Can AI be used with patient data?

#Ethics & regulation 26 February 2026 5 min read
Can AI be used with patient data?

A legitimate question, often given answers that are too vague

When a doctor dictates their report to an AI assistant, are they sending medical data to an American company? When a nurse uses a chatbot to look up a protocol, do they risk compromising a patient’s confidentiality? Can a hospital entrust the analysis of its records to an external algorithm without breaching medical confidentiality?

These questions are not paranoid. They are professionally legitimate, ethically serious, and legally important. And they deserve precise answers; not reassuring formulas as vague as “we’re GDPR-compliant.”

The reality is nuanced: yes, AI can be used with patient data, but under strict conditions, within well-defined frameworks, and with practices that differ according to the tools, the contexts and the types of data concerned.

Understanding these distinctions has become an essential professional skill for any caregiver who uses, or is considering using, AI tools in their practice.

What the law says: health data, a category apart

The General Data Protection Regulation (GDPR), applied in France since 2018, classifies health data in the category of sensitive data, alongside genetic, biometric, religious data or data relating to sexual orientation. Their processing is in principle prohibited, unless one of the legal exceptions provided for by article 9 of the GDPR applies.

In healthcare, the main exceptions legitimising the processing of health data are:

  • Processing necessary for the medical care of the patient (with their implied consent within the framework of care)
  • Processing for scientific or medical research purposes, under conditions
  • Processing carried out by a healthcare professional bound by professional confidentiality
  • Processing in the public interest (public health, epidemiology)

In France, the CNIL (National Commission for Information Technology and Civil Liberties) is the competent supervisory authority. It has significant powers of sanction: up to 4% of a company’s global turnover, or €20 million.

The key distinction: identifying, pseudonymised or anonymised data

Directly identifying data

This is data that makes it possible to directly identify a person: surname, first name, social security number, precise date of birth, address, telephone number. Coupled with medical information, it constitutes personal health data in the strictest sense.

Pseudonymised data

Pseudonymisation consists of replacing direct identifiers with a code or an artificial identifier, while retaining the possibility of re-identifying the person if necessary. Pseudonymised data remains personal data within the meaning of the GDPR.

Anonymised data

Anonymisation, in the strict sense of the GDPR, refers to the process by which any possibility of re-identification is irreversibly removed. Truly anonymised data is no longer personal data and can therefore be processed freely.

⚠ The problem? True anonymisation is technically difficult to achieve, especially in healthcare. Studies have demonstrated that it is possible to re-identify patients from seemingly anonymised data by cross-referencing different sources.

What you have the right to do: the concrete cases

Using AI for your own practice with your own patients

A healthcare professional who uses an AI tool in the context of the direct care of their patients may, under certain conditions, process health data with that tool. The main condition is that the tool be GDPR-compliant and that the processing of the data be covered by a Data Processing Agreement (DPA) with the provider.

Using a mainstream generative AI tool (ChatGPT, Gemini…)

This is where the risk is most often poorly assessed. Tools such as ChatGPT in its free or standard version, or other mainstream conversational AIs, are not GDPR-compliant processors for the processing of health data.

Entering a patient’s name, social security number, history, test results or any element allowing their identification into a mainstream tool constitutes a breach of the GDPR and a violation of medical confidentiality.

The practical rule is simple: if you need AI to write a letter, prepare a standard response, look up information or generate a generic document, you can use these tools by systematically replacing the patient’s information with generics (“the patient,” “the 65-year-old female patient with a history of type 2 diabetes,” etc.).

The professional and enterprise versions of AI tools

Several generative AI publishers offer versions specifically designed for professional uses, including suitable GDPR guarantees. This is the case for Microsoft Azure OpenAI Service, Claude for Enterprise from Anthropic, or French and European solutions such as Mistral AI and its professional offerings dedicated to the healthcare sector.

The Health Data Hub and the French framework for AI research

The Health Data Hub (HDH), created by the Ma Santé 2022 law, is the national platform that centralises and secures French health data to allow its exploitation for research and innovation purposes. Access to HDH data is subject to a strict authorisation process, managed jointly by the CNIL and the CESREES.

Medical confidentiality and the responsibility of the healthcare professional

The GDPR is not the only applicable framework. Medical confidentiality, enshrined in article L. 1110-4 of the French Public Health Code, applies to all healthcare professionals.

Concretely, this means that:

  • You cannot dictate identifying information about a patient to a mainstream AI assistant without checking its data-processing terms
  • You cannot share a patient record with an external tool without checking that it is authorised to receive it
  • You may be held liable for a leak of health data resulting from non-compliant use of an AI tool, even if you were not aware of it

The good practices to adopt right now

Before using a new AI tool, systematically ask three questions: Where is the data I enter into it stored and processed? Is the publisher bound by a GDPR processing contract with my establishment or my structure? Can the data be used to train the model or transmitted to third parties?

Distinguish between uses with real data and generic uses. For anything that can be done without identifying data; looking up information, drafting letter templates, preparing therapeutic-education materials; you can use mainstream tools freely.

Consult your establishment’s DPO. All healthcare establishments are required to designate a Data Protection Officer.

Document your uses. The GDPR is based on a principle of accountability.

Train. The European Artificial Intelligence Act, which came into force in 2024, introduces new obligations for high-risk AI systems used in healthcare.

What changes with the European AI Act

The European Regulation on artificial intelligence (AI Act), adopted in 2024 and whose provisions apply gradually until 2027, classifies AI systems used in healthcare in the “high risk” category.

For healthcare professionals as users, the AI Act does not create new direct obligations, but it strengthens the requirements placed on the publishers of the tools you use.

Compliance is not an obstacle to innovation, it is its foundation

The question “can AI be used with patient data?” calls for a clear answer: yes, within a precise legal framework, with compliant tools, under the supervision of a responsible professional.

The good news is that this understanding can be acquired. It does not require in-depth legal training, but a few hours of structured learning are enough to transform a source of anxiety into a genuine professional skill.

Sources and references (10 sources cited, including the GDPR, the French Public Health Code, CNIL documentation, the Health Data Hub, and scientific articles)