AI Usage & Data Privacy Policy
Purpose: To ensure responsible use of AI tools while protecting client confidentiality.
Prohibited Data
- No Protected Health Information (PHI) or Personally Identifiable Information (PII) may ever be entered into public AI tools (including but not limited to ChatGPT, Gemini, Claude, etc.).
- This includes names, addresses, phone numbers, medical records, or any data that could be used to identify an individual.
Allowed Use
- General business queries, workflow assistance, and code generation that do not involve client‑specific data.
- Summaries or anonymized data that cannot be traced back to a patient or client.
"Friction Log" Habit
- Whenever you feel uncertain about whether a piece of information is permissible, log the question in the Friction Log (a shared, private doc).
- The log is reviewed weekly by the compliance officer who will provide guidance or permission.
- This habit creates a safety net and reinforces a culture of caution.
Enforcement
- Violations will be addressed according to our compliance policy and may result in disciplinary action.
Last reviewed: September 2026