A healthcare AI acceptable use policy tells staff which AI tools they may use, what patient data goes in, and who checks the output. It should name approved tools covered by a business associate agreement, ban protected health information in anything else, and require human review. The full template is below.
Takeaways
Name the approved tools
A policy that only says "don't" drives use underground. Say exactly which tools are allowed.
Tie PHI to the BAA
Patient data goes only into tools on a plan covered by a signed business associate agreement.
Keep a human in the loop
AI drafts. A qualified person reviews before anything reaches a patient, a chart or a payer.
Adapt it with counsel
State disclosure laws and your own risk tolerance will change some sections.
Why you need one now
Staff are already using AI. In a December 2025 Black Book survey, 58% of frontline health-system staff had used generic AI tools for work in the past 30 days. Of those, 17% sometimes or often included identifiable patient information. We cover the full picture in shadow AI in healthcare.
HIPAA doesn't name AI, but it already requires the pieces of this policy. Covered entities must train their workforce on privacy policies and apply sanctions when staff don't comply. Disclosures must stay within the minimum necessary standard. An AI acceptable use policy applies those rules to a new kind of tool.
How to use this template
- Replace every bracketed field, like [Organization name], with your details.
- Fill in Section 3 only after you've vetted each tool. Use our AI vendor BAA checklist.
- Check Section 7 against the states where your patients live. See AI disclosure laws for patient calls.
- Have counsel and your privacy officer review it. Then train staff before it takes effect.
The policy template
[Organization name] Artificial Intelligence Acceptable Use Policy
Effective date: [Date]. Policy owner: [Privacy Officer name and title]. Approved by: [Name, title].
1. Purpose
This policy sets rules for using artificial intelligence (AI) tools at [Organization name]. It protects patient privacy, keeps us compliant with HIPAA and state law, and lets staff use AI safely to do their work.
2. Scope
This policy applies to all workforce members, including employees, contractors, students, volunteers and clinicians with privileges. It covers any AI tool used for [Organization name] work, on any device, whether the tool is free or paid. This includes chatbots, writing assistants, transcription and note-taking tools, and AI features built into other software.
3. Approved tools
3.1. Workforce members may use only the AI tools listed below for work involving [Organization name] information.
3.2. Approved tools: [Tool name, plan or tier, approved uses, PHI allowed yes or no]. [Repeat for each tool.]
3.3. A tool may be approved for protected health information (PHI) only if two things are true. [Organization name] has a signed business associate agreement (BAA) covering that specific plan and feature. And the required HIPAA settings are turned on.
3.4. Staff must sign in with their [Organization name] work account. Personal accounts are not approved, even for the same product.
3.5. To request a new tool, contact [Name or team]. Do not use it until it is approved in writing.
4. Prohibited uses
Workforce members must not:
4.1. Enter PHI into any tool not approved for PHI in Section 3.
4.2. Use personal AI accounts for any [Organization name] work.
4.3. Use AI output to make a diagnosis, treatment decision, coverage decision or billing code selection without review by a qualified person.
4.4. Enter passwords, access credentials, or financial account numbers into any AI tool.
4.5. Use AI to create content that impersonates a real person or misleads patients about whether they are talking to AI.
4.6. Turn off audit logging, retention or privacy settings on an approved tool.
4.7. Use AI features an approved vendor excludes from its BAA, as listed by [Name or team].
5. Rules for protected health information
5.1. Minimum necessary. Enter only the PHI needed for the task. If a task can be done without identifiers, remove them first.
5.2. De-identification. Data counts as de-identified only if it meets HIPAA's Safe Harbor method or Expert Determination. Safe Harbor means all 18 listed identifiers are removed, with no actual knowledge that the rest could identify someone. When in doubt, treat it as PHI.
5.3. Uploads. Patient lists, payer reports, and exports from [EHR or practice management system name] may be uploaded only to tools approved for PHI.
5.4. Storage and export. AI output containing PHI must be stored only in [approved systems]. Do not download it to personal devices.
