Do you use ChatGPT to write clinical reports? What you need to know about your data

"Write a clinical report for a 32 year-old patient diagnosed with generalized anxiety disorder who has been 6 months of cognitive-behavioral treatment..."
If you ever hit something similar in ChatGPT, Gemini, Claude or any other generative AI, this article is for you. Because what you just did is send sensitive mental health data to a foreign company, probably without the patient's consent and in violation of at least three Argentine laws.
It's not a — trial is a reality. Many psychologists do it in good faith, trying to save time on administrative tasks. The problem is that most don't know what happens to those data after pressing "Enter".
What about the data you send to ChatGPT?
The short version
When you paste clinical data into ChatGPT (or other public generation AI), those data:
- Travel to servers in the US (or another country where the provider operates)
- They are stored by the supplier (at least temporarily)
- Can be reviewed by employees of the supplier for quality control
- Can be used to train future AI models (unless you explicitly disable it)
- Staff out of your control once you send them
The detailed version
OpenAI (ChatGPT)
According to OpenAI's terms of service (updated to 2025):
- Free and Plus: by default, conversations if used to train models. You can disable it in Settings → Data Controls → "Improve model for all." But even by deactivating it, OpenAI retains data for 30 days "for abuse monitoring"
- ChatGPT Team / Enterprise: data not used for training, but still stored on US servers
- API: data sent via API not used for training by default
Google (Gemini)
- Talks with Gemini (free version) used to improve product
- Google human reviewers can read your conversations
- Data is stored for up to 3 years
Other AIs (Claude, Copilot, etc.)
Each has its own policies, but the pattern is similar: the data you send is stored on the provider's servers, usually in the US.
Important
Even if you disable training, the data has already come out of your control. They are on servers of a foreign company, subject to legislation from another country, and you have no way of verifying that they were actually deleted.
Why is it a legal problem?
Violation of the 25.326 Law (Protection of Personal Data)
Mental health data are sensitive data (Art. 2). While Art. 8 enables you as a health professional to treat data from your patients, this has clear limits:
- Finality (Art. 4.3): Data cannot be used for purposes other than or incompatible with those that motivated its acquisition. The patient gave you his data for clinical care, not to send them to a technology company.
- Cession to third parties (Art. 11): Giving data to OpenAI or Google requires prior consent of the patient, informing him of the purpose and identity of the assignee. The assignee is subject to the same obligations and both respond jointly (Art. 11.4)
- International Transfer (Art. 12): Transfer of data to other countries requires adequate contractual guarantees (such as data processing agreements) and informed consent of the holder
- Service provision (Art. 25): When a third party provides data processing services, it cannot use them for any purpose other than that of the contract, nor assign them to other persons.
Does your patient know that your clinical data is on OpenAI servers? Probably not. Did you consent to that assignment? Almost certainly not.
Violation of professional secrecy
The professional secret obliges you not to disclose known information for the purpose of exercising your profession. When you post clinical data on ChatGPT, you are disclosure of confidential information to a third party (OpenAI, Google, etc.) without legal justification.
Article 156 of the Criminal Code punishes this conduct with a fine of $1.500 to $90.000 and a special disqualification from 6 months to 3 years.
Violation of the 26.529 Act (Patient's Rights)
The law establishes the patient's right to confidentiality of his health information. Sharing this information with an AI platform without consent violates this right.
Possible consequences
| Scope | Consequence |
|---|---|
| Legal (civil) | Claim for damages of the patient |
| Legal (criminal) | Art. 156 CP: fine from $1.500 to $90.000 and special disqualification from 6 months to 3 years |
| Administrative | Penalty of the AAIP (fines up to $100.000) |
| Ethics | Penalty of the professional college (up to suspension of professional license) |
| Professional | Loss of confidence, reputational damage |
"But I anonymize the data before I paste it."
It's the most common answer, and it's a good instinct, but it has problems:
Real anonymization is very difficult
Taking out the name is not enough. Mental health data are highly identifiable by context:
- "Patient of 34 years, psychologist, divorced 6 months ago, mother of two, attends in Palermo, with diagnosis of major depression..."
- Even if you don't name it, how many people fit that description in your professional circle?
Language models can reidentify
LLMs (Large Language Models) have the ability to cross information. If you mention sufficient details in a conversation, the model (or anyone accessing that data) could potentially identify the person.
It does not eliminate the legal problem
Even if the anonymization is perfect, the law specifically provides for dissociation of data (Art. 2): the processing of data in such a way that the information cannot be associated with a particular or determinable person. If the dissociation is complete, the data ceases to be personal. But if there is any element that allows them to associate with a person (directly or indirectly), they remain protected personal data and their transfer to a third party such as OpenAI requires consent (Art. 11).
Note
Anonymization reduces risk, but does not eliminate it. The only way to eliminate risk is not to send clinical data to public AI platforms.
What can you do with AI safely?
AI can be extremely useful for a psychologist. The problem is not the AI itself — is how and where the data is processed. Here are the safe ways:
1. Use AI without actual data
You can use ChatGPT or any AI for:
- Learning about a therapeutic approach or technique
- Order generic reporting models (no patient data)
- Researching a diagnosis or medication
- Writing texts for your website or social networks
- Preparation of psycho-educational material
