Massive Bio has made its inaugural strategic investment in Rivvi. Read the announcement

← Blog
COMPLIANCERivvi · October 1, 2026 · 7 min read

Healthcare AI Acceptable Use Policy: Free Template

A healthcare AI acceptable use policy tells staff which AI tools they may use, what patient data goes in, and who checks the output. It should name approved tools covered by a business associate agreement, ban protected health information in anything else, and require human review. The full template is below.

Takeaways

  1. Name the approved tools

    A policy that only says "don't" drives use underground. Say exactly which tools are allowed.

  2. Tie PHI to the BAA

    Patient data goes only into tools on a plan covered by a signed business associate agreement.

  3. Keep a human in the loop

    AI drafts. A qualified person reviews before anything reaches a patient, a chart or a payer.

  4. Adapt it with counsel

    State disclosure laws and your own risk tolerance will change some sections.

Why you need one now

Staff are already using AI. In a December 2025 Black Book survey, 58% of frontline health-system staff had used generic AI tools for work in the past 30 days. Of those, 17% sometimes or often included identifiable patient information. We cover the full picture in shadow AI in healthcare.

HIPAA doesn't name AI, but it already requires the pieces of this policy. Covered entities must train their workforce on privacy policies and apply sanctions when staff don't comply. Disclosures must stay within the minimum necessary standard. An AI acceptable use policy applies those rules to a new kind of tool.

How to use this template

  1. Replace every bracketed field, like [Organization name], with your details.
  2. Fill in Section 3 only after you've vetted each tool. Use our AI vendor BAA checklist.
  3. Check Section 7 against the states where your patients live. See AI disclosure laws for patient calls.
  4. Have counsel and your privacy officer review it. Then train staff before it takes effect.

The policy template

Legal Disclaimer

This template is for informational purposes only and does not constitute legal advice. It is a starting point. Adapt it with your legal counsel and privacy officer before you adopt it.

[Organization name] Artificial Intelligence Acceptable Use Policy

Effective date: [Date]. Policy owner: [Privacy Officer name and title]. Approved by: [Name, title].

1. Purpose

This policy sets rules for using artificial intelligence (AI) tools at [Organization name]. It protects patient privacy, keeps us compliant with HIPAA and state law, and lets staff use AI safely to do their work.

2. Scope

This policy applies to all workforce members, including employees, contractors, students, volunteers and clinicians with privileges. It covers any AI tool used for [Organization name] work, on any device, whether the tool is free or paid. This includes chatbots, writing assistants, transcription and note-taking tools, and AI features built into other software.

3. Approved tools

3.1. Workforce members may use only the AI tools listed below for work involving [Organization name] information.

3.2. Approved tools: [Tool name, plan or tier, approved uses, PHI allowed yes or no]. [Repeat for each tool.]

3.3. A tool may be approved for protected health information (PHI) only if two things are true. [Organization name] has a signed business associate agreement (BAA) covering that specific plan and feature. And the required HIPAA settings are turned on.

3.4. Staff must sign in with their [Organization name] work account. Personal accounts are not approved, even for the same product.

3.5. To request a new tool, contact [Name or team]. Do not use it until it is approved in writing.

4. Prohibited uses

Workforce members must not:

4.1. Enter PHI into any tool not approved for PHI in Section 3.

4.2. Use personal AI accounts for any [Organization name] work.

4.3. Use AI output to make a diagnosis, treatment decision, coverage decision or billing code selection without review by a qualified person.

4.4. Enter passwords, access credentials, or financial account numbers into any AI tool.

4.5. Use AI to create content that impersonates a real person or misleads patients about whether they are talking to AI.

4.6. Turn off audit logging, retention or privacy settings on an approved tool.

4.7. Use AI features an approved vendor excludes from its BAA, as listed by [Name or team].

5. Rules for protected health information

5.1. Minimum necessary. Enter only the PHI needed for the task. If a task can be done without identifiers, remove them first.

