Healthcare employees are looking for faster ways to complete routine work. An AI tool can summarize a document, draft a patient message, organize meeting notes, or help prepare administrative content in seconds.
The problem begins when employees use AI tools that the organization has not reviewed or approved. This practice is often called shadow AI, and it can create serious questions about where patient information is going, who can access it, and how it is being protected.
What Is Shadow AI?
Shadow AI is the use of artificial intelligence tools without the knowledge or approval of the organization’s leadership, compliance team, or IT provider.
An employee may create a personal account for a public AI assistant and use it to:
- Summarize clinical notes
- Rewrite patient communications
- Transcribe conversations
- Review billing information
- Draft referral letters
- Organize schedules or reports
The employee may be trying to save time, not bypass security. But entering protected health information into an unapproved tool can expose information to a system the organization has never evaluated.
Why Unapproved AI Tools Create HIPAA Risk
The HIPAA Security Rule requires regulated organizations to protect the confidentiality, integrity, and availability of electronic protected health information, or ePHI. It also requires an accurate and thorough assessment of risks and vulnerabilities affecting that information.
An organization cannot properly assess those risks when it does not know which AI tools employees are using.
Questions may remain unanswered:
- Does the provider store prompts or uploaded files?
- Can submitted information be used for other purposes?
- Who has access to the data?
- How long is the information retained?
- Can the organization delete or retrieve it?
- Has the provider agreed to safeguard ePHI?
When a technology provider creates, receives, maintains, or transmits ePHI on behalf of a covered entity, a HIPAA-compliant business associate agreement may be required. A healthcare organization must also understand the service and include it in its own risk analysis.
Key Takeaway: An AI tool being convenient, secure, or widely used does not automatically make it appropriate for patient information.
Start by Understanding How AI Is Already Being Used
Healthcare leaders should not assume employees are waiting for an official AI strategy.
A simple internal review can help identify:
- Which AI tools employees are using
- What tasks they are completing
- Whether patient information is being entered
- Whether accounts are personal or organization-managed
- Which tools have been reviewed by IT, security, or compliance
The goal should not be to punish employees for experimenting. It should be to understand current behavior before it becomes a larger compliance or security issue.
Give Employees Clear Alternatives
Telling employees not to use AI may not be enough. They need practical guidance they can follow.
An AI use policy should explain:
- Which tools are approved
- What information is prohibited
- Which tasks require human review
- How employees can request a new tool
- Who should be contacted with questions
- How suspected exposure should be reported
Organizations should also limit the use and disclosure of protected health information when it is not necessary for the intended purpose. This principle should remain part of the conversation when evaluating AI workflows.
Bring AI Into the HIPAA Risk Assessment
AI should be included alongside email, electronic health records, cloud platforms, mobile devices, backups, and other systems that may interact with ePHI.
BIS helps healthcare organizations identify where technology may be creating HIPAA risk, including tools and workflows that leadership may not know employees are using. A real risk assessment can uncover those gaps and help the organization decide what should be addressed first.