[nonimo]
EN
Download

Ahpra AI guidelines: what patient data stays out of ChatGPT

· Updated · Written and maintained by Joaquín Trapero, Nonimo

The Ahpra AI guidelines do not ban ChatGPT from a practice. They do something harder to live with: they leave every consequence with the practitioner. And the first case study Ahpra wrote to explain them is a clinician dictating findings into ChatGPT for a clean version of the notes, with a plain warning attached: “Any personal information entered into an AI tool which stores data offshore could lead to unintentional breaches of Australian privacy laws.”

So the working answer for a referral letter, a discharge summary or a report to an insurer is this. The patient’s identity does not go into a general chatbot: not their name, birth date, home address or phone, and least of all the government numbers. The clinical content can, once it no longer points at one person, and once your patients know that AI is part of how their letters get written.

The rest of this guide takes that answer apart for an Australian practice, rule by rule. The case note version of the same question, for disability providers, is in our guide to NDIS case notes and AI. This one is about the consulting room and the letters that leave it.

Ahpra AI guidelines: the short answer for letters and summaries

Ahpra published Meeting your professional obligations when using Artificial Intelligence in healthcare in August 2024, and the page carries a review date of 22 August 2024. It is not a registration standard and it creates no new offence. It applies the codes of conduct the National Boards already enforce to a new kind of tool, which is why most practitioners call it the Ahpra AI guidelines even though Ahpra itself calls the document guidance.

It rests on five principles. Two of them decide what may go into a chatbot in the first place, and the other three govern what you do with the draft that comes back.

principlewhat it asks of a letter drafted with AI
Accountabilityyou answer for the letter, whoever or whatever drafted it
Understandingknow how the tool handles data, and its limits
Transparencypatients should know AI is used in their care
Informed consentbefore a patient’s data goes into the tool
Ethical and legal issuesprivacy and health records law apply in full

Source: Ahpra, Meeting your professional obligations when using AI in healthcare, reviewed 22 August 2024.

Guidance on the code, not a new rule

The page matters because of what stands behind it. Every board’s code of conduct already requires practitioners to protect patient confidentiality, and a notification about a leaked letter would be assessed against the code. The AI page tells you how the board will read the code once a chatbot is involved.

For a small practice that matters, because there is nobody further up to hand the question to. Ahpra is clear that the practitioner stays responsible for safe and quality care, and a vendor’s assurance does not change that. What each chatbot offers, account type by account type, is compared in the Privacy Act comparison of chatbots.

The case study that describes an ordinary afternoon

Ahpra illustrated the guidance with two case studies. In the first, a practitioner dictates findings to ChatGPT, asks for a clean and grammatical version, and pastes it into the clinical notes. Drafting a referral letter in a chatbot is essentially the same thing, and the lessons Ahpra draws from it are the ones this guide follows.

Three of them carry the argument. The practitioner “should have explained to their patients/clients how AI will be used and obtained informed consent for its use”. The tool may keep data offshore. And what goes in may be accessed, used or even sold by the developer, which Ahpra says needs the patient’s explicit informed consent. The second case study, a scribing tool that added a diagnosis to a referral, comes back near the end.

What the RACGP says, and the Perth discharge summary

The college is blunter than the regulator. Its resource on conversational AI, first published in June 2025 and last updated in September 2025, lists “clinical letters, clinical notes and discharge summaries” among the documents these tools could help prepare. A few sections later it says: “GPs should never enter sensitive or identifying data into a conversational AI tool.”

Read side by side, those two sentences are the brief for this whole guide. The letter is a legitimate use of the tool. The patient inside the letter is not something the tool gets to see. The same resource asks GPs to be open about AI use in the practice privacy policy, which comes back in the section on consent.

Perth, May 2023: one discharge summary

Australia already has its cautionary tale. In May 2023 the chief executive of Perth’s South Metropolitan Health Service, which runs five hospitals, emailed staff that the use of AI technology including ChatGPT “for work-related activity that includes any patient or potentially sensitive health service information must cease immediately”. The ABC reported the email on 28 May 2023.

What followed is the instructive part. The service later clarified that one doctor had used the tool, for one patient discharge summary, and that no patient information had been breached. A single document was enough to stop five hospitals, and the instruction was aimed at the patient information, not at AI as such. What a chatbot keeps once you have pasted text into it is set out in what OpenAI does with a paste.

