Written by Dr. Roupen Odabashian MD, FRCPC, FASCO | Hematologist-Oncologist | Founder, MeDucationAI | Updated August 2026
Disclosure: Dr. Odabashian is the founder of MeDucationAI. This article is for professional education, not legal advice or a substitute for your institution’s privacy, security, or clinical-governance policies.
The short answer: HIPAA does not disappear when you use AI
AI can be useful for education, documentation, information retrieval, and clinical workflows. But putting patient information into an AI tool is a data-disclosure decision, not simply a productivity decision. Before a clinician or learner enters information into a tool, they should know what data is being entered, whether it is protected health information, where it goes, who can access it, whether the organization has approved the use case, and who remains accountable for the output.
The safest default is straightforward: do not enter protected health information into a public or unapproved AI tool. Use only organization-approved tools for clinical data, follow local policy, and verify every output before it affects patient care.
Watch the companion video: HIPAA & AI: What Happens to Patient Data When You Use AI Tools.
Why AI changes the privacy conversation
Generative AI feels like a chat box, but it may transmit text, files, prompts, metadata, and conversation history to systems outside your hospital or university. Whether that information is retained, used for product improvement, or processed by subcontractors depends on the specific product configuration and agreement. A tool’s consumer privacy notice is not a substitute for institutional review.
HIPAA applies to covered entities and business associates, and it requires safeguards for protected health information. If an AI vendor will create, receive, maintain, or transmit PHI on behalf of a covered entity, the organization must determine whether the vendor relationship and technical controls meet its compliance requirements. That work belongs with privacy, information-security, legal, and clinical-governance teams—not with an individual trainee at the point of care.
What counts as PHI when using AI?
PHI is broader than a patient’s name. It can include direct identifiers, dates, images, rare diagnoses combined with context, free-text notes, record numbers, locations, and other details that can reasonably identify a person. A clinical vignette that feels anonymous may still be identifiable when several details are combined.
Situation — Safer approach
--- — ---
Drafting a patient message from an actual chart — Use only an institution-approved tool and follow local workflow and review requirements.
Asking a public chatbot to summarize a clinical note — Do not paste the note. Use approved systems or create a fully fictional learning case.
Making teaching materials from a real patient encounter — Remove identifiers using the organization’s approved de-identification process and obtain any required approvals.
Studying a guideline or a publicly available paper — Avoid adding patient-specific details; verify the response against the original source.
De-identification is necessary, but it is not magic
Removing a name alone does not make a case safe. Under HIPAA, de-identification has specific standards, including the Safe Harbor method and expert determination. In clinical education, the practical lesson is to use the minimum necessary information, remove direct and indirect identifiers, and have an approved process for cases that originate from real care.
Do not assume that changing age, initials, or one date is enough. A rare disease, a distinctive timeline, a local event, and a specialty service can combine into an identifiable story. When in doubt, do not enter the case into an external system; ask your privacy or compliance team for guidance.
What should physicians ask before using an AI tool?
The following questions turn a vague “Is this HIPAA compliant?” discussion into a real safety review:
What data will enter the tool? Include text, files, images, voice, metadata, and copied chart fragments.
Is PHI involved? If yes, has the organization expressly approved this exact tool and use case?
Where is the data processed and stored? Know the vendor, applicable agreement, retention settings, and approved configuration.
Who can access the output? Consider vendor personnel, subcontractors, learners, faculty, and the care team.
What is the human review step? A clinician must remain responsible for clinical judgment, communication, and documentation.
How will errors be detected? AI can omit context, fabricate citations, or produce plausible but incorrect recommendations.
These questions should be built into the program’s AI policy, vendor-review process, and faculty development. For a practical institutional starting point, see MeDucationAI’s AI policy template and residency AI curriculum guide.
Does using an AI scribe or clinical decision-support tool require patient disclosure?
The answer depends on the tool, setting, institutional policy, and applicable law. Clinicians should not improvise. If an approved tool records, transcribes, or analyzes a clinical interaction, patients deserve clear communication about how it is being used and how their information is protected. Follow institutional consent and notice procedures rather than relying on a generic script.
The same principle applies to clinical decision support: AI may inform care, but it does not replace the clinician’s duty to evaluate the recommendation in the patient’s full context. The physician remains responsible for deciding whether an output is accurate, relevant, current, and appropriate.
A practical workflow for learners and clinicians
For study and teaching: Use fictional or formally de-identified cases. Cite the original guideline or paper, not the chatbot’s summary. Disclose permitted AI use according to your program’s policy.
For clinical work: Use only approved tools inside approved workflows. Never paste PHI into a consumer tool because it is convenient. Review output before it is copied into a record or shared with a patient.
For program leaders: Maintain a current list of approved tools and use cases, define prohibited uses, train faculty and learners, establish a review route for new tools, and revisit the policy as technology changes. The AMA’s AI-literacy policy reinforces the need for education across the training continuum; read our overview, The AMA Just Made AI Literacy Mandatory.
The bottom line
AI can improve learning and reduce administrative friction, but it also makes data governance a daily clinical skill. The right question is not whether an AI tool is impressive. It is whether this particular use, with this data, in this workflow, has been approved and can be carried out safely.
Start conservative. Protect patient information. Use approved systems. Keep human judgment in the loop. And make privacy literacy part of how your team learns to use AI.
Frequently asked questions
Can I paste a de-identified patient case into ChatGPT or another public AI tool?
Only if your organization’s policy permits it and the case is de-identified using an approved process. Removing a name does not necessarily remove re-identification risk.
Is an AI tool HIPAA compliant because its website says it is secure?
No single marketing claim answers the question. Your organization must assess the specific product, configuration, agreement, and intended use with its privacy and security teams.
Can AI write a clinical note?
An approved documentation tool may help with drafting, but the clinician must review the note for accuracy, completeness, privacy, and appropriate attribution before signing.
Who is responsible if an AI recommendation is wrong?
AI does not replace professional judgment. The clinician and organization must maintain appropriate oversight, escalation, and governance processes.
Watch the video here:

