Plainstart Back to the kit

Article

The Never-Enter List for a Small Health Practice

AI tools are useful for small practices. They are also genuinely risky if staff use them without clear rules. This article covers one specific risk: patient information entering general AI tools. It does not cover clinical decisions, treatment, diagnosis, or anything medical. It is general business guidance only, not professional or legal advice. Your practice's obligations sit with your professional bodies, your registration conditions, your contracts with clients, and the advisers who know your specific situation.

If you want a ready-made policy you can give to staff today, the AI Usage Policy for Medical and Health Practices is free to download.


Why Patient Information Is the Highest-Consequence Category a Small Business Can Hold

Most small businesses carry some sensitive data. A trades business holds bank details. A retailer holds purchase history. A health practice holds something different in kind, not just in degree.

Patient information combines identity, body, behaviour, and history in a single record. That combination means the consequences of exposure land on the patient, not primarily on the business. A person's mental health history, their medication, their attendance pattern, their referral to a specialist, none of that can be taken back once it is out. The business may face reputational and regulatory consequences. The patient faces something else: loss of control over information about their own body and life, with no way to reverse it.

This is why the harm calculus is different here. A data breach at an accounting firm is serious. A data breach at a health practice can affect a person's employment, insurance, relationships, and sense of safety in ways that persist for years. The scale of your practice does not change this. A single record is enough for real harm to occur. You do not need to expose a database of thousands. One patient's name attached to one clinical detail, entering one tool you did not intend, is sufficient.

Small practices sometimes assume they are low-value targets or that informal tool use by a handful of staff carries low risk. The risk does not scale with your headcount. It scales with the sensitivity of what flows through your systems, and for a health practice, that sensitivity is at the top of the range.


The Never-Enter List

These categories should not enter any general AI tool. General AI tools means consumer or business AI assistants, chatbots, writing tools, and similar products that are not specifically contracted, audited, and approved for health data handling in your jurisdiction.

Post this list where staff can see it. Make it a non-negotiable default, not a guideline.

Full name with any clinical or attendance detail attached A name plus a condition, a name plus an appointment type, a name plus a referral destination. Any of these combinations identifies a patient and discloses something about their health.

Contact details Phone numbers, email addresses, home addresses, or any combination of these that would allow a person to be identified or contacted.

Date of birth and age in combination with other identifiers Date of birth alone is lower risk. Combined with a name, suburb, or condition, it identifies a person precisely.

Medicare numbers, health fund membership numbers, patient file numbers, or any record identifiers These connect directly to formal health and insurance systems. They do not belong in general tools under any circumstances.

Clinical detail of any kind Diagnoses, symptoms, medications, procedures, test results, referrals, discharge notes, treatment plans. None of this should appear in any prompt, summary request, or document draft entered into a general AI tool.

Appointment records tied to a person An appointment type can reveal a condition or a specialist. Even without a name, a time, location, practitioner name, and appointment category together may identify someone in a small practice.

Images of patients or clinical documents Photos, scans, pathology reports, clinical letters, or any document that includes a patient's name or details. Several AI tools accept image inputs. A photo of a letter or a screen is still the underlying data.

Correspondence that names or describes a patient Letters to or from a patient, letters to or from a referral partner that name the patient, complaint correspondence, insurance correspondence. The content of the letter carries the risk, not the format.

Combinations that identify by inference A single piece of information that seems harmless may identify a person when combined with others. "Female patient, 34, referred from suburb X for Y condition, attending on Thursday afternoons" is identifiable in a small practice even without a name. Staff should apply the combination test: would a person who knows this community be able to work out who this is? If yes, it does not go in.


What Genuinely Can Use These Tools

The value of AI tools in a health practice administration context is real and it sits entirely in the non-patient area. The following categories are generally safe to use, provided no patient identifiers or clinical detail are included.

Staff rosters and scheduling templates Drafting shift patterns, cover templates, on-call schedules, and similar documents that refer to roles and times but not to patients.

Supplier and vendor correspondence Drafting emails to equipment suppliers, consumables vendors, IT support, landlords, or cleaners. None of this touches patient data.

Internal process documents Policies, standard operating procedures, onboarding checklists, cleaning schedules, equipment maintenance logs. These can all be drafted, improved, or reformatted with AI assistance.

General staff training material Scripts for reception phone manner, guides for handling general enquiries, induction documents, meeting agendas, team communication templates. Provided the training content does not use real patient examples, this is a productive use of these tools.

Marketing and external communications about the practice Website copy, service descriptions, bio drafts that do not include patient stories or case detail, social media posts about the practice itself.

Financial administration at the category level Drafting budget templates, supplier payment schedules, or cost comparison formats, provided these contain no patient billing detail or identifying information.


A Worked Example: Rewriting a Receptionist Task to Be Safe

Here is a situation a receptionist might face and how to handle it safely.

Original task (unsafe) A receptionist wants to draft a follow-up letter for a patient who missed an appointment. She types into an AI tool: "Write a letter to Sarah Thompson at [home address] reminding her she missed her appointment on Tuesday the 14th with Dr Patel for her anxiety review and asking her to call back."

This contains a full name, a home address, a date, a practitioner name, an appointment type, and a condition. It should not go anywhere near a general AI tool.

Rewritten task (safe) The receptionist drafts the letter herself using the practice's standard template for missed appointments, which already has the correct language. She then uses an AI tool to improve the tone of the generic template text only, pasting in: "Here is a letter template for missed appointments. Please make the tone warmer and easier to read." No patient detail is involved. She then fills in the actual patient details in the final document, offline, using the practice system.

The work that benefits from AI assistance is the template. The patient-specific information never touches the tool.

This is the pattern across all reception, administration, and coordination tasks. Build the template with AI. Fill the patient detail in separately, in your own systems, without AI involvement.


A Note on Obligations

Whatever privacy rules apply where you operate vary by jurisdiction and are worth checking with someone who knows your local requirements. Your professional registration body sets conduct standards that apply to patient information handling. Your engagement letters and contracts with patients and referrers may carry specific commitments. Your indemnity insurer may have conditions relevant to data handling. None of that sits with this article. It sits with your practice, your advisers, and the bodies that govern your registration.

This article is general business guidance only. It is not legal, regulatory, or professional advice of any kind.


Start With a Policy

A clear written policy is the first step. It tells staff what the rule is, gives them a reference point when they are unsure, and shows your practice has taken the matter seriously.

The AI Usage Policy for Medical and Health Practices is free. It is written in plain language, ready to hand to staff, and does not require a lawyer to read it.

If your practice needs a fuller system, including a data governance checklist, a 90-day adoption plan, and a tool scorecard, the full Plainstart AI Adoption Kit is available for $149. Individual prompt libraries are available for $39.

AI adoption, done properly.

Free, no email required

Build your own AI usage policy in about two minutes

Answer eight questions and the full policy writes itself around your business. Copy it, download it, put it in front of staff today.

Open the policy generator