Drafting Internal Communications With AI Without Turning Confidential Information Into Input
Workflow Under Review Views 1

Drafting Internal Communications With AI Without Turning Confidential Information Into Input

This article describes a bounded workflow for using AI to draft internal communications in a small behavioral-health practice while ensuring that confidential and identifiable information never enters the model.

Small behavioral-health practices generate a steady stream of internal communications: policy updates, staff reminders, meeting summaries, and process clarifications. AI tools that promise to draft these documents quickly are attractive. They are also risky if confidential or identifiable information enters the prompt. The operational challenge is to capture the efficiency of drafting support without turning protected details into model input.

This article describes the bounded approach we developed for internal drafting. The method is deliberately narrow. It treats AI as a language assistant for non-confidential structure and leaves all sensitive content in human hands. The resulting process is slower than unrestricted use of the tool. It is also the only version we have been willing to defend. The difference in speed is real. The difference in defensibility has proven more important for a practice that must be able to explain its data practices months after a message is sent.

The Core Rule: Structure In, Confidentiality Out

The first and non-negotiable rule is that no identifiable patient information, free-text clinical notes, or staff performance details may enter any external model. That rule immediately eliminates many tempting uses. What remains is the structural and stylistic work of internal writing: turning bullet points into coherent paragraphs, standardizing the tone of policy language, and generating first drafts of routine announcements that contain no protected data.

In practice this means staff prepare a sanitized outline before any AI interaction. The outline contains only the non-confidential skeleton of the message. The AI is asked to expand that skeleton into readable prose. Humans then insert the specific details, names, dates, and clinical or operational facts that the outline deliberately omitted.

Staff preparing sanitized outline before AI internal drafting

A Practical Workflow for Internal Drafting

The sequence we follow is short and repeatable:

  1. The author writes a bullet-point outline that excludes all confidential elements.

  2. The outline is submitted to the AI tool with a fixed prompt that requests only structural expansion and neutral professional tone.

  3. The AI returns a draft.

  4. The author reviews the draft for scope creep—any addition of content that was not in the outline is removed.

  5. The author inserts the confidential or practice-specific details by hand.

  6. A second person reviews the final version before distribution.

The dual review is intentional. The first review protects against the model introducing language that exceeds the sanitized outline. The second review protects against human error in the re-insertion of sensitive details. Both steps are logged with date and initials when the communication is policy-related or otherwise high-stakes.

Why the Extra Steps Are Worth the Time

Unrestricted drafting is faster in the moment. It also creates a data trail that the practice cannot later control or fully reconstruct. By forcing the confidential elements to remain outside the model, the practice keeps the exposure surface small and the audit path clear. The modest time cost of the extra steps is the price of a process that can be explained to staff, to patients if necessary, and to any future reviewer.

We have found that the discipline also improves the quality of the final communications. Authors who must first produce a clean outline tend to clarify their own thinking before the drafting begins. The AI then operates on better input, and the human editing step becomes more focused.

Prohibited content list for AI-assisted internal communications

Training Staff on the Boundary

The boundary between structure and confidential content is not self-enforcing. New staff and busy staff will occasionally test it, usually with good intentions. Training therefore includes concrete examples of outlines that are acceptable and outlines that cross the line. We also maintain a short list of prohibited categories that is reviewed whenever the process is taught. The list is short enough to remember and specific enough to leave little room for interpretation.

When an exception occurs—someone pastes a clinical note into the prompt by mistake—the incident is logged and the affected data path is examined. The goal is not punishment. The goal is to keep the boundary visible and to adjust training if the same mistake appears more than once. In the first three months of the process we recorded two such exceptions. Both involved well-intentioned attempts to save time. Both led to short refresher conversations rather than formal discipline. The log itself became a teaching tool.

We also discovered that the dual-review step catches most residual problems before a message is distributed. The second reviewer is instructed to look specifically for any content that could not have come from the sanitized outline. That focused instruction has proven more effective than a general request to “check the draft.”

That’s a judgment call, not a tool question. AI can assist with the language of internal communications. It cannot be allowed to become a convenient place to park confidential information for later retrieval or rewriting. Designing the workflow so that the confidential material never enters the model is the only approach we have found that remains defensible over time.

Slow is not the same as behind. The extra minutes required to sanitize an outline and re-insert details by hand have proven less costly than the alternative of discovering, after the fact, that sensitive content had been processed by a system the practice does not fully control. Practices that accept the slower method retain the ability to answer questions about data handling with confidence. Practices that prioritize speed often lose that ability the first time an unexpected detail appears in a model log or a vendor report.

Comments

No comments yet — be the first to share a thought.

Leave a comment

Last Updated:2026-09-29 10:29