By Christian Epperson
The average physician now loses nearly nine hours a week to administrative work. So when a free AI chatbot offers to draft a summary or an appeal letter in seconds, it's easy to see the appeal — and easy to see why so many are doing it quietly, without realizing the risk. In 2026, a leading patient-safety organization ranked the misuse of AI chatbots as the single largest health technology hazard of the year.
Three ways it quietly becomes a HIPAA problem
- “HIPAA-eligible” is not “HIPAA-compliant.” A tool that creates, receives, or transmits PHI on your behalf is legally a Business Associate — and needs a signed BAA before any patient data touches it.
- “De-identified” is harder than it sounds. Clinical narratives carry enough detail that re-identification is often possible, even after obvious identifiers are removed.
- Your patient data may train someone else's model. Free and consumer-tier AI tools often reuse submitted content to improve future versions — unless an enterprise agreement explicitly says otherwise.
Blocking AI outright rarely works. A more durable approach: a written AI use policy naming approved tools, vendor BAAs that explicitly prohibit training on your PHI, minimum-necessary access controls, and monitoring for PHI leaving the network through browser-based AI — the same way you'd watch for it leaving through email.
Christian Epperson Security Team lead with EPPTech.