The sector that already reports the most breaches

Perth was not a breach. A great deal of what does reach the regulator comes from practices like yours. The OAIC received 1,205 data breach notifications in 2025, the highest number since the scheme began in 2018, and health service providers were the most affected sector, with 225 of them, or 19% of the total.

1,205data breaches notified to the OAIC in 2025
225from health service providers
19%of the total, the largest sector
OAIC, Notifiable Data Breaches statistics for 2025, published 6 July 2026

Most of the 1,205 came from malicious or criminal activity, not from a pasted letter. The point is narrower: a practice that ends up explaining a disclosure to the OAIC will be explaining it to a regulator that sees health providers more often than anyone else.

Every line of a referral letter is health information

A referral letter feels like it has two parts: the clinical story, which is sensitive, and the header, which is admin. The Privacy Act does not draw that line. Section 6FA defines health information to include not only information about a person’s health or the services they receive, but also “other personal information collected to provide, or in providing, a health service”.

The OAIC’s Guide to health privacy spells out what that sweeps in: a patient’s name, address, admission and discharge dates, billing information and Medicare number. The header is health information too, and under section 6(1) health information is sensitive information. Every line of the letter sits in the most protected category the Act has, and turnover does not lift a health practice out of it, as the NDIS guide explains.

Why putting it into a chatbot counts as a disclosure

The OAIC has already said how it sees text typed into these tools. Its guidance for businesses buying AI products off the shelf, dated 21 October 2024, treats personal information put into an AI system as subject to APP 6. Its advice goes further: the better course, it says, is to keep personal information, “and particularly sensitive information”, away from public generative AI tools altogether.

APP 6 allows a secondary use or disclosure of health information only on narrow grounds, such as consent, or a purpose directly related to the original one that the patient would reasonably expect. A patient who agreed to a referral expects the specialist to read the letter. Whether they expect a software company to process it on the way is a far harder argument, and the practice is the one that has to make it.

Where each rule meets a referral letter pasted into a chatbot A referral letter moves from the clinical software to the practitioner's computer and then to a chatbot provider, often overseas. When the letter is pasted APP 6 applies, together with APP 9 for a Medicare number and the My Health Records Act for anything taken from My Health Record. On arrival overseas APP 8 applies, and in Victoria Health Privacy Principle 9 applies as soon as the letter leaves the state. Clinical software the letter is drafted Your computer selected and pasted Chatbot provider often overseas APP 6: the paste is a disclosure APP 9: the Medicare number My Health Records Act, s 59: anything taken from My Health Record APP 8: an overseas recipient Victoria, HPP 9: the letter has left the state
Where the rules in this guide attach to one pasted letter. Privacy Act 1988, My Health Records Act 2012, Health Records Act 2001 (Vic)

If the chatbot is hosted overseas, APP 8 adds a further layer: before disclosing to an overseas recipient you must do what is reasonable to see that it will not breach the principles, and its conduct can be treated as yours. That is why the account type and the contract behind it matter more than the brand on the screen.

The Medicare number has a principle of its own: APP 9

Most privacy advice treats every identifier alike. The Privacy Act does not. APP 9 deals separately with government related identifiers, numbers assigned to a person by a Commonwealth agency or a state authority, and the OAIC’s APP guidelines give the Medicare number as the first example.

APP 9.2 says an organisation must not use or disclose a government related identifier unless one of a short list of conditions applies: verifying the individual’s identity, meeting obligations to an agency or authority, a use the law requires or authorises, and a handful of permitted general situations, enforcement and prescribed cases. Polishing a referral letter in a chatbot appears nowhere in it.

A number the model has no use for

That is the best reason to take the number out rather than argue about it. The specialist needs the Medicare number to bill, and it travels in the referral you send from your clinical software. The model drafting the covering prose has no use for it. Leaving it in adds a second principle to defend if the letter ever surfaces, and buys nothing in the draft.

