CommercialAdministrativeMedium impact
[Ohio] Using AI responsibly to protect patient privacy
Anthem BCBS·OH·Provider Bulletin
Effective date
Mar 23, 2026
We identified it
May 3, 2026
Summary
Anthem Blue Cross and Blue Shield Ohio issued guidance on responsible AI use to protect patient privacy. Billing and clinical staff must not enter, upload, or paste protected health information (PHI) or personally identifiable information (PII) into unapproved AI tools (including public tools like ChatGPT), and must not assume non-approved tools are HIPAA-compliant or rely solely on AI for clinical decisions. This is an informational policy reinforcing existing privacy compliance obligations across all plan types in Ohio.
Action Required
By April 2026 (publication date): All billing team staff and providers must receive training on this AI privacy policy. Specifically: (1) Billing team must NOT input, paste, or upload any patient PHI or PII (names, medical record numbers, dates of birth, claim details, etc.) into ChatGPT, public AI tools, or any non-approved AI platforms; (2) Providers must not rely on unapproved AI tools for clinical decision-making or patient-specific conclusions; (3) Staff should consult organizational policies and IT/compliance leadership before using any new AI tool; (4) Document this training completion in staff files. Consequences of non-compliance include potential HIPAA violations, privacy breaches, regulatory fines, and loss of patient trust. Reference the full policy at https://providernews.anthem.com/ohio/articles/using-ai-responsibly-to-protect-patient-privacy-29258 during training.