Quick answers about using AI at Comagine Health — what's available, what's allowed, and how to stay safe and compliant. For full detail, see AI Policy ITS-0022.
Artificial intelligence (AI) refers to computer systems that perform tasks traditionally requiring human intelligence — understanding language, reasoning, recognizing patterns, generating content, making predictions or recommendations, and carrying out multi-step tasks.
At Comagine Health, "AI" covers several things: generative AI (the large language models behind Copilot, Gemini, Claude, and ChatGPT that produce text), AI features built into everyday software, predictive and machine-learning systems, and AI agents that can take actions on your behalf.
One thing to always remember: AI can sound authoritative even when it's wrong — so its output needs a human review.
Used well, AI can save time and raise the quality of everyday knowledge work. Common benefits include:
The goal is to support and augment your expertise — not replace it.
A few to keep front of mind:
This is exactly why approved tools, human review, and the data rules in this FAQ exist.
No. Comagine Health's position is that AI supports human work and innovation — it does not replace professional judgment, clinical expertise, managerial accountability, or regulatory responsibility.
AI is a tool to help you work more effectively. You remain responsible and accountable for your work, and that human ownership is central to how we use AI.
AI use is encouraged but not mandatory. The policy's purpose is to equip and encourage staff to use AI confidently, responsibly, and effectively — but AI is meant to support your work, not replace your professional judgment, clinical expertise, or accountability.
Use it where it genuinely helps. You remain fully responsible for any AI-assisted work product, including its accuracy and appropriateness.
For the Baseline tool (Microsoft Copilot Chat), no setup is needed — it's already included with your Microsoft 365 account. Sign in at copilot.microsoft.com with your @comagine.org credentials.
For any other tool, submit a HelpDesk ticket (freshservice@comagine.org). Before you begin, it's worth skimming the AI Policy and the approved use cases so you know what's in bounds.
Yes. Training and guidance are being provided as part of the AI rollout, alongside this FAQ and the AI @ Comagine Health hub. [Add specific session dates/registration link here.]
Materials and recordings will be posted to the ITS Corner. Watch for announcements via your manager and internal channels.
Microsoft Copilot is Microsoft's AI assistant, and it appears at all three tiers — from a free chat assistant for everyone up to a platform for building custom agents.
Beyond Microsoft Copilot, several tools are available across the access groups — the next few questions describe each one. At a glance:
Is there a cost to you? No — where a tool is approved for you, licenses are procured by ITS and may be covered by an indirect rate or a specific contract, so you don’t need to budget for it personally. Submit a HelpDesk ticket with your use case to request access, and see the AI @ Comagine Health hub for the full side-by-side comparison. For the complete inventory — including meeting assistants and tools with embedded AI — see the Approved Tools list.
Google's AI, available through our Google Workspace environment.
Anthropic's AI assistant, known for high-quality writing and careful document analysis.
OpenAI's enterprise assistant. We use ChatGPT Enterprise, which spans everyday chat and several agentic surfaces.
Submit a HelpDesk ticket (freshservice@comagine.org) describing your intended use case. ITS provisions approved tools for you.
If the tool or use case isn't approved yet, it goes through an AI Impact Assessment (AIA) first (see Section 4). For Agentic-group uses, written sign-off from your department VP and the VP of Product & Technology is also required.
On your own time and personal accounts, your personal AI use is your business.
But you may not use personal or free/consumer AI accounts for Comagine Health work, or enter any Comagine Health information into them. Work must go through ITS-provisioned @comagine.org accounts in enterprise/work mode, using only tools approved on the AI Inventory. Don't create Comagine accounts on any AI tool ITS hasn't provisioned.
Not by default. Restricted/sensitive data — PHI, PII, client-confidential, financial, and proprietary information — may only be entered into an AI tool when all three of these are true:
No tool is HIPAA-compliant by default — a BAA and ITS-approved configuration must be in place before any PHI. Absent those approvals, use only de-identified, non-sensitive, or public information. When in doubt, don't enter it — ask first.
Approved tools are provisioned and configured by ITS so that Comagine Health data is not used to train third-party models, not retained beyond what's needed for service delivery, and not shared beyond the vendor as necessary. Commercial data protection is enabled on baseline Copilot.
