Source note
This checklist is a practical educational resource, not legal or clinical advice. It is informed by Ahpra guidance on meeting professional obligations when using AI in healthcare andOAIC guidance on the Australian Privacy Principles.
Free resource
A practical pre-use checklist for Australian allied health professionals before putting information into ChatGPT, Claude, Copilot, Gemini, or any other AI tool.
The checklist is designed to slow the moment down: what information is involved, what task are you asking AI to perform, what does the tool do with the data, and who remains accountable for the output?
Why stop and check?
Allied health teams often use AI for sensible tasks: rewriting education material, summarising public information, planning training, or drafting admin text. The risk changes when the prompt includes identifiable client information, health details, consultation recordings, staff matters, complaints, contracts, or confidential business information.
Prompts may contain personal or health information. Some tools store inputs, keep histories, process data offshore, or use prompts to improve models.
AI scribes, transcription tools, and tools that use client data may require clear client explanation and informed consent before use.
AI output can be incomplete, biased, or confidently wrong. Clinical decisions and client-facing advice still need qualified human judgement.
A client may not expect their details to be entered into a public or personal AI account. Even one careless prompt can damage confidence in the practice.
Before using an AI tool, work out whether the prompt includes client, staff, business, or other sensitive information.
Have I removed names, dates of birth, addresses, phone numbers, email addresses, Medicare numbers, NDIS numbers, record numbers, appointment details, photos, and document metadata?
Could the person still be identified from rare conditions, locations, dates, workplaces, family details, or a combination of small clues?
Does this include staff issues, complaints, contracts, finances, referrals, or other confidential business information?
The risk changes depending on what you are asking AI to do.
Am I asking AI to diagnose, triage, assess risk, choose treatment, interpret clinical findings, or make a decision that should remain with a qualified professional?
Is the task lower risk, such as drafting generic education material, rewriting non-sensitive text, creating a meeting agenda, or summarising public information?
Could I get the same benefit by using a fictional, generalised, or de-identified example?
Do not assume every AI tool handles data in the same way.
Do I know whether the tool stores prompts, trains on inputs, keeps conversation history, or allows organisation-level data controls?
Is this a personal account, free account, business account, health-specific tool, or workplace-approved system?
Have I checked whether the tool's privacy settings and terms fit the type of information being used?
AI use should be visible, reviewable, and aligned with professional obligations.
Have I checked workplace policy, client consent expectations, privacy requirements, and professional obligations?
Would I be comfortable explaining this use to the client, my manager, my insurer, or a regulator?
Is a qualified person reviewing the output before it is used in clinical, educational, business, or public-facing decisions?
If you are unsure, do not paste it. Use a fictional example, remove more detail, ask for a generic structure, or get local approval before using the tool.
Download version
This PDF can be used as a desk reference, staff discussion prompt, or first-step AI safety resource for an allied health team.
This checklist is a practical educational resource, not legal or clinical advice. It is informed by Ahpra guidance on meeting professional obligations when using AI in healthcare andOAIC guidance on the Australian Privacy Principles.