Physicians are increasingly using AI for documentation and administrative work, but consumer chatbots can create HIPAA risk when protected health information is entered without proper safeguards or a business associate agreement.
Artificial intelligence is already part of many medical practices. The harder question, especially for physicians, is whether the tools being used are legally permitted to handle patient information.
In recent years, doctors across specialties have incorporated AI into both clinical and administrative work. In vascular and interventional radiology, the appeal is especially clear. AI can help speed image review, detect lesions, standardize procedural documentation, and reduce administrative demands on practices that are already under pressure. By 2024, 66% of U.S. physicians reported using some form of AI in practice, according to the American Medical Association, nearly double the level seen a year earlier.
What remains less visible is how those tools are being used at the practice level, and whether the systems clinicians rely on every day are allowed to receive the data they are given. That gap between convenience and compliance is where significant risk can begin.
A common scenario is easy to imagine because it is already happening. A physician in a busy interventional practice uses a consumer AI chatbot such as ChatGPT, Gemini, or a similar service to draft or polish a medical record addendum. To make the output more useful, the prompt includes the patient’s name, date of birth, procedure details, and clinical history. The result comes back in seconds and is neatly written. At the same time, the patient’s protected health information has been transmitted to a third-party system that does not have a business associate agreement with the practice, does not carry HIPAA compliance obligations, and may have no restriction on how the data are retained, analyzed, or used to train future models.
This is not a minor technical issue hidden in fine print. It is a direct breach of the HIPAA Privacy and Security Rules. Under 45 CFR §164.502, a covered entity cannot disclose protected health information to a third party, including a technology vendor, unless there is patient authorization or a valid business associate agreement. Consumer AI platforms do not typically sign business associate agreements as a standard condition of use. If identifiable patient data are entered into such a tool, the use is impermissible on its face, regardless of intent.
Medical Economics has previously reported that health care workers are sending patient data through unsanctioned AI tools more often than many organizations realize, and 81% of data policy violations in health care organizations involve regulated data, including protected health information. Those figures underscore that the problem is not hypothetical or isolated.
Vascular and interventional practices are especially exposed because their documentation burden is unusually high. Procedures can generate operative reports, postprocedure notes, complication documentation, imaging interpretations, and increasingly detailed medical necessity addenda. That pressure is heightened by the current audit environment around office-based peripheral vascular procedures. When documentation demands rise, any tool that saves time becomes more attractive.
Practice structure also matters. Many interventional radiology and vascular surgery groups are independent or small. Unlike large health systems that may deploy enterprise-grade, HIPAA-compliant AI platforms with formal governance, smaller practices often do not have dedicated compliance officers or information technology security staff. Physicians who turn to a consumer chatbot are usually trying to solve a real workflow problem with the tools that are available to them. The risk, however, still remains.
Under HIPAA, the covered entity, meaning the practice, carries the primary liability for unauthorized disclosure of protected health information. A physician’s personal use of a consumer AI tool for work-related documentation does not shift that liability to the vendor. It stays with the practice.
The timing is also notable. In May, the U.S. Department of Health and Human Services Office of Inspector General released a report that prompted further examination of physicians performing vascular procedures. With that scrutiny already in place, a separate HIPAA enforcement action is not far-fetched. It is an additional source of regulatory exposure.
The compliance requirements for AI in clinical documentation are not unclear, even if they are not consistently understood. Any AI system that will process, store, or transmit protected health information must be covered by a business associate agreement between the vendor and the covered entity before the tool is used. That agreement must spell out the permitted uses of protected health information, require the vendor to implement appropriate safeguards, and define breach notification obligations.
A business associate agreement is not the end of the analysis. Under the HIPAA Security Rule, 45 CFR §164.308, covered entities must complete a formal risk analysis before adopting any new technology that handles electronic protected health information, including AI tools. The assessment should consider the likelihood and potential impact of a PHI compromise, and it must be documented. Many practices that have started using AI documentation tools have not completed this step.
Medical Economics has described a five-pillar compliance approach for AI adoption in clinical workflows: transparency, informed consent, human oversight, documentation, and ongoing audit. According to that framework, those elements are the minimum practical structure for integrating AI into care processes.
For interventional practices that are already using or evaluating AI documentation tools, several steps address the biggest compliance gaps. First, inventory current AI use. Every physician and staff member should be asked what AI tools they use for work-related tasks. Informal use of consumer tools is often the least visible compliance gap and the one least likely to appear in a formal technology review.
Second, verify business associate agreement status before any use involving protected health information. If there is no business associate agreement in place with the vendor, PHI cannot be entered into the tool. That applies even to free tiers of enterprise products, because business associate agreement coverage typically requires a paid enterprise arrangement.
Third, conduct a security risk analysis. Before deploying any AI tool that will handle PHI, the practice should document the risk assessment. This is required under the HIPAA Security Rule and is not optional.
Fourth, establish a written acceptable-use policy. Physicians need clear guidance on which AI tools are approved for clinical documentation, which require business associate agreements, and which are prohibited for work-related PHI. Verbal instruction alone is not enough.
Fifth, train specifically on AI-related risks. General HIPAA training does not fully address the problems created by consumer AI tools. Physicians and staff should understand that data entered into chatbot prompts may be retained and used in ways the practice does not control.
AI is already playing a meaningful role in vascular and interventional practice, and the operational case for it is real. But the time saved by AI does not outweigh the regulatory exposure created when protected health information is handled outside a compliant framework.
The physicians most at risk are not necessarily those who deliberately set out to violate HIPAA. They are often the ones who use AI casually and assume that a widely available tool with a polished interface must also have the compliance infrastructure to match. That assumption is not safe.
Before the next prompt is entered, practices need to confirm that the tool can legally handle the information being shared. In this environment, that verification is part of basic professional responsibility.
Elina Sabilova, CPC, CFPC, CPMA, is a billing and compliance specialist in the Billing Department at WCH Service Bureau. She also serves as supervisor of revenue cycle management at the firm, where she oversees complex billing operations for high-volume specialty practices and works to maintain compliance with federal, state, payer, American Medical Association, and Society of Interventional Radiology guidelines.
Personalise this feed
Your specialty. Your sources. Your digest.
All set up in under 2 minutes.
Personalise this feed
Your specialty. Your sources. Your digest.
All set up in under 2 minutes.