
Written by Dr. Patrick Howell | CEO, HealthWorks Medical
Artificial intelligence isn’t coming to the workplace.
It’s already here.
Employees are using AI to write emails, summarize meetings, analyze spreadsheets, take notes, answer questions, and automate everyday tasks.
And increasingly, AI isn’t something employees have to sit down at a computer to use.
It’s in their phones.
It’s in meeting software.
It’s in wearable devices.
It’s even in their glasses.
That creates tremendous opportunity but it also creates an entirely new category of risk employers need to start managing.
And in healthcare, occupational health, HR, and other environments involving sensitive employee information, the stakes can be even higher.
What I’m Going to Teach You
- Why employers need an AI policy now, not five years from now
- How everyday AI tools can create unexpected privacy risks
- Why AI-enabled wearables create an entirely new challenge
- What healthcare and HR leaders should be thinking about
- How to embrace AI without losing control of your information
The Problem Isn’t AI
Let’s start here:
AI can be incredibly valuable.
At HealthWorks, we’re excited about its potential.
AI can help organizations:
✔ Reduce administrative work
✔ Analyze large amounts of information
✔ Improve workflows
✔ Identify trends
✔ Automate repetitive tasks
✔ Support better decision-making
The answer isn’t banning AI. The challenge is making sure employees understand where, when, and how it should be used.
Your Employees May Already Be Putting Company Information Into AI
Here’s a simple question every executive should ask:
What information are our employees putting into AI tools today?
Because the answer may surprise you.
An employee could paste:
- An email from a customer
- An employee medical restriction
- A workers’ compensation case summary
- An incident report
- A spreadsheet containing employee information
- Notes from a patient encounter
into an AI application and ask:
“Can you summarize this for me?”
From the employee’s perspective, they’re simply trying to become more productive.
From the organization’s perspective, however, sensitive information may have just been entered into a technology platform that hasn’t been approved for that use.
Convenience doesn’t automatically equal compliance.
Then Came the Glasses
This is where the conversation becomes even more interesting.
AI-enabled smart glasses, including devices such as Ray-Ban Meta glasses, can look remarkably similar to ordinary eyewear.
Yet these devices can include cameras, microphones, voice-controlled AI capabilities, and the ability to capture photos and video.
Imagine an employee walking into:
A medical clinic.
An occupational health examination.
A workers’ compensation evaluation.
An HR meeting.
A safety investigation.
A manufacturing facility containing proprietary processes.
They may now be wearing technology capable of capturing information from the environment around them.
Suddenly the traditional workplace rule: “Don’t take pictures in this area” may no longer be enough.
Healthcare Raises the Stakes
Healthcare environments present an especially important example.
Medical information isn’t simply another category of company data.
Organizations subject to HIPAA have specific obligations surrounding the protection of protected health information.
A recording could potentially capture:
- A patient conversation
- A computer screen
- A medical document
- Another patient’s name
- A diagnosis being discussed
- An employee’s medical information
And because today’s devices can capture both audio and video, employees may not always recognize how much information is being collected.
For occupational health programs, employers should also understand an important distinction:
Not every piece of employee health information is governed by HIPAA.
Depending on who holds the information and why, different privacy, employment, workers’ compensation, disability, state recording, and other laws may apply.
That makes having clear organizational rules even more important.
The New Question: What Counts as a Recording Device?
Twenty years ago, controlling recording devices was relatively simple.
You could prohibit cameras.
Then smartphones changed the equation.
Now we’re entering another transition.
Smart glasses.
AI wearables.
Automated meeting transcription.
AI note-taking assistants.
Voice-enabled devices.
Computer-vision systems.
The recording device of tomorrow may not look like a recording device at all.
That’s why policies need to focus less on specific products and more on capabilities.
5 Questions Every Employer Should Answer
1. What AI Tools Are Approved?
Employees shouldn’t have to guess.
Create a list of approved AI platforms and clearly define acceptable uses.
2. What Information Can Never Be Entered?
Clearly define restricted information.
Depending on your organization, that may include:
- Protected health information
- Employee medical information
- Personally identifiable information
- Customer information
- Proprietary business information
- Legal or privileged information
3. Where Are Recording Devices Prohibited?
Don’t limit the policy to cell phones.
Consider any device capable of recording, transmitting, processing, or storing audio, video, images, or sensitive information.
That includes wearable technology.
4. Do Employees Understand the Difference Between Convenience and Authorization?
An application being publicly available doesn’t mean it’s approved for company information.
Employees need simple rules they can actually understand.
5. Who Owns AI Governance?
This cannot live exclusively with IT.
Depending on the organization, AI governance should involve:
IT + Legal + HR + Compliance + Operations + Clinical Leadership
Healthcare organizations may also need privacy and security leadership involved.
Don’t Ban It. Govern It.
This may be the most important takeaway.
Trying to completely eliminate AI from the workplace is probably unrealistic for most organizations.
Employees will find tools that make their jobs easier.
The better strategy is creating guardrails.
Tell employees:
✔ Which tools they can use
✔ What information they can share
✔ What they cannot share
✔ Where recording is prohibited
✔ Who approves new technology
✔ What to do when they’re unsure
A one-page policy employees understand is more useful than a 40-page policy nobody reads.
Takeaways
- AI adoption is happening faster than most workplace policies are changing.
- AI isn’t limited to ChatGPT, it’s increasingly embedded in phones, software, wearables, and glasses.
- Healthcare and employee medical information create particularly significant privacy considerations.
- Smart glasses and AI-enabled recording devices may require employers to rethink traditional recording policies.
- The goal shouldn’t be eliminating AI. It should be responsible adoption with clear guardrails.
My Challenge to You
Ask your leadership team this question at your next meeting:
“If an employee walked into a confidential meeting tomorrow wearing AI-enabled smart glasses, would our policy clearly tell us what to do?”
If the answer is no, your technology may already be moving faster than your policies.
Your Next Step
Take inventory of how AI is currently being used across your organization, especially anywhere employees interact with medical, HR, safety, or other sensitive information.
Then establish clear rules around approved AI tools, sensitive information, recording devices, and wearable technology.
The organizations that benefit most from AI won’t necessarily be the ones that adopt it fastest.
They’ll be the ones that learn how to use it responsibly.