AI and Generative Technology Use at CUIMC
As we embrace innovative technologies to support the Columbia University Irving Medical Center's (CUIMC) mission, it is crucial to understand the responsible use of AI and generative technology tools at CUIMC to ensure compliance with healthcare regulatory standards and to safeguard sensitive information. Start by selecting your role for tailored guidance on the responsible, compliant use of Artificial Intelligence (AI) and generative technology tools across Columbia University Irving Medical Center, then use the shared reference sections below.
Find Guidance for Your Role
Clinicians
AI may support clinical work, but any information that could identify a patient is Protected Health Information (PHI) and may only be entered into tools approved for Sensitive Data.
Tools You Can Use
Columbia ChatGPT Education, Microsoft Copilot (approved products), CU CHAT (OpenAI models), AWS Bedrock (compliant architecture).
See the full AI Tools × Data Classification matrix below for exactly which edition of each tool is approved for PHI. Additional AI tools available and approved for clinical use through NYP are listed here.
Do
- Draft or summarize clinical documentation only inside PHI-approved tools using your CUIMC account.
- Verify the on-screen approval indicator where applicable before entering any patient data.
- Treat AI output as a draft — clinicians remain responsible for accuracy.
- Review the Guidelines for the Use of AI in Clinical Care Delivery.
Don't
- Paste patient identifiers into non-approved or personal tools.
- Assume a tool available through CUIT is cleared for PHI at CUIMC.
How To Get a Clinical Use Case Approved
Submit to the CUIMC IT PMO request process → CUIMC IT PMO routes to the NYP IT PMO → reviewed by the Tri-Institutional AI Governance Committee as appropriate.
Training for You
Researchers
Research data may include Sensitive Data such as Research Health Information (RHI). These may only be used in approved environments, and protocol use carries additional review requirements.
Tools You Can Use
Columbia ChatGPT Education, Microsoft Copilot (approved products), CU CHAT (OpenAI models), AWS Bedrock & Bedrock AgentCore (build/deploy), Gemini/Gemini Notebook Enterprise in GCP (CUIMC IT).
See the full AI Tools × Data Classification matrix below for exactly which edition of each tool is approved for RHI.
Do
- Use approved tools on CUIMC-managed systems and endpoints inside CUIMC AWS accounts or CUIMC-managed systems for Sensitive Data.
- Report AI use in approved research activities and verify outputs against authoritative sources.
- Review the Guidelines for the Use of AI in Research with Sensitive Data (including RHI).
Don't
- Enter RHI or identifiable participant data into non-approved tools.
- Deploy locally installed models without an IT Risk Assessment.
How To Get a Research Use Case Approved
Submit through your existing IRB process → routed to the CUIMC AIGC for review as appropriate. Research protocol use of Sensitive Data requires IRB and TRAC/ACORD approval.
Training for You
Faculty, Students & Trainees
For coursework and study, use tools approved for the classification of data you are using. Always follow your program's academic integrity rules.
Although FERPA data such as student education records generally fall under the Confidential data classification, elements such as a student's identifying or health information are PII or PHI which are classified as Sensitive; when this overlap occurs, the higher data sensitivity classification and tool restrictions apply.
See the full AI Tools × Data Classification matrix below for exactly which edition of each tool is approved for each data class.
Tools You Can Use
Columbia ChatGPT Education, CU CHAT, Microsoft Copilot, Gemini, Gemini Notebook, Claude — non-sensitive data only.
Do
- Use AI as an aid — for summarizing content, brainstorming, and outlining.
- Sign in with your CUIMC account to use enterprise, data-protected versions.
- Follow course and program policies on permitted AI use.
- Review the Guidelines for the Use of AI in Education and Training with Sensitive Data.
Don't
- Enter patient data, clinical cases with identifiers, or classmates' personal information into tools not approved for Sensitive Data.
- Rely on AI output without verifying it against authoritative sources.
