How to safely use AI at Behavioral Framework

Safe Use of Artificial Intelligence (AI) Tools

Knowledge Base Article  |  Behavioral Framework  |  IT & Security

Effective Date: June 2026  |  Policy Owner: IT & Security  |  Audience: All Staff

 

Section 1: Overview

AI tools help us work smarter, but they require care — especially in a behavioral health environment where we handle sensitive client information. This policy explains what’s safe to share, what to avoid, and how to stay protected.

 

One of the most important things to understand: not all AI tools are equal under HIPAA. Some of our tools have a Business Associate Agreement (BAA) — a legal contract that makes the vendor responsible for protecting health information. Others do not. This makes a significant difference in what you’re allowed to do with each tool.

 

Section 2: Understanding BAAs — Why It Matters

What is a BAA?

A Business Associate Agreement (BAA) is a required contract under the Health Insurance Portability and Accountability Act (HIPAA). When a company we use signs a BAA with us, they are legally obligated to protect client health information and are liable if they mishandle it.

 

Without a BAA: sharing client information with that tool is a HIPAA violation — even accidentally.

With a BAA: the tool is HIPAA-covered, but you must still use it carefully and only share what’s necessary.

 

Section 3: Our Tools and Their HIPAA Status

The table below summarizes which tools are covered under a Business Associate Agreement (BAA) and whether PHI may be used in each.

 

Tool

BAA in Place?

HIPAA-Covered?

PHI Allowed?

Google Workspace & Gemini

YES

YES

With caution — only when necessary

Claude (claude.ai)

YES

YES

With caution — only when necessary

Microsoft 365 & Copilot

YES

YES

With caution — only when necessary

ChatGPT (OpenAI)

NO

NO

NEVER — HIPAA violation

Monday.com

NO

NO

NEVER — HIPAA violation

Asana

NO

NO

NEVER — HIPAA violation

 

Google Gemini (gemini.google.com) — BAA: In Place

Google’s AI assistant, also embedded in Gmail ("Help me write"), Google Docs, Sheets, and Slides. Because Behavioral Framework has a BAA with Google Workspace, Gemini is HIPAA-covered. This does not mean you should freely enter PHI — it means the platform meets the minimum legal requirement. Always ask: "Is sharing this information necessary to do my job right now?"

 

ChatGPT (chatgpt.com) — BAA: NOT IN PLACE — HIGH RISK

OpenAI’s standalone AI assistant. Behavioral Framework does NOT have a BAA with OpenAI. Entering any client information, diagnoses, case details, or other PHI into ChatGPT is a HIPAA violation. This applies even if you are using a personal account, even on a personal device, and even if you think the information is "de-identified." Do not use ChatGPT for any work that touches client information.

 

Claude (claude.ai) — BAA: In Place

Anthropic’s AI assistant, used for writing, analysis, and document tasks. Behavioral Framework has a BAA with Anthropic. Claude is HIPAA-covered for organizational use. Still: only share PHI when it’s necessary for the task, and do not share more than required.

 

Microsoft Copilot — BAA: In Place

Built into Microsoft 365: Word, Excel, PowerPoint, Outlook, and Teams. Behavioral Framework has a BAA with Microsoft. Copilot within your managed Microsoft 365 account is HIPAA-covered.

 

Note: Copilot.microsoft.com accessed outside of your work Microsoft 365 account may NOT carry the same BAA protections — always use Copilot from within your Microsoft 365 apps, not from a personal browser session.

 

Monday.com AI — BAA: NOT IN PLACE — HIGH RISK

Monday.com has built-in AI features for task summaries, updates, and project descriptions. Behavioral Framework does NOT have a BAA with Monday.com. Do not enter client names, case details, diagnoses, or any PHI into Monday.com — including in task names, notes, updates, or AI-generated summaries. Monday.com may be used for general project management, staffing coordination, and internal workflows that do not involve client PHI.

 

Asana AI — BAA: NOT IN PLACE — HIGH RISK

Asana has built-in AI for task drafting, project summaries, and smart fields. Behavioral Framework does NOT have a BAA with Asana. Same rule applies: no PHI in Asana under any circumstances.

 

Gmail Confidential Mode

Not an AI tool, but a privacy feature covered in a separate guide. When communicating via email about anything sensitive, use Confidential Mode. See "How to Send an Encrypted Email in Gmail" for step-by-step instructions.

 


 

Section 4: What Is PHI and PII — and Why It Matters

PHI (Protected Health Information): Any information that could identify someone’s health condition, treatment, diagnosis, or services.

