Public AI chatbots may store and reuse information entered by users, raising privacy and compliance concerns for physicians who type patient details into consumer tools not built for HIPAA protection.
Artificial intelligence chatbots have quickly become a time-saving tool for physicians, but questions are growing about what happens when patient information is entered into a public model. According to Medical Economics, the concern is not just theoretical. Experts are warning that consumer-facing tools may not handle protected health information the way clinical systems are expected to do, creating privacy and compliance risks for medical practices.
The issue centers on public large language models, including tools such as ChatGPT and Gemini. Unlike electronic health record systems that are designed around HIPAA compliance, these chatbots were not built to safeguard protected health information. That difference matters because physicians may be tempted to use them for routine tasks, such as drafting a note or summarizing a visit, without fully considering how the information is handled once it is entered.
The article says public LLMs can store, process, and in some cases reuse the information they receive. That means patient details typed into a chatbot could be retained in ways the physician did not intend or approve. Once information leaves a secure system, there is no guarantee that it remains private, and it can become difficult to trace where it went afterward. For practices that use these tools casually or without clear policies, the risk may be easy to underestimate.
Medical Economics notes that the danger is not limited to privacy alone. Physicians who use consumer-grade AI tools for clinical tasks rather than dedicated, FDA-cleared software may also face compliance problems. Even when the intent is simply to save time, the legal exposure can increase if a practice relies on tools that were not designed for protected health information. The article says many physicians are left guessing about how securely their inputs are being handled because the business models behind these chatbots were not built with patient data in mind.
The piece says this gap between convenience and privacy has become a growing concern as AI tools become more common in everyday practice. A chatbot may seem like an easy shortcut, but the article warns that typing in patient details can create problems that are hard to undo. If information is stored or reused, a physician may not know where it ends up or how it is used later.
To better understand how these risks play out, Medical Economics spoke with Harley Sugarman, founder and CEO of Anagram Security. The article says Sugarman discussed how these concerns can appear in ordinary practice and what physicians should be doing differently. However, the source provided here does not include the details of that discussion, so those specifics were not reported in the available text.
The central message of the article is straightforward: physicians should be cautious about entering patient information into public AI models. Tools like ChatGPT and Gemini may be useful for some tasks, but the article emphasizes that they were not designed as secure repositories for protected health information. That makes them a poor fit for handling patient details in the same way a compliant health record system would.
The privacy concern also has practical consequences for medical practices that may not have fully considered how staff use AI tools. Even a brief prompt containing patient information could create downstream risk if the model stores or reuses the content. Because the source says tracing where data goes after it leaves a secure environment can be difficult, practices may not realize the extent of exposure until later.
Medical Economics frames the issue as one that many practices have not fully reckoned with yet. The convenience of public chatbots can make them attractive, especially in busy clinical settings, but the article warns that convenience should not be confused with safety. If a tool was not built to protect protected health information, physicians should not assume it will handle patient data securely.
The article does not provide a checklist of best practices or specific policy recommendations in the text supplied here. Instead, it underscores the broader risk: public AI chatbots can store, process, and sometimes reuse information, and that creates potential privacy and compliance problems when patient data is entered into them. For physicians, the key takeaway is to think carefully before using consumer AI tools for anything involving protected health information.
Personalise this feed
Your specialty. Your sources. Your digest.
All set up in under 2 minutes.
Personalise this feed
Your specialty. Your sources. Your digest.
All set up in under 2 minutes.