How to safely use AI at Behavioral Framework
Safe Use of Artificial Intelligence (AI) Tools
Knowledge Base Article | Behavioral Framework | IT & Security
Effective Date: June 2026 | Policy Owner: IT & Security | Audience: All Staff
Section 1: Overview
AI tools help us work smarter, but they require care — especially in a behavioral health environment where we handle sensitive client information. This policy explains what’s safe to share, what to avoid, and how to stay protected.
One of the most important things to understand: not all AI tools are equal under HIPAA. Some of our tools have a Business Associate Agreement (BAA) — a legal contract that makes the vendor responsible for protecting health information. Others do not. This makes a significant difference in what you’re allowed to do with each tool.
Section 2: Understanding BAAs — Why It Matters
|
What is a BAA? A Business Associate Agreement (BAA) is a required contract under the Health Insurance Portability and Accountability Act (HIPAA). When a company we use signs a BAA with us, they are legally obligated to protect client health information and are liable if they mishandle it.
Without a BAA: sharing client information with that tool is a HIPAA violation — even accidentally. With a BAA: the tool is HIPAA-covered, but you must still use it carefully and only share what’s necessary. |
Section 3: Our Tools and Their HIPAA Status
The table below summarizes which tools are covered under a Business Associate Agreement (BAA) and whether PHI may be used in each.
|
Tool |
BAA in Place? |
HIPAA-Covered? |
PHI Allowed? |
|
Google Workspace & Gemini |
YES |
YES |
With caution — only when necessary |
|
Claude (claude.ai) |
YES |
YES |
With caution — only when necessary |
|
Microsoft 365 & Copilot |
YES |
YES |
With caution — only when necessary |
|
ChatGPT (OpenAI) |
NO |
NO |
NEVER — HIPAA violation |
|
Monday.com |
NO |
NO |
NEVER — HIPAA violation |
|
Asana |
NO |
NO |
NEVER — HIPAA violation |
Google Gemini (gemini.google.com) — BAA: In Place
Google’s AI assistant, also embedded in Gmail ("Help me write"), Google Docs, Sheets, and Slides. Because Behavioral Framework has a BAA with Google Workspace, Gemini is HIPAA-covered. This does not mean you should freely enter PHI — it means the platform meets the minimum legal requirement. Always ask: "Is sharing this information necessary to do my job right now?"
ChatGPT (chatgpt.com) — BAA: NOT IN PLACE — HIGH RISK
|
OpenAI’s standalone AI assistant. Behavioral Framework does NOT have a BAA with OpenAI. Entering any client information, diagnoses, case details, or other PHI into ChatGPT is a HIPAA violation. This applies even if you are using a personal account, even on a personal device, and even if you think the information is "de-identified." Do not use ChatGPT for any work that touches client information. |
Claude (claude.ai) — BAA: In Place
Anthropic’s AI assistant, used for writing, analysis, and document tasks. Behavioral Framework has a BAA with Anthropic. Claude is HIPAA-covered for organizational use. Still: only share PHI when it’s necessary for the task, and do not share more than required.
Microsoft Copilot — BAA: In Place
Built into Microsoft 365: Word, Excel, PowerPoint, Outlook, and Teams. Behavioral Framework has a BAA with Microsoft. Copilot within your managed Microsoft 365 account is HIPAA-covered.
Note: Copilot.microsoft.com accessed outside of your work Microsoft 365 account may NOT carry the same BAA protections — always use Copilot from within your Microsoft 365 apps, not from a personal browser session.
Monday.com AI — BAA: NOT IN PLACE — HIGH RISK
|
Monday.com has built-in AI features for task summaries, updates, and project descriptions. Behavioral Framework does NOT have a BAA with Monday.com. Do not enter client names, case details, diagnoses, or any PHI into Monday.com — including in task names, notes, updates, or AI-generated summaries. Monday.com may be used for general project management, staffing coordination, and internal workflows that do not involve client PHI. |
Asana AI — BAA: NOT IN PLACE — HIGH RISK
|
Asana has built-in AI for task drafting, project summaries, and smart fields. Behavioral Framework does NOT have a BAA with Asana. Same rule applies: no PHI in Asana under any circumstances. |
Gmail Confidential Mode
Not an AI tool, but a privacy feature covered in a separate guide. When communicating via email about anything sensitive, use Confidential Mode. See "How to Send an Encrypted Email in Gmail" for step-by-step instructions.
