AI and Generative Technology Use at CUIMC

As we embrace innovative technologies to support the Columbia University Irving Medical Center's (CUIMC) mission, it is crucial to understand the responsible use of AI and generative technology tools at CUIMC to ensure compliance with healthcare regulatory standards and to safeguard sensitive information. Start by selecting your role for tailored guidance on the responsible, compliant use of Artificial Intelligence (AI) and generative technology tools across Columbia University Irving Medical Center, then use the shared reference sections below.

Find Guidance for Your Role

Clinicians

AI may support clinical work, but any information that could identify a patient is Protected Health Information (PHI) and may only be entered into tools approved for Sensitive Data.

Tools You Can Use
Columbia ChatGPT Education, Microsoft Copilot (approved products), CU CHAT (OpenAI models), AWS Bedrock (compliant architecture).

See the full AI Tools × Data Classification matrix below for exactly which edition of each tool is approved for PHI. Additional AI tools available and approved for clinical use through NYP are listed here.

Do 

Don't 

  • Paste patient identifiers into non-approved or personal tools.
  • Assume a tool available through CUIT is cleared for PHI at CUIMC.

How To Get a Clinical Use Case Approved
​​
Submit to the CUIMC IT PMO request process → CUIMC IT PMO routes to the NYP IT PMO → reviewed by the Tri-Institutional AI Governance Committee as appropriate.

Training for You

Researchers

Research data may include Sensitive Data such as Research Health Information (RHI). These may only be used in approved environments, and protocol use carries additional review requirements.

Tools You Can Use

Columbia ChatGPT Education, Microsoft Copilot (approved products), CU CHAT (OpenAI models), AWS Bedrock & Bedrock AgentCore (build/deploy), Gemini/Gemini Notebook Enterprise in GCP (CUIMC IT).

See the full AI Tools × Data Classification matrix below for exactly which edition of each tool is approved for RHI.

Do

Don't

  • Enter RHI or identifiable participant data into non-approved tools.
  • Deploy locally installed models without an IT Risk Assessment.

How To Get a Research Use Case Approved

Submit through your existing IRB process → routed to the CUIMC AIGC for review as appropriate. Research protocol use of Sensitive Data requires IRB and TRAC/ACORD approval.

Training for You

Faculty, Students & Trainees

For coursework and study, use tools approved for the classification of data you are using. Always follow your program's academic integrity rules.

Although FERPA data such as student education records generally fall under the Confidential data classification, elements such as a student's identifying or health information are PII or PHI which are classified as Sensitive; when this overlap occurs, the higher data sensitivity classification and tool restrictions apply.

See the full AI Tools × Data Classification matrix below for exactly which edition of each tool is approved for each data class.

Tools You Can Use

Columbia ChatGPT Education, CU CHAT, Microsoft Copilot, Gemini, Gemini Notebook, Claude — non-sensitive data only.

Do

Don't

  • Enter patient data, clinical cases with identifiers, or classmates' personal information into tools not approved for Sensitive Data.
  • Rely on AI output without verifying it against authoritative sources.

How To Get Help or Approval

For general questions, email 5HELP (5help@cumc.columbia.edu). For educational use cases involving sensitive data, submit a request through the CUIMC IT PMO request process.

Training for You

Administrative Staff

Administrative work often involves Confidential and Internal data (policies, drafts, financial, HR, student records). Use approved tools, and remember that some administrative data is Sensitive Data.

See the full AI Tools × Data Classification matrix below for exactly which edition of each tool is approved for each data class.

Tools You Can Use

Columbia ChatGPT Education, Microsoft Copilot (approved products), CU CHAT.

Do

Don't

  • Put any Non-Public Data into unapproved AI tools.
  • Share financial, HR, or student records outside approved, authenticated tools.

How To Get an Administrative Use Case Approved

Submit Educational and Administrative use cases through the CUIMC IT PMO request process; CUIMC IT and relevant review groups evaluate compliance, security, and data-handling risks. General questions → 5HELP.

Training for You

Guidelines

Related Policies

AI Tools × Data Classification: What Each Tool Is Approved For

This matrix shows, for each AI tool, which classes of data it is approved to be used with at CUIMC. Available from indicates whether the tool is provisioned by CUIT (broader University) or CUIMC IT. Note how the same brand can differ: e.g., Google Gemini/Gemini Notebook in Google Workspace (CUIT) is not approved for Sensitive Data, while the Enterprise editions in GCP (CUIMC IT) are — a direct illustration of the HIPAA difference explained above.

