Can a clinic let an AI assistant near patient data?
The question every clinic asks first, and the one most vendors answer too confidently. The honest answer has a shape: some of a patient's message can be masked automatically, some cannot, and the difference decides what you are allowed to put the assistant in front of.
What is masked before anything leaves, and what is not
Structured identifiers are replaced with tokens at intake, before any model is called: national ID numbers, telephone numbers, card numbers, medical record numbers. The originals are held encrypted and the replacement is reversible by the clinic, so staff still see the real values. Names written in free text are NOT detected automatically. That is a real limit, not a footnote: a message saying "my mother Sarah has chest pain" carries a name through.
Where the data goes, and how to ask about it
Processing involves sub-processors, and the only honest things to say are which categories of them there are, that they are bound by data-processing agreements, and that a specific hosting jurisdiction can be agreed per clinic on request. A vendor who answers "your data never leaves" is either not using a model at all or is not telling you the truth. Ask for the sub-processor list, not a reassurance.
The safety that matters most is refusal, not encryption
Encryption protects the message in transit and at rest. It does nothing about the real clinical risk, which is an assistant that answers a question it should have escalated. Emergency symptoms, whether a treatment suits a particular patient, dosage, and anything about a named colleague or another patient must be refused and routed to a person. A clinic should require that behaviour in writing and test it before going live.
Three questions worth more than any certificate
What exactly is masked, and what is not. Which sub-processors receive the text, and under what agreement. What the assistant does when it does not know - verbatim, with an example. A vendor who answers all three plainly is telling you how it fails, and that is the only information a clinic can act on.
Frequently asked questions
Is it safe to let an AI assistant handle patient messages?
What patient information is masked before the model sees it?
Does patient data leave the clinic?
Can the assistant give medical advice if we configure it to?
What should we ask a vendor before signing?
Get in touch
Leave your details and we will reply. You do not need a sales call to get an answer.