AI in General Practice: What You Need to Check Before Go-Live

AI is becoming part of everyday primary care.  Practices are using it to draft consultation notes, summarise information, manage workflow, prepare correspondence and support clinical and administrative tasks.

That brings real opportunities.  It also raises a common question:

“Do we need a DPIA?”

A Data Protection Impact Assessment, or DPIA, should not be seen as a barrier to innovation.  Done properly, it helps a practice understand what the technology is doing, identify risks early and put sensible safeguards in place.

When is a DPIA needed?

Under UK data protection law, a DPIA is required where proposed processing is likely to create a high risk to people's rights and freedoms.

The practice should ask:

“What is changing, what personal information is involved, and could this create a significant risk for patients or staff?”

Not every use of AI automatically needs a DPIA.  However, the ICO identifies AI as innovative technology.  Where its use is combined with another recognised high-risk factor, such as sensitive health information, a DPIA is required.

If a practice decides that a DPIA is not required, that decision should still be recorded.  A short screening assessment can show how the decision was reached.

What about common AI uses?

The product name does not decide whether a DPIA is required.  Using Copilot to draft a generic meeting agenda is very different from asking it to analyse patient information.  What matters is how the tool is used, what information is involved and what risks it creates.

Pseudonymised information can still be personal data under UK GDPR.

What should a good DPIA cover?

A good DPIA should tell the story of the processing in plain English.

It should explain what the AI does, why it is being used, what information is involved, where it goes, who processes it and how it is protected.

It should also consider:

  • The lawful basis for processing
  • The Article 9 condition for health information
  • Whether patients are clearly informed
  • Retention and international processing
  • Whether information can be used to train or improve the AI
  • How AI-generated outputs are checked
  • What happens if the AI gets something wrong; and
  • How changes to the system will be reviewed.

Most importantly, a DPIA should focus on risks to people, not just risks to the organisation.  An inaccurate summary could affect care, while poor transparency could leave patients unaware of what is happening to their data.

A DPIA is not the whole assurance process

Completing a DPIA does not mean an AI product is automatically ready to go live.

Where DCB0160 applies, the practice must also manage the clinical risks of deploying and using the system.  This includes appropriate Clinical Safety Officer, or CSO, involvement and completion of the required clinical safety documentation, such as the clinical safety case and hazard log.

The DPIA and clinical safety assessment look at different risks:

The DPIA asks: “Could the way people's information is being used cause harm?”

The clinical safety assessment asks: “Could using this technology contribute to unsafe care?”

An AI system might be secure from a data protection perspective but still create a clinical risk if it produces an incorrect summary or misses important information.  For clinical AI, both assessments matter.  One does not replace the other.

AI scribes are a good example.  Practices should understand whether audio is retained, where processing takes place, how notes are checked and how patients are informed.  The clinician remains responsible for reviewing the final clinical record.

What about due diligence?

A DPIA is only one part of deciding whether an AI product is suitable.

Before implementation, practices should obtain enough evidence to understand both the technology and the organisation supplying it. Depending on the product, this may include reviewing relevant DTAC evidence, DSPT status, DCB0129 clinical safety documentation, cyber security assurance and contractual arrangements.

Practices should also understand where information is hosted, whether subprocessors are involved, whether data leaves the UK, how long information is retained and whether patient information can be used for model training or development.

A supplier saying that a product is “GDPR compliant” is not enough. The practice needs evidence that the product, configuration and proposed use have been properly assessed.

What about ChatGPT and Copilot?

Using an AI assistant to draft a generic policy or training document is very different from entering patient or staff information into it.

Practices should not put identifiable or confidential information into an AI service simply because it is readily available.  The specific product, licence or configuration, contractual arrangements, data flows and intended use should first be assessed and authorised.

A personal or free account should not be treated as interchangeable with an organisation-approved enterprise service.

When should the DPO and CSO be involved?

Early.

The best time to involve the DPO and, where relevant, the CSO is before the system goes live and while there is still time to influence how it will be used.

The DPO advises on data protection risks and whether a DPIA is required.  The CSO considers clinical safety risks where DCB0160 applies.  The practice remains accountable for deciding whether the technology is suitable and safe to use.

The bottom line

AI can bring real benefits to general practice.  Good governance should help practices use that technology safely, not make innovation unnecessarily difficult.

A DPIA is an important part of that process, but it is not the whole process.

Ask yourself:

“Do you understand what the AI is doing with people's information, what could go wrong from a data protection or clinical safety perspective, and what safeguards are in place?”

If the answer is yes, the assurance process has done its job.  If the answer is no, it has probably shown you what still needs to be resolved before you press “go live”.

Share