The numbers in a typical letter are not all the patient’s, and different rules apply to them:

identifierwhosethe rule that bites
Medicare numberpatientAPP 9, named by the OAIC as an example
Centrelink CRNpatientAPP 9, named by the OAIC as an example
DVA file numberpatientAPP 9 on the Act’s definition: DVA assigns it
Individual Healthcare Identifierpatientits own Act, with an offence in s 26
hospital UR numberpatientAPP 6, and APP 9 where a public hospital assigned it
Medicare provider numberpractitionerAPP 9 on the Act’s definition: Services Australia assigns it
Ahpra registration numberpractitioneron a public register, still personal information

Sources: Privacy Act 1988, s 6(1) and APP 9; OAIC, APP guidelines chapter 9, paragraph 9.8; Healthcare Identifiers Act 2010 (s 26).

The healthcare identifier is the odd one out, because misusing it can be a criminal offence under its own Act rather than a privacy complaint. The detail, with the penalty, is in the guide for NDIS providers, and it applies to a GP letter just as much.

My Health Record and state health records law

Two more statutes can follow a letter out of the practice, depending on where its content came from and where the practice is. Neither replaces the Privacy Act. Both add to it, and both are easy to forget because they never come up in chatbot marketing.

What came through My Health Record carries its own penalty

If part of the letter was copied out of the patient’s My Health Record, section 59 of the My Health Records Act 2012 goes with it. It prohibits using or disclosing health information obtained through the system unless the Act authorises it, and the offence applies where the person knows or is reckless about that. Section 61 is the authorisation practices rely on every day: collection, use and disclosure for providing healthcare to the patient, within the access controls the patient has set.

Whether putting that content into an overseas chatbot to tidy a letter counts as providing healthcare has not been tested, as far as we could find. The cost of being wrong is written into section 59 itself: an offence carrying up to 5 years’ imprisonment or 300 penalty units or both, and a separate civil penalty of 1,500 penalty units.

1,500
penalty units: the civil penalty in section 59 of the My Health Records Act 2012, compilation of 1 July 2026

In practice, the takeaway is simple. Anything that reached the letter through the My Health Record viewer, such as a shared health summary or a hospital discharge summary, is the part to strip hardest, and the part least worth pasting whole.

Victoria: the letter only has to leave the state

Three jurisdictions add health records statutes that reach private practices. Victoria’s Health Records Act 2001 applies to health information handled by private sector providers, and its Health Privacy Principle 9 covers transborder data flows. The Health Complaints Commissioner summarises it in one line: “When health information travels outside Victoria, the holder has a responsibility to ensure that the privacy of the information is safeguarded.”

Outside Victoria, not outside Australia. A chatbot served from Sydney is already over that line. New South Wales has the Health Records and Information Privacy Act 2002 and the ACT the Health Records (Privacy and Access) Act 1997, and a practice in either should read its own principles before assuming the Privacy Act is the whole story.

lawwhat it addswhat brings it in for a pasted letter
My Health Records Act 2012, s 59no use or disclosure of information obtained through My Health Record unless the Act authorises itcontent copied out of the patient’s My Health Record
Health Records Act 2001 (Vic), HPP 9transborder data flowsthe letter leaving Victoria, even to a chatbot served from Sydney
Health Records and Information Privacy Act 2002 (NSW)its own principlesa practice in New South Wales
Health Records (Privacy and Access) Act 1997 (ACT)its own principlesa practice in the ACT

Sources: My Health Records Act 2012 (Cth), s 59 and s 61; Health Records Act 2001 (Vic); Health Complaints Commissioner (Vic).

Where a given chatbot keeps its data is worth checking tool by tool; for Microsoft’s, see our Copilot guide.

Ahpra lists informed consent among its five principles, and its first case study says that using patient data in a public tool “requires explicit informed consent of the patient/client that their data could be used, viewed and/or sold by others”. Few patients would sign that sentence, and few practices would want to put it in front of them.

That is the most practical argument for taking the patient out of the text. When nothing in the letter identifies anyone, there is far less for a patient to agree to, and the conversation at reception becomes a short one instead of an awkward one.

What still has to be said

Consent does not disappear entirely. Ahpra’s transparency principle and the RACGP resource both expect patients to know AI is part of how the practice works, and the RACGP asks practices to say so in the privacy policy. APP 1.4 already requires that policy to state whether you are likely to disclose personal information overseas and, where practicable, to which countries.

A short passage in the privacy policy and on the new patient form covers most of it. The practice uses AI tools to help draft letters and summaries, identifying details are removed before any text leaves the practice, and a doctor reads everything before it is sent. It is honest, and it describes what the practice actually does. For the policy the passage sits in, you can adapt our AI policy template.

