Privacy and AI

Private AI vs. shared AI in a nursing facility

· ChartRail team · 5 min read
A small private server cabinet in a bright healthcare office
The short answer

Shared AI runs on a vendor's multi-customer servers, so resident data leaves your control. Private AI runs on a server in your facility or a private cloud dedicated to you, often using open-source models, so no outside AI company receives the data. Under HIPAA, any vendor that handles resident information on your behalf is a business associate and needs a signed BAA, even if the data is encrypted.

Almost every AI vendor pitching a nursing facility says some version of "your data is safe with us." For a DON or administrator, that phrase is hard to evaluate. Where does the resident information actually go? Who can see it? Is it used to train someone else's model? This guide explains the difference between shared AI and private AI in plain terms, and gives you the questions to ask before any resident information touches an AI tool.

What is the difference between shared AI and private AI?

Shared AI is a model that runs on a vendor's servers and serves many customers at once. Consumer chatbots are the most familiar example. Your text is sent over the internet, processed on infrastructure you don't control, and the vendor's terms decide how long it is kept and how it can be used.

Private AI is a model that runs in an environment dedicated to you: a server inside your facility, or a private cloud environment reserved for your organization. Many private deployments use open-source models, whose weights can be downloaded and run on your own hardware, so no outside AI company needs to receive the data at all.

Shared (public) AIPrivate AI
Where it runsThe vendor's multi-customer serversYour facility's server or a private cloud dedicated to you
Who receives resident dataThe AI vendor, plus any subprocessorsOnly systems inside your controlled environment
Training on your dataDepends on the vendor's terms and settingsNo outside model is trained on it
HIPAA paperworkRequires a Business Associate Agreement (BAA) with the vendor before any PHI is sharedA BAA still applies to any vendor that hosts or supports the system
Best forGeneral tasks with no resident informationWork that touches charts, referrals and nursing notes

Does HIPAA allow nurses to use AI chatbots?

HIPAA does not ban AI, but it controls who can receive protected health information (PHI). Under HHS guidance, a cloud service provider that "creates, receives, maintains, or transmits" electronic PHI on behalf of a covered entity is a business associate, and a Business Associate Agreement is required.1 That applies even when the data is encrypted and the provider doesn't hold the key.1

In practice, that means a nurse pasting a resident's details into a consumer chatbot, with no BAA in place, creates a real compliance problem, however well-intentioned. The fix is not "never use AI." It is to use AI tools that were set up for PHI from the start.2

"Your data never leaves the building" should be a statement about architecture, not a promise in a sales deck.

What does "your data never leaves the building" actually mean?

When a vendor says it, ask them to show you where each of these happens:

Questions to ask any AI vendor before sharing resident data

How ChartRail handles this

ChartRail runs a private, open-source language model on a server inside your facility or in a private cloud environment dedicated to you. It reads the EHR and referral packets you already have, and sends nothing to shared public AI. Every line in a handoff summary links back to its source page, so nurses can verify it before acting on it.

This article is general information, not legal advice. Talk with your compliance officer or counsel about your facility's specific obligations.

Frequently asked questions

What is private AI in healthcare?

Private AI is an AI model that runs in an environment dedicated to one organization, such as a server inside the facility or a private cloud, so patient data is not sent to a shared public AI service.

Can nurses put resident information into ChatGPT or other public chatbots?

Not without the right agreements in place. Under HIPAA, a service that receives protected health information on a facility's behalf is a business associate and requires a Business Associate Agreement. Consumer chatbot use without one creates compliance risk.

Is a BAA needed if the AI vendor encrypts the data?

Yes. HHS guidance says lacking an encryption key does not exempt a cloud service provider from business associate status, so a BAA is still required.

What is an open-source AI model?

An open-source model is one whose weights are publicly available, so an organization can download it and run it on its own hardware instead of sending data to the model's creator.

How can a nursing facility check whether an AI vendor is really private?

Ask where the model runs, where documents are stored, whether any outside AI service is called, whether data is used for training, and whether the vendor will sign a BAA.

See ChartRail run a real shift handoff.

Book a 30-minute demo with our founders, or ask about our design partner program.

Book a demo