Comagine Health ← Back to AI Hub
AI @ Comagine Health

AI — Frequently Asked Questions

Quick answers about using AI at Comagine Health — what's available, what's allowed, and how to stay safe and compliant. For full detail, see AI Policy ITS-0022.

The short version: AI is encouraged to help you work better — but you stay accountable for everything it produces. Use only approved tools through your Comagine account, keep a human reviewing every output, and never put sensitive data into a tool that isn't approved for it. When in doubt, ask before you act.
1AI Basics
What is AI?

Artificial intelligence (AI) refers to computer systems that perform tasks traditionally requiring human intelligence — understanding language, reasoning, recognizing patterns, generating content, making predictions or recommendations, and carrying out multi-step tasks.

At Comagine Health, "AI" covers several things: generative AI (the large language models behind Copilot, Gemini, Claude, and ChatGPT that produce text), AI features built into everyday software, predictive and machine-learning systems, and AI agents that can take actions on your behalf.

One thing to always remember: AI can sound authoritative even when it's wrong — so its output needs a human review.

What are the benefits of using AI at Comagine Health?

Used well, AI can save time and raise the quality of everyday knowledge work. Common benefits include:

  • Faster drafting and editing of communications and documents
  • Quick summarization of long materials — reports, RFPs, contracts, policy sets
  • Research, ideation, and brainstorming support
  • Help with data analysis and visualization
  • Formatting and completing structured documentation
  • Less time on repetitive tasks, so you can focus on judgment-heavy work

The goal is to support and augment your expertise — not replace it.

What are AI's limitations and risks I should know about?

A few to keep front of mind:

  • Hallucinations — AI can produce confident, plausible-sounding content that is inaccurate or fabricated. Always verify facts, figures, and sources.
  • Bias — outputs can reflect biases in training data and produce unfair or skewed results.
  • Data sensitivity — never enter restricted or sensitive data into a tool that isn't approved for it.
  • Not a substitute for judgment — AI informs your work, but a qualified human stays accountable for every output and decision.

This is exactly why approved tools, human review, and the data rules in this FAQ exist.

Will AI replace my job?

No. Comagine Health's position is that AI supports human work and innovation — it does not replace professional judgment, clinical expertise, managerial accountability, or regulatory responsibility.

AI is a tool to help you work more effectively. You remain responsible and accountable for your work, and that human ownership is central to how we use AI.

2Getting Started
Am I expected to use AI in my role?

AI use is encouraged but not mandatory. The policy's purpose is to equip and encourage staff to use AI confidently, responsibly, and effectively — but AI is meant to support your work, not replace your professional judgment, clinical expertise, or accountability.

Use it where it genuinely helps. You remain fully responsible for any AI-assisted work product, including its accuracy and appropriateness.

Do I need to do anything to get started?

For the Baseline tool (Microsoft Copilot Chat), no setup is needed — it's already included with your Microsoft 365 account. Sign in at copilot.microsoft.com with your @comagine.org credentials.

For any other tool, submit a HelpDesk ticket (freshservice@comagine.org). Before you begin, it's worth skimming the AI Policy and the approved use cases so you know what's in bounds.

Will training be provided? When?

Yes. Training and guidance are being provided as part of the AI rollout, alongside this FAQ and the AI @ Comagine Health hub. [Add specific session dates/registration link here.]

Materials and recordings will be posted to the ITS Corner. Watch for announcements via your manager and internal channels.

3Tools & Access
What is Copilot, and what can it do?

Microsoft Copilot is Microsoft's AI assistant, and it appears at all three tiers — from a free chat assistant for everyone up to a platform for building custom agents.

