Most of us would be very careful about who we allowed into a treatment room.
If another person was sitting in the corner taking notes, we would want to know who they were, why they were there, what they were writing down, where those notes would be kept and whether the patient understood what was happening.
AI is starting to create a similar situation, although in a less visible way.
It may not be physically present in the room, but it can now draft, summarise, listen, transcribe, tidy up correspondence and help produce records. Used carefully, that may be helpful. Most practice owners can see the attraction of anything that reduces admin and gives clinicians a little more breathing space.
The difficulty is that patient information does not become less sensitive because it is being handled by software.
That is really where the new Osgo guide sits. The recent data protection changes are not a reason for panic, and they do not mean every practice needs to start again. The basic principles remain the same. Keep patient information confidential, store it securely, use it lawfully and make sure the team understands their responsibilities.
What has changed is the need to tighten up some of the practical gaps.
A patient asking for “everything you have on me” may be making a Subject Access Request, even if they do not use those words. A broad request may need clarification. A data protection complaint needs a clear internal route. A privacy notice may need updating. An AI tool may be perfectly useful for drafting a staff memo, but completely unsuitable for handling identifiable patient information.
These are not dramatic situations. They are the sort of small, ordinary moments that happen in real practices.
A receptionist receives an email and is unsure whether it counts as a formal request. A clinician removes a patient’s name from a case summary but leaves enough detail for the person to be recognised. Someone tries an AI note-taking system before the practice has checked where the data goes. None of this comes from bad intent. It usually comes from a lack of clear process.
That is why having a simple guide matters.
Not to create more paperwork for the sake of it, but to give the practice a few clear habits. Who handles data requests? What should be logged? What should never be copied into AI? Which systems are approved? How are patients informed if AI is used in documentation? Who checks the final clinical record?
For most clinics, the next step is a short review rather than a major project.
Check the privacy notice. Make sure staff can recognise a Subject Access Request. Put a simple AI use policy in writing. Decide what information must never be uploaded. Review any clinical documentation tools before they become part of the working day.
Good compliance often looks quite ordinary from the outside. It is usually a set of sensible decisions, written down clearly, and understood by the people who actually run the day-to-day clinic.
That is what this guide is designed to help with.