted, filed. One leaver's scribe account still active: removed, and the leaver checklist updated. Five letters spot-checked: all clean. Shared links: none open outside the organisation." If a review ever finds nothing at all, ask the staff question again more specifically ("Have you used anything on your phone to summarise, translate or type for you?"), because a blank answer usually means the question was too vague.
Questions practices ask about patient data and AI
Is de-identified patient information still personal data?
Often, yes. Removing a name doesn't make information anonymous if the rest could still identify someone, especially in a small community or with a rare condition. Treat de-identified text as lower risk rather than no risk: keep it to approved tools and remove anything distinctive. Your data-protection adviser can tell you where the legal line sits for your practice.
Can we use Microsoft 365 Copilot or Gemini in Workspace with patient letters?
Their business versions don't train on your content by default and work within your existing tenant, which is a good start. Whether they're suitable for patient information depends on the terms you've agreed with Microsoft or Google, how your files and permissions are set up, and what your health-privacy rules require. Check the contract, tidy file permissions first, and record the decision in your AI register.
Do we have to tell patients we use AI for admin tasks?
If AI tools process patient information, your privacy notice should normally describe that use and the suppliers involved, just as it would for any other processor. For tools that listen to consultations, tell patients directly and ask first. For drafting generic letters with no patient data, there's usually nothing to disclose, but check your notice covers what you actually do.
Further reads
- How to Roll Out an AI Scribe Without Losing Patient Trust — Applying these checks to an AI scribe rollout, step by step.
- Patient Reviews and AI Replies: Staying Within Confidentiality — The confidentiality trap in replying to online reviews with AI.
- AI Note-Taking Tools for Therapists: A Confidentiality Checklist — The stricter version of these checks for therapy notes.
- What to Ask Before Buying Any AI Tool for a Medical Practice — Questions to ask before any new AI tool joins the register.
- AI Incident Response Plan for Small Businesses (With Template) — A fuller incident plan to sit behind section G of the checklist.
- Do You Need a DPIA Before Using AI Tools? — Whether your practice needs a formal impact assessment.
- Does ChatGPT Train on Client Data? Business vs Free Plans — How ChatGPT's free and business plans differ on training.
- AI Scribe Costs Compared: What Small Clinics Pay in 2026 — Published AI scribe prices side by side, yearly budgets for three clinic sizes, cost per note, and the extra costs and contract terms that change the total.
- A Worked AI Implementation Plan for a Small Medical Practice — One small medical practice's 12-week AI plan, from time audit to scribe rollout and phone overflow, with the costs, the numbers at day 90 and the lessons.
- How Dental Practices Use AI for Recalls and Appointment Reminders — Six stages for adding AI to dental recalls and reminders, from cleaning the recall list to letting AI handle patient replies within safe limits.
- Winning Back Lapsed Dental Patients With AI Messages — How to find lapsed dental patients, split them by why they stopped coming, and use AI to write reactivation messages that don't guilt or scare.
- Writing Pet Owner Emails and Treatment Explanations With AI — Turn a vet's shorthand into discharge emails, estimate explanations and results letters owners understand, with the vet still checking every clinical line.
- Explaining Lens Options and Eye Test Results With AI Help — Prompts and checked templates for explaining prescriptions, lens choices and eye test findings to patients in plain English, with the clinician in charge.
- Creating Home Exercise Programmes With AI for Physio Patients — A physio-led workflow for AI-assisted home exercise programmes: shorthand to patient instructions, pain rules, delivery tools and adherence messages.
- How Independent Opticians Can Use AI for Recalls and Bookings — Four kinds of optician recall, the wording that gets them booked, an assistant for booking questions, and the figures to track, for independent practices.
- What Is an AI Scribe and How Does It Work in a Consultation? — The consultation stage by stage: capture, transcript, speaker separation, note drafting and sign-off, with the errors each stage produces and how to spot them.
- Can Therapists Use ChatGPT for Session Notes? — Personal plan, de-identified shorthand, business plan or a therapy note tool: where each lands, and why removing a name rarely removes the client.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: published reporting on which OpenAI products carry health-data agreements (January 2026 update); vendor business-plan privacy documentation (checked September 2026).