How To Get Help or Approval
For general questions, email 5HELP (5help@cumc.columbia.edu). For educational use cases involving sensitive data, submit a request through the CUIMC IT PMO request process.
Training for You
Administrative Staff
Administrative work often involves Confidential and Internal data (policies, drafts, financial, HR, student records). Use approved tools, and remember that some administrative data is Sensitive Data.
See the full AI Tools × Data Classification matrix below for exactly which edition of each tool is approved for each data class.
Tools You Can Use
Columbia ChatGPT Education, Microsoft Copilot (approved products), CU CHAT.
Do
- Draft emails, memos, and policies in approved tools via your CUIMC O365 account (Copilot keeps data in the CUIMC tenant).
- Use approved ChatGPT and Copilot for Confidential and Internal data.
- Review the CUIMC Training on Responsible Use of AI in Healthcare and Research.
Don't
- Put any Non-Public Data into unapproved AI tools.
- Share financial, HR, or student records outside approved, authenticated tools.
How To Get an Administrative Use Case Approved
Submit Educational and Administrative use cases through the CUIMC IT PMO request process; CUIMC IT and relevant review groups evaluate compliance, security, and data-handling risks. General questions → 5HELP.
Training for You
Guidelines
- Guidelines for the Use of AI in Clinical Care Delivery
- Guidelines for the Use of AI in Education and Training with Sensitive Data
- Guidelines for the Use of AI in Research with Sensitive Data (including RHI)
Related Policies
AI Tools × Data Classification: What Each Tool Is Approved For
This matrix shows, for each AI tool, which classes of data it is approved to be used with at CUIMC. Available from indicates whether the tool is provisioned by CUIT (broader University) or CUIMC IT. Note how the same brand can differ: e.g., Google Gemini/Gemini Notebook in Google Workspace (CUIT) is not approved for Sensitive Data, while the Enterprise editions in GCP (CUIMC IT) are — a direct illustration of the HIPAA difference explained above.
As mentioned above, due to CUIMC's risk management posture, the approval for use of tools with Sensitive Data may be different than the University's general posture, which is documented here.
Because AI platforms evolve rapidly, protecting patient and institutional data is a shared responsibility. Users are expected to exercise sound judgment and comply with HIPAA and University policy whenever using AI tools. Safe and compliant use depends on both the technology and the judgment of each user.
Although CUIMC IT has implemented technical safeguards to reduce the risk of inappropriate data sharing, no technical control can fully prevent accidental disclosure of sensitive information as new features are introduced. AI vendors frequently introduce new capabilities through software updates. New features may become available before CUIMC IT has completed a security review. The presence of a feature in the application does not imply that it has been evaluated or approved for use with regulated or sensitive institutional information.
Legend: ✓ approved · — not approved · footnote markers (*, **) explained below the table.
| Tool | Approved for use at CUIMC | Sensitive Data (PHI, PII, RHI) | Confidential** / Internal | Public | Available from |
|---|---|---|---|---|---|
| End User Assistants (Chat, Productivity & Research) | |||||
| Personal / Non-UNI LLMs (personal ChatGPT, Gemini, etc.) | — | — | — | ✓ | Personal |
| Columbia ChatGPT Education | ✓ | ✓ | ✓ | ✓ | CUIT |
| CU CHAT | ✓ | ✓* | ✓ | ✓ | CUIT |
| Google Gemini in Google Workspace | — | — | ✓ | ✓ | CUIT |
| Google Gemini Notebook in Google Workspace | — | — | ✓ | ✓ | CUIT |
| Columbia Claude for Education | — | — | ✓ | ✓ | CUIT |
| Microsoft Copilot Chat† | ✓ | ✓ | ✓ | ✓ | CUIMC IT |
