Obsidian Ridge

Compliance

AI usage policy for law firms and dental offices

A copyable staff AI policy, plus browser and device controls to manage client data, approved tools and incident reporting.

SMB

A useful AI usage policy tells staff which tools they may use, which information they may enter, who approves exceptions and how to report a mistake. Put those decisions in writing before relying on a block list. The policy below is an original starting template for a law firm or dental office to adapt and approve.

Obsidian Ridge deploys and manages the Island Enterprise Browser at $18 per user per month, month-to-month with no minimum, with zero-configuration initial onboarding and CISSP-led support for businesses in the Research Triangle and across the United States. Managed browser policies give your business control over work-app access and how client data is copied, downloaded, uploaded or printed. Island AI Protect is an add-on, priced separately; its price is not published. Obsidian Ridge runs AI security assessments with Traceforce that find the AI apps and agents running on your employees' devices, show what client data and systems they can reach, and flag risky actions, with a CISSP walking you through the findings and fixes for businesses in the Research Triangle and across the United States; contact us for pricing, billing unit and engagement term, with no minimum. Those are different scopes: managed browser controls and a separately scoped assessment of AI use.

What should the policy protect?

For lawyers, ABA Formal Opinion 512 discusses professional duties when using generative AI, including competence, confidentiality and communication. Approving a tool does not approve every client matter or every data use.

For HIPAA-regulated practices, a service that creates, receives, maintains or transmits ePHI on the practice's behalf can involve business-associate obligations. HHS explains that an appropriate BAA and compliance with applicable safeguards are needed for covered cloud uses. A consumer account should not be treated as approved simply because it offers a privacy setting. HHS cloud guidance.

Copyable one-page policy

Approve this with the people responsible for privacy, professional obligations and IT. Maintain the approved-tool register and reporting contact separately so staff can find current details.

STAFF USE OF GENERATIVE AI

Purpose and scope
This policy applies to work performed for the practice using AI websites,
applications, browser extensions, coding assistants and automated agents.
It applies on work devices and whenever practice information is involved.

Approved tools and accounts
Use only tools and work accounts in the practice's approved-tool register.
Approval names the permitted tasks, data, settings and responsible owner.
Do not connect personal AI accounts, browser extensions or agents to work
email, files, clinical systems or case-management systems without approval.

Information restrictions
Do not enter client, patient, taxpayer, payment or authentication information
into an unapproved tool. Do not upload matter files, clinical records,
recordings or screenshots containing that information. Removing a name alone
does not establish that information is anonymous or properly de-identified.
Use public or invented examples for experimentation.

Permissions and actions
Request approval before granting an AI tool access to mail, drives, calendars,
local files or other systems. Use the least access needed for the approved
task. An agent must not send communications, change records or make purchases
without the authorized person's review and approval.

Review and professional responsibility
Check AI output for accuracy, sources and inappropriate disclosure before
using it. A qualified person remains responsible for professional work.
Follow any client-consent, patient-privacy and contractual requirements.

Mistakes and concerns
Report a wrong upload, unexpected access or unintended action promptly to
the practice's designated reporting contact. Preserve the relevant facts;
do not delete records or continue experimenting to investigate alone.

Ownership and maintenance
The practice's designated owner approves exceptions in writing, records
training and updates this policy when tools, tasks or obligations change.
Staff must know where the approved-tool register and reporting contact live.

Which controls can help enforce it?

The managed browser supplies policies for work-app access and supported data movement. Island describes AI Protect as controls for employee AI use in the browser. Confirm the supported sites, allowed actions, work-account rules and exception process in the proposal. Island AI Protect overview.

That does not prove coverage of a desktop AI application, a command-line agent or a personal device outside management. The Traceforce assessment examines the agreed device and AI-tool scope. Findings still need an owner, a decision and a record of the changes made. See the AI assessment comparison before choosing a browser control, discovery tool or assessment.

How should staff learn the policy?

Use examples from the practice: a client letter, a radiograph screenshot, a bank detail and a public marketing paragraph. Ask which tool and data combination is approved and where an exception goes. Keep completion records and repeat the exercise when the tools or rules change.

Ridge Plus costs $50 per person per month on an annual term, billed monthly, with no minimum. It adds staff training, email-security configuration and a secure browser to Ridge Core; business onboarding is separate. Obsidian Ridge's Ridge Core includes endpoint MDR and Microsoft 365 or Google Workspace ITDR at $25 per person per month, month-to-month with no minimum and business onboarding separate. Huntress's SOC monitors and acts 24/7; Obsidian Ridge provides CISSP-led follow-through within one business day, serving the Research Triangle and businesses across the United States. Managed training can support the programme, but the practice must approve its policy and decisions. A technical block should explain the permitted next step, not leave staff to invent a workaround.

What should happen after an accidental upload?

Follow the incident process, preserve the relevant tool, account, time and information details, and involve the authorized privacy/security contact. That person can coordinate containment and assess contractual, professional and legal duties. Do not promise that deleting a conversation removes every copy or reverses access already granted.

For the broader programme, use the law-firm guide or dental programme. Our pricing, Readiness Sprint and questionnaire worksheet separate ongoing controls from evidence work. Talk with us to scope the systems the policy needs to cover.

Sources

Fetched October 2, 2026.

Last updated

October 2, 2026. We refresh this content as the threat landscape and tools evolve.

FAQ

Questions readers usually ask next

How can we stop staff pasting client data into ChatGPT?

Set an approved-tool and approved-data policy, train staff and enforce the supported rules on managed work access. Browser controls can restrict supported uploads and copying. They do not automatically cover personal devices, every application or every AI agent.

Does removing a patient or client name make AI use safe?

No. Removing a name does not prove that the remaining information is anonymous or properly de-identified. Apply your approved data rules and seek appropriate privacy or legal review before sharing sensitive information.

Is Island AI Protect included in the browser price?

Island AI Protect is a separately priced add-on. The published standalone browser rate is for Island Enterprise Browser. Ask for the add-on quote and supported enforcement scope.

Is this template legal advice or proof of compliance?

No. It is an operational starting point that the practice must approve and adapt. It does not replace professional duties, a HIPAA analysis, client terms or legal review.

Full bio & provenanceSee related service

Related reading