As mentioned above, due to CUIMC's risk management posture, the approval for use of tools with Sensitive Data may be different than the University's general posture, which is documented here.

Because AI platforms evolve rapidly, protecting patient and institutional data is a shared responsibility. Users are expected to exercise sound judgment and comply with HIPAA and University policy whenever using AI tools. Safe and compliant use depends on both the technology and the judgment of each user.

Although CUIMC IT has implemented technical safeguards to reduce the risk of inappropriate data sharing, no technical control can fully prevent accidental disclosure of sensitive information as new features are introduced. AI vendors frequently introduce new capabilities through software updates. New features may become available before CUIMC IT has completed a security review. The presence of a feature in the application does not imply that it has been evaluated or approved for use with regulated or sensitive institutional information.

Legend: approved  ·  not approved  ·  footnote markers (*, **) explained below the table.

Tool Approved for use at CUIMC Sensitive Data (PHI, PII, RHI) Confidential** / Internal Public Available from
End User Assistants (Chat, Productivity & Research)
Personal / Non-UNI LLMs (personal ChatGPT, Gemini, etc.) Personal
Columbia ChatGPT Education CUIT
CU CHAT ✓* CUIT
Google Gemini in Google Workspace CUIT
Google Gemini Notebook in Google Workspace CUIT
Columbia Claude for Education CUIT
Microsoft Copilot Chat CUIMC IT
Microsoft M365 Copilot CUIMC IT
Microsoft Copilot in Fabric CUIMC IT
Google Gemini Enterprise 
(coming soon)
CUIMC IT
Google Gemini Notebook Enterprise 
(coming soon)
CUIMC IT
Anthropic Claude Desktop [Chat] CUIMC IT
OpenAI ChatGPT Desktop [Chat] CUIMC IT
Autonomous and Coding Agents ***
OpenAI ChatGPT Desktop [Codex] CUIMC IT
Anthropic Claude Desktop [Code] CUIMC IT
OpenAI ChatGPT Desktop [Work] CUIMC IT
Anthropic Claude Desktop [CoWork] CUIMC IT
Developer and Enterprise Platforms
OpenAI ChatGPT Education API ✓** CUIT
Claude API for Education CUIT
Amazon AWS Bedrock ✓*** CUIMC IT
Microsoft Copilot Studio CUIMC IT
GitHub Copilot in VS Code CUIMC IT

Visual Indicators In Approved AI Tools

To help users confirm they are using the approved software versions, visual indicators are displayed within the interfaces of some CUIMC-sanctioned AI tools. Users should always verify these indicators before entering any CUIMC-related data. If these elements are missing, you may not be using the approved instance. In such cases, immediately stop and report any issue to CUIMC IT Security Office

  • Columbia ChatGPT Education: Displays the Columbia University logo(1) at the bottom left of the interface.
  • Microsoft Copilot**: Displays a shield icon (may appear as a green outline with a checkmark(2), a grey outline on a white background(3)  or a white outline on a dark background(4), depending on the device) in the chat interface, indicating that Enterprise Data Protection applies to the session. Additionally, confirm your CUIMC email address, indicating you are logged into the CUIMC account.
Icons that represent AI tools at CUIMC

 

Governance

Reviews of AI-related requests are based on the use case and nature of the request.

If your use case is… Submit via…
General questions about availability and use Email 5HELP (5help@cumc.columbia.edu)
Educational & Administrative CUIMC IT PMO request process; CUIMC IT and relevant review groups evaluate compliance, security, and data-handling risks.
Research Existing IRB process(es); routed to the CUIMC AIGC for review as appropriate.
Clinical CUIMC IT PMO request process → guided to the NYP IT PMO → routed to the Tri-Institutional AI Governance Committee as appropriate.

Training Modules

Other Resources

Additional Guidance

All use of AI, Large Language Models (LLM), Natural Language Processors (NLP), or Machine Learning (ML) systems at the Medical Center must comply with HIPAA and other relevant healthcare and IT regulations to uphold the highest standards of patient privacy and data security. For locally installed AI models, a formal IT Risk Assessment review is required before deployment to evaluate potential security, privacy, and compliance risks.

CUIMC IT may monitor AI software usage to ensure compliance with these guidelines. When generating AI content for audiences beyond your immediate use, verify all AI-generated information through authoritative sources and report its use in approved research activities. This practice ensures information integrity and helps avoid AI-related negative outcomes such as the dissemination of inaccuracies or biases.

Should you have questions regarding AI tools, become aware of any data exposures or misuse of sensitive information, or need to report issues verifying approved tool instances, contact the CUIMC IT Security Office.

Back to top