Can Front Desk Staff Use AI to Write Patient Emails?
Somebody at your front desk has already tried it. A recall letter that needed rewording, a difficult email to a patient about a balance, an insurance explanation that had to be said three different ways. It saved twenty minutes and nobody mentioned it.
Can front desk staff use AI to write patient emails?
For administrative writing, yes — but only on a practice account with a vendor agreement in place, and never with anything that identifies the patient or strays into clinical advice. On a personal ChatGPT account with a patient’s name in the prompt, that is a disclosure of protected health information to a third party.
The line that actually matters
It is not AI or no AI. It is identifiable or not, and administrative or clinical. Those two questions settle almost every real case.
Reasonably safe
“Rewrite this appointment reminder to be warmer and shorter.” “Draft a template explaining our late-cancellation policy.” “Give me three ways to phrase a request for updated insurance information.” No patient in the prompt, no clinical content, and a human sends the final version.
Not safe
Anything with a name, date of birth, account number, appointment date tied to a person, diagnosis, or medication. Pasting an inbound patient email in to get help replying — that email is the PHI. Asking the tool what a symptom might mean, which quietly turns a receptionist into someone giving clinical guidance.
The grey area, handled honestly
Stripping the name out of an otherwise detailed message is better than not doing it, and it is not the same as de-identification. If the remaining details would let someone work out who it is, treat it as identifiable.
The account is the whole thing
The same tool behaves completely differently depending on how it was signed into. A personal sign-up gives the practice no oversight, no retention terms in its favour, and no agreement covering patient information. A business tier with a signed vendor agreement gives you data-handling terms, administrative control and inputs excluded from training.
Any vendor whose product touches patient information is a business associate, and the agreement should be signed before anything touches your systems — not after. That single requirement rules out most consumer AI accounts for anything patient-related, and it is the cleanest test to apply.
What we find when we look
Two things, almost every time.
Nobody has said what is allowed. Staff are not being reckless; they are filling a silence. Practices that write one page and approve one tool see the behaviour change immediately, because most people want to do the right thing and simply do not know where the line is.
Something is already connected that nobody remembers approving. An assistant that reads the inbox where referrals arrive, a note-taker that joined a call once, an automation moving documents. These hold standing access, granted by one click, with no expiry and no alert. When we audited our own tenant we found ChatGPT able to read every file we owned. That story is here.
Four things to do this month
- Approve one tool on a practice account, with the vendor agreement signed. Then remove the others rather than leaving them connected.
- Write the one-page rule. What may never go in a prompt, who to ask, and that a human reviews anything a patient will read. Our template is free.
- Say the clinical boundary out loud. Front desk staff are not clinicians and the tool must not blur that. It is worth a sentence in the policy and a sentence in a team meeting.
- Check what already has access to the mailbox where patient information arrives. This is the step almost everyone skips.
A note on note-takers
If an AI assistant is joining calls, that is a separate problem with a state statute attached — Florida requires consent from every participant and a violation is a third-degree felony, entirely apart from HIPAA. We covered that here.
We are a small IT company in Haines City that supports practices across Polk and Osceola. If it would help to have someone tell you plainly what currently has access to your patient data, we will look for nothing — and if it comes back clean, we will say so.
Related: a medical practice offboarding checklist. General information, not legal advice.
More on using AI without creating a problem
- Can employees use ChatGPT with company data?
- Is it legal to use an AI note-taker in Florida?
- Does AI on client tax data trigger section 7216?
- Can a law firm use ChatGPT without breaching confidentiality?
- Does AI estimating actually work for a contractor?
The practical starting point: a free one-page AI acceptable use policy you can copy and issue this week, and how we approach AI consulting.