The CT HMIS Policies & Procedures Manual has been updated with a new HMIS Artificial Intelligence (AI) Use Policy (Policy 214). The policy establishes requirements for protecting Client Data when AI tools are used.
AI tools can be useful for many work activities, but they can also create privacy and security risks when Client Data is entered into them. The most important rule to remember is:
Client Data may never be entered into an Unsecured AI system.
Client Data includes more than names and other direct identifiers. It can include demographics, case notes, histories, assessments, service records, program enrollment, outcomes, narratives, and information derived from HMIS records. Even information that appears anonymous may potentially identify a client when combined with other details.
What HMIS Users Need to Know
- Only appropriately secured AI solutions may be used with Client Data.
- A paid AI subscription is not automatically considered secure.
- Using a personal AI account does not change HMIS confidentiality requirements.
- The same requirements apply whether you are using an agency computer, personal computer, phone, or other device.
- AI-generated information should be reviewed and validated for accuracy before it is relied upon.
- Agencies are responsible for establishing appropriate AI governance, training staff, monitoring AI use, and protecting Client Data.
The HMIS AI Policy Self-Reflection Checklist is also available to help agencies consider how AI is currently being used and identify potential privacy, confidentiality, security, and compliance concerns.
When in doubt, don’t enter the data.
Please review the updated CT HMIS Policies & Procedures Manual, Version 8.1, and the HMIS AI Policy Self-Reflection Checklist with your agency staff.
HMIS AI Policy Checklist Companion
CT HMIS Policies and Procedures v8.1