Every tool's privacy, security, and data-retention posture is evaluated through the AI Impact Assessment (AIA) before approval. For PHI, a Business Associate Agreement (BAA) and a documented, approved configuration are required.
Comagine Health may monitor, log, and audit AI use — including prompts, outputs, configurations, and access patterns — where legally permitted and consistent with the Employee Handbook and security policies.
Monitoring is used to verify policy compliance, investigate suspected incidents, support continuous improvement, and meet regulatory, accreditation, and contractual obligations (Policy §5.5).
Report promptly — even if you're not sure an incident occurred.
Examples worth reporting: accidental PHI disclosure in an unapproved tool, AI-generated misinformation used in a deliverable, or signs of bias in outputs. Retaliation for good-faith reporting is prohibited.
The AI Impact Assessment (AIA) is the formal evaluation completed and approved before any new AI system, capability, model, or new high-risk use case can be used at Comagine Health. It's how something gets added to the list of what's approved.
An AIA documents: the purpose and business value; data inputs/outputs and their classification (and whether our data could train the vendor's models); privacy, security, and regulatory implications (HIPAA, state AI laws, accreditation, contracts); bias and fairness risks; explainability and limitations; the required level of human oversight; the validation/testing plan; and rollback/incident-response plans.
Approvals require sign-off from Security, Legal/Compliance, the relevant department leader, and ITS. AIAs are refreshed at least annually and whenever there's a material change. How it fits you: if the tool or use case you need isn't already approved, the AIA is the path to get it approved — start with a HelpDesk ticket.
The AI Inventory is the central, ITS-maintained, authoritative record of every AI system, capability, feature, and model approved for use at Comagine Health — along with the approved use cases, the data classifications each may handle, and any restrictions.
The rule of thumb: if it's not on the AI Inventory as approved for your use, it's not approved. You can check it on CoNet or confirm via a HelpDesk ticket.
A catalog of AI uses reviewed and approved under the policy, so use cases can be added or changed without re-issuing the whole policy. The initial approved use cases are:
All permitted use cases are conditional on data security and governance requirements. New or high-risk use cases are added through the AIA.
Yes. Human-in-the-loop (HITL) is the default and mandatory level of oversight: a qualified person reviews and approves each AI output before it's used, sent, or acted on. Expect errors, hallucinations, and bias, and correct them — accountability stays with you and Comagine Health, not the tool.
Human-on-the-loop (HOTL) — supervising a more autonomous system with the ability to intervene — is permitted only for use cases formally approved through an AIA.
Use professional judgment, consulting your manager where helpful. Disclosure is required only where law, regulation, a client contract, or another Comagine policy requires it.
It's generally not needed when AI played a supporting role — brainstorming, early drafting, grammar, formatting — and you shaped, validated, and own the final output.
Only in line with each client's AI policy. Obtain and follow it — some clients prohibit AI for deliverables, note-taking, or other uses. If a client has no AI policy, follow Comagine Health policy.
Where a client's policy conflicts with ours, contact Compliance via HelpDesk before proceeding.
AI agents take multi-step actions on your behalf — sending messages, modifying records, executing transactions — so they carry a higher risk profile than chat-based AI. They require an approved AIA, human-on-the-loop supervision with override/rollback, and written sign-off from your department VP and the VP of Product & Technology.
Autonomous AI is prohibited for any public-impacting decision, and assigning your substantive duties to an AI agent without human accountability is not allowed.
Yes, with an approved tool (e.g., Microsoft 365 Copilot) — but participants must be informed before any AI transcription or recording, you must review the notes for accuracy before circulating them, and you must never transcribe meetings on client engagements that prohibit it.
Violations may result in corrective action up to and including termination of employment or contract. That said, most issues are honest mistakes — report them promptly so they can be addressed and so we can improve guidance and guardrails.
Follow the escalation path for use/interpretation questions: project manager → manager → department vice president.
For technical questions about AI tools and access, submit a HelpDesk ticket (freshservice@comagine.org). Corporate Compliance and ITS are available as a backstop. You can also start at the ITS Corner.