Skip Navigation
Your Hospital May Use ChatGPT. Here’s Why That Should Concern Your Compliance Team

Blog Post

Your Hospital May Use ChatGPT. Here’s Why That Should Concern Your Compliance Team

By Adam Rosenberg

You probably have an AI governance policy in draft. IT may have flagged it as a roadmap item. Leadership may have agreed to revisit it next quarter. Meanwhile, clinical and administrative staff are already using ChatGPT. Not waiting for approval, not flagging it to IT, and not triggering a single alert in your compliance infrastructure.

This isn’t speculation. Physician AI use jumped from 38% in 2023 and has since reached 81% as of 2026. The tools became easier to use, but the documentation burden didn’t shrink.

The gap between what your staff is doing and what your compliance team can see has widened faster than most health system leadership has noticed.

Your Staff Aren’t Waiting for a Policy

This behavior isn’t coming from bad actors. It’s coming from staff who are behind on documentation and have found a faster way to get through it.

Clinical and administrative staff carry documentation pressure that hasn’t eased: prior authorization letters, discharge summaries, incident reports, progress notes, and controlled substance records all require careful, time-consuming writing. 

ChatGPT and Gemini cut that time down fast. They’re free, browser-based, and require no IT approval, no procurement cycle, and no training.

The workflow takes under a minute:

  1. Open a browser tab (no IT approval required)
  2. Paste a patient note, incident report, or controlled substance record
  3. Clean up the language, copy the output
  4. Close the tab and move on

No ransomware alarm fires. No log entry appears in your infrastructure. No Business Associate Agreement (BAA) is triggered. From a compliance monitoring standpoint, that interaction is invisible. It looks identical to a staff member Googling a drug interaction.

This is what’s commonly called “shadow AI“: unapproved tools that solve a real problem fast, operating entirely outside governed systems. 

At scale, across a health system with hundreds or thousands of staff, it creates an unmeasured HIPAA advisory exposure that most compliance teams have never formally assessed.

What Your Compliance Team Can’t See

Most compliance infrastructure is built around systems the organization controls: EHR access logs, network activity, credentialed user behavior. Browser-based AI tools sit outside that perimeter entirely.

Consider what your patient privacy monitoring infrastructure can and can’t capture today:

What Compliance Can SeeWhat Compliance Can’t See
EHR access logsBrowser-based AI tool use
Credentialed system loginsFree-tier ChatGPT or Gemini sessions
Network access anomaliesPHI pasted into external tools
Governed application activityUnapproved workflows on work devices

About 93% of patient privacy breaches are caused by unauthorized access. The average hospital generates 60 million audit-worthy events, and manual review can’t catch what isn’t logged in the first place. Informal AI use creates exactly that scenario: PHI or healthcare-specific data moving outside governed systems with no timestamp, no record, and no way to assess scope after the fact.

If asked today how many staff members used an unapproved AI tool with patient data in the last 30 days, most compliance teams couldn’t answer.

Why ChatGPT and Gemini Aren’t Built for This

Consumer-grade AI tools weren’t designed for HIPAA-regulated environments, and the structural gaps are specific.

Public versions of ChatGPT and Gemini operate without a signed BAA. Every time a staff member pastes protected health information (PHI) into a free-tier session, a potential HIPAA violation has occurred. Silently, with no audit trail and no notification.

Even when a BAA exists, it may not be enough. Most enterprise agreements cover data security but stop short of the language needed to govern AI-specific risks:

What a Standard BAA CoversWhat It Typically Doesn’t Cover
Encryption and data storageVendor use of PHI to train AI models
Access controlsFine-tuning on submitted data
Breach notification obligationsOpt-out defaults for model training
Security incident proceduresStaff use of personal or free-tier accounts

That last row is where informal AI use falls entirely outside any agreement. Staff using personal accounts or free-tier tools on work devices aren’t covered by an enterprise contract, regardless of what that contract says.

Healthcare data breaches cost an average of $9.77 million per incident, making healthcare the most expensive sector for breach recovery for 14 consecutive years. At that cost, informal AI use isn’t a theoretical concern. It’s a financial one.

