Free tools Windows power users keep installed
One-click scans. No signup required.
Do not put identifiable medical records, accommodation documents, personnel files, or confidential work material into a public or unapproved AI tool. Whether a particular use is allowed depends on what the information is, who holds it and in what role, what the AI provider does with it, and which laws and contracts apply. In the United States, HIPAA does not automatically cover every health-related record, and removing a person’s name does not necessarily make a record safe to share.
Start by identifying the record, the holder, and the recipient
The same health detail can be subject to different rules depending on where it came from and why it is held. A hospital handling patient information, an employer managing an accommodation request, and a consumer AI service receiving a prompt do not automatically have the same legal duties. Use this distinction before deciding whether an AI workflow is appropriate.
| Information and holder | Key distinction | What to check before AI use |
|---|---|---|
| Patient information held by a health plan, qualifying provider, clearinghouse, or relevant business associate | HIPAA may apply to protected health information (PHI) in the covered role and workflow. | Confirm the organization’s role, permitted purpose and disclosures, safeguards, minimum-necessary practices where applicable, and any required business associate agreement. |
| Medical information held by an employer about an applicant or employee | HHS says HIPAA does not protect employment records, even when they contain health information. ADA confidentiality requirements may still apply to covered employers. | Check who may access the information, whether it is kept in a separate medical file, and whether the proposed use and disclosure are allowed. |
| General personnel information, such as performance or scheduling material | It is not automatically PHI, but it can still be confidential, contractually protected, or subject to employment and privacy rules. | Follow organizational policy and applicable law; remove details not needed for the task and use only an approved workflow. |
| Information sent to a consumer AI service or used for an employment decision | The provider’s handling terms and the purpose of the AI use matter. Employment discrimination protections remain relevant when AI is used at work. | Verify data access, retention, reuse, deletion, security, and human oversight rather than relying on a generic claim such as “HIPAA compliant.” |
HIPAA applies to health plans, health care clearinghouses, certain providers that conduct specified electronic transactions, and business associates handling PHI in relevant circumstances. An employer does not bring every workplace record under HIPAA merely because it also operates a health plan or a hospital. HHS’s workplace guidance says the Privacy Rule generally governs disclosures by providers, not the questions an employer may ask; a provider generally cannot disclose information to an employer without authorization unless another legal basis applies.
If you are an employee, applicant, or patient, check before you submit
Pause before using a public or unapproved AI tool
Do not paste identifiable patient records, doctor’s notes, leave records, accommodation requests, personnel records, or confidential work documents into a tool unless the relevant organization has approved that exact use. Check your employer’s or provider’s policy and the service terms. If the rules or data flow are unclear, ask the organization’s privacy, security, or compliance contact before uploading anything.
#1 Best Overall
Verify the whole data flow
A prompt is not the only possible exposure. Consider uploaded files, generated summaries, chat history, browser extensions, and connected apps. For the exact service and account you would use, verify:
- What information is collected and which people or systems can access prompts, files, and outputs.
- How long the service retains that information and how deletion works.
- Whether inputs or outputs may be reused for service improvement or model training.
- What the service and your organization require for security, incident reporting, and approved use.
Terms can vary by service, account, contract, and settings; do not infer a particular provider’s practices from a general product label.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
Share less, but do not mistake name removal for de-identification
If a workflow is approved, provide only the details needed for the task. Remove direct identifiers and irrelevant facts where possible, but combinations of dates, job titles, locations, rare diagnoses, or distinctive events may still identify someone. Where HIPAA applies, de-identification follows specified methods; deleting a name alone is not equivalent to meeting them.
Use practical access and workspace safeguards
Where policy requires, use an approved organizational account and device, enable available access controls and multifactor authentication, avoid shared accounts, and keep sensitive files in access-controlled systems. Follow retention and incident-reporting rules. In a shared office, clinic, or public place, position the screen to reduce casual viewing; an optional privacy filter can help with nearby onlookers, but it cannot protect information transmitted to an AI provider.
Rank #3
If you manage a workplace or healthcare workflow, approve the use—not just the tool
Map the information and each party’s role
Before selecting a workflow, document what information enters it, where it comes from, the purpose, recipients, retention, and who can access it. Determine whether the organization is acting as a HIPAA covered entity or business associate for that specific information and activity, or as an employer holding employment records. If a service provider may access PHI for a covered entity, determine whether it is acting as a business associate and whether a business associate agreement and written limits on use are required.
Set controls for the actual workflow
Have privacy, security, legal, and HR functions review the proposed tool and use. Establish role-based access and data-minimization practices where applicable, retention and purpose limits, workforce training, and periodic safeguard reviews. Ensure public-facing privacy and security statements match actual practices. A “HIPAA compliant” label is not a universal certification that every organization, vendor, dataset, or AI use is lawful or safe.
Rank #4
Keep workplace medical information confidential
EEOC guidance says covered employers generally must keep applicant and employee medical information confidential and in separate medical files, including when the information is stored electronically. Limited disclosures may be allowed in circumstances such as providing managers information needed for accommodations or work restrictions, giving safety staff information for emergencies, or responding to officials investigating compliance. Do not send accommodation documents into a general-purpose AI workflow without a specific approved basis and safeguards.
Review AI used in employment decisions
AI can create an employment-decision risk as well as a data-handling risk. EEOC worker guidance issued in 2024 explains that existing federal employment discrimination laws remain relevant when employers use AI, including protections relating to disability and genetic information. Assess possible discriminatory effects and provide appropriate human oversight; the guidance is not an exhaustive compliance framework for every system or decision.
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
Know the limits of the federal rules
The ADA places limits on disability-related inquiries and medical examinations at different stages—before an offer, after a conditional offer, and during employment. The applicable requirements depend on the facts and stage of the process, so this overview cannot determine whether a particular request or decision is lawful.
HIPAA and the ADA are only part of the U.S. legal picture. State privacy statutes, state and local employment laws, sector-specific requirements, collective bargaining agreements, contracts, and non-U.S. laws may add obligations. HHS and FTC guidance on health-data practices emphasizes safeguards, training, purpose and retention policies, and accurate privacy representations; FTC materials also recognize that information from which health can be inferred may count as health information in relevant consumer-health contexts. That does not mean every employee record is covered by the Health Breach Notification Rule.
For a concrete situation involving real patient or employee information, take the proposed workflow to the organization’s privacy, security, or legal contact, or to qualified counsel. General guidance cannot establish whether a specific disclosure or AI use is permitted.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




