Protect Patient Data by Giving AI a Smaller Job
Consider a workflow test for an Arlington practice: a Botox booking request includes a medication history, and the automation copies it into an unreviewed chatbot. My rule is simple: give AI the smallest job that helps your patient, not the largest pile of patient information it can accept.
My rule is simple: give AI the smallest job that helps your patient, not the largest pile of patient information it can accept.
Does my booking assistant need the patient's medical history?
In that hypothetical test, the failure happens when a scheduling task becomes a reason to copy clinical details. I would separate the request for an appointment from the medical questions your clinical team needs to review.
HHS guidance provides the legal distinction: HIPAA's minimum necessary standard generally limits covered uses, disclosures, and requests for protected health information. It also has exceptions, including disclosures to or requests by healthcare providers for treatment. It is not a blanket instruction to withhold information needed for care. (hhs.gov)
My design preference is narrower than "let the assistant handle everything." Let it explain the booking process. Route patient-specific medical questions to your approved clinical workflow.
Protecting patient data with AI starts with defining what the assistant should not receive. For appointment support, I would keep clinical intake separate rather than make a general chatbot the doorway to your patient's medical history.
It is not a blanket instruction to withhold information needed for care.
Is a signed BAA enough to approve an AI tool?
HHS's cloud-computing guidance pairs business associate agreements with risk analysis and risk management. The agreement is part of the obligation, not a substitute for reviewing how electronic protected health information is handled. (hhs.gov)
For the Arlington booking test, I would ask your vendor to identify the exact service covered by its agreement. Then I would ask where the request is stored, who can access it, whether it enters support logs, and what happens when you delete it.
I would not approve the workflow because a sales page says "HIPAA compliant." I would want answers about the actual configuration your staff will use.
A signed business associate agreement does not finish your HIPAA review. HHS also calls for risk analysis and risk management, so evaluate the service and its data handling rather than treating a contract as permission to send everything. (hhs.gov)
A signed business associate agreement does not finish your HIPAA review.
How do I check where patient information goes?
HHS's risk-analysis guidance calls for identifying potential risks and vulnerabilities to electronic protected health information. That makes the path information takes through your workflow a necessary subject for review. (hhs.gov)
I call my proposed review a "copy map." Start with the booking form and trace each destination: the assistant, calendar, staff notification, conversation history, and any debugging record. Mark every place that receives or retains the submitted text.
Use synthetic test information, not a real patient's details. In the Botox booking test, include an obviously fictional clinical note and inspect whether it appears somewhere the booking task did not need it.
The copy map is a practical review aid, not a compliance certification. Its purpose is to make every destination visible before you decide which information belongs in the workflow.
Use synthetic test information, not a real patient's details.
Should I launch if the vendor cannot explain the data path?
I would not launch that patient-data workflow. If the vendor cannot explain where a medication history goes, I cannot justify asking you to trust the automation with it.
Keep the proposed assistant on public practice information while the patient-data workflow is reviewed. Have your privacy or security lead assess the intended use, applicable obligations, and safeguards before introducing real patient information.
If you want help defining that boundary, start with a focused automation review. Bring the booking process you want to improve, not patient records.
My position on HIPAA compliance is simple: an unanswered data-handling question is a reason to pause, not a detail to fix after launch. I would rather give your practice a smaller, reviewed automation than a bigger system you cannot explain.

