
Artificial intelligence isn't coming to the workplace. It's already here.
Employees are using tools like ChatGPT, Microsoft Copilot, Google Gemini and other AI-powered applications to write emails, summarize information, create reports, brainstorm ideas, develop presentations and save time on routine administrative work.
For a Human Service Organization, that can be a very good thing.
AI has the potential to reduce paperwork, improve productivity and give case managers, social workers, clinicians and administrative staff more time to focus on the people they serve.
But there's a problem.
If your employees are using AI and your organization doesn't have an AI policy, every employee is essentially making up the rules for themselves.
And when your organization deals with confidential client information, Protected Health Information (PHI), personnel records, financial information and other sensitive data, that's a risk you don't want to ignore.
"We Don't Use AI" Probably Isn't an AI Policy
We've heard similar statements before with other technologies:
"Our employees don't use personal cloud storage."
"Nobody is accessing company email from their personal phone."
"Our employees wouldn't click on a suspicious link."
Then reality happens.
AI is no different.
An employee may copy a case note into a public AI tool and ask it to "clean this up."
Someone in HR may paste information from an employee evaluation into AI and ask for help rewriting it.
A manager may upload a spreadsheet and ask AI to identify trends.
A case manager may ask AI to summarize information about a client.
The employee may have absolutely no bad intentions. In fact, they're probably just trying to work faster.
The problem is that confidential information may now have been provided to a third-party system that your organization never reviewed or approved.
That's exactly why an AI policy is becoming an important part of an organization's overall technology, cybersecurity and compliance policies.
AI Can Be Extremely Useful — With Guardrails
The answer isn't necessarily to ban AI.
In many organizations, banning it completely may simply encourage employees to use it without telling anyone.
A better approach is to establish clear rules about which AI tools employees may use, what information can be entered into them and what employees are responsible for reviewing before AI-generated content is used.
That's especially important because AI-generated information can sound extremely confident while still being incomplete, biased or simply wrong.
NIST's Generative AI Risk Management Profile recommends that organizations actively identify and manage risks associated with generative AI rather than treating AI as just another software application.
Human oversight should therefore be one of the most important parts of your policy.
AI can assist a staff member.
AI should not replace the staff member's professional judgment.
Confidential Information Is One of the Biggest Concerns
For Human Service Organizations, this issue deserves special attention.
Depending on the services your organization provides, employees may have access to:
- Client names and contact information
- Medical and behavioral health information
- Case notes
- Treatment plans
- Social Security numbers
- Medicaid or insurance information
- Employee personnel records
- Payroll information
- Financial information
- Passwords and security information
- Internal business documents
Employees need to understand that copying information into an AI system is still sharing information with another system or provider.
For organizations regulated by HIPAA, the situation becomes even more important. HHS guidance makes clear that when a third-party cloud provider creates, receives, maintains or transmits electronic PHI on behalf of a regulated organization, HIPAA requirements—including appropriate business associate arrangements where applicable—must be considered.
In other words:
Don't assume an AI application is safe for client information simply because it's popular, because you have a paid account, or because another organization is using it.
Have your technology, security and compliance people review it first.
Your AI Policy Doesn't Need to Be 50 Pages Long
The most useful policy is one your employees can actually understand.
At a minimum, your Human Service Organization should clearly address:
- Approved AI tools. Tell employees which AI applications are approved for company use. Don't make employees guess.
- Information that must NEVER be entered into an unapproved AI system. This should include PHI, Personally Identifiable Information (PII), passwords, client records, employee information, confidential business information and other sensitive data.
- Human review of AI-generated work. Employees remain responsible for checking accuracy, appropriateness and completeness before using AI-generated material.
- AI and client decisions. AI should not independently make clinical, eligibility, disciplinary, employment, treatment or other high-impact decisions about people.
- Fact-checking. AI can produce inaccurate information, fabricated references and other errors. Employees must verify important information using authoritative sources.
- Vendor approval. New AI products and AI features should be reviewed by IT/security before employees begin using them for agency business.
- Reporting mistakes. Employees should know exactly who to contact if confidential information is accidentally entered into an unapproved AI system.
- Training. An AI policy won't accomplish much if employees don't understand it. Include AI awareness in regular security and compliance training.
Don't Forget About AI That's Hiding Inside Software You Already Own
There's another challenge organizations need to consider.
AI isn't limited to ChatGPT.
AI capabilities are rapidly being built into productivity software, browsers, meeting applications, email systems, search products, CRMs, electronic health records and other applications.
That means an organization should maintain an inventory of approved AI capabilities—not simply a list of AI websites employees aren't allowed to visit.
This is also why AI governance shouldn't be viewed as a one-time project.
Technology changes. Vendors change. Features change. Regulations change.
Your policy needs to change with them.
Start With a Risk Assessment
Before establishing your policy, ask a few basic questions:
What AI tools are employees currently using?
You may be surprised by the answer.
Then determine:
- What information employees are putting into those systems.
- Which AI tools have been formally approved.
- Whether those vendors have appropriate security and privacy protections.
- Which business processes could benefit from AI.
- Which activities should require additional human review.
- Which activities should be completely prohibited.
For organizations subject to HIPAA, risk analysis is already a foundational component of protecting electronic PHI. HHS guidance emphasizes identifying where ePHI is created, received, maintained or transmitted, identifying threats and vulnerabilities, and implementing appropriate safeguards.
AI should become part of that conversation.
AI Isn't the Problem. Unmanaged AI Is.
There are tremendous opportunities for Human Service Organizations to use AI.
Imagine reducing the amount of time employees spend drafting routine correspondence, organizing information, creating training materials, preparing meeting agendas or completing other administrative tasks.
That means less paperwork and more time available for your organization's real mission: helping people.
But there's a big difference between adopting AI and simply allowing AI to happen.
Organizations that establish reasonable policies, train their employees and carefully evaluate the AI tools they use will be in a much better position to take advantage of the productivity benefits while reducing unnecessary security, privacy and compliance risks.
If your organization doesn't currently have an AI policy, now is the time to create one.
Because whether you have an AI strategy or not, there's a good chance some of your employees already do.
Need Help Creating an AI Strategy for Your Human Service Organization?
At Willetts Tech, we specialize in helping Human Service Organizations use technology more effectively while protecting the information and systems they depend on.
We can help your organization evaluate AI tools, identify security and privacy concerns, establish appropriate technology safeguards and develop a practical approach to introducing AI into your workplace.
The goal isn't technology for technology's sake. It's using technology to help your staff work more efficiently so they can spend more time helping the people you serve.
Contact Willetts Tech to start the conversation.
Need help creating an AI Use Policy for your organization? The AI Use Policy Builder makes it easy to create a customized, ready-to-review policy in just a few steps. Simply answer a series of questions about approved AI tools, prohibited uses, and high-risk activities, then download your completed policy as a Word document or PDF. Best of all, everything you enter stays in your browser and is not uploaded or sent anywhere. Try the AI Use Policy Builder:



