HIPAA and AI Writing Tools: What You Can and Cannot Paste
Under HIPAA, pasting protected health information into an AI service without a Business Associate Agreement is a disclosure to an unauthorized third party. The tool being helpful, popular, or well-intentioned does not change that. The deciding question is whether the vendor has signed a BAA and whether the data left your control at all.
This is not legal advice, and your compliance officer is the authority for your organization. But the shape of the analysis is consistent enough to be worth understanding before you paste anything.
What Counts as PHI in an Email
People underestimate this constantly. PHI is health information combined with anything that could identify the individual, and HIPAA lists eighteen identifier categories. Names, dates including appointment dates, phone numbers, email addresses, medical record numbers, and more.
Which means a great deal of ordinary correspondence qualifies. “Can you rewrite this so it sounds gentler? Mrs. Alvarez missed her Thursday follow-up for the knee replacement and we need to reschedule” is PHI. It contains a name, a date, and a condition.
The instinct that you are only asking for grammar help does not change what is in the text. The tool receives all of it.
Where the BAA Line Falls
A Business Associate Agreement is the mechanism that lets a covered entity share PHI with a vendor. Without one, the vendor is not a business associate and the sharing is a disclosure.
Consumer AI services generally do not sign BAAs. Some enterprise tiers of major AI vendors do, under specific configurations and often at significant cost. The enterprise tier having a BAA does not mean the free tier does, and staff routinely do not know which one they are logged into.
So the practical rule for most healthcare settings: no PHI into any AI service unless your compliance team has confirmed a signed BAA covering that specific product and configuration, in writing.
Where On-Device Processing Changes Things
If text is processed entirely on a workstation you already control, and nothing is transmitted, there is no disclosure to a third party. The data never left the covered entity.
This is a materially different analysis from the cloud case, and it is why on-device tools are increasingly the approved option in clinical settings. It does not remove your other obligations. The workstation still needs the security controls HIPAA requires: access control, encryption at rest, audit capability, and so on. But the third-party disclosure question, which is the one that blocks cloud AI, does not arise.
Verify the claim rather than trusting a marketing page. Ask specifically: during processing, does any text leave the machine, and what network activity exists at all. A truthful answer will name exceptions such as model downloads and update checks.
De-Identification Is Harder Than It Looks
The common workaround is to strip identifiers and paste the rest. It is legitimate in principle and unreliable in practice.
Doing it properly means removing all eighteen identifier categories, and the ones people miss are the indirect ones: a rare diagnosis in a small town, an unusual employer, a date that combines with other context. Re-identification research has repeatedly shown that supposedly de-identified records can be matched back with surprisingly little outside data.
If your workflow depends on staff correctly de-identifying under time pressure, dozens of times a day, it will fail eventually.
Writing About Patients Without Naming Them
Where you do need to communicate carefully, structure helps as much as tooling.
Before:
Mrs. Alvarez didn’t show up again for her post-op knee follow-up on Thursday, that’s the second time, and honestly at this point I’m not sure what else we can do about it.
After:
The patient missed the scheduled post-operative follow-up for the second time. Please contact them to reschedule and note the pattern in the record for the care team.
The second version carries the operational content without the narrative detail, and it is also simply better clinical communication.
A Wrivio Context for this could say:
Rewrite this as a professional clinical communication. Neutral register, complete sentences, no frustration or editorializing. Refer to the patient by role rather than by name where the name is not required. State the fact, the action needed, and who is responsible. Keep every date, clinical detail, and instruction exactly as written and do not add clinical information that is not in the original.
Press Ctrl+Shift+Space and run this in Local mode, so the text is processed on the workstation and no PHI is transmitted. Check the diff, because in clinical text an altered detail is a patient safety issue, not just an editing error.
Common Questions
Does my hospital’s approved AI tool cover this?
Only for the specific products and configurations named in the BAA. Ask your compliance office for the list rather than assuming.
Is it safe if I use my personal account outside work hours?
No. HIPAA obligations follow the information, not the device or the clock.
What about dictation and transcription tools?
Same analysis. Audio containing PHI is PHI, and cloud transcription is a disclosure.
Who is liable if staff paste PHI into a chatbot?
The covered entity, which is why clear policy and an approved local alternative matter more than reminders.
Download Wrivio for Windows to rewrite sensitive text with a model that runs on the workstation, so nothing is transmitted to a third party.
Read Next
What Zero Data Retention Actually Means
Vendors say zero retention, no training, and enterprise grade. Here is what each claim covers, what it quietly excludes, and the questions that get you a straight answer.
AI Clauses in Client Contracts: What They Actually Mean for Your Writing
Client contracts increasingly restrict AI use. Here is how to read the common clause types, what they cover, and how to stay compliant without giving up tooling.
How Freelancers Should Handle Client Data in AI Tools
You signed the NDA personally. Here is how to use AI writing tools without breaching client confidentiality, and what to put in your own contracts.
How Much RAM Do You Need to Run a Local LLM?
A straight answer by model size, why free RAM matters more than installed RAM, and how to work out whether your current machine can handle it before downloading anything.
This article is filed underPrivacy & Compliance, which has 53 articles.