What comes out of a referral letter, in order

The order matters because the first items are mechanical and certain, and the last ones are judgement. Software can take care of the top of the list. Nobody but the author of the letter can do the bottom.

  1. The header block. Name, date of birth, address, phone and email. Replace them with a role and an age band, such as “a woman in her late sixties”.
  2. Government numbers. Medicare, the IHI, the DVA file number and any Centrelink CRN. The model needs none of them.
  3. Practice and hospital numbers. UR numbers, pathology accession numbers, and provider numbers, including your own.
  4. Other people. Relatives, carers and colleagues named in the history, unless the letter needs them to make sense.
  5. Dates that pin the story. Exact admission and discharge dates can become an interval: “admitted for four days in August”.
  6. The detail that identifies on its own. A rare diagnosis, a public role, an occupation that has one holder in a small town.
  7. A final read. Read the text as a stranger with a local newspaper would, and ask whether they could name the patient.
An invented referral to an OT in Nonimo 0.2.8, with the NDIS number and an unlabelled IHI covered
Nonimo 0.2.8 on a Mac, straight after the keypress, on an invented referral to an OT.

That screenshot comes from the referral on our page for NDIS providers, not the GP letter below, but it shows how a covered value looks on screen: a highlighted label, the original on hover, and a click to put it back. In it the NDIS number and an IHI with no label in front are both covered.

What the model needs, and what it never needs

A model drafting a referral needs the clinical question, the findings, the medication list, the relevant history and the tone you want. It never needs the identity. When the draft comes back, the header goes back on in your clinical software, which is also where the letter is signed and sent from, so the full version never leaves the system it belongs in.

For why stripping identifiers falls short of de-identification in the legal sense, read our explainer on de-identified and anonymised data.

A referral letter through Nonimo 0.2.8, before and after

We ran an invented GP referral through Nonimo 0.2.8 on 23 September 2026, on Mac and on Windows, with the same result on both. The patient, the doctors and the clinic do not exist. The Medicare number and the IHI were generated so that they pass their check digits, which is the point of the test.

BEFORE
Dr Ines Kowalczyk, Northcote Family Clinic, Provider No. 4396218Y
Dear Dr Adeyemi,
Re: Mrs Rosalind Featherstonehaugh
Date of birth 14/06/1957. IHI 8003 6068 5969 2414, Medicare 4345 36733 1
44 Banksia Grove, Thornbury VIC 3071. Mobile 0491 570 156, email r.featherstone@example.com
Thank you for seeing Rosalind, a retired school librarian with exertional chest
tightness since July. Her daughter Priya drives her to appointments.

AFTER (Nonimo 0.2.8)
[PERSON_1] [PERSON_2], Northcote Family Clinic, Provider No. [REFERENCE_1]
Dear [PERSON_3],
Re: Mrs [PERSON_4]
Date of birth [BIRTH_DATE_1]. IHI [IHI_1], Medicare [MEDICARE_1]
[ADDRESS_1], [ADDRESS_2]. Mobile [PHONE_1], email [EMAIL_1]
Thank you for seeing [PERSON_5], a retired school librarian with exertional chest
tightness since July. Her daughter Priya drives her to appointments.

Nonimo runs on Mac and Windows. You highlight the letter and press a single key, the identifiers it recognises become labels on that computer, and the real values return when you read the reply. The table that links labels to values stays encrypted on the same machine.

It takes out the identifiers it recognises, not every detail that points at the patient. “A retired school librarian” and her daughter Priya are still in the AFTER, which is why steps four and six of the list above stay with the author, and why the letter is still health information on your side.

What the app keeps on the machine, and how, is set out on Nonimo’s security page, and what we receive from it on our privacy page.

AI scribes are a different question

An AI scribe listens to the consultation and writes the note, and increasingly the letter, inside the scribe vendor’s service. The RACGP treats scribes as a separate subject with a separate resource, and Ahpra’s second case study is a scribing tool that added a plausible diagnosis to a referral letter.

That case turns on other things: whether the tool meets the definition of a medical device and has to be on the ARTG, whether it hallucinated, and who checked the record before signing. The privacy question is the vendor’s contract and the consent of everyone in the room. Nonimo does nothing there, because the audio never passes through text you select. The practical difference between one practitioner’s account and a practice rollout is covered on our page for organisations.

