AI medical report writing without breaching patient confidentiality
Your notes are there, the report still has to be written. AI can structure it in seconds, as long as you never hand it anything that identifies the patient.
Your notes are there, the report still has to be written. AI can structure it in seconds, as long as you never hand it anything that identifies the patient.
The consultation is over, the next patient is waiting, and for now the report amounts to a few abbreviated lines. Tonight they will have to become a readable letter to the GP, a summary for the record, and sometimes an explanation for the patient. It is repetitive writing work, and it is exactly what AI does well.
But it has to be done without breaching medical confidentiality. Here is a simple method, built on one principle: the AI works on the clinical content, never on the patient's identity.
In Switzerland, medical professional secrecy is set out in Article 321 of the Swiss Criminal Code; most other countries have equivalent rules for doctors and healthcare staff. Health data is also classed as sensitive data under the Swiss FADP and the GDPR: its processing is strictly regulated.
Pasting named consultation notes into a consumer AI tool therefore means passing identifiable health data to a third party, often abroad, which may keep it. That is not a grey area.
One point also needs to be clear: IA Confidential is neither patient record software nor a health data host. It stores nothing from your consultations, and that is precisely why it should not become one. The patient record stays in your practice software; the AI only helps you write.
1. Remove the identity before you write. Replace the name with a description that is useful for the reasoning: "54-year-old woman with type 2 diabetes". Date of birth, address, health insurance or national identification number add nothing to the writing: they stay in your software. You will add them to the final letter, after the AI has done its part.
2. Stay on a confidential model. By default, IA Confidential answers with open models installed on servers in Switzerland, which pass nothing on to third parties. For this kind of formatting work, they are all you need. If you ever select an external model and your message still contains sensitive data, the Confidentiality filter steps in and offers to answer with a confidential model instead.
3. Create a "Consultations" space. In its instructions, describe your format once and for all: for example reason for visit, history, examination, conclusion, plan. State your specialty, the expected register and the length. Every new report will follow this template without you having to ask again.
4. State your constraint once. In your profile, the constraints section lets you indicate that you are bound by professional secrecy. This profile is kept in your browser and is never sent to external models.
5. Paste your notes, ask for the format you need. A letter to a colleague, a summary for the record, or a simplified version for the patient: one consultation can produce all three. The assistant writes them as documents that you can edit, print to PDF or export to Word.
6. Reread everything, add the identity at the end. Check every value, every dosage, every term. Then transfer the document into your software, where you add the patient's identity.

It excels at structuring messy notes, harmonising vocabulary, turning abbreviations into full sentences, and adapting the same content for two different readers: a colleague and a patient.
It must not make a diagnosis for you, or suggest a treatment you have not decided on. An AI can be confidently wrong, shift a value, swap left and right, invent a recommendation. Every report should be reread as if you had dictated it to a hurried locum: carefully, line by line.
With a confidential model, your notes and the answer are processed on servers located in Switzerland, and nothing is kept on our side: the conversation history stays in your browser. We could not hand over your exchanges even if asked to.
Above all, if you apply the first step, what travels cannot identify a patient: that is the best protection, whatever the tool.
Two practical precautions. On a shared computer in the practice or on the ward, the history can be read by anyone using the same browser session: use a personal session and close it when you leave. And do not use the history as an archive: your patient record remains the reference.
Here are my consultation notes for a 54-year-old woman with type 2 diabetes, seen for poor glycaemic control. Write a letter to her GP in the format reason for visit, history, examination, conclusion, plan. Keep my values exactly as they are, do not add any recommendation I have not written, and flag any information that seems missing or contradictory.
Then paste your notes, with no name or identifier.
Other professions bound by secrecy follow the same logic: read our guide for lawyers, or our general advice on using AI at work safely.
To try it on a fictitious consultation: open the chat.