Acceptable AI Use
Approved tools, data classes, staff rules, and enforcement in the working environment.
Workplace assistants
Assistants built into an organization’s approved productivity environment may be considered after identity, sharing, permissions, data boundaries, and licensing are reviewed. For Microsoft 365 tenants, Copilot is considered in this subsection only after a readiness review; it is not enabled immediately or by default.
Other enterprise tools
Enterprise tools outside the core productivity tenant require a documented business owner, security and privacy review, defined data flows, retention terms, access controls, and an approved use case before deployment.
Consumer or unsanctioned tools
Consumer and unapproved tools may not receive organizational data, credentials, ePHI, client matter, or proprietary information. Staff must not install an extension, connect a mailbox, upload a file, or create an account to work around the approved process.
Line-of-business tools after review
A line-of-business tool may be approved when its workflow, vendor terms, access model, data handling, logging, and human review are documented. Approval is specific to the use case and data class; it is not a general permission for every feature.
Purpose
Acceptable AI Use gives Austin and Central Texas clinics and regulated SMBs a usable framework for deciding which tools may be used, what information may enter them, and who reviews the result. The policy belongs in the tenant, endpoints, email, web controls, and daily staff decisions—not in a document no one operates.
AI use must support an approved business purpose, stay within the organization’s data boundaries, and retain accountable human ownership. ALCON can help assess the current environment, write the policy, remediate controls, and establish review evidence. The client remains responsible for business decisions, legal obligations, and the accuracy of its internal policy.
Data classes
Handling and human review must match the sensitivity of the information and the approved workflow.
ePHI
ePHI requires the highest level of care. Staff must not enter ePHI into a public AI site. Any proposed handling must be within a documented, in-scope program with appropriate vendor and data-flow review, controls, and contractual terms.
HR information
Employee records, performance information, compensation, medical information, and candidate data require an approved workflow, limited access, and human review. Do not use a general assistant to make employment decisions.
Financial information
Banking details, payment information, financial statements, tax records, and sensitive forecasts require an approved tool and business owner. Verify outputs and do not use generated content as authorization for a payment or transfer.
Legal information
Client matter, privileged communications, contracts under review, and legal advice require approved handling and human review. Do not assume that a tool’s label or account type establishes privilege or confidentiality.
Public marketing information
Publicly released marketing material may be used only when the workflow is approved and the content is reviewed before publication. Public status does not remove the need to check accuracy, rights, confidential context, or misleading claims.
Staff rules
- Use only tools and workflows approved for the task and data class.
- Do not enter ePHI, credentials, secrets, client matter, HR, financial, or legal information into a public or unsanctioned tool.
- Minimize data. Remove names, identifiers, account numbers, unnecessary context, and attachments when an approved workflow permits use.
- Verify output before it is sent, filed, published, acted on, or used in a client or clinical workflow. A person remains accountable.
- Do not use generated output as the sole basis for a clinical, employment, legal, financial, access, or security decision.
- Report an accidental disclosure, unexpected tool behavior, incorrect output, or suspected policy violation promptly through the organization’s normal escalation path.
- Do not connect an assistant to a mailbox, shared drive, site, device, or line-of-business system without documented approval and an owner.
Vendor and Business Associate notes
Vendor review must cover data location and flows, retention and deletion, access and administration, model or service use, logging, incident notification, subcontractors, and export or revocation. Contract language and a Business Associate Agreement may be required for in-scope services involving ePHI; a product label alone is not enough.
ALCON DTS signs a Business Associate Agreement for in-scope services. The covered entity retains its legal obligation, and vendor/data-flow decisions remain part of the documented HIPAA program. See Healthcare IT and HIPAA consulting.
Enforcement in the working environment
Policy works when it is connected to technical controls and operating routines. Depending on the environment and approved scope, enforcement may include:
Connect policy decisions to technical controls and operating routines across the working environment.
Microsoft 365
Entra roles and MFA, sharing, guest access, Purview/DLP, retention, audit logs, and license hygiene.
Mailbox permissions, attachment and link protections, authentication, reporting, and escalation.
Endpoints
Managed Windows, macOS, iPhone, and iPad devices, approved applications, updates, encryption, and endpoint protection.
Web controls
Approved-site categories, access restrictions where appropriate, DNS or browser controls, and monitoring aligned with policy.
Review cadence
Review the policy at least annually and whenever a material change occurs: a new tool or connector, a new data class or workflow, a vendor or contract change, an incident, or a significant tenant or endpoint change. Operational teams should review exceptions and evidence on a regular cadence appropriate to risk, with owners and due dates recorded.
Put acceptable use into operation
Policy works when it is connected to the tenant, endpoints, email, web controls, and daily staff decisions.
Call 512-892-6900 · Email info@alcondts.com











