About Writing What I Cover AI Series Instagram Contact Subscribe Free

AI Implementation · 2 min read

The HIPAA Problem With AI Isn't the Tool. It's the Account.

Walk into most practices right now and someone is already using AI. A coordinator drafting a patient follow-up in ChatGPT. A provider pasting consult notes into a chatbot to tidy them up. An owner asking an AI to summarize a stack of intake forms. None of it went through a policy. It started on its own, because it made the day shorter.

That is where the HIPAA exposure actually lives, and most practices are looking at the wrong part of it.

Here is the piece people get wrong. The risk is not that AI tools violate HIPAA. That framing is too broad, and it isn't true. Plenty of AI can be used in a compliant way. The risk is the account. A free or personal AI account has no business associate agreement behind it. So anything your team pastes in, patient names, photos, chart notes, treatment histories, is now sitting inside a consumer product with no contract protecting it, and in some cases with permission to use what you typed to train the model. The tool might be fine. The account is the problem.

Once you see it that way, the fix gets simple. You are not banning AI. You are drawing one line: no patient information in a consumer account, ever. If an AI is going to touch anything that identifies a patient, it has to run through an arrangement that carries a signed business associate agreement, the same standard you already hold your EHR and your payment processor to. Everything else, marketing copy, internal SOP drafts, research, general questions, can happen in the tools your team already likes.

I would not put patient data anywhere near a personal ChatGPT or Claude login, and I tell every practice the same thing. Not because AI is dangerous, but because a consumer account was never built to hold protected health information, and no one signed anything that says it has to.

The practices that handle this well do three unglamorous things. They tell the team, in plain language, what counts as patient information and what does not. They give people one approved place to do the AI work that touches patient data, so there is a compliant option instead of a workaround. And they write it down, because a rule that lives only in someone's head is a rule you can't prove you had when it mattered.

That last point is the one owners underrate. When a question comes up later, the difference between a policy and a problem is whether you can show the line existed before the mistake did.

So before you evaluate a single AI feature, check the account behind it. Protect the account, not just the tool.

One more thing, because a policy like this has legal edges I won't pretend to cover from a blog post. If you're putting real structure around AI and patient data, work with a healthcare attorney who understands the AI nuances, not just general HIPAA. If you'd like names, I keep a short list of attorneys I trust in the healthcare space. Email me at audrey@theaudreyaesthetic.com and I'll send them over.

Frequently asked questions

Does using ChatGPT in a med spa automatically break HIPAA?

No. The issue isn't the tool, it's whether patient information goes into an account with no business associate agreement. Keep protected health information out of consumer accounts and most everyday AI use is fine.

What AI is safe for patient information?

Any arrangement that carries a signed business associate agreement and keeps your data out of model training, held to the same standard as your EHR. For anything that identifies a patient, that agreement is the line.

The Audrey Aesthetic | theaudreyaesthetic.com

© Audrey Campbell 2026

Operator-grade analysis, in your inbox.

AI implementation, practice operations, and brand strategy for the aesthetics industry. No spam.

Considering a project, a role, or a collaboration? Get in touch →