| Microsoft M365 Copilot† | ✓ | ✓ | ✓ | ✓ | CUIMC IT |
| Microsoft Copilot in Fabric† | ✓ | ✓ | ✓ | ✓ | CUIMC IT |
| Google Gemini Enterprise (coming soon) |
✓ | ✓ | ✓ | ✓ | CUIMC IT |
| Google Gemini Notebook Enterprise (coming soon) |
✓ | ✓ | ✓ | ✓ | CUIMC IT |
| Anthropic Claude Desktop [Chat]‡ | — | — | ✓ | ✓ | CUIMC IT |
| OpenAI ChatGPT Desktop [Chat]‡ | — | — | ✓ | ✓ | CUIMC IT |
| Autonomous and Coding Agents *** | |||||
| OpenAI ChatGPT Desktop [Codex]‡ | ✓ | ✓ | ✓ | ✓ | CUIMC IT |
| Anthropic Claude Desktop [Code]‡ | — | — | ✓ | ✓ | CUIMC IT |
| OpenAI ChatGPT Desktop [Work]‡ | — | — | — | ✓ | CUIMC IT |
| Anthropic Claude Desktop [CoWork]‡ | — | — | — | ✓ | CUIMC IT |
| Developer and Enterprise Platforms | |||||
| OpenAI ChatGPT Education API | ✓ | ✓** | ✓ | ✓ | CUIT |
| Claude API for Education | — | — | ✓ | ✓ | CUIT |
| Amazon AWS Bedrock | ✓ | ✓*** | ✓ | ✓ | CUIMC IT |
| Microsoft Copilot Studio† | — | — | ✓ | ✓ | CUIMC IT |
| GitHub Copilot in VS Code† | — | — | — | ✓ | CUIMC IT |
Visual Indicators In Approved AI Tools
To help users confirm they are using the approved software versions, visual indicators are displayed within the interfaces of some CUIMC-sanctioned AI tools. Users should always verify these indicators before entering any CUIMC-related data. If these elements are missing, you may not be using the approved instance. In such cases, immediately stop and report any issue to CUIMC IT Security Office
- Columbia ChatGPT Education: Displays the Columbia University logo(1) at the bottom left of the interface.
- Microsoft Copilot**: Displays a shield icon (may appear as a green outline with a checkmark(2), a grey outline on a white background(3) or a white outline on a dark background(4), depending on the device) in the chat interface, indicating that Enterprise Data Protection applies to the session. Additionally, confirm your CUIMC email address, indicating you are logged into the CUIMC account.
Governance
Reviews of AI-related requests are based on the use case and nature of the request.
| If your use case is… | Submit via… |
|---|---|
| General questions about availability and use | Email 5HELP (5help@cumc.columbia.edu) |
| Educational & Administrative | CUIMC IT PMO request process; CUIMC IT and relevant review groups evaluate compliance, security, and data-handling risks. |
| Research | Existing IRB process(es); routed to the CUIMC AIGC for review as appropriate. |
| Clinical | CUIMC IT PMO request process → guided to the NYP IT PMO → routed to the Tri-Institutional AI Governance Committee as appropriate. |
Training Modules
- CUIT Training on Generative AI (scroll to "Training Videos")
- CUIMC Training on Responsible Use of AI in Healthcare and Research
- VP&S Training on AI Clinical Care Delivery
Other Resources
Additional Guidance
All use of AI, Large Language Models (LLM), Natural Language Processors (NLP), or Machine Learning (ML) systems at the Medical Center must comply with HIPAA and other relevant healthcare and IT regulations to uphold the highest standards of patient privacy and data security. For locally installed AI models, a formal IT Risk Assessment review is required before deployment to evaluate potential security, privacy, and compliance risks.
CUIMC IT may monitor AI software usage to ensure compliance with these guidelines. When generating AI content for audiences beyond your immediate use, verify all AI-generated information through authoritative sources and report its use in approved research activities. This practice ensures information integrity and helps avoid AI-related negative outcomes such as the dissemination of inaccuracies or biases.
Should you have questions regarding AI tools, become aware of any data exposures or misuse of sensitive information, or need to report issues verifying approved tool instances, contact the CUIMC IT Security Office.