5.2. De-identification. Data counts as de-identified only if it meets HIPAA's Safe Harbor method or Expert Determination. Safe Harbor means all 18 listed identifiers are removed, with no actual knowledge that the rest could identify someone. When in doubt, treat it as PHI.

5.3. Uploads. Patient lists, payer reports, and exports from [EHR or practice management system name] may be uploaded only to tools approved for PHI.

5.4. Storage and export. AI output containing PHI must be stored only in [approved systems]. Do not download it to personal devices.

6. Human review of output

6.1. AI output can be wrong, incomplete or made up. Treat it as a draft.

6.2. A qualified workforce member must review AI output before it is used. That includes sending it to a patient, entering it in a medical record, submitting it to a payer or regulator, or using it for a clinical decision.

6.3. The reviewer is responsible for the final content as if they wrote it.

6.4. For clinical content, the reviewer must be a [licensed or certified health care provider / role].

7. Patient-facing AI disclosure

7.1. Any AI tool that talks with patients by phone, text, chat or email must tell them it is AI at the start of the interaction.

7.2. Every AI interaction must tell the patient how to reach a human at [Organization name].

7.3. AI-generated messages about clinical information must meet the disclosure laws of the patient's state. [Insert state requirements, for example California Health and Safety Code 1339.75.]

7.4. Automated calls and texts must follow [Organization name]'s TCPA policy, including consent and opt-out rules.

8. Incident reporting

8.1. Report any suspected misuse, including PHI entered into an unapproved tool, to [Privacy Officer, phone, email] within [24 hours] of discovery.

8.2. Do not try to fix it yourself by deleting chats. Report first, so the incident can be assessed and documented.

8.3. [Organization name] will assess each report under its breach notification procedures.

8.4. Good-faith self-reports will be considered when deciding on any sanction.

9. Training

9.1. All workforce members must complete AI training before using any approved tool, and every [12 months] after.

9.2. Training covers this policy, approved tools, what counts as PHI, and examples of allowed and prohibited uses.

9.3. [Name or team] keeps training records.

10. Enforcement

10.1. Violations may lead to sanctions up to and including termination of employment or contract, consistent with [Organization name]'s sanctions policy.

10.2. [Organization name] may monitor use of approved tools and network traffic to AI services to enforce this policy.

11. Review cadence

11.1. [Policy owner] reviews this policy at least every [12 months], and sooner when laws, vendor terms or approved tools change.

11.2. The approved tool list in Section 3 is reviewed every [6 months], including each vendor's current BAA scope.

11.3. Prior versions are retained for at least six years.

Acknowledgment. I have read and agree to follow this policy. Name: [ ]. Signature: [ ]. Date: [ ].

Notes on the hard sections

Section 3 is the one that matters most. Approval is plan-specific. OpenAI says ChatGPT Free, Plus, Pro and Business are not eligible for its BAA. Anthropic says Claude Team, Free, Pro and Max plans can't enable HIPAA. Microsoft Copilot Chat supports its BAA only when users sign in with a work (Entra) account. Our guide to using AI with patient data lists which plans qualify.

Section 4.7 catches the fine print. Vendors exclude features even under a BAA. OpenAI excludes features like improved memory. Anthropic says Cowork "is not yet covered" under its BAA. Your list should name these.

Section 11.3 isn't arbitrary. HIPAA requires covered entities to keep policy documentation for six years from the date it was created or last in effect, whichever is later.

Fill in Section 3 with a tool that has a BAA

Rivvi is a HIPAA-compliant AI workspace. Free for you and two colleagues, with a HIPAA BAA.

Putting a tool in Section 3

A policy without an approved tool is just a ban. Rivvi is a HIPAA-compliant AI workspace where staff can upload patient lists and payer reports and work with them. A HIPAA BAA is included on the free plan. Rivvi is SOC 2 Type II, patient data is not used to train third-party models, and PHI access is logged. See the security page for details.

Give your policy an approved tool

You and two colleagues, with a HIPAA BAA. No card. No clock.

Sources

Try it on your own data today.

Free to start. Most teams are using it the same day.