BaselineCopilot Chat — available to all staff through Microsoft 365. A secure, web-based chat at copilot.microsoft.com with commercial data protection (prompts aren't used to train the models). Good for Q&A, drafting emails/memos, summarizing text you paste in, brainstorming, and basic coding or formula help. Chat only — no integration inside the Office apps.
AdvancedMicrosoft 365 Copilot (full add-on) — embedded directly in Word, Excel, Teams, Outlook, and SharePoint. Summarize meetings and draft follow-ups in Teams, draft and rewrite in Word, generate formulas and insights in Excel, draft and summarize email in Outlook, and search across your document libraries.
AgenticCopilot Studio (+ Azure AI Foundry) — build custom AI agents and automated workflows, with access to open-weight and Azure-hosted models. For developers/architects; agentic uses require an approved AIA and the agentic sign-offs.
What other AI tools are available to me? Is there a cost?

Beyond Microsoft Copilot, several tools are available across the access groups — the next few questions describe each one. At a glance:

BaselineMicrosoft Copilot Chat — all staff.
AdvancedMicrosoft 365 Copilot, Google Gemini & NotebookLM, and Claude Enterprise.
AgenticCopilot Studio, Gemini Advanced, Claude Enterprise, and ChatGPT Enterprise.

Is there a cost to you? No — where a tool is approved for you, licenses are procured by ITS and may be covered by an indirect rate or a specific contract, so you don’t need to budget for it personally. Submit a HelpDesk ticket with your use case to request access, and see the AI @ Comagine Health hub for the full side-by-side comparison. For the complete inventory — including meeting assistants and tools with embedded AI — see the Approved Tools list.

What are Google Gemini and NotebookLM?

Google's AI, available through our Google Workspace environment.

AdvancedGemini & NotebookLM — available through our Google Workspace for Nonprofits plan. Gemini assists with drafting and editing in Docs, Slides, Gmail, and Sheets, plus long-document summarization. NotebookLM answers questions grounded strictly in documents you upload — ideal for RFP and contract analysis — and can generate audio overviews of complex source sets.
AgenticGemini Advanced + Deep Research (Google One AI Premium) — Gemini 2.5 Pro reasoning, a 1M-token context window, NotebookLM Plus, and Deep Research, which autonomously searches the web and synthesizes a cited report.
What is Claude?

Anthropic's AI assistant, known for high-quality writing and careful document analysis.

AdvancedClaude Enterprise — Claude Chat (Standard seat) — strong writing quality, a large context window, persistent Projects, and shared workspaces. Well suited to consulting deliverables, nuanced client communications, and light coding.
AgenticClaude Enterprise — Cowork & Code (Premium seat) — agentic surfaces for multi-step file and task work and AI coding (EHR/API integrations), plus Extended Thinking and enterprise admin controls/SSO. Agentic use requires an approved AIA and sign-offs. See the Approved Tools list for the full surface and seat breakdown.
What is ChatGPT?

OpenAI's enterprise assistant. We use ChatGPT Enterprise, which spans everyday chat and several agentic surfaces.

AdvancedChatGPT Enterprise — Chat — everyday assistant with advanced reasoning models.
AgenticChatGPT Enterprise — Deep Research, Codex & Agents — autonomous multi-source research with cited reports, an AI coding agent, and multi-step task automation. Agentic use requires an approved AIA and sign-offs.
How do I request access to Advanced or Agentic tools, or a brand-new tool?

Submit a HelpDesk ticket (freshservice@comagine.org) describing your intended use case. ITS provisions approved tools for you.

If the tool or use case isn't approved yet, it goes through an AI Impact Assessment (AIA) first (see Section 4). For Agentic-group uses, written sign-off from your department VP and the VP of Product & Technology is also required.

Can I still use AI tools I already use outside of work?

On your own time and personal accounts, your personal AI use is your business.

But you may not use personal or free/consumer AI accounts for Comagine Health work, or enter any Comagine Health information into them. Work must go through ITS-provisioned @comagine.org accounts in enterprise/work mode, using only tools approved on the AI Inventory. Don't create Comagine accounts on any AI tool ITS hasn't provisioned.

4Data, Privacy & Security
Are these tools safe to use with sensitive information? Can I enter PHI, PII, or proprietary information?

Not by default. Restricted/sensitive data — PHI, PII, client-confidential, financial, and proprietary information — may only be entered into an AI tool when all three of these are true:

  • The tool is approved on the AI Inventory for that data classification;
  • Your use case is in the Approved AI Use Cases catalog (or an AIA-approved department procedure); and
  • The use complies with applicable contracts and regulations.

