CommercialAdministrativeMedium impact
[New York] Using AI responsibly to protect patient privacy
Anthem BCBS·NY·Provider Bulletin
Effective date
Mar 23, 2026
We identified it
May 3, 2026
Summary
Anthem has issued guidance on responsible AI use to protect patient privacy across New York. The policy prohibits staff from entering, uploading, or pasting protected health information (PHI) or personally identifiable information (PII) into unapproved AI tools (including ChatGPT), and requires organizational governance and HIPAA compliance verification before using any AI tools for clinical or administrative purposes.
Action Required
By April 2026 (per publication date): All billing team staff must comply with this guidance immediately. (1) REQUIREMENTS: Prohibit entry of any patient PHI/PII into consumer AI tools like ChatGPT, Copilot, or other unapproved applications—this includes patient names, medical record numbers, diagnoses, procedure codes, and insurance information. (2) Verify with compliance/IT that any AI tools currently used in billing workflows are approved and HIPAA-compliant before continuing use. (3) Train all billing staff on what constitutes PHI/PII and update standard operating procedures to explicitly ban unapproved AI tool usage. (4) Do not rely on AI for final clinical decision-making or patient-specific conclusions—always verify AI outputs with qualified clinical staff. (5) Contact your organization's compliance officer or Anthem provider relations if questions arise. CONSEQUENCES: Unauthorized use of consumer AI tools with patient data may result in HIPAA violations, privacy breaches, regulatory penalties, and reputational damage to the practice.