The AI Tab Next to the Patient Record: What Santa Clarita Practices Are Pasting Into ChatGPT
Somewhere in Santa Clarita this week, a front desk coordinator had a letter to write, 20 minutes to write it in, and a browser tab open. She pasted in what she had, asked for a cleaner version, and got one. It was good. It saved her the 20 minutes. Nobody was told, because nothing happened that felt like it needed telling.
That is the shape of this in almost every practice we see. Not a policy violation, not a careless employee, just a person finishing the work with the fastest tool on the desk. The exposure is not the technology and it is not the person. It is the account the work went through, because the difference between a free tab and a covered business account is written into the contract rather than into the model, and the two are easy to confuse when both of them answer politely.
Overview
Start with the rule rather than the tool, because the rule has not changed and it settles most of the argument. Under HIPAA, a business associate is a person or company that creates, receives, maintains or transmits protected health information on behalf of a covered entity, and the definition sits at 45 CFR 160.103. Where that relationship exists, 45 CFR 164.502(e) requires the covered entity to obtain satisfactory assurances in the form of a written agreement before the information is disclosed. There is no size exception in that sentence and no exception for software that is clever.
A general purpose AI service that receives a paragraph of patient detail is doing exactly what the definition describes. So the question a Santa Clarita practice actually faces is not whether AI is allowed. It is whether the specific account in use is one the vendor has agreed to stand behind in writing, and that turns out to be a narrow and checkable question with a published answer.
The same question arrives in different clothing in every other regulated office in the Valley. For an accounting firm it comes through the service provider element of the Safeguards Rule, which asks you to select providers capable of maintaining appropriate safeguards and to require those safeguards by contract, the ground our piece on the written plan most small firms do not have covers in full. For a law firm it comes through the duty of confidentiality, and the American Bar Association addressed it directly in 2024. For a registered adviser it arrives through Regulation S-P, whose 2024 amendments require a written incident response program and notice to affected individuals as soon as practicable and no later than 30 days after becoming aware of an incident, with the smaller entity compliance date falling this year.
Four professions, one mechanism: information about somebody else, handed to a third party, on terms nobody read. This piece is about reading them, and about the one sentence that has to be written down afterward.
The Challenge
Not used for training is not the same as covered by a BAA, and the market blurs the two constantly. These are separate promises about separate things, and a practice can have the first without the second. OpenAI states that by default it does not use data from ChatGPT Enterprise, ChatGPT Business, ChatGPT Edu, ChatGPT for Healthcare, ChatGPT for Teachers or the API platform, including inputs and outputs, to train or improve its models. That is a genuine improvement over a personal account and it is worth paying for on its own merits. It is also not a business associate agreement, and OpenAI does not present it as one.
The tier a small practice is most likely to buy is the tier without the paper. On its own help pages, OpenAI states that it does not offer a BAA for ChatGPT Business, and that BAA coverage runs to ChatGPT Enterprise and Edu on sales managed accounts, to ChatGPT for Healthcare, and to API healthcare customers, with most API services covered subject to listed exceptions. Read those two vendor statements together and the practical result is sharp: a 6 person practice that upgraded to Business to be responsible improved its privacy position and did not enter a HIPAA arrangement. That is not a trick played on anybody. It is written down. It is simply not the thing the office believes it bought.
The suite you already pay for may be the better door. Most practices in the Valley already run Microsoft 365 or Google Workspace, and both vendors have taken a position. Microsoft makes its HIPAA business associate agreement available through the Online Services Data Protection Addendum by default to customers who are covered entities or business associates, and lists Microsoft 365 Copilot and Copilot Chat among the in scope services. Google requires an administrator to review and accept a business associate amendment, states that customers without one must not use PHI in Google Workspace or Cloud Identity services, and covers only what appears on its HIPAA Included Functionality list, where specific Gemini features are named rather than everything wearing the Gemini badge. The door may already be open, unlocked by a checkbox nobody has clicked.
Both vendors then say the part that gets skipped. Microsoft states plainly that using its services does not on its own achieve HIPAA compliance and that the customer remains responsible for an adequate program and for how the services are actually used. Google puts the same responsibility on the administrator. The agreement moves the vendor into a defined role. It does not decide what your staff type, which account they are signed into, or whether anyone checked. That part has never been purchasable and still is not.
