Should I put that in Chat GPT?
You are writing a report and decide to ask an AI tool to help you improve the wording. You remove the client’s name, paste in a section of the report and press enter.
No name = no problem, right? Unfortunately, it is not that simple.
A person’s full name is not the only thing that needs to be removed in order to de-identify some-ones health information. A combination of age, diagnosis, location, family circumstances, service provider, unusual behaviour or a particular incident may be enough to identify someone, even without their name. In a small community or group of people like those supported by disability services, health clinics or specialist health practices, surprisingly few details may be required before everyone knows exactly who is being discussed.
There is now a significant amount of research examining generative AI in medical practice, and we have only scrapped the surface in how we can use AI in health. Health assistants that can provide patient specific advice, improved diagnostics, new drugs, better clinical decision making are some of the areas that are being explored by AI health companies. But most health practitioners that I know are just amazed at how our lives have been changed by being able to use AI generated session summaries / transcripts as progress notes!! Research on the use of AI in health is also identifying high level risks involving data storage, unclear secondary uses, cyberattacks, re-identification and unintended disclosure of sensitive information. These risks require technical safeguards and organisational controls, not simply reliance on an individual practitioner’s judgement (Chen & Esmaeilzadeh, 2024)
Let’s have a look at what your professional and ethical responsibilities are when it comes to using AI in your work and how you can mitigate some of them.
Firstly, the free version of AI apps and the business version of AI apps are (usually) not the same thing
A publicly available and often free versions of AI based products and an paid version operating within a businesses approved digital environment can have very different privacy, contractual and security arrangements. This means just because your workplace uses co-pilot, chatGPT, Claude or a transcription software within their IT environment at work, you should not assume that these programs are safe to use on your home computer as a personal account. Just be aware that paying for a tool does not automatically make it suitable for use with health information. Similarly, seeing words such as ‘secure’, ‘encrypted’ or ‘enterprise-grade’ on a sales page does not establish compliance with privacy laws.
But I have de-identified the information?
Removing names is a useful step, but it does not necessarily de-identify information.
Information is only genuinely de-identified when there is no reasonable likelihood that the individual can be re-identified. The more detailed, unusual or context-specific the information, the greater the risk.
For example, “A 14-year-old NDIS participant with a diagnosis of autism spectrum disorder living in regional Victoria” may sound anonymous. Add a distinctive behaviour, a secondary rare condition, a recent school incident or a particular family arrangement, and the person could become readily identifiable to practitioners, school staff or community members.
What do professional bodies and the law say about using AI?
The Office of the Australian Information Commission (OAIC), recommends that organisations do not enter personal information, particularly sensitive information into publicly available generative AI tools because of the significant and complex privacy risks.
The Australian Privacy Act 1988 and associated Australian Privacy Principles (APP) regulate how health businesses handle personal information. They apply to ALL businesses who manage people’s health information, there are no small business exemptions! So if you are a sole practitioner with 3 clients, they still apply. The Australian Privacy Principles include requirements relating to the collection, use, disclosure, accuracy, security and cross-border handling of information. In addition to the Privacy Act, State and territory requirements may also apply. For example in Victoria, health information is regulated by the Health Records Act 2001 and its Health Privacy Principles. These address matters including collection, use and disclosure, data security and openness about information handling practices.
Most allied health professional bodies, AHPRA and the NDIS Commission and Aged Care Commission have all released position statements on the use of AI. In February 2026, the NDIS Quality and Safeguards Commission released a position statement on using AI in the development of behaviour support plans. It states that AI may assist with administrative elements, but must not replace the professional judgement, direct engagement, assessment and person-centred processes required of a behaviour support practitioner. The practitioner remains accountable for the plan, including its accuracy, quality and compliance. The Commission also warns against entering identifiable or sensitive participant information into publicly available AI tools. NDIS Commission position statement
This is important because a behaviour support plan may contain extraordinarily sensitive material: diagnoses, trauma histories, behaviours of concern, family relationships, risks, restrictive practices and information about other people.
Changing a name to “Participant A” does not make all of that information harmless.
What do all these principles mean practically?
The relevant question should not be “should I put this in ChatGPT”
The better questions are:
Am I authorised to disclose this information to ChatGPT?
Is using AI compatible with the reason I collected the information?
Where will the information be processed and stored?
Who can access it?
Is it retained or used to improve the algorithm?
Can it be deleted?
What does my agreement with ChatGPT actually guarantee?
Have I told clients how their information may be used?
Is consent required?
Has my organisation completed a risk assessment and formally approved this use? A practical traffic-light approach
Until your organisation has properly assessed and approved its tools, consider the following starting point.
Green—generally lower risk
Creating agendas
Brainstorming training topics
Improving generic website content
Developing fictional case studies
Creating procedure structures without operational or client details
Amber—requires organisational assessment
Analysing internal business information
Transcribing meetings
Summarising organisational documents
Using integrated AI within email or client-management systems
Drafting content based on sufficiently de-identified scenarios
Red—do not enter into an unapproved public AI tool
Client names or contact details
Progress notes
Reports and assessments
Medical or diagnostic information
Behaviour support plans
Session recordings or transcripts
Information that could reasonably identify a person
AI can absolutely have a place in healthcare. The aim is not to frighten practitioners away from it. The aim is to replace guesswork with informed, confident decision-making.
If you find yourself hovering over the enter button and wondering whether the information is safe, pause. That moment of hesitation is not evidence that you are bad at technology.
It is evidence that your organisation needs a clearer system for deciding what tools can be used, for what purpose and with what information.
References
Commonwealth of Australia. Privacy Act 1988.
Murdoch, B. (2024). Privacy and artificial intelligence: challenges for protecting health information in a new era. BMC Medical Ethics, 25.
NDIS Quality and Safeguards Commission (2026). Position statement: Use of artificial intelligence in the development of behaviour support plans.
Office of the Australian Information Commissioner (2025). Guidance on privacy and the use of commercially available AI products.
Victorian Government. Health Records Act 2001 (Vic).
General information only. Privacy and professional obligations vary according to the organisation, jurisdiction, profession, contract and intended AI use.