Clinic owners, medical directors, and privacy officers in Ontario

Our clinic approved an AI scribe. Can clinicians still paste notes into ChatGPT?

Sources verified Sanitized Ai Team

The short answer

Approval attaches to a tool, not to the patient data. An AI scribe chosen through Ontario's AI Scribe Program comes with vetting, contract terms and a privacy assessment; a personal ChatGPT account comes with none of those, so pasting identifiable patient notes into it can be an unauthorized disclosure under PHIPA. Close the gap by giving clinicians a sanctioned way to draft letters and summaries, and by catching identifiable data before it reaches unapproved tools.

The situation

A family health team in Ontario did everything by the book. It picked an AI scribe from the provincial vendor list, completed a privacy assessment, updated its consent script, and trained physicians and nurse practitioners. The scribe now drafts the visit note, and charting time has dropped.

Then the rest of the day happens. A physician needs a referral letter to a cardiologist, a plain-language summary for a patient who struggles with English, and a narrative for an insurer's disability form. The scribe either does not produce those documents or produces them in a format that needs heavy editing. So she copies the finished note, opens ChatGPT in a personal account, and asks for a letter. The approved tool covered the encounter. An unapproved tool covered everything after it.

This is the gap: clinics have approved one AI workflow, and staff reasonably conclude that AI is now allowed. The patient data does not know which tool it is in.

What the rules actually say

The scribe program vets tools, not behaviour

The Ontario AI Scribe Program was set up by the Ministry of Health and Ontario Health with Supply Ontario and OntarioMD. According to OntarioMD's program FAQ, the vendor-of-record list was published on June 3, 2025; vendors were evaluated against provincial clinical, privacy and security requirements; they must undergo regular independent threat risk assessments; and they are prohibited from storing or using patient data beyond providing scribe services. Supply Ontario describes the same arrangement. None of that vetting extends to a chatbot account a clinician opens on their own.

The CPSO: no AI-specific rule, same obligations

The CPSO's Advice to the Profession on using AI in clinical practice (last updated August 2025) is advice, not a binding policy. It notes that no specific law or policy currently addresses AI and that physicians' core expectations are unchanged. It says patient data entered into AI applications must be kept private and secure, that physicians should consider how data will be transferred, stored and used and whether reasonable safeguards exist, and that physicians remain accountable for AI output, including documentation. It does not endorse specific tools; it points to the provincial scribe program and Canada Health Infoway's program.

PHIPA: the custodian's duties

Under PHIPA, a health information custodian:

  • must not collect, use or disclose personal health information without consent unless the Act permits it (s. 29), and must not use more than is reasonably necessary (s. 30);
  • must take reasonable steps to protect that information against theft, loss and unauthorized use or disclosure (s. 12(1));
  • must notify the individual at the first reasonable opportunity if it is used or disclosed without authority (s. 12(2)), and notify the Commissioner where prescribed circumstances apply (s. 12(3));
  • remains responsible for information handled by its agents, including staff, and must take reasonable steps to keep them within the Act (s. 17).

In January 2026 the Information and Privacy Commissioner of Ontario released guidance and a checklist on AI scribes, stressing governance and accountability measures before new AI tools enter a practice. The logic runs the same way for any AI tool: a custodian is expected to know which tools touch patient data and to have assessed them.

Why policies and bans fall short

The approved scribe can make the problem harder to see. Staff hear "we use AI now" and extend that to tools no one assessed. A policy that says "use only approved AI tools" does not tell a busy clinician how to produce the referral letter the scribe cannot.

Blocking ChatGPT on clinic devices pushes the task to a phone or home computer, where the clinic has no visibility at all. Gartner reported in 2026 that 88% of employees with enterprise AI access also use personal AI tools for work, which is the scribe gap in one number. Our article on shadow AI in clinical workflows describes how this traffic bypasses EMR security entirely. If a sanctioned tool leaves the letter-writing need unmet, the need does not go away.

What a practical control looks like

Treat the scribe rollout as step one, then close the gap around it. Confirm the specifics with your privacy officer, counsel, or the CMPA.

  1. Map the post-encounter tasks. List what clinicians and staff do with a finished note: referrals, patient summaries, forms, insurer letters, translations. Check which ones the scribe or EMR can handle.
  2. Provide a sanctioned route for the rest. Use the scribe's letter features where they exist, or approve an enterprise assistant with the same diligence you applied to the scribe: agreement, privacy assessment, retention settings. Our guide on sanctioned AI rollouts and shadow AI covers this pattern.
  3. Write a one-page rule. Which tool for which task, and a plain statement that identifiable patient information never goes into personal AI accounts.
  4. Train every agent, not only physicians: nurse practitioners, residents, medical office assistants and billing staff, since section 17 makes the custodian answerable for all of them.
  5. Set the incident path. Decide in advance how a paste into an unapproved tool is assessed under section 12, who decides on notification, and when to call the CMPA.
  6. Keep records of approvals, training and caught events to show the reasonable steps section 12(1) expects.

Sanitized Ai is a browser extension for Chrome, Edge and Firefox that supports steps 3 to 6. When a clinician pastes a note or uploads a file to one of the major AI assistants, it detects health information, patient identifiers and other personal information, and redacts or blocks it before submission. The clinician sees a plain-language explanation of what was flagged and why, which turns the one-page rule into coaching at the moment of use.

Once a note is submitted to a public AI tool it cannot be recalled and becomes subject to the provider's terms, which can permit retention. Administrators see a dashboard of flagged-event metadata (which tool, what type of data, which policy, when) and never the prompt content, so the clinic gets audit-ready records without reading anyone's prompts. That record can support a showing of reasonable safeguards, though no tool guarantees a regulatory outcome. For Quebec clinics, see our guide on the health and social services information act, or visit our healthtech page.

Frequently asked questions

Does the CPSO prohibit physicians from using ChatGPT?

No specific prohibition exists. The CPSO's Advice to the Profession on AI is guidance rather than a binding policy, and it states that there is currently no specific law or policy on AI and that physicians' core obligations are unchanged. It also says that all patient data entered into AI applications must be kept private and secure, which applies to general-purpose chatbots as much as to scribes.

Is it acceptable to use ChatGPT if the clinician removes the patient's name first?

It lowers the risk but does not settle the question. PHIPA tells custodians not to use personal health information if other information will serve the purpose, and not to use more than is reasonably necessary. Clinical narratives often identify a patient through dates, rare conditions or family details, so talk to your privacy officer before relying on manual de-identification.

Would an enterprise AI assistant fix the problem?

It can be part of the answer if the clinic applies the same diligence it used for the scribe: a written agreement, a privacy impact assessment, and configuration that limits retention and use. It still leaves personal accounts open in another browser tab, which is why clinics pair a sanctioned tool with a control at the prompt.

A clinician already pasted a patient note into ChatGPT. What does PHIPA require?

If it amounts to an unauthorized use or disclosure, section 12 requires the custodian to notify the patient at the first reasonable opportunity and, where prescribed circumstances apply, to notify the Information and Privacy Commissioner. The custodian also remains responsible for its agents under section 17. Assess the facts with your privacy officer, counsel or the CMPA.

Close the gap between the rule and the prompt box.

Sanitized Ai is a browser extension that coaches staff at the moment they type, redacts or blocks sensitive data before it reaches an AI tool, and gives administrators audit-ready records of flagged events without showing prompt content.

Talk to us

Primary sources

This guide summarizes the cited sources as of the verification date. It is practical guidance, not legal advice. Confirm your obligations with your regulator or counsel.

For your industry

Related guides

Further reading