For a law firm the obligation runs through consent, not just contract. The ABA issued Formal Opinion 512 on 29 July 2024, its first ethics guidance on generative AI. The core of it is unremarkable and demanding at once: the duty of confidentiality under Model Rule 1.6 applies to information put into these tools, and where a self learning tool would receive client information, informed client consent is the relevant standard rather than the lawyer own comfort. Rule 1.4 sits underneath it, since the client is entitled to be consulted about the means used. A firm that has not had that conversation has not made the decision. It has postponed it.
And the account is only half the exposure. The other half is what comes back. These systems produce fluent text that is sometimes wrong, which matters most in exactly the settings this piece is aimed at: a clinical summary, a client letter, a set of figures, a citation. Nothing in a BAA makes an output correct. The review step is the control, and it belongs to a person who would have been accountable for the sentence anyway.
Why It Matters
5 reasons this is worth an hour now rather than an incident later:
This is shadow IT with better manners. The pattern is the one our piece on the systems you do not control described before AI arrived to accelerate it: a tool adopted quietly by good employees to do their jobs faster, invisible to whoever is accountable for the data. The difference now is the speed of adoption and the fact that the tool asks for the sensitive part by design, because that is what makes the answer good.
This page will not print a percentage of employees pasting confidential data into AI, and the reason is the point. Those figures circulate widely and they move buyers. We went looking for a sourceable one, which is the only responsible thing to do with a number used to sell, and what we found were vendor surveys and telemetry from companies selling the product that blocks the behavior, with definitions and populations that are not comparable and often not published. So the number stays off this page. The obligation does not need it. A practice that acts on a statistic nobody can trace has learned the wrong habit, which is the habit our piece on how AI reads the fine print is really about, and the same discipline we applied to the penalty figures in the Safeguards piece.
The cyber insurance application is going to ask. Applications have started carrying questions about AI usage and governance, and the answers are representations rather than opinions, which is the whole argument of our piece on the audit you already signed. A practice that has written its line down can answer in a sentence. A practice that has not is answering from memory about behavior it has never looked at.
The vendor relationship is a dependency like every other one. Terms move, tiers get renamed, features arrive switched on. That is the ordinary condition of hosted software rather than a scandal, and it is why our piece on aligned software and extraction software treats the business model as a security fact and why third party vendor risk follows the data wherever it goes. An AI vendor is now one of the places your client information lives, and it belongs on the inventory beside the practice management system.
Staff will keep using it, and that is not the failure. The work is real, the time pressure is real, and the tool helps. A practice that treats this as a discipline problem will spend a year losing an argument. A practice that treats it as an access decision will spend an afternoon and have an answer, which is the same move our piece on what AI did to phishing reached: when the human tell disappears, the control has to move to something structural.
What Organizations Should Watch For
- Personal accounts signed in with work email, or with a personal one. The most common arrangement in a small office is nobody account: a free login, made by whoever needed it first, owned by no one, invisible to any administrator and unaffected by anything you configure.
- A paid tier assumed to be a covered tier. Ask which product, on which plan, under which agreement. Business, Enterprise, Edu and API are different answers with different paper behind them, and the invoice does not say which one you are on in the language the rule uses.
- AI features that arrived switched on inside tools you already had. The note taker in the meeting app, the summarizer in the inbox, the assistant in the practice management suite. Each one is a decision somebody made, and mostly not you.
- Recording and transcription in clinical or client conversations. These handle the most sensitive material in the building by design, and the vendor list for them is long and young. This is the category to check first and hardest.
- Client or patient identifiers inside prompts that did not need them. Most of the work these tools do well can be done with the name, the number and the date of birth taken out. Habit, not policy, is what determines whether they are.
- Output pasted into a record without a human read. A confident paragraph that nobody checked is the failure mode that will embarrass a practice long before a breach does.
- A written policy nobody can quote. If the rule cannot be said out loud at the front desk in one sentence, it is not operating, whatever the binder says.
- Accounts that outlive the person. An AI account made by a departed employee, holding a year of prompts, tied to an address nobody controls. The mechanics are the ones our piece on offboarding as a security event lays out, and this is a new place for the same old orphan to hide.
Recommended Actions
- Ask the question without a penalty attached to it. Find out what is actually in use by asking people who are not in trouble. An office that expects punishment will report nothing, and you will have bought silence rather than an inventory.
- Check the tier you are on and read what it says about a BAA. This is a 10 minute job with a definite answer. If protected health information or client data has been going into a tier the vendor does not cover, you want to know that this week rather than during an application or an audit.
- Open the door you already own before you buy another one. If you run Microsoft 365 or Google Workspace, check whether the business associate agreement is in place and which AI features it covers, then point staff at that tool by name. The cheapest approved door is usually the one already paid for.
