A smartphone glowing with an AI chat screen on an office desk late at night, next to unfinished documentation

Shadow AI and the HIPAA and 42 CFR Part 2 Violation Dilemma

September 29, 2026•8 min read

Staff in substance use disorder (SUD) treatment and behavioral health programs are under constant pressure to keep up with progress notes, treatment plan updates, and utilization reviews. Falling behind means overtime, missed evenings, and a backlog that keeps growing. So staff are turning to AI tools to catch up, often without anyone approving them. Shadow AI is a problem for businesses too, but we’ll address those issues in a future post.

The short answer: Shadow AI is staff use of AI tools that leadership hasn't approved or doesn't know about. In behavioral health, it becomes a compliance problem the moment client information goes into a personal AI account. That can be an impermissible disclosure under HIPAA and 42 CFR Part 2, with licensure, accreditation, and payer contracts consequences. Banning AI doesn't fix it. Finding out what's happening, assessing the exposure, and giving staff a safe alternative does.

Key Takeaways

  • Shadow AI is a workload symptom, not rebellion. Staff use tools like ChatGPT, Claude, and Gemini to survive documentation demands, not to put the program at risk.

  • Personal AI accounts are the core risk. Pasting client notes, intake summaries, or session transcripts into a personal account, free or paid, can be an impermissible disclosure under HIPAA and 42 CFR Part 2.

  • Removing names doesn't make it safe. Clinical details, life circumstances, and locations can identify a client even without a name or date of birth.

  • Bans push the behavior out of sight. If the underlying workload isn't addressed, staff move to personal phones, where leadership has no visibility.

  • The fix is operational. Find out what's in use, assess any past exposure with your privacy officer, provide approved tools, and set clear rules in the form of an AI use technology policy.

Why Staff Turn to Unapproved AI Tools

Shadow AI rarely starts with bad intent. A clinician falls behind on notes, sees a YouTube video or social media post showing how an AI tool can draft in seconds what takes them 45 minutes, and tries it. It works, so they tell a colleague, and within weeks it's a routine way to get their work done.

It isn't limited to clinicians. Admissions, utilization review, billing, and administrative staff face the same pressure and the same temptation. In most programs, leadership has no idea which tools are in use, what's being entered, or where that data goes afterward. This means zero regulation and oversight on how the AI is used in their facility.

Why Consumer AI Tools Are a Risk for SUD Records The account type matters more than the price. Personal AI accounts, free or paid, are designed for individuals. They don't come with a business associate agreement (BAA), and the program has no control over how data is stored, used, or deleted. Some vendors offer business or enterprise plans with a BAA and a commitment not to train its models on the inputs it receives (ex. customer data). However, these agreements have to be entered by leadership, not individual users for protected health information to be protected.

Data policies vary and change. Most AI software consumer plans use conversations to improve their models unless the user opts out. Deleted chats may disappear from the user’s view, the data can be retained on AI software servers.

Memory features mix work with personal use. Some AI tools remember details from past conversations to personalize future ones. When a counselor uses one account for personal questions and client notes, client information gets tied to that personal profile.

Sharing features can expose data. In 2025, about 4,500 ChatGPT conversations that users had shared with a "discoverable" setting turned up in Google search results. OpenAI removed the feature, but copies can remain. A single shared link to a chat with client details is a disclosure.

HIPAA vs. 42 CFR Part 2: What's at Stake

HIPAA protects health information broadly. 42 CFR Part 2 adds stricter federal protections specifically for SUD treatment records.

  • Part 2 protects the fact of treatment itself. Information that identifies someone as a patient of an SUD program generally can't be disclosed without written consent or a specific exception, such as a court order that meets Part 2 requirements.

  • The 2024 rule changed some things, not this one. Patients can now sign a single consent covering treatment, payment, and health care operations. Entering records into a personal chatbot account is not an exception to the statute.

  • Part 2 now follows HIPAA's breach rules. Since the compliance date of February 16, 2026, Part 2 programs follow the HIPAA Breach Notification Rule and face HIPAA-style penalties. The HHS Office for Civil Rights is enforcing it.

  • De-identification is more than removing a name. HIPAA has specific de-identification standards. Details like an uncommon job, a court case, a family situation, or a small town can identify a client when combined. Individual staff members are placing themselves in the position to determine what de-identified standards are when they engage in Shadow AI by using AI outside of agency approval.

  • Licensure and accreditation are on the line. A confidentiality failure can lead to state licensing action, payer audits, and accreditation findings. In September 2025, the Joint Commission and the Coalition for Health AI released guidance calling for AI governance policies, staff training, and monitoring. It's voluntary today but is expected to shape future accreditation.