No tool is HIPAA-compliant by default — a BAA and ITS-approved configuration must be in place before any PHI. Absent those approvals, use only de-identified, non-sensitive, or public information. When in doubt, don't enter it — ask first.

How is data protected when using these tools?

Approved tools are provisioned and configured by ITS so that Comagine Health data is not used to train third-party models, not retained beyond what's needed for service delivery, and not shared beyond the vendor as necessary. Commercial data protection is enabled on baseline Copilot.

Every tool's privacy, security, and data-retention posture is evaluated through the AI Impact Assessment (AIA) before approval. For PHI, a Business Associate Agreement (BAA) and a documented, approved configuration are required.

How will AI usage be monitored, if at all?

Comagine Health may monitor, log, and audit AI use — including prompts, outputs, configurations, and access patterns — where legally permitted and consistent with the Employee Handbook and security policies.

Monitoring is used to verify policy compliance, investigate suspected incidents, support continuous improvement, and meet regulatory, accreditation, and contractual obligations (Policy §5.5).

How do I report a security or compliance concern?

Report promptly — even if you're not sure an incident occurred.

  • Tool/technical issues: submit a HelpDesk ticket (freshservice@comagine.org).
  • Privacy, security, ethics, or compliance concerns: report through Navex, the confidential reporting system (anonymous where permitted by law).

Examples worth reporting: accidental PHI disclosure in an unapproved tool, AI-generated misinformation used in a deliverable, or signs of bias in outputs. Retaliation for good-faith reporting is prohibited.

5Governance & Key Concepts
What is the AI Impact Assessment (AIA), and how does it fit in?

The AI Impact Assessment (AIA) is the formal evaluation completed and approved before any new AI system, capability, model, or new high-risk use case can be used at Comagine Health. It's how something gets added to the list of what's approved.

An AIA documents: the purpose and business value; data inputs/outputs and their classification (and whether our data could train the vendor's models); privacy, security, and regulatory implications (HIPAA, state AI laws, accreditation, contracts); bias and fairness risks; explainability and limitations; the required level of human oversight; the validation/testing plan; and rollback/incident-response plans.

Approvals require sign-off from Security, Legal/Compliance, the relevant department leader, and ITS. AIAs are refreshed at least annually and whenever there's a material change. How it fits you: if the tool or use case you need isn't already approved, the AIA is the path to get it approved — start with a HelpDesk ticket.

What is the AI Inventory?

The AI Inventory is the central, ITS-maintained, authoritative record of every AI system, capability, feature, and model approved for use at Comagine Health — along with the approved use cases, the data classifications each may handle, and any restrictions.

The rule of thumb: if it's not on the AI Inventory as approved for your use, it's not approved. You can check it on CoNet or confirm via a HelpDesk ticket.

What are "approved use cases"?

A catalog of AI uses reviewed and approved under the policy, so use cases can be added or changed without re-issuing the whole policy. The initial approved use cases are:

  • Drafting & refining communications (with human review and editing)
  • Research & summarization
  • Brainstorming & ideation
  • Productivity enhancement
  • Data analysis & visualization
  • Formatting & completing structured documentation
  • Clinical decision support (restricted — clinician remains accountable)

All permitted use cases are conditional on data security and governance requirements. New or high-risk use cases are added through the AIA.

Do I really have to review everything the AI produces? (Human-in-the-loop)

Yes. Human-in-the-loop (HITL) is the default and mandatory level of oversight: a qualified person reviews and approves each AI output before it's used, sent, or acted on. Expect errors, hallucinations, and bias, and correct them — accountability stays with you and Comagine Health, not the tool.

Human-on-the-loop (HOTL) — supervising a more autonomous system with the ability to intervene — is permitted only for use cases formally approved through an AIA.

Do I need to disclose when I've used AI?

Use professional judgment, consulting your manager where helpful. Disclosure is required only where law, regulation, a client contract, or another Comagine policy requires it.

