CommercialAdministrativeMedium impact
[California] Using AI responsibly to protect patient privacy
Anthem BCBS·CA·Provider Bulletin
Effective date
Mar 23, 2026
We identified it
May 3, 2026
Summary
Anthem Blue Cross issued administrative guidance on responsible AI use to protect patient privacy. Billing and clinical staff must not enter, upload, or share protected health information (PHI) or personally identifiable information (PII) into unapproved or public AI tools (such as ChatGPT), and must not assume non-approved tools are HIPAA-compliant. This is a policy reinforcement rather than a new billing or coverage change.
Action Required
By April 2026: All billing, clinical, and administrative staff must be trained on this AI privacy policy. Specifically: (1) Billing team must ensure no PHI/PII is entered into any unapproved AI tools when performing billing tasks, research, or documentation; (2) Providers and billing staff must review organizational policies on approved AI tools before using any AI for clinical decision support or billing automation; (3) Compliance/IT leadership should audit current AI tool usage to confirm no unapproved tools are being used with patient data; (4) Update staff onboarding and annual compliance training to include this guidance. Non-compliance could result in HIPAA violations, state privacy law violations (California-specific), and potential breach notification requirements.