Clinic Note / 6 minute read

How should a medical practice write an AI use policy?

By The New Business School teaching team. Updated .

Your medical practice AI use policy should name the approved tools, permitted tasks, prohibited data, required agreements, access rules, human review steps, record retention, incident reporting path, and policy owner. Write your first version around the workflows staff use now. Then connect it to your HIPAA risk analysis and existing privacy and security policies.

You will be able to draft a one page policy that staff can follow during a normal workday.

Use one page and nine fields

Start with this structure:

  1. Purpose. State which practice work the policy covers.
  2. Approved tools. Name the exact products, workspaces, and approved features.
  3. Permitted tasks. List the tasks staff may complete in each tool.
  4. Prohibited information. State what staff may never enter into an unapproved tool.
  5. Agreements and settings. Name the required BAA, retention, access, and security settings.
  6. Human review. Name who checks each type of output before it is used.
  7. Records. State what becomes part of the medical record and how long other data is kept.
  8. Incidents. Give one place to report a mistake, unexpected output, or suspected disclosure.
  9. Owner and review date. Name the person who approves changes and the next review date.

HHS calls risk analysis the first step in identifying and applying safeguards for ePHI. The policy should point to that work. It should not pretend that one page replaces it.

Make the rule easy to follow

Avoid a rule such as "Use AI responsibly." Staff cannot test their next action against it.

Use a rule such as:

Staff may use [approved tool and workspace] to draft [named task]. Do not enter [prohibited information]. [Role] must review the output before [final action]. Report mistakes or unexpected disclosures to [owner and channel] on the same workday.

Write one rule for each active workflow. Add new tools through the approval process, not through quiet staff adoption.

Clinician example

A dental practice approves one tool for drafting patient letters from information already held in its EHR. The policy names the covered workspace, permitted fields, required review by the treating dentist, and the incident contact. It also says that staff may use a public chat tool for public marketing drafts only, with no patient or private business information.

The rules are different because the data and purpose are different.

Your turn

Draft the nine fields for one current workflow. Ask a staff member who did not write the policy to answer two questions:

  1. Can I tell which tool and task are approved?
  2. Can I tell what to do if I make a mistake?

Revise any field that does not produce a clear answer. Then send the draft to the practice's privacy lead or counsel before it becomes policy.

Save this recap

  • Name exact tools, features, tasks, and prohibited data.
  • Connect the policy to the practice's risk analysis.
  • Put a person in charge of every final output.
  • Give staff one incident reporting path.
  • Review the policy when a tool, contract, feature, or workflow changes.

Frequently asked questions

How long should a first AI use policy be?

A first policy can fit on one page if it clearly names approved tools, allowed tasks, prohibited information, required review, the person who owns the policy, and the incident reporting path.

Should an AI policy list every possible tool?

List the tools the practice has reviewed and approved. Require staff to request approval before using another tool for practice work, especially when patient or business information may be involved.

How often should a practice review its AI policy?

Review it whenever a tool, feature, vendor agreement, workflow, or material risk changes. Set a regular review date as a backstop and document each revision.

Sources checked

This article is educational and is not legal, compliance, or clinical advice. Check your state law, licensing rules, contracts, and current vendor terms with qualified counsel.

Put the checklist to work

BRING ONE PRACTICE WORKFLOW.

In a 75 minutes, one to one session, you will map the data, review the risks, and leave with one useful workflow or a clear build plan. Keep patient information out of the training session.

BOOK DOCTOR CHATGPT$165, 75 minutes, one to one