       Client names paired with diagnoses

       Session notes

       Treatment dates

       Insurance info

       Medical record numbers

       Referral information

 

PII (Personally Identifiable Information): Any information that could identify a specific person.

       Full name + address

       Social Security Numbers

       Date of birth

       Phone numbers

       Email addresses

       Financial account numbers

 

Why it matters: We work in a behavioral health environment. HIPAA requires us to protect client health information. Violations can result in fines of up to $50,000 per incident and serious damage to client trust.

 

Section 5: What You Should Never Enter Into AI Tools

WARNING: NEVER ENTER THE FOLLOWING INTO AI TOOLS

For ALL tools (including those with BAAs):

       Client names, initials, or any identifying information (unless absolutely required by your job function)

       Social Security Numbers, dates of birth, insurance IDs

       Passwords, access credentials, or security codes

       Confidential contracts or legal documents not approved for sharing

       Employee personal information without HR approval

 

For tools WITHOUT a BAA (ChatGPT, Monday.com, Asana) — additionally prohibited:

       Any case or project information that could be linked to a client

       Any diagnosis, condition, or treatment reference

       Any internal information about client services or outcomes

       Internal financial data or payroll

 

Section 6: What Is Generally Safe

Safe for all tools (always verify no PHI is included):

       Drafting professional emails without client details

       Creating meeting agendas or project summaries using only generic descriptions

       Writing or editing internal policies and procedures

       Brainstorming ideas for projects or presentations

       Formatting documents or spreadsheets with no sensitive data

       Generating templates and forms with placeholder/example data

 


 

Section 7: Tool-by-Tool Quick Reference

Use this table as a quick guide for each tool. Text in red/bold indicates high-risk zones.

 

Tool

BAA?

Common AI Features

Safe Use

Never Use

Google Gemini

BAA

Writing help, email drafting, doc summaries

Templates, general writing, internal comms

PHI beyond what's necessary, passwords

ChatGPT

NO BAA

Q&A, writing, research

General non-client research and writing

ALL client info, ANY PHI or PII, internal financial/HR data

Claude

BAA

Writing, analysis, document drafting

Policy writing, templates, general analysis

PHI beyond what's necessary, passwords

Microsoft Copilot

BAA

Draft/summarize emails, analyze data, create slides

Internal formatting, agendas, reports

Client data in non-M365 Copilot sessions

Monday.com AI

NO BAA

Task summaries, update drafts

Generic project tasks (no client info)

Client names, case details, ANY PHI or PII

Asana AI

NO BAA

Task drafting, project summaries

Generic project tracking (no client info)

ANY PHI or PII, client identifiers

 

Section 8: Tips for Using AI Safely

       Always re-read AI-generated content before sending — AI can make mistakes

       Never copy and paste session notes or client files into any AI tool

       If you’re unsure whether something is safe to share, don’t share it — ask IT

       For ChatGPT, Monday.com, and Asana: when in doubt, leave it out

       Disable chat history in ChatGPT when working on anything sensitive (Settings > Data Controls > Improve the model for everyone — turn off). Note: this does not make ChatGPT HIPAA-compliant — it just reduces your exposure.

       Only use Microsoft Copilot from within your work Microsoft 365 account, not from a personal browser

       Treat AI tools without BAAs like a public whiteboard: don’t write anything on them you wouldn’t want anyone to see

       Log out of personal AI accounts on work devices

 

Section 9: What to Do If Something Goes Wrong

If you accidentally share PHI/PII with an AI tool — especially one without a BAA:

 

1.     Stop the conversation immediately — do not continue

2.     Screenshot or note what was shared (for your incident report)

3.     Report to IT within 24 hours — this may trigger a required HIPAA breach assessment

4.     Submit a ticket at https://help.behavioralframework.com

 

Important

Early reporting is essential. Sharing PHI with a non-BAA vendor like ChatGPT, Monday.com, or Asana may constitute a reportable HIPAA breach. The sooner IT is notified, the better we can respond. There is no penalty for reporting an honest mistake — but there are serious consequences for not reporting.

 

Section 10: Need Help?

Questions about AI tools or data security? Our IT team is here to help. Submit a ticket at https://help.behavioralframework.com or reach out to your manager.

 

Behavioral Framework — IT & Security  |  Confidential  |  Do Not Distribute

Did this answer your question? Thanks for the feedback There was a problem submitting your feedback. Please try again later.

Still need help? Contact Us Contact Us