6. Human review of output
6.1. AI output can be wrong, incomplete or made up. Treat it as a draft.
6.2. A qualified workforce member must review AI output before it is used. That includes sending it to a patient, entering it in a medical record, submitting it to a payer or regulator, or using it for a clinical decision.
6.3. The reviewer is responsible for the final content as if they wrote it.
6.4. For clinical content, the reviewer must be a [licensed or certified health care provider / role].
7. Patient-facing AI disclosure
7.1. Any AI tool that talks with patients by phone, text, chat or email must tell them it is AI at the start of the interaction.
7.2. Every AI interaction must tell the patient how to reach a human at [Organization name].
7.3. AI-generated messages about clinical information must meet the disclosure laws of the patient's state. [Insert state requirements, for example California Health and Safety Code 1339.75.]
7.4. Automated calls and texts must follow [Organization name]'s TCPA policy, including consent and opt-out rules.
8. Incident reporting
8.1. Report any suspected misuse, including PHI entered into an unapproved tool, to [Privacy Officer, phone, email] within [24 hours] of discovery.
8.2. Do not try to fix it yourself by deleting chats. Report first, so the incident can be assessed and documented.
8.3. [Organization name] will assess each report under its breach notification procedures.
8.4. Good-faith self-reports will be considered when deciding on any sanction.
9. Training
9.1. All workforce members must complete AI training before using any approved tool, and every [12 months] after.
9.2. Training covers this policy, approved tools, what counts as PHI, and examples of allowed and prohibited uses.
9.3. [Name or team] keeps training records.
10. Enforcement
10.1. Violations may lead to sanctions up to and including termination of employment or contract, consistent with [Organization name]'s sanctions policy.
10.2. [Organization name] may monitor use of approved tools and network traffic to AI services to enforce this policy.
11. Review cadence
11.1. [Policy owner] reviews this policy at least every [12 months], and sooner when laws, vendor terms or approved tools change.
11.2. The approved tool list in Section 3 is reviewed every [6 months], including each vendor's current BAA scope.
11.3. Prior versions are retained for at least six years.
Acknowledgment. I have read and agree to follow this policy. Name: [ ]. Signature: [ ]. Date: [ ].
Notes on the hard sections
Section 3 is the one that matters most. Approval is plan-specific. OpenAI says ChatGPT Free, Plus, Pro and Business are not eligible for its BAA. Anthropic says Claude Team, Free, Pro and Max plans can't enable HIPAA. Microsoft Copilot Chat supports its BAA only when users sign in with a work (Entra) account. Our guide to using AI with patient data lists which plans qualify.
Section 4.7 catches the fine print. Vendors exclude features even under a BAA. OpenAI excludes features like improved memory. Anthropic says Cowork "is not yet covered" under its BAA. Your list should name these.
Section 11.3 isn't arbitrary. HIPAA requires covered entities to keep policy documentation for six years from the date it was created or last in effect, whichever is later.
Fill in Section 3 with a tool that has a BAA
Rivvi is a HIPAA-compliant AI workspace. Free for you and two colleagues, with a HIPAA BAA.
Putting a tool in Section 3
A policy without an approved tool is just a ban. Rivvi is a HIPAA-compliant AI workspace where staff can upload patient lists and payer reports and work with them. A HIPAA BAA is included on the free plan. Rivvi is SOC 2 Type II, patient data is not used to train third-party models, and PHI access is logged. See the security page for details.
Give your policy an approved tool
You and two colleagues, with a HIPAA BAA. No card. No clock.
Sources
- Black Book Market Research: hidden work and shadow AI are driving health-system AI pilots
- eCFR: 45 CFR 164.530 administrative requirements (training, sanctions, documentation)
- eCFR: 45 CFR 164.502 minimum necessary
- eCFR: 45 CFR 164.514 de-identification
- OpenAI: HIPAA Implementation and Configuration Guide (July 9, 2026)
- OpenAI: HIPAA eligible products and functionality
- Anthropic: HIPAA-ready Enterprise plans
- Anthropic: Business Associate Agreements for commercial customers
- Microsoft: Copilot Chat FAQ
- California AB 3030 text