Acceptable AI Use

Approved tools, data classes, staff rules, and enforcement in the working environment.

Team discussing workplace tools and workflow

Workplace assistants

Assistants built into an organization’s approved productivity environment may be considered after identity, sharing, permissions, data boundaries, and licensing are reviewed. For Microsoft 365 tenants, Copilot is considered in this subsection only after a readiness review; it is not enabled immediately or by default.

Learn more
Enterprise workplace with technology workstations

Other enterprise tools

Enterprise tools outside the core productivity tenant require a documented business owner, security and privacy review, defined data flows, retention terms, access controls, and an approved use case before deployment.

Learn more
Padlock on a keyboard representing blocked unsanctioned access

Consumer or unsanctioned tools

Consumer and unapproved tools may not receive organizational data, credentials, ePHI, client matter, or proprietary information. Staff must not install an extension, connect a mailbox, upload a file, or create an account to work around the approved process.

Learn more
Colleagues reviewing a line-of-business workflow

Line-of-business tools after review

A line-of-business tool may be approved when its workflow, vendor terms, access model, data handling, logging, and human review are documented. Approval is specific to the use case and data class; it is not a general permission for every feature.

Learn more

Purpose

Acceptable AI Use gives Austin and Central Texas clinics and regulated SMBs a usable framework for deciding which tools may be used, what information may enter them, and who reviews the result. The policy belongs in the tenant, endpoints, email, web controls, and daily staff decisions—not in a document no one operates.

AI use must support an approved business purpose, stay within the organization’s data boundaries, and retain accountable human ownership. ALCON can help assess the current environment, write the policy, remediate controls, and establish review evidence. The client remains responsible for business decisions, legal obligations, and the accuracy of its internal policy.

Person reviewing a policy checklist

Data classes

Handling and human review must match the sensitivity of the information and the approved workflow.

Clinician using a mobile device in a healthcare setting

ePHI

ePHI requires the highest level of care. Staff must not enter ePHI into a public AI site. Any proposed handling must be within a documented, in-scope program with appropriate vendor and data-flow review, controls, and contractual terms.

Learn more

HR information

Employee records, performance information, compensation, medical information, and candidate data require an approved workflow, limited access, and human review. Do not use a general assistant to make employment decisions.

Learn more

Financial information

Banking details, payment information, financial statements, tax records, and sensitive forecasts require an approved tool and business owner. Verify outputs and do not use generated content as authorization for a payment or transfer.

Learn more

Legal information

Client matter, privileged communications, contracts under review, and legal advice require approved handling and human review. Do not assume that a tool’s label or account type establishes privilege or confidentiality.

Learn more

Public marketing information

Publicly released marketing material may be used only when the workflow is approved and the content is reviewed before publication. Public status does not remove the need to check accuracy, rights, confidential context, or misleading claims.

Learn more

Staff rules

  1. Use only tools and workflows approved for the task and data class.
  2. Do not enter ePHI, credentials, secrets, client matter, HR, financial, or legal information into a public or unsanctioned tool.
  3. Minimize data. Remove names, identifiers, account numbers, unnecessary context, and attachments when an approved workflow permits use.
  4. Verify output before it is sent, filed, published, acted on, or used in a client or clinical workflow. A person remains accountable.
  5. Do not use generated output as the sole basis for a clinical, employment, legal, financial, access, or security decision.
  6. Report an accidental disclosure, unexpected tool behavior, incorrect output, or suspected policy violation promptly through the organization’s normal escalation path.
  7. Do not connect an assistant to a mailbox, shared drive, site, device, or line-of-business system without documented approval and an owner.
Staff attending a workplace training session
Colleagues reviewing vendor information on laptops

Vendor and Business Associate notes

Vendor review must cover data location and flows, retention and deletion, access and administration, model or service use, logging, incident notification, subcontractors, and export or revocation. Contract language and a Business Associate Agreement may be required for in-scope services involving ePHI; a product label alone is not enough.

ALCON DTS signs a Business Associate Agreement for in-scope services. The covered entity retains its legal obligation, and vendor/data-flow decisions remain part of the documented HIPAA program. See Healthcare IT and HIPAA consulting.

Enforcement in the working environment

Policy works when it is connected to technical controls and operating routines. Depending on the environment and approved scope, enforcement may include:

Connect policy decisions to technical controls and operating routines across the working environment.

Workplace administration dashboard on a monitor

Microsoft 365

Entra roles and MFA, sharing, guest access, Purview/DLP, retention, audit logs, and license hygiene.

Learn more

Email

Mailbox permissions, attachment and link protections, authentication, reporting, and escalation.

Learn more

Endpoints

Managed Windows, macOS, iPhone, and iPad devices, approved applications, updates, encryption, and endpoint protection.

Learn more

Web controls

Approved-site categories, access restrictions where appropriate, DNS or browser controls, and monitoring aligned with policy.

Learn more

Review cadence

Review the policy at least annually and whenever a material change occurs: a new tool or connector, a new data class or workflow, a vendor or contract change, an incident, or a significant tenant or endpoint change. Operational teams should review exceptions and evidence on a regular cadence appropriate to risk, with owners and due dates recorded.

Calendar open for a scheduled review

Put acceptable use into operation

Policy works when it is connected to the tenant, endpoints, email, web controls, and daily staff decisions.

Call 512-892-6900 · Email info@alcondts.com

Request a tenant reviewSee AI Readiness