← The Health AI Toolkit

Practical AI workflows for a health practice

Try a research question, a visit note or a care map with public sources and made-up records. These exercises show what to ask for and what to check.

Maya is a made-up case for these exercises. Connecting tools to real clinical records needs separate approval and testing.

Start with one exercise

Check a research claim

1. Starter · About 15 min

Ask a clinical or health question, find the relevant papers and check what they support before you make a recommendation.

Bring: A population-level research question and a public paper.

Make: A checked claim with a source and limits.

Build a care map from a made-up case

2. Starter · About 25 min

Bring someone’s history, goals and next steps into one place. Try it with Maya’s made-up case.

Bring: Maya’s fictional S1–S8 packet. Add S9 only after the first review.

Make: One browser file with goals, sources, open questions and owners.

Review a patient message before updating the record

3. Starter · About 15 min

Turn a patient message into a draft note you can check. Keep the original message and approve any change to the record yourself.

Bring: A fictional message and record excerpt; Maya’s S4 and S5 work for this exercise.

Make: A proposed change beside the original record.

Set up a weekly research brief

4. Next step · About 20 min

Try a regular research update from public sources. Check one result before deciding who will review it and where it should go.

Bring: A topic, population, review window and allowed public sources.

Make: A checked research draft and a separate schedule plan.

Setup and privacy checks

Get a BAA in place before sharing PHI

Setup review · About 20 min

Before using patient records, check whether you need a BAA, which services it covers and how to set up the account.

Bring: The proposed workflow, actual account and vendor agreements.

Make: A list of the account, covered services and approval checks.

Use a coding agent without exposing patient files

Setup review · About 20 min

Give the coding tool a separate practice folder, then check its file, network and app permissions. A folder alone does not limit access.

Bring: A dedicated workspace and fictional sample rows.

Make: A fictional prototype and a permission review.

De-identify before sharing: more than removing a name

Setup review · About 15 min

Removing a name is not enough. Use a recognized method and check the whole record, including notes and file details.

Bring: Use fictional records to rehearse; do not upload real records to an unapproved service.

Make: A record of the chosen method and review.

Check what your AI tool can access

Setup review · About 20 min

Before connecting a tool to your practice, check what it can read, what it can change and where it keeps copies.

Bring: The proposed workflow and actual permission settings.

Make: A map of what the tool can read, do and store.

Does HIPAA apply to your practice?

Setup review · About 20 min

Start with whether HIPAA applies to your practice. Then check the task and the information you plan to share.

Bring: The practice’s status and the information used in the proposed workflow.

Make: Questions for the practice’s privacy or legal lead.

Check how long a tool keeps your data

Setup review · About 15 min

“Not used for training” does not mean “not stored.” Check the service’s storage, deletion and retention terms.

Bring: The exact product, feature, account and agreement.

Make: A dated record of training, retention, access and deletion settings.