AHAI article

When sensitive information goes into the wrong AI tool

What can happen when personal, health, staff, or confidential business information is entered into an unapproved AI tool, and how allied health teams can reduce the risk.

AI tools can feel like a private conversation. You type something in, get a useful answer back, and move on. But for allied health work, the prompt is not just a prompt. It may contain personal information, health information, clinical context, staff information, or confidential business details.

Once that information is entered into the wrong tool, the problem is not only that the answer might be inaccurate. The bigger issue is that the information may have moved into a system your practice does not control.

“Outside your control” does not mean the same thing for every tool

Different AI tools handle information in different ways. A health-specific AI scribe with an Australian privacy assessment, a workplace-approved enterprise AI account, a free public chatbot, and a personal browser extension may all have very different rules.

Before using a tool with sensitive information, you need to understand:

  • whether prompts and uploaded files are stored
  • whether conversation history is retained
  • whether staff or contractors can review inputs for support, safety, or quality purposes
  • whether data is processed or stored outside Australia
  • whether inputs can be used to train or improve the model
  • whether the organisation has an admin console, audit logs, retention controls, and deletion controls
  • whether the tool has been approved for personal or health information

The risk is highest when a clinician or staff member uses a public, personal, or free AI tool without knowing these answers.

The data may be stored somewhere you did not intend

When you paste referral text, assessment notes, appointment details, a transcript, or a complaint into an AI tool, the information may be saved in that tool’s systems. It may also remain in browser history, chat history, exported files, integrations, backups, logs, or connected apps.

That matters because health information is not ordinary text. A few details can identify a person even if their name is removed. A rare condition, a location, an appointment date, an occupation, and a family situation can be enough to make the person recognisable.

The information may be used in ways you did not expect

Some AI services use prompts, files, feedback, or conversations to improve their systems unless settings, account type, or contract terms say otherwise. Other tools may say they do not train on your inputs, but still store them for a period of time for safety, abuse monitoring, troubleshooting, or product improvement.

This does not mean every AI tool will expose client details to another user. It does mean you should not assume that information entered into an AI tool stays inside your clinic in the same way as information in your practice management system.

For allied health teams, the safer question is:

Would we be comfortable if this exact information was stored, reviewed, processed overseas, retained in logs, or used to improve an external service?

If the answer is no, do not enter it into that tool.

The data may reappear indirectly

People often worry that a client note pasted into AI will later be repeated word-for-word to someone else. That is not the most common or predictable risk, and it should not be described as inevitable.

The more practical risk is loss of control. Sensitive information may remain in records, logs, histories, training or evaluation datasets, screenshots, exports, support tickets, or connected systems. In some AI systems, information used for training or improvement may also influence future outputs in indirect or unpredictable ways.

Even if the chance of direct repetition is low, allied health teams should treat personal and health information as information that should not be casually placed into systems that are not approved for it.

The output may create a second risk

The first risk is what you put into the tool. The second risk is what comes out.

AI can produce text that sounds polished but is clinically unsafe, incomplete, biased, or wrong. If the tool has been given sensitive clinical information, the output may also contain a new version of that information: a summary, letter, report, email, exercise plan, or recommendation.

That output then needs the same care as any other clinical or business record. It should be reviewed by a qualified person before it is used with a client, added to a record, sent to another provider, or used to guide a decision.

AI scribes and transcription tools create an extra layer of risk because they may record or process a real consultation. Ahpra guidance says practitioners should involve patients in decisions to use AI tools that require input of personal patient data, and that generative AI scribing will generally require informed consent.

In plain English: if an AI tool is listening to, recording, transcribing, or processing a consultation, clients should know what is happening and why.

A safer default for everyday practice

Before entering information into AI, pause and ask:

  • Is this identifiable personal or health information?
  • Could the person be recognised even if their name is removed?
  • Is this tool approved for this type of information?
  • Do I know where the data goes and how long it is kept?
  • Does the client need to be told or asked for consent?
  • Could I use a fictional, generalised, or de-identified version instead?
  • Who will review the output before it is used?

AI can be very useful in allied health. The goal is not to avoid it. The goal is to keep the benefits while making sure client trust, privacy, clinical judgement, and professional accountability are not quietly handed over to a tool that was never approved for that job.

For a practical prompt-by-prompt check, use the Before You Paste Into AI checklist. It is designed to help allied health teams slow down before pasting, uploading, dictating, or transcribing information into an AI tool.

Related reading: Why you should not paste client information into public AI tools and What not to paste into ChatGPT or other AI tools.

This article is a practical educational resource, not legal, privacy, regulatory, or clinical advice. Useful starting points include Ahpra’s guidance on AI in healthcare and the OAIC’s overview of the Australian Privacy Principles.