How to Respond to Shadow AI in Your Program

1. Find out what's being used.

  • Announce a disclosure period where staff can report the AI tools they've used without facing disciplinary action. A disclosure period protects staff from discipline. It does not waive their reporting obligations.

  • Review web traffic logs on company networks for visits to AI sites.

  • Check browser extensions on work devices.

  • Look for AI subscriptions in expense reports.

  • Ask your Electronic Health Record (EHR) and software vendors which AI features are already switched on.

2. Assess past exposure.

  • Work with your privacy officer or counsel to determine whether client information was disclosed, and complete a breach risk assessment.

  • Have staff delete relevant chats and shared links, and turn off training and memory settings. This limits further exposure, but it doesn't undo the past disclosure.

  • Follow your breach notification obligations if the assessment calls for it.

3. Fix the workload problem behind it.

  • Map where documentation time is actually lost, such as progress notes, treatment plan updates, or utilization review appeals.

  • Pick the problem with the biggest impact on staff, and involve staff in choosing it.

4. Provide an approved alternative.

  • Choose a tool with a BAA, no training on your data, audit logs, and access controls. Review how it handles Part 2 records specifically.

  • Keep it simple. A tool that fits the existing workflow will be used. A complex platform won't.

  • Block unapproved AI sites and implement a safe, compliant alternative for them to use.

5. Set rules and keep watching.

  • Write clear SOPs covering which tools are approved, what information may never be entered, and which outputs need human review. We created a Toolkit that helps you fast track this process.

  • Train every department on the policy and new systems, not just clinical staff.

  • Set up regular feedback so the solution keeps working as needs change.

  • Recheck for new tools and features on a schedule.

This follows the same approach we use for any AI adoption work. We describe our RISE Method in our blog post, "Why Won't My Team Use the AI Tools We Paid For?".

Frequently Asked Questions

Can therapists use ChatGPT if they leave out the client's name and date of birth?
No. Removing direct identifiers doesn't meet HIPAA de-identification standards, and contextual details can still identify a client. Any AI use involving client information should happen only in an approved tool with a BAA and appropriate safeguards.

Is a paid ChatGPT or Claude account HIPAA compliant?
No. Compliance depends on a business agreement that includes a BAA, data protections, and administrative controls, plus your own policies and training. Paying for a personal account or even an enterprise account doesn't provide any protections for patient health information.

Does an AI note-taker that records sessions require client consent?
Yes. Get documented, informed consent in all cases to protect your license and to avoid the slightest possibility of a 42 CFR Part 2 or HIPAA violation. State recording laws vary, and some states now require specific consent for AI use in therapy. Illinois's 2025 law, for example, requires it in certain cases, including recording or transcribing sessions. The consent should explain how audio is captured, processed, stored, and deleted.

What should we do if we find staff using unapproved AI tools?
Find out the extent of use, involve your privacy officer to assess whether client information was exposed, and follow breach notification rules if required. Then identify what’s causing staff to turn to AI, provide a compliant alternative, and put SOPs and monitoring in place.

Will surveyors and auditors check for AI use?
Checking for AI use policies and the regulation of Shadow AI in treatment programs is not a formal standard yet. Accreditors are moving in that direction. The Joint Commission's 2025 guidance with the Coalition for Health AI calls for AI policies, training, and monitoring. The National Institute of Health, National Association of Addiction Treatment Providers, and the National Substance Use and Mental Health Services Survey are having discussions about Shadow AI on a national level. Treat this as a sign of where licensing and surveys are headed. That is just our take on all of the panel discussions and white papers about the issue.

Know What's Happening Before a Regulator Does Your program needs an AI use policy even if you've never approved an AI tool, because your staff may already be using one. In a 15-minute call, we'll talk through where client information may be at risk and how our AI Use Technology Toolkit helps you put a compliant AI use policy in place.

Schedule a Call With Us: https://calendly.com/micheledavisnyc/15-minute-meeting

Related Reading

  • Why Won't My Team Use the AI Tools We Paid For?

  • How Much Access Should You Give an AI Agent in Your Business?

  • Is It Safe to Use AI Tools That Train on Your Business Data?

Michele Davis

Michele Davis

Michele Davis is the Founder and CEO of Gemstone Consulting Services. She helps companies adopt AI in their operations with the governance, workflows, and staff training for sustainable team adoption. She brings 16 years of leadership experience in nonprofit, government, and human services settings, which includes programs subject to HIPAA and 42 CFR Part 2. She created the proprietary RISE Method and hosts the Bots in the Building podcast.

LinkedIn logo icon
Instagram logo icon
Youtube logo icon
Back to Blog