Rule: If it does not include data from any actual patient, there is no problem.
2 Use clinical software with integrated and secure AI
The key difference is where data is processed. A clinical software that integrates AI safely:
- Processes data in a controlled environment
- It does not send them to public platforms
- He doesn't use them to train models.
- It's got end to end encryption.
- Compliance with data protection legislation
3. Use local AI (for advanced users)
There are AI models that run locally on your computer, without sending data to any server:
- LM Studio: free interface for running local models
- Call: command line tool for local models
Data never leaves your computer. The disadvantage is that it requires technical knowledge and a powerful computer.
What Many Psychologists Do Wrong (Unknowingly)
Paste session notes in ChatGPT to "improve writing"
You're sending the full content of a session to OpenAI. It's the most direct violation.
Tell an AI the session summary
If you use a cloud transcription or dictation service (non-local), audio data travels to external servers.
Ask AI to "analyze" a case
"I have a patient with these characteristics, what differential diagnosis would you do?" — if you included real data, you already shared them.
Upload clinical documents for the AI to summarize
PDFs of evaluations, reports from other professionals, test protocols... if you upload them to ChatGPT, they're stored.
Use AI browser extensions
Some extensions that offer "assisted writing" send everything you write to their servers. If you use them while completing an online medical records, that data is leaking.
Important
Check your browser extensions. Some AI extensions read everything you write on any — website including your clinical software.
Comparative: Public AI vs. Integrated Clinical AI
| Criterion | ChatGPT / Gemini (public) | IA integrated into safe clinical software |
|---|---|---|
| Where are the data processed? | Provider Servers (USA) | Environment controlled by clinical software |
| Are they used to train AI? | Possibly (depends on plan) | No |
| Who can access? | Provider employees, possible gaps | Only you. |
| Does Law 25.326 comply? | Not automatically | Should (check with provider) |
| Does anonymization require? | Yes (and still risky) | No (data are already in a protected environment) |
| Patient consent | Necessary and probably not granted | Covered by consent of clinical software |
| What if there is a gap? | You have no control or information. | The provider must notify you |
What should your informed consent say?
If you use AI tools in your practice (of any kind), your informed consent should include:
- What AI tools you use (name them)
- What do you use them for (reporting, transcription, clinical suggestions)
- If patient data are processed by AI and, if so, where
- What security measures the tool has
- That data is not used to train models (if applicable)
Frequently Asked Questions
"Is ChatGPT Team or Enterprise safe for clinical data?"
It is significantly better than the free version because it does not use data to train. But the data is still stored on OpenAI servers in the US, and OpenAI employees can access it in exceptional circumstances. For mental health data in Argentina, it remains problematic from the point of view of the 25.326 Law.
"What if I use the OpenAI API?"
Better than chat, because the data sent via API is not used to train by default and the retention is 30 days. But it is still a data transfer to a third party (Art. 11). You would need the patient's consent informing the purpose and identity of the assignee, and Art. 25 requires the service provider not to use the data for a different purpose than the contracted one.
"Is it the same as using Google Docs to write reports?"
It is similar in the sense that data is on Google servers. The difference is that with ChatGPT there is the possibility (depending on the plan) that data is used to train AI and that human reviewers read them. With Google Docs, data is stored but not used to train language models.
"Brauni uses AI? Is it different?"
Yes, Brauni uses AI to assist in clinical documentation. The fundamental difference is that data is processed in a safe environment with end-to-end encryption, is not sent to public AI platforms and is never used to train models. The patient is also informed through informed consent.
How to use AI safely with Brauni
Brauni integrates artificial intelligence responsibly:
- IA that does not train with your data: Your clinical information is never used to improve AI models
- End-to-end encryption: Clinical data remain encrypted at all times
- No third-party access: Data is not sent to OpenAI, Google or any other public platform
- Safe processing: AI assists without compromising confidentiality
- Total transparency: You know exactly what AI does with your data
- Integrated Consent: The use of AI is covered in the informed consent of the patient
Free Brauni test for 30 days, no card
Automatic session notes, digital medical records and more.
Start for freeSummary
| Question | Response |
|---|---|
| Can I paste clinical data into ChatGPT? | No. It violates 25.326 law, professional secrecy and the 26.529 law |
| What if I anonymize the data? | It reduces the risk but does not eliminate it. Real anonymization is very difficult |
| Can I use ChatGPT for generic questions? | Yeah, as long as you don't include real patient data. |
| What alternative do I have? | Clinical software with integrated AI securely, or local AI |
| What if I already did? | Disable training, delete conversations, and do no more. Evaluate whether you need to notify the patient |
| Is AI bad for psychology? | No. AI can be very useful. The problem is to use public AI with sensitive data |
Related articles

Privacy and Security
Your clinical data does not train any AI: how and why we guarantee it
We explain with technical transparency why your patient data in Brauni is never used to train AI models. Vertex AI, contracts and architecture.

Privacy and Security
WhatsApp with patients: limits, risks and good practices
How to use WhatsApp with patients without breaking the frame or confidentiality: clear boundaries, crisis protocol and good practices for psychologists.

Privacy and Security
Record therapy sessions: what the law says and how to do it right
Recording therapy sessions is legal only with prior informed consent. What Argentine law requires, how to write the clause and how to save the audio.