When the letter is drafted in the chatbot after all

Many practices use both. The scribe produces the note, and a clinician then pastes a section into a general chatbot to rewrite it for a patient or a specialist. At that moment the scribe’s contract no longer covers the text, and everything earlier in this guide applies to the paste, from APP 6 to the number in the header.

The question to ask before the letter goes in

Ahpra, the RACGP and the OAIC all arrive at the same test from different directions. Before a letter goes into a chatbot, could anyone reading it on the other side say who it is about?

If the answer is yes, the fix is rarely to give up the tool. It is to take out the header, the numbers and the few details that make one patient recognisable, and to keep the clinical content that makes the draft worth having. The same fix holds for the rest of the sensitive list, which turns up in payslips, leave certificates and CVs rather than in clinical notes.

The obligations around that step, from the privacy policy to the overseas disclosure, are dealt with in the Privacy Act guide on choosing a tool, and the wider picture of what a paste amounts to in our guide to whether it is a data breach.

Sources

Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.

Common questions

What do the Ahpra AI guidelines say about patient data?

The Ahpra AI guidelines, published in August 2024, leave responsibility with the practitioner and expect informed consent before a patient's data goes into an AI tool. Ahpra's first case study, a clinician dictating findings into ChatGPT, warns that a tool storing data offshore could lead to breaches of Australian privacy laws. Nonimo takes care of the mechanical step, replacing the names and numbers it can recognise with placeholders on the practice computer before anything reaches the chatbot.

Can I put patient data into ChatGPT in Australia?

Not the part that identifies the patient, on any reading of the regulators. The OAIC told businesses in October 2024 that the better course is to keep personal information, sensitive information above all, away from public generative AI tools, and every line of a referral letter counts as health information. The clinical content can go in once nobody can be picked out from it. Nonimo covers names and numbers it recognises before the paste, and you judge the rest.

Can a patient's Medicare number go into an AI tool?

It is hard to justify. The Medicare number is a government related identifier, and APP 9.2 permits its use or disclosure only for a short list of purposes, such as verifying identity or meeting obligations to an agency. Drafting a letter in a chatbot is not among them, and the model gains nothing from the number. Nonimo replaces a Medicare number it recognises next to its label without asking, because the check digit confirms it.

Does the RACGP allow GPs to use ChatGPT?

It does not forbid it, and it is cautious. The RACGP resource on conversational AI, last updated in September 2025, lists clinical letters and discharge summaries as possible uses, then says GPs should never enter sensitive or identifying data into such a tool. It also asks practices to mention AI use in their privacy policy. Nonimo is built for that gap: the identifiers come out on the practice computer, the drafting still happens in the chatbot.

Do I need patient consent to use AI for referral letters?

Ahpra expects it where patient data goes into the tool. Its case study says patients should be told how AI will be used and give informed consent before any use, and that putting their data into a public tool needs explicit consent that others could use or view it. Removing identifiers first shrinks what patients are asked to accept. Nonimo does that removal on the computer, and telling patients remains the practice's job.

Why did Perth hospitals stop staff using ChatGPT?

In May 2023 Perth's South Metropolitan Health Service, which covers five hospitals, told staff to stop using AI tools such as ChatGPT for any work involving patient information, because patient confidentiality could not be assured. The service later said a single doctor had used it for one discharge summary, with no breach. Nonimo exists for the step that email described: keeping the patient out of the text before it reaches a public chatbot.

Does taking the name out make a letter safe for AI?

Rarely. A letter still carries the date of birth, the address, the Medicare number and a story that can point at one person in a small town. The Privacy Act asks whether the patient is reasonably identifiable, not whether the name is gone. Nonimo replaces the names and numbers it recognises and shows each change, but an occupation, a rare condition or a relative's first name are judgements it leaves to you.

Does Nonimo work with AI scribes?

No. An AI scribe listens to the consultation and writes the note inside the scribe vendor's service, so the question there is that vendor's contract, the TGA status of the tool and the consent in the room. Nonimo works on text you select on a Mac or Windows computer before it goes into a chatbot such as ChatGPT, Claude or Copilot, which is the case this guide is about: drafting a letter.