A clinic manager told us she had set up a new AI scheduling tool over a weekend. It was cheap, it worked, and by Monday it was answering after hours calls and booking patients. We asked one question: did the vendor sign a business associate agreement? Silence. She had uploaded a spreadsheet of two thousand patients, names, phone numbers and appointment reasons, into a tool she found in an ad, and nobody had checked where that data went or who could see it. The tool was great. The setup was a lawsuit waiting to happen.
This is the tension running through healthcare right now. Everyone wants the speed and savings AI brings to the front desk and to marketing. Almost nobody is asking the boring question underneath it: what happens to the patient data you just fed into it.
The news: executives are excited about AI and scared of what it opens up
In a recent MedCity News roundup, healthcare executives weighing in on AI readiness landed on the same theme over and over. They see the upside, but their number one concern is the growing risk of cybersecurity threats that come with rushing new tools into a practice. Capitol Weekly ran a parallel story this week on how the growing use of AI tools has some medical providers on edge, worried they are moving faster than their ability to keep patient information safe.
Both stories point at the same gap. Adoption is racing ahead of security. A tool gets added because it saves time on Monday, and the questions about data, access and compliance get pushed to a someday that never comes. In healthcare, someday tends to arrive as a breach notice.
Why healthcare is the biggest target on the internet
Patient records are worth more to criminals than credit cards, because you cannot cancel a diagnosis or reissue a date of birth. That is why healthcare keeps topping the charts for both the number and the cost of breaches. The IBM Cost of a Data Breach Report has put healthcare at the most expensive spot for well over a decade, and the 2024 Change Healthcare ransomware attack exposed data tied to an estimated 190 million people, one of the largest health breaches ever recorded.
It is not only the giants. Scroll the federal breach portal that the HHS Office for Civil Rights keeps, sometimes called the wall of shame, and you will find small clinics and single location practices listed right next to hospital systems. Attackers are not hunting for prestige. They are hunting for soft targets, and a busy practice that plugged patient data into an unvetted tool is exactly that.
The blind spot: your marketing and front desk touch patient data too
When practice owners think about data security, they picture the clinical records system. Fair enough. But the tools that keep collecting protected health information are often the ones nobody thinks of as clinical at all:
- The website intake form that captures a name, a phone number and what the visit is about.
- The chatbot that logs why a patient is reaching out at eleven at night.
- The AI phone assistant that records and transcribes every call.
- The patient list you upload to run a Meta or Google ad campaign.
- The review request tool that knows who came in and when.
Every one of those handles information that identifies a patient, which means every one of them falls under HIPAA. A marketing tool is not exempt because it is marketing. If it holds a patient's data, it needs the same care as anything in your records room. This is the part that trips up practices moving fast, and it is why we push clients to think about security before they think about features. We wrote a full checklist on this in what to check before you sign an AI vendor, because the excitement of a demo is exactly when people skip the questions that matter.
The five questions to ask before you plug anything in
You do not need to be a security engineer to protect your practice. You need to ask five plain questions and refuse to move forward until you get clear answers. If a vendor gets cagey on any of them, that is your answer.
1. Will you sign a business associate agreement?
This is the first filter and the fastest. Under HIPAA, any company that handles protected health information for you must sign a business associate agreement, a contract that legally binds them to protect the data and tell you if it is breached. A serious healthcare vendor has this ready and hands it over without drama. If a tool touches patient data and will not sign one, stop there. No signed agreement means the liability is entirely yours.
2. Where is the data stored, and is it encrypted?
Ask where patient information physically lives and whether it is encrypted both while it sits and while it moves. You want data kept in the United States, encrypted at rest and in transit. Vague answers about the cloud are not good enough. A vendor that takes security seriously can tell you exactly where your patients' data sits.
3. Do you use my patient data to train public AI models?
This is the new one, and it is the question most owners never think to ask. Some AI tools feed the data you put in back into public models. That means a patient's information could influence answers given to strangers, which is a nightmare in healthcare. You want a firm no: your patient data is used only to serve your practice and never to train a shared or public model.
4. Who can access the data, and is that access logged?
Find out who on the vendor's side can see patient records, and whether every look is logged. The right setup limits access to the few people who truly need it and keeps an audit trail of who touched what. If anyone at the company can browse your patient list and nothing gets recorded, the tool is a leak waiting to happen.
5. Can I export and permanently delete a patient's data?
Patients have the right to their records and, in many cases, to have data removed. Your tools need to honor that. Ask whether you can pull a full export and whether you can permanently delete a specific patient on request. A vendor that cannot delete data cleanly is a vendor that never designed for privacy in the first place.
A fast sniff test
Send those five questions in one email and watch how the vendor answers. A healthcare ready company replies with short, confident, specific answers and offers to send the paperwork. A risky one sends back a sales pitch, changes the subject, or promises to check with the team and goes silent. The way they answer tells you as much as the answers themselves.
Our honest opinion: adopt AI, just do not be reckless about it
We are a healthcare marketing agency that builds with AI every day, so we are not here to scare you off it. AI on the phones and in your booking flow is one of the biggest wins a practice can get right now. Turning it off because of security fear would be its own mistake, and your competitors who use it well will pull ahead. We have made the case for why AI belongs in a modern practice in what small practices should actually do about AI.
The point is not fear, it is discipline. The practices that win with AI are the ones that move fast on the tools and slow on the vetting. They ask the five questions, they get the agreement signed, and then they let the technology run. Speed and safety are not opposites here. Choosing a vendor that already did the security work simply means you get both. Skipping the questions is how a time saver turns into the most expensive weekend of your year.
There is a trust angle too. Patients are getting sharper about where their information goes, and a practice that can honestly say it protects their data has an edge. We dug into that in how transparency about AI builds patient trust. Security is not just a legal box. It is part of the reputation you are trying to grow.
How EtherealMinds handles patient data
When we build a patient acquisition system for a practice, security is part of the design, not a disclaimer at the bottom. We work inside signed business associate agreements, keep patient data in protected United States infrastructure, and build intake forms, booking flows and websites that collect only what they need and guard it properly. Our ad and social work follows the same rule, so your patient lists are never floating around in a tool that treats them carelessly.
The same holds for our AI receptionist. It answers your calls, books patients around the clock and captures where each one came from, and it does that inside a setup built for healthcare privacy from the start. You get the speed of AI on the front desk without gambling with the data your patients trusted you to hold.
So before you plug the next shiny tool into your practice, ask the five questions. Get the agreement signed. Then let the AI do its job. That is how you take the upside the whole industry is chasing without becoming the next line on a breach report.
Add AI to your practice without risking patient data
Book a free strategy call. We will show you where your current tools may be exposing patient information, and how to run AI on your phones, website and marketing inside a setup built for healthcare privacy. No jargon, no scare tactics, no pressure.
Book a free strategy call →