- Write the line in one sentence, and make it about identifiers rather than about attitude. Which account is approved, and what may not be typed into anything: names, dates of birth, record and account numbers, financial detail, anything from a client file. A sentence gets followed. A page gets filed.
- Keep the review step with the person who signs. Whoever is accountable for the letter, the summary or the return is accountable for reading it. Nothing about the tool moves that, and no agreement covers a wrong sentence.
- Law firms: have the consent conversation before the tool is used, not after. Formal Opinion 512 puts client information into self learning tools on the consent side of the line. That is a conversation with a client and a note in the file, and it is far easier before the work than in a complaint.
- Put AI vendors on the inventory and the plan. They belong in the data inventory, in the service provider list, and in whatever written program you keep, which for an accounting firm is the plan our Safeguards piece works through and for a practice is the same risk analysis you already maintain.
- Set a date to look again. Terms and tiers in this market move faster than in any other category of software you buy. A short calendar reminder to re read the page you relied on is not busywork here, it is the only way the decision stays true.
The SecureLynx Perspective
Observe:
What we find in medical practices, accounting firms and law offices around Santa Clarita is not a governance failure, it is an unasked question. The tools came in through the browser rather than through procurement, so there was no moment at which anybody was supposed to decide, and the people using them are the conscientious ones who were trying to keep up. So the first pass is a conversation and an inventory rather than a policy: what is being used, on whose account, on which tier, and for what kind of material. That usually takes an afternoon and it is nearly always less alarming and more specific than the practice feared.
Adapt:
Then the work is narrow. Establish one approved door, usually inside the suite the practice already licenses, with the agreement actually accepted and the covered features confirmed rather than assumed. Turn off or discourage what is left, which is ordinary account and license administration rather than a project, write the single sentence the staff can carry, and put the vendor on the inventory where it belongs, which is the ordinary compliance and risk work rather than anything exotic. The technical layer underneath is the same access control, account ownership and logging we would be doing regardless, and the record of the decision is exportable from the client portal with the primary copy yours.
Protect:
The limits, stated plainly, because on this subject they matter more than the offer. We cannot certify anybody as compliant and no provider can. We are not your attorney, and whether a particular use of a particular tool is permissible in your practice is a question for counsel and, for a law firm, for the rules that govern you rather than for us. Vendor terms in this market change, so anything we tell you today is a reading of what is published today, and we will say so rather than pretend otherwise. A practice that checks its own tier, accepts the agreement it already qualifies for and writes one honest sentence has done the substance of this without hiring anyone, and we would rather say so than sell around it. Our pricing is published and the agreements are readable before you ever call. Point the first hard question at us.
Common questions
Our Santa Clarita practice pays for ChatGPT Business. Does that make it safe for patient information?
Paying is not the same as being covered, and this is the single most useful distinction on the subject. OpenAI states that by default it does not use data from ChatGPT Business, Enterprise, Edu or the API platform to train its models, which is a real protection and is worth having. It also states plainly that it does not offer a business associate agreement for ChatGPT Business. Those two facts sit side by side in the vendor own documentation. A BAA is available for ChatGPT Enterprise and Edu on sales managed accounts, for ChatGPT for Healthcare, and for API healthcare customers. So a practice on the Business tier has bought a privacy improvement rather than a HIPAA arrangement, and without a signed BAA the protected health information should not go in. Check the tier you are actually on, not the tier you meant to buy.
Should we just ban AI in the office and be done with it?
A ban is easy to write and almost impossible to hold, because the work it speeds up is real and the phone in the pocket is outside your control. What a ban usually produces is the same behavior with less visibility, which is the worst of both. The alternative is not permissive, it is specific. Name one approved door, meaning one account on a tier whose paper you have read, turn off or discourage everything else, and write a single sentence that says what may be typed into it and what may not. Staff follow a line they can remember. They cannot follow a policy that only says no while the work still needs finishing.
We already run Microsoft 365 or Google Workspace. Are we covered for the AI features?
Possibly, and the answer comes from the paper rather than from the login screen. Microsoft makes its HIPAA business associate agreement available through the Online Services Data Protection Addendum by default to customers who are covered entities or business associates, and it lists Microsoft 365 Copilot and Copilot Chat among the in scope services. Google requires an administrator to review and accept a business associate amendment, and only the services on its HIPAA Included Functionality list are covered, with specific Gemini features named there rather than everything carrying the Gemini label. Both vendors say something a practice should read twice: the agreement supports your compliance, it does not by itself achieve it. The configuration, the training and the decision about what goes in remain yours.