Responsible AIfor Behavioral Health
Planning tool · Privacy & Security

Document how
an AI tool handles data.

This worksheet helps teams review an AI tool before buying it. Record what data it gets, who uses it, how long it is kept, and where it goes. IT, privacy, security, and buying teams fill it out.

Map the data, review the service, and record the approved use.
Map the data, review the service, and record the approved use.
Inputs

Information entering

Processing

Tools, models & vendors

Outputs

Records & onward sharing

Use types of data and made-up examples. Do not enter real client details here. This page does not save your answers.

Seven areas to record.

01

Information entering the tool

List the types of data the tool gets. Include private health data, also called PHI, and staff data.

02

Processing locations

Where does the tool do its work? Name the companies, AI models, and places involved. Include other firms the seller uses.

03

Retention and deletion

What data is kept? For how long? How can you get it back or delete it?

04

Model improvement

Can the tool use your data or its records to improve the AI? List the rules and contracts that control this.

05

Access

Which staff, seller staff, and other firms can see the data?

06

Logging

What does the tool record about its use? Include requests, results, and access. Who checks these records?

07

Outputs and onward sharing

Where do results go? List what is copied, shared, or saved in the electronic health record, also called an EHR.

Name who is in charge.

For each task, name the tool, its purpose, and who is in charge. Add who checks it, the proof you have, and what is still unknown. Record approval and the next review date. Update this map when the tool or its data use changes.

A tool for planning and review. It does not prove that a system is safe or meets the law.