These are the most tightly regulated categories of information in almost every jurisdiction — special category data under GDPR Article 9, protected health information under HIPAA, sensitive personal data under India's DPDP Act.
And this is the one page here where the consequences can land on you personally rather than on your employer. Worth reading the next section properly.
Privilege can be waived, and waiver doesn't reverse. Legal professional privilege protects communications on condition that they're kept confidential. Disclose privileged material to a third party and you've handed the other side a serious argument that protection is gone — potentially across the whole subject matter, not just the paragraph you pasted. Your client can lose in discovery because someone wanted a faster summary.
HIPAA reaches individuals. Wrongful disclosure of protected health information carries criminal penalties for the person who made the disclosure, not only the covered entity. Most data-protection regimes stop at the organisation. This one doesn't.
Your professional body has its own view. Medical councils, bar associations and regulators impose duties of confidentiality that sit entirely separately from your employer's IT policy. Clearing it with IT doesn't clear it with them, and they are the ones holding your registration.
This is where well-intentioned people get caught. Deleting the name feels like it solves the problem. It doesn't.
HIPAA's Safe Harbor method lists eighteen identifiers that have to come out — names, all geography finer than a state, every date more specific than a year, phone and fax numbers, email, SSN, medical record and account numbers, device identifiers, URLs, IP addresses, biometrics, full-face photographs, and any other unique code.
The reason the list is that long: a rare condition, plus an admission date, plus a town of thirty thousand people identifies exactly one person. So does an unusual occupation in a case summary. Re-identification doesn't need a name — it needs enough narrowing, and clinical and legal narratives are made of narrowing details.
Ask about the pattern, not the person. The clinical or legal reasoning you're after doesn't depend on whose record it is.
Summarise and suggest
next steps:
Alex Morgan, 62,
MRN 4471-C, admitted
14 April to Central General,
T2DM, presenting with
persistent hyperglycaemia
on metformin, twice daily…
For an older adult with
type 2 diabetes and
persistent hyperglycaemia
despite maximal metformin —
what escalation options
are usually considered,
and what should be ruled
out first?
Same clinical answer. No record left your organisation. The same move works for law: describe the legal question and the shape of the facts, without the parties, the matter number, or the quoted correspondence.
Narrower here than anywhere else on this site. For health data under HIPAA you need a signed Business Associate Agreement with the vendor — not an enterprise subscription, a BAA. Under GDPR you need an Article 9 condition for processing special category data, on top of the usual lawful basis and a DPA. Under DPDP, sensitive personal data carries its own consent and localisation questions.
Clinical and legal AI tools that meet these terms genuinely exist, and some are very good. What makes them usable is the paperwork behind them, not the model inside them. If nobody can tell you whether the BAA is signed, the answer is no.
Escalate today. Not tomorrow, and not after you've decided how bad it was — that assessment isn't yours to make alone.
Mandatory breach notification clocks are short and they run from discovery: 72 hours under GDPR, 60 days under HIPAA's breach rule, and DPDP expects prompt reporting too. Tell your DPO, privacy officer or compliance lead, and say plainly what was pasted and where. If privileged material was involved, tell the supervising lawyer immediately — there are steps that can be taken to argue against waiver, and they get weaker with every day of delay.