It's generally not needed when AI played a supporting role — brainstorming, early drafting, grammar, formatting — and you shaped, validated, and own the final output.

Can I use AI on client or contract work?

Only in line with each client's AI policy. Obtain and follow it — some clients prohibit AI for deliverables, note-taking, or other uses. If a client has no AI policy, follow Comagine Health policy.

Where a client's policy conflicts with ours, contact Compliance via HelpDesk before proceeding.

What about AI agents / "agentic" AI?

AI agents take multi-step actions on your behalf — sending messages, modifying records, executing transactions — so they carry a higher risk profile than chat-based AI. They require an approved AIA, human-on-the-loop supervision with override/rollback, and written sign-off from your department VP and the VP of Product & Technology.

Autonomous AI is prohibited for any public-impacting decision, and assigning your substantive duties to an AI agent without human accountability is not allowed.

Can I use AI to take or transcribe meeting notes?

Yes, with an approved tool (e.g., Microsoft 365 Copilot) — but participants must be informed before any AI transcription or recording, you must review the notes for accuracy before circulating them, and you must never transcribe meetings on client engagements that prohibit it.

What happens if I don't follow the policy?

Violations may result in corrective action up to and including termination of employment or contract. That said, most issues are honest mistakes — report them promptly so they can be addressed and so we can improve guidance and guardrails.

Who do I contact if I have questions about using AI?

Follow the escalation path for use/interpretation questions: project manager → manager → department vice president.

For technical questions about AI tools and access, submit a HelpDesk ticket (freshservice@comagine.org). Corporate Compliance and ITS are available as a backstop. You can also start at the ITS Corner.

Key Terms
AI Impact Assessment (AIA)
The formal evaluation completed and approved before any new AI tool, capability, model, or high-risk use case is allowed. It reviews purpose, data, privacy/security/regulatory impact, bias, explainability, human oversight, and validation — and records approvals. It's the process that adds something to the AI Inventory.
AI Inventory
The authoritative, ITS-maintained list of all AI tools, capabilities, and models approved for Comagine Health, with the approved use cases and permitted data classifications. If it's not listed as approved for your use, it's not approved.
Approved AI Use Cases
The catalog of AI uses reviewed and approved under the policy (e.g., drafting, summarization, data analysis), each with conditions. Referenced by the policy so use cases can change without re-issuing it.
Business Associate Agreement (BAA)
A contract with a vendor required under HIPAA before protected health information may be processed. A BAA plus an approved configuration is mandatory before any PHI goes into a tool.
Human-in-the-Loop (HITL)
The default, mandatory oversight model — a qualified person reviews and approves each AI output before it is used or acted upon.
Human-on-the-Loop (HOTL)
A human supervises a more autonomous system, able to monitor, intervene, override, or halt it. Permitted only for use cases approved through an AIA; never for autonomous public-impacting decisions.
AI Agent / Agentic AI
An AI system that plans and takes multi-step actions on your behalf (e.g., sending messages, modifying records). Higher risk; requires an approved AIA, HOTL supervision, and VP sign-off.
Public-Impacting Decision
Any decision, recommendation, or action affecting a client, patient, member, applicant, employee, or the public, or carrying legal/financial/regulatory/contractual consequences. A qualified human must make or approve these; AI may not make them autonomously.
Hallucination
AI output that is inaccurate, fabricated, or unsupported but presented as factual. Always verify facts, sources, and figures before relying on AI output.
High-Risk AI Use Case
A use that, if it fails or is misused, could materially harm people or the organization, or that triggers heightened regulatory requirements — including clinical, eligibility, coverage, payment, employment, public-facing, or regulated contexts. Requires an AIA.
Restricted / Sensitive Data
Information that's confidential, regulated, or proprietary — including PHI (protected health information), PII (personally identifiable information), client-confidential, financial, and proprietary company data. May only be used in tools approved for that classification.
Prompt Injection
A security attack where malicious content hidden in data fed to an AI causes it to behave in unintended ways. Be cautious pasting untrusted content into AI tools.