
Shared AI runs on a vendor's multi-customer servers, so resident data leaves your control. Private AI runs on a server in your facility or a private cloud dedicated to you, often using open-source models, so no outside AI company receives the data. Under HIPAA, any vendor that handles resident information on your behalf is a business associate and needs a signed BAA, even if the data is encrypted.
Almost every AI vendor pitching a nursing facility says some version of "your data is safe with us." For a DON or administrator, that phrase is hard to evaluate. Where does the resident information actually go? Who can see it? Is it used to train someone else's model? This guide explains the difference between shared AI and private AI in plain terms, and gives you the questions to ask before any resident information touches an AI tool.
What is the difference between shared AI and private AI?
Shared AI is a model that runs on a vendor's servers and serves many customers at once. Consumer chatbots are the most familiar example. Your text is sent over the internet, processed on infrastructure you don't control, and the vendor's terms decide how long it is kept and how it can be used.
Private AI is a model that runs in an environment dedicated to you: a server inside your facility, or a private cloud environment reserved for your organization. Many private deployments use open-source models, whose weights can be downloaded and run on your own hardware, so no outside AI company needs to receive the data at all.
| Shared (public) AI | Private AI | |
|---|---|---|
| Where it runs | The vendor's multi-customer servers | Your facility's server or a private cloud dedicated to you |
| Who receives resident data | The AI vendor, plus any subprocessors | Only systems inside your controlled environment |
| Training on your data | Depends on the vendor's terms and settings | No outside model is trained on it |
| HIPAA paperwork | Requires a Business Associate Agreement (BAA) with the vendor before any PHI is shared | A BAA still applies to any vendor that hosts or supports the system |
| Best for | General tasks with no resident information | Work that touches charts, referrals and nursing notes |
Does HIPAA allow nurses to use AI chatbots?
HIPAA does not ban AI, but it controls who can receive protected health information (PHI). Under HHS guidance, a cloud service provider that "creates, receives, maintains, or transmits" electronic PHI on behalf of a covered entity is a business associate, and a Business Associate Agreement is required.1 That applies even when the data is encrypted and the provider doesn't hold the key.1
In practice, that means a nurse pasting a resident's details into a consumer chatbot, with no BAA in place, creates a real compliance problem, however well-intentioned. The fix is not "never use AI." It is to use AI tools that were set up for PHI from the start.2
What does "your data never leaves the building" actually mean?
When a vendor says it, ask them to show you where each of these happens:
- Where the model runs. On a server in your facility, in a private cloud environment dedicated to you, or on the vendor's shared infrastructure?
- Where documents are stored. Referral packets, notes and summaries should sit in the same controlled environment as the model.
- What leaves the environment. Ideally nothing containing PHI. Updates and monitoring should not require copying resident data out.
- Whether any outside AI service is called. Some "private" products still forward text to a public AI provider in the background. Ask directly.
- Training. Confirm in writing that resident data is not used to train any model outside your environment.
- Access and audit. Who can see summaries, and is every view logged?
Questions to ask any AI vendor before sharing resident data
- Will you sign a Business Associate Agreement?1,2
- Can the system run on our own server or in a private cloud dedicated to us?
- Does any resident information ever go to a shared or public AI model?
- Is our data used to train or improve models for other customers?
- Can nurses see the source page behind every AI-generated statement?
- What happens to our data if we end the contract?
How ChartRail handles this
ChartRail runs a private, open-source language model on a server inside your facility or in a private cloud environment dedicated to you. It reads the EHR and referral packets you already have, and sends nothing to shared public AI. Every line in a handoff summary links back to its source page, so nurses can verify it before acting on it.
This article is general information, not legal advice. Talk with your compliance officer or counsel about your facility's specific obligations.
Frequently asked questions
What is private AI in healthcare?
Private AI is an AI model that runs in an environment dedicated to one organization, such as a server inside the facility or a private cloud, so patient data is not sent to a shared public AI service.
Can nurses put resident information into ChatGPT or other public chatbots?
Not without the right agreements in place. Under HIPAA, a service that receives protected health information on a facility's behalf is a business associate and requires a Business Associate Agreement. Consumer chatbot use without one creates compliance risk.
Is a BAA needed if the AI vendor encrypts the data?
Yes. HHS guidance says lacking an encryption key does not exempt a cloud service provider from business associate status, so a BAA is still required.
What is an open-source AI model?
An open-source model is one whose weights are publicly available, so an organization can download it and run it on its own hardware instead of sending data to the model's creator.
How can a nursing facility check whether an AI vendor is really private?
Ask where the model runs, where documents are stored, whether any outside AI service is called, whether data is used for training, and whether the vendor will sign a BAA.
Book a 30-minute demo with our founders, or ask about our design partner program.
Book a demo