Episode 613: You Discovered Non-Compliant AI Use in Your Practice. Now What?
In this episode, we share concrete steps to take if you’ve discovered staff members using non-approved AI platforms in your practice.
We discuss:
The misconceptions around what constitutes PHI (and why information used to write a progress note absolutely is PHI)
Why this is a reportable HIPAA breach
Why reporting a HIPAA breach is nowhere near as scary or impactful as you may fear
The difference between a large breach and a small breach, and reporting deadlines for each
Client notification deadlines for breaches
How state law can impact or add to reporting deadlines
Steps to take after discovering non-compliant AI use in your practice
What to investigate, how to document, how to mitigate, how to notify clients, and when to consult an attorney