# Our House AI Governance Discussion Guide

**Working session:** Monday, August 17, 2026 — Individual frame  
**Purpose:** establish a practical plan for safe AI use and identify the questions that must be answered before PHI (protected health information, such as private health details) or other sensitive data enters an AI task.

## Opening principle

A tool is not safe just because it says “HIPAA compliant.” Our House needs to check the exact plan, account, setup, data, task, and review process.

This is a working discussion guide, not a legal opinion, HIPAA determination, Business Associate Agreement, security assessment, or production approval.

## Monday outcome

Each Champion leaves with:

1. One real workflow stated clearly.
2. One safe first experiment.
3. One data boundary identified.
4. One human review point.
5. One measure of success.

The group leaves with a preliminary list of workflows that are green to explore, amber pending verification, or red until formally approved.

## The five governance layers

### 1. Policy

- What may employees do today?
- What is restricted or prohibited?
- What requires manager, IT, compliance, legal, or executive approval?
- Who owns policy updates and staff training?

### 2. Platform

- Which exact ChatGPT, Copilot, or Claude plan and tenant are being used?
- Is the account organization-managed or personal?
- What administrator controls, retention settings, connectors, and audit tools are available?
- Can access be revoked when an employee changes roles or leaves?

### 3. Data

- What data is public, internal, confidential, employee, financial, resident, or PHI?
- What is the minimum necessary data for the workflow?
- Can the first prototype use a sanitized or approved export?
- Where is data stored, retained, deleted, backed up, and logged?

### 4. Workflow

- May AI draft, summarize, classify, retrieve, recommend, or execute?
- What may the system never decide or change?
- Where must a named human review and approve?
- What happens when the output is incomplete, wrong, or unavailable?

### 5. Oversight

- Who owns the workflow?
- Who reviews the output?
- What evidence shows that it is safe and useful?
- How are errors, incidents, access changes, and model changes handled?

## Traffic-light working rule

### Green — explore now

Public information, generic training, brainstorming, de-identified examples, and administrative work that contains no sensitive data.

### Amber — verify first

Internal documents, employee information, operational reports, finance exports, resident-adjacent workflows, connectors, shared assistants, and agents using organizational context.

### Red — hold until approved

PHI, clinical records, medication data, resident identifiers, physician orders, autonomous chart changes, autonomous corrective action, or automatic external communication.

## Questions for IT, compliance, and leadership

- Is Our House the covered entity, and is the vendor acting as a business associate for the proposed use?
- Is a signed BAA (Business Associate Agreement, a contract for handling PHI) required, and if so, is it in place for the exact product and plan?
- Is customer data excluded from model training?
- What are the retention, deletion, backup, and residency rules?
- Are access controls role-based and identity-linked?
- Are prompts, outputs, tool calls, and agent actions auditable?
- Can administrators disable a workflow or revoke access quickly?
- What incident-response and breach-notification process applies?
- What is the human approval step before consequential action?
- What evidence is required before moving from a sandbox or export-first pilot to production data?

## Key terms

### HIPAA

**Health Insurance Portability and Accountability Act.** This is a U.S. law that sets rules for protecting private health information.

### PHI

**Protected health information.** This means private health details that can identify a person, such as care records, medicine information, or a resident’s name tied to care.

### BAA

**Business Associate Agreement.** This is a contract that sets rules for a company that handles PHI for a health care organization.

### Covered entity

A health care provider, health plan, or health care clearinghouse that must follow HIPAA rules.

### Business associate

A company that handles PHI for a covered entity, such as a service or software company.

### De-identified data

Data changed so it cannot reasonably be used to identify a person.

### Sanitized data

Data cleaned to remove private details that are not needed for the task.

### Tenant

The company’s separate space inside a shared software system.

### Role-based access

Giving people only the system access they need for their job.

### Audit log

A record that shows who used a system, what they did, and when they did it.

### Data retention

How long a system keeps data before it deletes it.

### Data residency

The country or region where data is stored and handled.

### Incident response

The steps a company takes when something goes wrong or data may be at risk.

### Breach notification

The required notice when private data may have been seen, lost, or stolen.

### Sandbox

A separate test space where people can try a tool without using live company data.

### Production

The real work system used with live company data and real tasks.

### Autonomous

Work done by AI on its own, without a person checking each step first.

## Safe first-pilot pattern

1. Select one recurring workflow with a clear owner and measurable burden.
2. Use a sanitized or approved export.
3. Produce a review queue, draft, comparison, or recommendation—not an autonomous decision.
4. Require named human review before any action.
5. Record inputs, outputs, corrections, time, errors, and exceptions.
6. Review the evidence with IT, compliance, and leadership.
7. Decide whether to stop, revise, expand, or pursue a governed production configuration.

The leading candidate is an export-first MedCart audit comparison. The fastest low-risk productivity proof is Tish’s approval-response tracking workflow. Neither should be described as approved for PHI until the relevant platform and organizational controls are verified.

## Day One practice: build a Color Check skill

Each Champion can build a small skill called **AI Use Color Check**. It can live in ChatGPT, Claude, or a Microsoft Copilot compliance agent. Its job is to help sort an idea—not to give legal approval.

### What the skill should ask

1. What task do you want help with?
2. What data would the task use?
3. Would the data include PHI, resident details, staff details, money data, or other private data?
4. What would AI do: draft, sum up, find, suggest, or act?
5. Who will check the result before anything important happens?

### How it should sort the idea

- **GREEN — Try it now:** Public or basic training data, no private details, and a person checks the result.
- **YELLOW — Check first:** Internal, staff, money, or resident-related data; a shared tool; or unclear access, storage, or review rules.
- **RED — Stop for approval:** PHI, care records, medicine data, resident IDs, AI-made chart changes, automatic discipline, or outside messages sent by AI.

### Starter instructions

> You are the AI Use Color Check skill. Ask the five questions above. Sort the idea as GREEN, YELLOW, or RED. Give three short reasons. Name the data risk, the human review step, and the next safe action. Never say an idea is legally approved. If you cannot tell, choose YELLOW and say what must be checked.

### Practice

Use the skill on one real work idea, with names and private details removed. Save the result. Then compare answers as a group. The goal is to learn what makes a use case safe, what needs a check, and what must wait.
