Medicare AdvantageAdministrativeMedium impact
[Virginia] Using AI responsibly to protect patient privacy
Anthem BCBS·VA·Provider Bulletin
Effective date
Mar 23, 2026
We identified it
May 3, 2026
Summary
This is a provider guidance bulletin on responsible AI use to protect patient privacy, effective March 23, 2026. Providers and billing staff must not enter, upload, or share protected health information (PHI) or personally identifiable information (PII) into unapproved AI tools (including ChatGPT) as this violates privacy laws and HIPAA regulations. The policy applies to Anthem plans in Virginia and requires adherence to organizational AI governance policies.
Action Required
By March 23, 2026: All billing team members and clinical staff must review and acknowledge this policy. Specific actions: (1) Do NOT enter, paste, or upload any PHI or PII into public or unapproved AI tools such as ChatGPT; (2) Verify that any AI tools used in your practice are approved by your organization and confirmed HIPAA-compliant before use; (3) Never rely solely on AI for clinical decision-making or patient-specific conclusions; (4) Refer all questions about approved AI tools to your compliance or IT department and subject matter experts. Update staff training materials and conduct team training sessions. Document staff completion of this training. Non-compliance risks HIPAA violations, regulatory fines, and breach notifications. This applies to all staff handling patient information at the practice.