Massive Bio has made its inaugural strategic investment in Rivvi. Read the announcement

← Blog
COMPLIANCERivvi · October 1, 2026 · 7 min read

Shadow AI in Healthcare: What Staff Paste Into ChatGPT

Shadow AI in healthcare is staff using AI tools their organization hasn't approved, like personal ChatGPT or Gemini accounts. Surveys show it is common. The HIPAA problem is specific. Protected health information pasted into a tool with no business associate agreement is a disclosure HIPAA doesn't permit. The fix is a sanctioned tool, not a ban.

Takeaways

  1. It's already happening

    In a December 2025 Black Book survey, 58% of frontline health-system staff had used generic AI tools for work in the past 30 days.

  2. Some of it includes patients

    17% of those users said they sometimes or often include identifiable patient information.

  3. The legal exposure is the missing BAA

    Consumer AI plans don't come with a business associate agreement, so PHI pasted there has no contract protecting it.

  4. Bans don't work without an alternative

    Inventory what people use, write a policy, give them a tool with a BAA, and train them on it.

What shadow AI looks like in a practice

Shadow AI is any AI tool used for work outside your organization's approval and controls. In a clinic it rarely looks dramatic. It looks like this:

  • A front-desk lead pastes a no-show list into ChatGPT to draft reminder scripts.
  • A care coordinator uploads a payer gap report to a free chatbot to sort it by priority.
  • A physician dictates a patient summary into a personal AI app to clean up the wording.
  • A billing specialist asks a consumer chatbot to explain a denial and includes the claim details.

Each of these is a reasonable thing to want help with. That's the point. People reach for these tools because the work is real and the tools are good.

How common it is

Several 2025 and 2026 surveys measured it from different angles. The methods differ, but they point the same way.

58%

Frontline staff using generic AI for work (30 days)

Black Book, Dec 2025

17%

Of those, sometimes or often include patient identifiers

Black Book, Dec 2025

97%

Clinicians using AI at work who used generalist tools

Elsevier, Jul 2025

32%

Clinicians who say their institution gives adequate AI access

Elsevier, Jul 2025

  • Wolters Kluwer (survey of 518 providers and administrators, released January 22, 2026): 40% had encountered unauthorized AI tools at work. The full report says 17% personally used them, and 1 in 10 used one for direct patient care.
  • Black Book Market Research (228 US health-system staff, released December 17, 2025): 58% of frontline staff used generic tools like ChatGPT, Gemini or Copilot for work in the past 30 days, and 39% used them weekly or more.
  • Elsevier Clinician of the Future 2025 (2,206 clinicians in 109 countries): 48% had used AI for work. Of those, 97% used generalist tools like ChatGPT.
  • AMA 2026 physician survey (1,692 physicians, released March 12, 2026): 81% of physicians use AI, up from 38% in 2023. 71% have privacy concerns about non-institutional tools, versus 42% for institutional ones.
  • Netskope Healthcare 2025: 81% of data-policy violations it observed in healthcare involved regulated healthcare data.

Why it happens

The Elsevier number explains most of it. Only 32% of clinicians say their institution gives them adequate access to AI. When the sanctioned option doesn't exist, people use the one on their phone.

Three conditions show up again and again:

  1. No approved tool. Leadership said "don't use ChatGPT" but didn't say what to use instead.
  2. Real workload. Spreadsheets, call lists, payer reports and letters pile up. AI makes them faster.
  3. No clear line. Staff don't know which data is fine to paste and which isn't, so they guess.

The AMA data also shows physicians already sense the risk. They trust institutional tools more than personal ones. They just need the institutional one to exist.

The actual HIPAA exposure

Here is the specific problem, without the scare language.

Protected health information (PHI) is individually identifiable health information held by a covered entity or its business associates. Under HIPAA, a vendor that "creates, receives, maintains, or transmits PHI" on your behalf is a business associate. You need a signed business associate agreement (BAA) with that vendor before sharing PHI.

Consumer AI plans don't offer one. OpenAI's July 9, 2026 HIPAA guide says ChatGPT Free, Plus, Pro and Business "are not Eligible Services." Anthropic says Claude's Team, Free, Pro and Max plans "can't enable HIPAA." Google says consumer Gemini chats may be read by human reviewers.

So when a staff member pastes a patient list into a personal account, your organization has disclosed PHI to a vendor with no BAA. That is a privacy incident you need to assess, not a technicality. Under HHS's January 2026 inflation adjustment, civil penalties start at $145 per violation when you didn't know. They climb steeply for willful neglect, with an annual cap of $2,190,294.

Two things are worth being precise about:

  • It's the plan, not the brand. ChatGPT for Healthcare, Claude Enterprise with HIPAA enabled, Microsoft Copilot Chat with a work sign-in, and Gemini in Workspace can all be covered under a BAA. See how to use AI with patient data for the full list.
  • De-identified data is different. Data stripped of identifiers under HIPAA's de-identification rules is no longer PHI. Most staff don't de-identify correctly by hand, though.

Give your team the AI they're allowed to use

Rivvi's free plan covers you and two colleagues, with a HIPAA BAA. No card. No clock.

What to do about it

A ban alone pushes the behavior further out of view. The pattern that works has four parts.

  1. 1

    Inventory what people use

    Find out before you write rules

    Run an anonymous survey asking which AI tools staff use and for what. Ask IT for browser and network logs of AI domains. Make it clear the goal is a better tool, not discipline.

  2. 2

    Write an acceptable use policy

    Say what's approved and what isn't

    Name approved tools, prohibited uses, rules for PHI, and human review of AI output. Our free acceptable use policy template has all of it.

  3. 3

    Provide a sanctioned tool with a BAA

    Replace the personal accounts

    Pick a tool on a plan that includes a BAA, with the HIPAA settings turned on. Vet it with the BAA checklist. Then tell staff exactly where to log in.

  4. 4

    Train, then check

    Make the line obvious

    Show real examples of what can and can't be pasted. Repeat at onboarding and yearly. Recheck usage logs after rollout to see whether personal accounts drop off.

Two linked resources do most of the work:

What to do if PHI already went into a personal account

Assume it has happened somewhere. When you find a case, don't punish first. Treat it as a privacy incident:

  1. Have the staff member report it to your privacy officer, with the tool, date and data involved.
  2. Don't delete the chat yet. You may need it to document what was shared.
  3. Run your normal breach risk assessment and record the outcome.
  4. Move that person's workflow onto the sanctioned tool the same week, so it doesn't repeat.

Self-reports only happen if people believe they won't be fired for being honest. Say that in the policy.

HIPAA already requires the training piece. Covered entities "must train all members of its workforce" on privacy policies and must apply sanctions when staff don't comply. An AI policy belongs inside that program, not beside it.

Where Rivvi fits

Rivvi is built for this exact gap. It's a HIPAA-compliant AI workspace where staff chat, upload patient lists and payer reports, and build work product. The free plan includes a HIPAA BAA. Rivvi is SOC 2 Type II, patient data is not used to train third-party models, and PHI access is logged.

That means the front-desk lead with the no-show list has somewhere legitimate to put it. Uploads are enriched against CMS and NPI registry data, and the workspace keeps an organization memory your team can view and correct.

If you're comparing options, see Rivvi vs ChatGPT or our breakdown of whether ChatGPT is HIPAA compliant.

Replace shadow AI with sanctioned AI

Free for you and two colleagues, with a HIPAA BAA. No card. No clock.

Sources

Try it on your own data today.

Free to start. Most teams are using it the same day.