The Free Tier Is the Real Exposure

Enterprise ChatGPT agreements don’t cover staff using personal accounts. Health systems that have negotiated enterprise AI contracts may still have widespread free-tier use that they’ve never assessed. The compliance gap isn’t between approved and unapproved enterprise contracts. It’s between governed tools and whatever a staff member opened in a browser tab before their 9 AM shift.

A few questions worth asking now:

  • Does your approved-tools policy address free-tier consumer AI, or only enterprise software?
  • Can your current infrastructure detect when PHI leaves the EHR and enters a browser-based tool?
  • Is your BAA language, if one exists, explicit about prohibiting training data use?

The Regulatory Ground Is Shifting

The informal AI-use problem is about to become a formal compliance obligation.

In December 2024, HHS OCR published a proposed update to the HIPAA Security Rule, the first significant revision since 2013. The rule is on HHS’s regulatory agenda for May 2026. Three obligations directly relevant to informal AI use:

  • Written technology asset inventory. Covered entities would be required to document every AI tool that touches ePHI, including tools staff are using informally.
  • Expanded risk analysis. Risk assessments must account for all systems that “create, receive, maintain, or transmit ePHI,” with AI tools explicitly included.
  • Formal governance of AI-related data flows. Movement of ePHI into and out of AI systems must be mapped and documented.

Once that framework takes effect, “we didn’t know staff were using ChatGPT” stops being an explanation and becomes evidence of a governance failure. Under the HITECH Act’s penalty structure, HIPAA violations for willful neglect carry penalties up to $1.5 million per identical provision per year. A required inventory that was never built doesn’t leave much room for that defense.

What the HCA Healthcare Data Breach Lawsuit Settlement Reveals

The HCA Healthcare data breach lawsuit settlement put a number on what uncontrolled data exposure looks like at scale. In July 2023, HCA Healthcare disclosed a breach with the following scope:

  • 11.27 million patients affected across 20 states
  • 27.7 million records were stolen from an external storage location used to automate email formatting
  • 27 class action lawsuits consolidated into a single case
  • $35 million settlement granted final approval in October 2025
  • Up to $5,000 per class member for documented losses
  • HCA committed to maintaining specific cybersecurity measures for two years

The HCA breach didn’t originate with ChatGPT. The point isn’t which tool was involved. It’s what happens when PHI moves through any unmonitored system at scale. Informal AI use runs that same risk across every department, every day, through workflow shortcuts that compliance teams have no visibility into.

What to Do Before the Next Policy Review

Banning AI won’t work. Staff will find another tool, and a blanket prohibition without a governed alternative just pushes the behavior further out of sight. The goal is to close the gap between what’s happening and what compliance can actually see.

Starting points:

  • Audit actual behavior, not assumed behavior. Survey which AI tools are used across departments on the assumption that unapproved tools are already in use. Design the assessment to surface what’s happening, not confirm what policy says should be happening.
  • Map PHI data flows into and out of AI tools. This is a proposed regulatory requirement under the HIPAA Security Rule NPRM. Building that inventory now puts you ahead of enforcement rather than behind it.
  • Review BAA language for training data prohibitions specifically. Storage and encryption coverage isn’t enough. Any AI tool touching ePHI needs a contract that explicitly prohibits the vendor from using that data to train models.
  • Build an approved-tools list before issuing a policy. Staff need a governed alternative. A policy that only says “no” doesn’t solve the documentation problem that drove informal use in the first place.

305 million patient records were compromised in 2024, a 26% increase over the prior year. A single OCR investigation triggered by a staff member’s ChatGPT session can open a review of your entire risk analysis posture, breach or no breach.

Healthcare data security software built for compliance environments, like Bluesight’s PrivacyPro, audits up to 100% of system accesses and uses machine learning to surface violations before they escalate. That kind of coverage matters most when the exposure doesn’t announce itself.

If you’re reassessing your infrastructure in light of where informal AI use has already gone, understanding what separates effective privacy monitoring tools from noisy ones is a useful place to start.

The informal AI use happening in your health system right now won’t show up in your current audit logs. The compliance team doesn’t have a record of it. IT doesn’t have a flag for it. And the regulatory framework that formalizes your obligation to account for it is close.

Schedule a demo today to see how PrivacyPro gives compliance teams the coverage to know what’s actually happening in their organization.