Massive Bio has made its inaugural strategic investment in Rivvi. Read the announcement

← Glossary

Definition · Allowed AI at work

AI acceptable use policy

An AI acceptable use policy is a written set of rules for staff. It says which AI tools they may use at work, what data they may enter, and how AI output gets checked before use. In healthcare it names approved tools covered by a Business Associate Agreement, bars PHI in anything else, and assigns clear accountability.

What an AI acceptable use policy is

An AI acceptable use policy, or AI AUP, is the part of an organization's governance that covers everyday AI use by staff. It turns broad principles into concrete rules. Which tools are approved, and for what? What data is off limits? Who do staff ask when something is unclear?

A healthcare AI policy usually covers six things. Approved tools, each with a signed BAA. Data rules, including the minimum necessary standard. Human review of anything clinical or patient-facing. Patient disclosure where state law requires it, as in California, Utah, and Texas. Training for staff. And a simple way to report errors or accidental PHI exposure.

A policy without an approved tool tends to fail, because staff keep using whatever helps them finish the work. The policy should point to a tool people can actually use, with a BAA, logging, and admin controls. Rivvi is a HIPAA-compliant AI workspace that can serve as that approved tool, with a BAA included on the free plan.

Questions

AI acceptable use policies, answered

What should an AI acceptable use policy include?
Start with a list of approved tools and what each may be used for. Add rules on PHI and other sensitive data, and required human review for clinical or patient-facing output. Then cover patient disclosure, training, incident reporting, an owner, and a review date. Keep it short enough that staff will actually read it.
Does HIPAA require an AI policy?
HIPAA does not mention AI by name. It does require a security risk analysis, written privacy and security policies, workforce training, and sanctions for violations. Any AI tool that touches PHI falls under those duties, so a written AI policy is the practical way to meet them.
Who should own the AI policy in a practice?
Usually the privacy or compliance officer, working with IT and a clinical lead. In a small practice that may be the practice manager. One named owner should approve new tools, answer staff questions, track incidents, and update the policy as tools and state laws change.
Can an AI policy just ban AI tools?
It can, but bans tend to push use out of sight rather than end it. Surveys of health-system staff in 2025 and 2026 found many already use unapproved AI tools for work. An approved, BAA-covered option gives staff a compliant path and gives the organization visibility.

Try it on your own data today.

Free to start. Most teams are using it the same day.