Back to blog
Compliance··7 min read

Can Nursing Home Staff Use ChatGPT With Resident Data?

Consumer AI tiers carry no BAA, which makes pasting resident details into one a disclosure. What is actually allowed, what counts as identifiable in a small facility, and the one-page policy that fixes it.

The question usually arrives the same way. An administrator hears that someone on the floor has been using a chatbot to clean up charting notes, and nobody in the building can say whether that is a problem, a reportable breach, or fine. Meanwhile the staff member was trying to do a better job at 11pm with a phone in one hand.

Here is the straight version, with the parts that are settled separated from the parts that are a judgment call.

The short answer

Consumer AI tiers are not covered. The free, personal and small-team plans from the major assistants do not come with a business associate agreement, and vendors say so in their own documentation. Under HIPAA, putting protected health information into a service with no BAA in place is a disclosure to an uncovered third party. Intent does not change that, and neither does deleting the chat afterward.

Enterprise and healthcare-specific tiers are a different situation. Several vendors now offer plans that can be covered once your organization signs a BAA with them. The BAA is the thing that matters, not the brand name and not the model. A plan is covered when the agreement is executed, not when the sales page says HIPAA.

What actually counts as resident information

This is where facilities get caught, because the rule is broader than most people assume. It is not only the name and the diagnosis. The following are all identifiers under HIPAA and all of them show up in the kind of text someone would paste into a chatbot:

  • Name, room number, admission date, or discharge date.
  • Ages over 89, and any date more specific than a year for someone in that group.
  • A family member’s name or phone number appearing in a note.
  • Enough clinical detail that a person in your building could work out who it is, even with the name removed. In a 90-bed facility that threshold is much lower than in a hospital.

That last one is the reason “I took the name out” is not a reliable defense in long-term care specifically. Small populations re-identify easily.

What is genuinely allowed

Plenty, and it is worth saying clearly, because a policy that reads as “no AI ever” gets ignored rather than followed. With no resident information involved at all, staff can reasonably use a general assistant to:

  • Draft a staffing memo, a family newsletter, or a job posting.
  • Rewrite a policy paragraph for readability, using no real resident examples.
  • Ask general clinical or regulatory questions with no case attached, the same way they would search the web.
  • Build a training outline or an in-service agenda.

The line is the data, not the tool. That framing is easier for a floor nurse to remember than a list of approved products.

What to actually do about it

In order, because the order matters more than the individual steps:

  • Find out what is already happening. Ask, without a disciplinary frame. People will tell you if the question is not a trap, and the answer is almost never zero.
  • Write one page. What is allowed, what is not, which tool is approved, and who to ask. One page that people read beats a policy binder nobody opens.
  • Give them somewhere to go. A prohibition with no approved alternative pushes the behavior onto personal phones where you cannot see it. Decide on one covered tool, or decide there is none yet and say that plainly.
  • Get it into the annual signature cycle. Acceptable use, reviewed and signed, alongside the policies you already run. That is the artifact a reviewer or a board asks for.
  • Add the vendor to the BAA register. If you do sign an enterprise agreement, it belongs on the same list as the pharmacy and the billing service, with a renewal date.

Where we sit on this

Disclosure, since it is relevant: our own support platform is built BAA-gated. Healthcare customers accept a business associate agreement before they can purchase, and the AI routing behind it was chosen so that covered-entity traffic stays inside agreements we have signed rather than a general consumer endpoint. We mention it because most people selling AI governance right now have a slide deck, and you are entitled to ask what the vendor did with their own system before taking their advice about yours.

None of that is a certification. HIPAA has no certifying body for vendors, and anyone telling you they are HIPAA-certified is telling you something that does not exist. What can exist is evidence: a signed agreement, a written policy, a risk analysis with dates on it, and an access review someone actually performed.

If you want that evidence assembled for your building, the senior care page covers how the assessment ladder works, and the compliance page covers what a Security Risk Analysis actually contains. If you only take one thing from this article, take the one-page policy. It is free, it takes an afternoon, and it is the difference between a finding and a conversation.

Back to all posts

Need IT help now?

Don't wait for a blog post to solve your problem. Get AI support or connect with a background-checked Utah technician.

Try the AI free