AI in the Practice: Saving Time Without Putting Patient Information at Risk
AI in the Practice: Saving Time Without Putting Patient Information at Risk
AI has moved into medical practices faster than most practices have written rules for it. In the American Medical Association's 2026 Physician Survey on Augmented Intelligence, 81% of physicians said they use AI professionally, more than double the 2023 rate. Documentation and research summaries top the list.
The tools are easy. Sign up with an email, paste in some text, and get a clean summary in seconds. That ease is the appeal, and it's also the gap. A physician tries a new transcription app on a busy Tuesday. A front desk employee uploads a billing spreadsheet to fix the formatting. Nobody stopped to check how the service handles what it received.
This isn't an argument against AI. It's an argument for deciding, as a practice, which tools you use, what goes into them, and who checks what comes out.

Where AI Helps, and Where It Goes Wrong
Most AI mistakes in a practice aren't dramatic. They're shortcuts taken by good employees trying to save time. Here's what that looks like day to day:
| Task | A reasonable approach | Where it goes wrong |
|---|---|---|
| Staff meeting agenda | Ask an AI tool to organize a list of general topics (scheduling changes, new phone system, holiday hours). | Attaching patient records or a chart export "for context" on a case you plan to discuss. |
| Summarizing an encounter | Using a practice-approved, BAA-covered documentation tool, with the physician reviewing the summary before it's signed. | Pasting visit notes into a personal chatbot account on a phone or home laptop. |
| Patient billing spreadsheet | Working with de-identified data, or using an approved tool covered by an agreement that permits that data. | Uploading the full file, with names, birth dates, and account numbers, to a free tool to clean up columns. |
| Recording an appointment | An approved ambient AI scribe, set up by the practice, with patients informed according to practice policy and state law. | A physician downloading a scribe app on their own and recording visits without anyone reviewing it first. |
The pattern is the same in every row. The task is fine. The problem is the tool, the account, or the data that went into it.
The Tool and the Account Matter More Than the Brand
A familiar name doesn't make a service appropriate for patient information. Neither does a paid subscription.
Many AI companies offer personal, team, and enterprise versions of the same product, each with different terms for storage, retention, and how your data may be used. Those terms also change over time. What matters is the agreement attached to the specific account your staff is logged into, not the logo on the screen.
HIPAA has a clear position here. When a vendor creates, receives, maintains, or transmits protected health information (PHI) on your behalf, that vendor is a business associate, and you need a signed Business Associate Agreement (BAA) before sharing PHI with it. HHS has stated this directly in its Guidance on HIPAA & Cloud Computing, and it has said that using a cloud service to maintain electronic PHI without a BAA is a violation of the HIPAA Rules. A $20/month personal plan almost never comes with a BAA.
Our recommendation: use AI services the practice has approved, under accounts the practice controls, with documented protections that prevent patient information and confidential practice data from being used to train shared or general-purpose models.
What Happens to the Information Afterward
Typing something into an AI tool doesn't publish it to the internet. The real questions are about copies, access, and control. Ask each of these separately, because a good answer to one tells you nothing about the others:
- Storage. Where is the data kept, and is it encrypted in transit and at rest?
- Retention. How long are prompts, uploaded files, recordings, and transcripts kept? Can the practice delete them, and does deletion actually remove them?
- Access. Who at the vendor can view your data, and why? On your side, can an administrator see who used the tool and what they submitted?
- Sharing. Does the vendor pass data to other companies, such as hosting providers or the AI model provider behind the app? Under HIPAA, a business associate's subcontractors that handle PHI need their own BAAs.
- Model training. Is your data used to train or improve models? Is the "no" written into the contract, or is it a settings toggle that someone could switch back on?
A "no training" commitment is worth having. It's one line in the review, not the whole review. A tool can promise never to train on your data and still keep it for years, give broad internal access, or share it with a subcontractor.
What the Government Expects
This is a practical summary, not legal advice. It's worth separating what HIPAA requires from what we recommend.
What HIPAA requires today:
- A BAA with any vendor handling PHI on your behalf. This includes AI vendors. See HHS guidance on Business Associate Contracts.
- A security risk analysis that covers all electronic PHI. The Security Rule requires an "accurate and thorough" assessment of risks to electronic PHI, plus steps to reduce those risks. A new AI tool that touches patient data belongs in that analysis. HHS explains the requirement in its Guidance on Risk Analysis, and OCR is actively enforcing it: its Risk Analysis Initiative had reached 13 completed investigations as of April 2026.
- Minimum necessary. For most uses outside of treatment, practices must limit PHI to the minimum necessary to accomplish the purpose.
- Workforce training and breach response. Staff must be trained on your privacy and security policies, and an impermissible disclosure of PHI may trigger obligations under the Breach Notification Rule.
What we recommend (good practice, not a specific legal mandate):
- A written list of approved AI tools
- An AI use policy that spells out what information can and can't be entered
- Contractual "no training" commitments from vendors
- Human review of every AI output before it's used
What's coming. HHS proposed the first major update to the Security Rule since 2013, published in January 2025. It would add more specific requirements around asset inventories, encryption, and multifactor authentication. It is not final, and HHS states that the current Security Rule remains in effect in the meantime. Final action is now projected for July 2027.
Recording patient conversations can also raise consent questions under state law, separate from HIPAA. Check your state's rules before turning on any ambient scribe.
Five Simple Rules for Physicians and Staff
Policies only work if people can remember them. Start here:
- Use approved tools only, through practice accounts. If a tool isn't on the list, ask before using it for work. Personal accounts stay personal.
- Know what never goes in. Patient names, records, images, billing exports, and confidential business data (contracts, payroll, financials) stay out of any tool that isn't approved for that type of information.
- Get a review before turning on recording or connecting systems. Linking an AI tool to email, calendars, or the EHR gives it ongoing access, not a one-time look. That decision belongs to the practice, not one user.
- A person checks every output. AI summaries, letters, and coding suggestions can be wrong in confident-sounding ways. A qualified person reviews anything before it goes into a chart, to a patient, or to a payer.
- Report mistakes right away, without blame. If someone uploads the wrong file, they should know exactly who to tell. Fast reporting gives the practice time to assess the incident and meet any notification deadlines. People hide mistakes when they expect to be punished for them.
How Cutting Edge Computers Can Help
AI can give your team back real time, especially on documentation and administrative work. The practices that get the most from it treat adoption as an organizational decision: they pick the tools, sign the agreements, set the boundaries, and train their people. The ones that run into trouble let each employee figure it out alone.
CEC can help. We work with medical practices to evaluate AI tools, review security settings and vendor agreements, and put practical staff policies in place. Contact Cutting Edge Computers to start the conversation.
Sources:
- American Medical Association, More than 80% of physicians use AI professionally: AMA survey (March 2026)
- HHS, Guidance on HIPAA & Cloud Computing
- HHS FAQ, Using a cloud service provider to maintain ePHI without a BAA
- HHS, Business Associates
- HHS, Business Associate Contracts
- HHS, Guidance on Risk Analysis
- HHS Press Release, OCR Settles Four HIPAA Security Rule Ransomware Investigations (April 23, 2026)
- HHS, Minimum Necessary Requirement
- HHS, Breach Notification Rule
- HHS, HIPAA Security Rule NPRM
- Troutman Pepper Locke, HIPAA Rulemaking Delays: Trends, Causes, and the Future of the Pending Security Rule Update (July 2026)




