Part 1 | Meeting generative AI
Chapter 6. How to think about personal information and security
Key points
- Anonymise personal information before entering it
- Some services offer a setting that keeps your input out of training
- "It looks risky, so I will never use it" is itself a long-term risk
The worry is entirely reasonable
Everyone using AI wonders about
- how personal information is handled
- whether input is used for training
- how data from the hospital or facility is treated
Healthcare, long-term care and welfare are fields with a high duty of confidentiality, so this is a healthy concern.
The minimum rules
In practice, take the following care:
- do not use real names (Mr A, Ms B, patient X)
- do not name the hospital or facility
- do not write addresses, phone numbers or identifying IDs
- do not casually upload photographs of faces or clinical imaging
- do not paste in confidential internal documents (unpublished material, contracts) as they are
This is less a special "rule for using AI" than the same instinct you would apply to social media or an external email.
Use the settings that keep your input out of training
Most generative AI services provide some of:
- a setting that keeps history out of training
- a privacy mode
- temporary chat
- limits on data retention
- business plans where non-use for training is contractually explicit
If it concerns you, start here:
- turn off "use my data for training" in your account settings
- do important work in temporary chat mode
- for organisational use, look at business or API plans
Never using it is also a risk
The choice of
"it looks risky, so I will never use it"
may itself carry risk from here. The productivity gap between colleagues, other facilities and other professions who do use it could widen considerably over a few years.
Start touching it in the areas that contain no personal information at all:
- personal use
- study
- organising your own information
- looking up general information
That is a realistic distance to keep.
A checklist for the breath before you press send
- No real names, addresses, phone numbers or IDs?
- No hospital or facility name slipped into the text?
- Not pasting an unpublished internal document wholesale?
- Have I asked myself: would I be comfortable handing this to a third party?
- If needed, am I in temporary chat or with training turned off?
Saving this checklist as your own first message in ChatGPT is a good habit.
A prompt to try
In the case note below, replace every piece of personal information, and anything that could identify an individual, with a mask (◯◯). Keep the medical content, the course of events and the meaning of the assessments intact as far as possible.
[Case note] (paste the text you want anonymised here)
Generative AI works well as an anonymisation assistant like this.
Chapter 6 summary
- Anonymise personal information and facility names before entering them
- Use training-off settings, temporary chat and business plans as appropriate
- Never using it is also a risk over the medium term; start where it is safe