Does a small behavioral health practice need an AI policy?
It is easy to assume a written AI policy is a big-hospital problem, the kind of thing a compliance department writes and a practice with one therapist and a part-time biller can set aside for later. That assumption was reasonable a couple of years ago. It is not anymore.
What changed
The floor for AI oversight in healthcare has been written down. The Joint Commission, the accreditor most healthcare organizations answer to, now has a certification for responsible AI use, and it built the underlying guidance with the Coalition for Health AI, a group of more than 150 health systems. Their playbooks describe what responsible use looks like, and the short version is not complicated. A written policy, an inventory of which AI tools handle patient data, and a named person responsible for them.
None of the older rules went away either. HIPAA still applies to patient information you put into an AI tool, whatever the vendor's marketing says. Substance use records are held to a stricter standard, since 42 CFR Part 2 now has a federal enforcement program behind it for the first time in the rule's fifty year history. And states are starting to add their own requirements, mostly some version of telling patients when AI is involved in their care and keeping a record of what the tool does.
Put together, the expectation of a written policy is not coming. It is here, and a small organization using an AI scribe or a chatbot with nothing written down is behind a published standard.
Why small behavioral health orgs are the most exposed
Behavioral health organizations hold the most sensitive records in medicine. Therapy notes, treatment history, things a person has told no one else. The AI tools showing up in these practices sit right on top of that. An ambient scribe listens to a session and drafts the note, which means it is recording the most private conversation in the building, and the audio and drafts it produces are health records like any other. In addiction treatment they are often Part 2 records, where a wrong retention setting or a missing agreement with the vendor is the kind of thing the new enforcement program was built for. None of this is a reason to avoid the tools, it is a reason to write down how they are used.
The part people get wrong
I build platforms with these same AI tools, so I will say plainly that the risk is rarely the tool itself. It is using a capable tool with nobody deciding what it is allowed to do. A practice buys a scribe, a few people start using it, the settings are whatever the default was, and no one can say for certain where the recordings go or how long they stay there. That is not a technology failure. It is a missing decision, and a policy is just that decision written down.
The other common failure is organizations trying to sort this out entirely on their own, patching together rules from vendor PDFs and half-remembered training. That can hold for a while, but it usually leaves gaps that only show up when someone asks a hard question, and by then the fix costs far more time than getting it right once would have.
What actually goes in it
For a small provider, a workable AI policy fits on about two pages. It answers a handful of plain questions.
- Which AI tools are allowed, and which are not.
- What patient information each one is permitted to handle.
- Who checked the settings, and who is responsible for them.
- What clients are told, and when.
- How long anything the tool creates is kept, and where.
That is most of it. A signed agreement with each vendor that handles patient data, the retention and sharing settings actually checked rather than assumed, and a short consent script clients hear before a session is recorded. None of it requires new software. It asks you to decide, once, and write it down.
The point
An AI policy has stopped being paperwork for its own sake. It is the documented floor that accreditors and regulators will measure a practice against, and for a small organization it is a short document, not a project. I know the rules behind the paperwork, including 42 CFR Part 2, and Tinker Works saves small organizations time managing documentation, including the kind that keeps new tools on the right side of the rules. If you or someone you know is bringing AI into a small practice and nobody has written down how it is used, feel free to send them my way for a free quote.