Responsible AIfor Behavioral Health
Free training · For care teams

Organizational AI Awareness

A complete lesson with facilitator guidance, practice activities, and answer notes.

By Cody Saunders, LMSW · October 11, 2026

Everyone has a part in responsible use

AI may appear in a chat tool, an email app, or a record system. A new summary button can look like a small change while sending information through a new service. Staff need a shared way to recognize these features and ask for help before using them with sensitive information.

This free lesson is for the whole behavioral health team. It helps people notice where AI enters daily work, follow approved uses, and report concerns clearly. It does not ask every staff member to become a technology expert. It gives them a practical role: know the allowed task, protect the information, check the result, and speak up when something changes.

Audience, goals, and setup

This 45-minute lesson is for clinical, front-desk, billing, operations, and support staff. No prior AI knowledge is required. The facilitator needs the host’s current approved-use list, help contact, and incident reporting process. If these are missing, identify the gap with the host before teaching that staff have a ready path to use.

By the end, staff should be able to recognize an AI feature, explain why office work may contain private data, distinguish an approved use from an unreviewed shortcut, and make a factual report without sharing client details in the wrong place.

Prepare the fictional cases below and a blank page for a help message. Live tool use is not needed. Do not collect real records, passwords, or private examples. Use public or made-up material throughout. This lesson does not authorize a new tool, establish compliance, or promise continuing education credit.

Session timing and facilitator guidance

0–5 minutes: Connect to daily work. Ask staff to name features such as draft, summarize, transcribe, or suggest a reply. Do not assume every feature uses AI. Explain that uncertainty is a good reason to check the approved-use list.

5–12 minutes: Explain the shared habits. Teach the short guide below. Ask a front-desk or billing staff member to explain why their work can still involve private information.

12–22 minutes: Sort three situations. Use Activity 1. Have small groups explain what is allowed under each fictional rule, what needs review, and what information is involved.

22–32 minutes: Practice a help message. Use Activity 2. Read two answers aloud without naming staff. Show how a clear message helps the right team respond.

32–40 minutes: Respond to a mistake. Use Activity 3. Walk through the host’s real reporting contact and process. Keep legal determinations with the responsible people.

40–45 minutes: Teach back. Ask learners to name their approved alternative, help contact, and first action when a feature asks for new information. Revisit any point that is unclear.

A shared guide for everyday work

AI is software that can perform tasks such as finding patterns or creating content. Generative AI creates content. A prompt is a request you give it. An output is its reply. A useful reply still needs checks because the tool can add wrong or invented details.

First, know the exact approved use. Product names alone are not enough. A team may approve public staff guides in one work account but not meeting recordings in that same app. Check the task, account, feature, and allowed information.

Second, look at the data. An appointment list or billing file may contain private client information even though the task is administrative. A story without a name may still reveal a person through dates or rare events. Do not use real cases to test a new tool. Keep practice fictional.

Third, check before sharing a result. AI can change dates, omit a rule, or create a contact that does not exist. Compare important details with the real source. Do not let a draft become an official message just because it sounds polished. The assigned owner approves the final version.

Fourth, ask when the task changes. A new recording feature, outside recipient, or personal account can change the review needed. Use the approved alternative while the new use is reviewed. A pause should leave staff a workable way to finish the task.

Finally, report concerns through the host’s process. Name the tool, feature, task, and what happened. Keep client information out of an ordinary support message unless the approved incident process specifically provides a secure place for it. Do not forward sensitive screenshots into a group chat to ask whether they are safe.

Activity 1: What is approved here?

Use this fictional rule: “Staff may use the approved work account to draft guides from current public office policies. The policy owner reviews them before release. Client data and recordings are not allowed under this approval.”

Situation A: A staff member wants to shorten a public policy using that account and send the draft to the policy owner.

Situation B: A billing worker wants to upload unpaid claims with names and dates to the same tool.

Situation C: A supervisor wants to turn on a new meeting recorder for a case discussion.