Section 4: What Is PHI and PII — and Why It Matters
PHI (Protected Health Information): Any information that could identify someone’s health condition, treatment, diagnosis, or services.
• Client names paired with diagnoses
• Session notes
• Treatment dates
• Insurance info
• Medical record numbers
• Referral information
PII (Personally Identifiable Information): Any information that could identify a specific person.
• Full name + address
• Social Security Numbers
• Date of birth
• Phone numbers
• Email addresses
• Financial account numbers
Why it matters: We work in a behavioral health environment. HIPAA requires us to protect client health information. Violations can result in fines of up to $50,000 per incident and serious damage to client trust.
Section 5: What You Should Never Enter Into AI Tools
|
WARNING: NEVER ENTER THE FOLLOWING INTO AI TOOLS For ALL tools (including those with BAAs): • Client names, initials, or any identifying information (unless absolutely required by your job function) • Social Security Numbers, dates of birth, insurance IDs • Passwords, access credentials, or security codes • Confidential contracts or legal documents not approved for sharing • Employee personal information without HR approval
For tools WITHOUT a BAA (ChatGPT, Monday.com, Asana) — additionally prohibited: • Any case or project information that could be linked to a client • Any diagnosis, condition, or treatment reference • Any internal information about client services or outcomes • Internal financial data or payroll |
Section 6: What Is Generally Safe
|
Safe for all tools (always verify no PHI is included): • Drafting professional emails without client details • Creating meeting agendas or project summaries using only generic descriptions • Writing or editing internal policies and procedures • Brainstorming ideas for projects or presentations • Formatting documents or spreadsheets with no sensitive data • Generating templates and forms with placeholder/example data |
Section 7: Tool-by-Tool Quick Reference
Use this table as a quick guide for each tool. Text in red/bold indicates high-risk zones.
|
Tool |
BAA? |
Common AI Features |
Safe Use |
Never Use |
|
Google Gemini |
BAA |
Writing help, email drafting, doc summaries |
Templates, general writing, internal comms |
PHI beyond what's necessary, passwords |
|
ChatGPT |
NO BAA |
Q&A, writing, research |
General non-client research and writing |
ALL client info, ANY PHI or PII, internal financial/HR data |
|
Claude |
BAA |
Writing, analysis, document drafting |
Policy writing, templates, general analysis |
PHI beyond what's necessary, passwords |
|
Microsoft Copilot |
BAA |
Draft/summarize emails, analyze data, create slides |
Internal formatting, agendas, reports |
Client data in non-M365 Copilot sessions |
|
Monday.com AI |
NO BAA |
Task summaries, update drafts |
Generic project tasks (no client info) |
Client names, case details, ANY PHI or PII |
|
Asana AI |
NO BAA |
Task drafting, project summaries |
Generic project tracking (no client info) |
ANY PHI or PII, client identifiers |
Section 8: Tips for Using AI Safely
• Always re-read AI-generated content before sending — AI can make mistakes
• Never copy and paste session notes or client files into any AI tool
• If you’re unsure whether something is safe to share, don’t share it — ask IT
• For ChatGPT, Monday.com, and Asana: when in doubt, leave it out
• Disable chat history in ChatGPT when working on anything sensitive (Settings > Data Controls > Improve the model for everyone — turn off). Note: this does not make ChatGPT HIPAA-compliant — it just reduces your exposure.
• Only use Microsoft Copilot from within your work Microsoft 365 account, not from a personal browser
• Treat AI tools without BAAs like a public whiteboard: don’t write anything on them you wouldn’t want anyone to see
• Log out of personal AI accounts on work devices
Section 9: What to Do If Something Goes Wrong
If you accidentally share PHI/PII with an AI tool — especially one without a BAA:
1. Stop the conversation immediately — do not continue
2. Screenshot or note what was shared (for your incident report)
3. Report to IT within 24 hours — this may trigger a required HIPAA breach assessment
4. Submit a ticket at https://help.behavioralframework.com
|
Important Early reporting is essential. Sharing PHI with a non-BAA vendor like ChatGPT, Monday.com, or Asana may constitute a reportable HIPAA breach. The sooner IT is notified, the better we can respond. There is no penalty for reporting an honest mistake — but there are serious consequences for not reporting. |
Section 10: Need Help?
Questions about AI tools or data security? Our IT team is here to help. Submit a ticket at https://help.behavioralframework.com or reach out to your manager.
Behavioral Framework — IT & Security | Confidential | Do Not Distribute