- A quick word on "training"
- What goes in, and what never does
- Check the tool before you upload anything
- Build it in four steps
- The "I don't know" test
- Use it twice
- What a person must still decide
Your front desk answers the same questions every week. What are your fees? Do I need a referral? What should I bring? What's the cancellation policy?
An AI assistant can help with those answers. The question owners ask first is the right one: is it safe to put clinic documents into ChatGPT, or any similar tool?
The answer depends almost entirely on which documents.
A quick word on "training"
When people say "train AI on my clinic", they usually mean something simpler. You give the tool a set of documents, and it reads them when answering. The underlying model isn't being retrained on your files.
That difference matters. It means you control what the assistant can see, and the most important decision happens before you upload anything.
What goes in, and what never does
Think of it as two piles.
Fine to use: your own published and policy information
- Fees and payment options as they appear on your website
- Opening hours, location, parking and access details
- Forms and what they're for
- What to bring to a first appointment
- Cancellation and rescheduling policy
- How referrals work at your clinic
- Answers to common admin questions, written by you
This is about how your clinic runs, not about any person.
Keep out: anything about a client, patient or participant
- Clinical notes, assessments and reports
- Client or participant records of any kind
- Intake forms that have been filled in
- Emails or messages from clients
- Anything with a name, date of birth, plan number, Medicare number or other identifying detail
- Staff records
Never put patient or participant records into an AI tool to build a knowledge base. If a document mixes both piles, such as a policy with a worked example using a real client, remove the client details or leave the document out.
Check the tool before you upload anything
Before you add a single file, open the tool's settings and its data or privacy page. Look for answers to these questions:
- Where is the data stored? Which country, and under which company's terms?
- Is your content used to improve the provider's models? Is there a setting to turn that off, and is it on or off for your account type?
- Who in your team can see it? Can you limit access to specific people?
- How do you delete it? Can you remove a file, a conversation or the whole project?
- Is there a business or team plan with different terms? Free and paid plans can work differently.
Write the answers down with the date. Terms change, so revisit them.
Two pieces of reading are worth your time here. Ahpra has published guidance on meeting your professional obligations when using AI in healthcare, which says the practitioner stays responsible and must apply human judgement to anything AI produces. The Office of the Australian Information Commissioner has guidance on privacy and the use of commercially available AI products, and recommends that organisations don't enter personal information, particularly sensitive information such as health information, into publicly available generative AI tools. Read both at the source. This post is general information, not legal advice, and those are the documents your decisions should rest on.
Build it in four steps
1. Make a folder of answers
Create one document per topic: fees, referrals, first appointment, cancellations, forms, access. Write each answer in plain language, the way your best receptionist would explain it. Date every document.
2. Create a project or assistant
Most AI tools let you create a project, workspace or custom assistant and attach documents to it. Add only the folder from step 1.
3. Write its instructions
Tell it what it's for, what it may answer, and what it must hand to a person. The prompt below is a starting point.
4. Test it before anyone relies on it
Ask it twenty real questions your front desk gets. Check every answer against your documents.
The "I don't know" test
AI tools can produce confident answers that aren't in your documents. This is often called hallucination, and it's the main thing to test for.
Ask the assistant ten questions it should not be able to answer, for example:
- "Can I stop taking my medication before my appointment?"
- "What did my physio write in my notes last week?"
- "Is your clinic cheaper than the one down the road?"
- "Will the NDIS fund this for me?"
A good result is the same every time: it says it can't help with that and points the person to a human. If it guesses, tighten the instructions and test again. Keep a log of the questions and results so you can repeat the test whenever you change a document.
Use it twice
Once it passes testing, the same knowledge base can serve two jobs:
- For staff: a quick way to check the current policy wording without hunting through folders.
- For your website chat: answering admin questions out of hours, with clear wording that it's an automated assistant and a path to a person.
Start with the staff version. Your team will spot gaps faster than any test you write.
Prompt you can copy
You are an admin assistant for [clinic name], a [type of practice] in [suburb]. You answer questions about how the clinic runs, using ONLY the documents attached to this project. You may answer questions about: fees, hours, location, forms, referrals, what to bring, cancellations and booking. You must not: - give clinical, medical or therapy advice of any kind - guess, or answer from general knowledge - discuss any individual client, patient or participant - compare us with other providers If a question is outside the documents, or touches on health, treatment, funding decisions or anything urgent, reply: "That's one for our team. Please call [number] or email [address]." If someone seems distressed or at risk, give [crisis line details] and our phone number. Keep answers short and plain. Quote the policy wording where it helps.
You decide what goes in the brackets, what the assistant may cover, and where the line sits. The tool follows the brief you write.
What a person must still decide
- Which documents go in, and who checks they hold no client details
- Which tool and plan to use, after reading its data terms
- Where the assistant must stop and hand to a person
- Who reviews the answers, and how often the documents are updated
- Whether your reading of the Ahpra and privacy guidance needs a second opinion from your professional body or adviser
Your checklist
- Sort your documents into "fine to use" and "keep out"
- Remove any client details from mixed documents, or leave them out
- Check the tool's data storage, model-training and deletion settings, and note the date
- Read the Ahpra AI guidance and the OAIC AI privacy guidance at the source
- Write one dated answer document per topic
- Set up the project with only those documents and your instructions
- Test twenty real questions and ten it shouldn't answer
- Start with the staff version before any website chat
If you'd like this set up for you, that's what the free check is for.
General information only — not clinical, legal or financial advice. No client is named and nothing here describes a patient or participant. Written by Aishah Shah, Western Sydney.