Dramatically backlit medieval figures depicted in Sterling Memorial Library's stained glass windows

Guidance for the Use of Moderate-Risk AI Tools in Health Sciences Courses

Faculty are responsible for ensuring that any use of AI tools in a Health Sciences course complies with Yale policies governing privacy, security, clinical information, and research data.

Overview

Several AI tools available through Yale are approved for use with Moderate Risk Data when accessed through their approved Yale implementations and authentication methods. Examples include Gemini LTI, which uses Yale Google Workspace (EliApps) accounts, and BoodleBox, which is available through an approved Canvas @ Yale integration managed by the Poorvu Center. These approved access pathways are an important component of Yale’s privacy, security, and governance controls.

These tools can support activities such as study guides, writing support, AI-assisted learning, collaborative exercises, knowledge-grounded chatbots, and engagement with course materials.  

Moderate Risk approval means these tools may be used with many forms of educational information, including FERPA-protected educational records. However, approval for Moderate Risk Data does not authorize the use of HIPAA-protected health information (PHI), electronic protected health information (ePHI), clinical patient data, or other restricted health sciences data.  

Faculty are responsible for ensuring that any use of AI tools in a Health Sciences course complies with Yale policies governing privacy, security, clinical information, and research data.  

Appropriate Educational Uses / Use Cases

Moderate-risk AI tools may be appropriate for:

  • Course study guides built from instructional materials.
  • Review and practice activities based on lectures, readings, or publicly available content.
  • Course-specific tutoring, coaching, or FAQ assistants.
  • Assistance with writing, reflection, brainstorming, or concept review.
  • AI literacy and critical evaluation activities.
  • Collaborative learning activities.
  • Analysis of de-identified educational scenarios created specifically for instruction.
  • Simulations using fictional patients or synthetic case studies.
  • Research skill development using approved instructional materials.  

Prohibited Educational Uses / Use Cases

Moderate-risk AI tools should not be used for:

  • Entry, upload, or discussion of HIPAA-protected health information (PHI).
  • Patient case materials containing identifiable patient information.
  • Clinical documentation, medical records, or screenshots from clinical systems.
  • Restricted research data, including identifiable human-subject research data.
  • Clinical decision-making involving real patients.
  • Information obtained from clinical placements, patient encounters, or healthcare operations.
  • Any activity that would require a HIPAA-compliant environment.  

Required Guardrails for Course Use

Faculty who choose to use approved Moderate Risk AI tools in Health Sciences courses should implement the following safeguards. 

Students and instructors must access AI tools through Yale-approved authentication methods and Yale-supported implementations. Use of personal accounts or non-Yale versions of these tools may be subject to different privacy protections and data handling practices. 

Examples include: 

  • Gemini LTI: Access through Canvas using a Yale Google Workspace (EliApps) account. Personal Google accounts should not be used for course activities. 
  • BoodleBox: Access through the approved Canvas @ Yale integration provided through the Poorvu Center pilot. Students and instructors should not create separate personal accounts for course-related activities. 

Using Yale-authenticated accounts helps ensure that institutional privacy, security, and governance controls apply to the educational use of these tools.

Students should be explicitly instructed not to enter: 

  • Patient names 
  • Medical record numbers 
  • Dates of birth 
  • Clinical notes 
  • Diagnostic images 
  • Patient photographs 
  • Identifiable research participant information 
  • Any other identifiable health information 

If an educational case study is used, it must be fully de-identified and suitable for instructional purposes.

When designing activities involving diagnosis, treatment planning, clinical reasoning, or healthcare decision-making, faculty should provide: 

  • Synthetic patients 
  • Fictional scenarios 
  • Standardized educational cases 
  • Properly de-identified educational materials 

Students should never use information from actual patients encountered during clinical rotations, practica, research activities, or professional practice experiences. De-identification must meet applicable Yale and HIPAA de-identification requirements.

AI-generated responses may be inaccurate, incomplete, misleading, or fabricated. 

Faculty should require students to: 

  • Evaluate outputs critically. 
  • Verify important claims against course materials and authoritative sources. 
  • Cite appropriate references. 
  • Exercise professional judgment. 
  • Avoid treating AI-generated responses as authoritative clinical guidance.  

Course materials should clearly communicate: 

  • Whether AI use is required, optional, or prohibited. 
  • What information may and may not be entered. 
  • How AI-assisted work may be used in assignments. 
  • Expectations regarding academic integrity and attribution. 
  • Any course-specific requirements related to AI use.

Faculty should ensure that any materials uploaded to AI platforms are appropriate for instructional use and do not contain: 

  • PHI or ePHI 
  • Restricted research data 
  • Identifiable patient information 
  • Other data prohibited by Yale policy 

This review should apply to documents, images, datasets, presentations, and any other materials shared through AI-enabled platforms. 

Gemini LTI

Gemini LTI integrates Google Gemini, including Gems and NotebookLM, directly into Canvas courses. Users authenticate using Yale Google Workspace (EliApps) accounts. Faculty should ensure that any source materials used in NotebookLM or shared through Gems comply with applicable privacy and data protection requirements.  

BoodleBox

BoodleBox is available through Canvas as part of a limited pilot administered by the Poorvu Center. Access must be requested and approved before implementation in a course. BoodleBox supports multiple AI models, collaborative learning activities, instructor-created AI experiences, and AI literacy development. Faculty should ensure that assignment instructions clearly prohibit the submission of PHI, ePHI, identifiable patient information, and restricted research data.  

Recommended Faculty Statement for Syllabi or Course Sites

This course may incorporate Yale-approved artificial intelligence tools to support teaching and learning activities. These tools are approved for use with Yale Moderate Risk Data but are not approved for HIPAA-regulated information, electronic protected health information (ePHI), identifiable patient information, or restricted research data. Students must not enter patient information, clinical documentation, identifiable research data, or other restricted information into AI systems used in this course. Any clinical cases used with these tools must be fictional, synthetic, or appropriately de-identified. AI-generated responses should be critically evaluated and verified using course materials and other authoritative sources. Students remain responsible for the accuracy and integrity of all submitted work.

When to Consult Additional Guidance

Faculty should consult their school’s leadership, privacy officers, compliance offices, or Yale Health Sciences AI guidance whenever planned use involves:

  • Clinical education involving real patient information
  • Clinical systems or medical records
  • Human-subject research data
  • HIPAA-regulated information
  • Healthcare operational data
  • New instructional uses that may raise privacy, security, or compliance concerns.