Ask groups to identify the permitted use and the two uses that need review. Have them name an approved alternative for the task while waiting.

Answer and debrief: A fits the stated rule if the source is current and the owner checks the draft. B includes client data and falls outside the approval. C adds recording and case information, also outside approval. Staff should use the usual approved billing or meeting process while those proposals are reviewed. An administrative label or an approved product name does not cover every task.

Ask the group which real help contact would receive these questions. Do not leave the exercise with only “ask someone.” Give the actual role or channel supplied by the host.

Activity 2: Write a useful request for help

A fictional email app adds a “summarize thread” button. A worker wants to use it on a thread about client scheduling. They do not know whether the feature sends text to another provider.

Ask each learner to write a short request for review. It should name the app and feature, describe the task without client details, and explain what they need to know before using it.

Answer and debrief: One useful message is: “Our email app now has a summarize-thread feature. I would like to use it for scheduling work, which can include private client information. Is this feature approved in our work account, and what data is allowed? I will use our current process until I hear back.”

The message gives enough context to route the question without copying the thread. Staff do not need to prove the full data path themselves. The responsible review team can check the provider, settings, contract, and storage. A consumer account’s rules may differ from a work account’s rules.

Activity 3: A mistake has happened

A fictional worker realizes they pasted part of a real client message into a personal chatbot. They want to hide the mistake because they fear blame. A coworker suggests deleting the chat and saying nothing.

Ask learners: What should happen first? What should not be assumed? What information would help the responsible team review the event?

Answer and debrief: Stop the unapproved use and promptly follow the host’s incident reporting process. Do not paste more data into the tool. Deleting a visible chat does not prove every copy is gone, and the worker should not independently decide the event is harmless. The responsible team needs facts such as the service, account, approximate time, type of information, and actions already taken. Use its secure reporting method. Do not spread the client message to coworkers.

The facilitator should explain the host’s actual response path. This lesson does not determine whether a legal breach occurred or what notice is required. Those decisions belong to the responsible reviewers under applicable rules. A clear reporting culture helps a team respond to facts rather than guess at what happened.

Why the rules matter

For organizations covered by HIPAA, services that handle protected health information on their behalf can have business associate duties. HHS explains agreements and safeguards in its cloud computing guidance. Staff should follow the reviewed use for their setting. They should not interpret a privacy slogan or a consent form as blanket permission.

NIST’s Generative AI Profile describes risks including false content and privacy concerns. It is voluntary guidance, not a law or a product endorsement. The shared habits here are suggested teaching steps that help staff follow their organization’s actual rules.

Good habits can support a calmer workflow. A clear approved task may reduce repeated questions and make useful drafting easier to test. It still needs evidence before leaders claim less paperwork, lower costs, better billing, or better care. Staff feedback is part of that evidence.

Check learning and follow up

Ask learners to complete three sentences: “Our approved use allows…”, “If a new feature asks for private information, I…”, and “If I make a mistake, I report it through…”. Listen for specific limits, a pause and help request, and the host’s actual reporting path.

If learners cannot name the contact or alternative, fix that gap with the host. Do not treat a signed attendance sheet as proof that staff can follow an unclear process. These teach-back checks are informal learning activities, not a validated assessment.

After the lesson, share the current approved-use list with a date and owner. Give staff a way to ask about new features. Review recurring questions to see where the instructions need improvement. Use fictional examples in future refreshers.

Sources and related resources

Sources checked October 11, 2026. Every rule, situation, message, and incident in this module is fictional. The lesson does not establish legal compliance, clinical benefit, certification, or continuing education credit.

HHS guidance on HIPAA and cloud computing: duties for covered organizations and business associates; not approval of a specific product.

NIST Generative AI Profile, July 2024: voluntary risk guidance, including privacy and false-content risks.

Read Shadow AI and AI Terms for Care Teams. Reviewers can use the existing data-handling worksheet and purchasing checklist. To discuss free team training, visit Work With Me.

Download the editable lesson

Back to all resources