What Is Generative AI in Healthcare?
Generative AI in healthcare is the use of large language models and related generative systems to draft, summarize, translate, and reason over clinical and operational text and data — from a visit note to a triage protocol to a patient education handout. Where earlier healthcare AI focused on narrow predictive tasks (imaging classification, risk scoring), generative AI is broad and language-native: it works across the unstructured text that makes up most of a health system's knowledge and most of a clinician's day.
Adoption has moved fast. McKinsey's late-2025 healthcare survey found generative AI implementation climbed from 25% in 2023 to 47% in 2024 to 50% by the end of 2025, with more than 80% of adopters having already put a first use case in front of end users (McKinsey & Company, 2025). But healthcare is not a generic enterprise buyer. Every one of these applications can touch protected health information (PHI), so the question is never just "what can the model do" — it is "where does the data go, and can we prove it." That constraint is what makes this vertical different, and it is the thread running through the rest of this guide.
This page covers applications, use cases, and secure deployment. If you are choosing a tool to buy and need a HIPAA checklist and a ranked comparison, start with HIPAA-compliant AI tools for healthcare. For the broader modernization view, see healthcare digital transformation.
Applications of Generative AI in Healthcare
The highest-value applications of generative AI in healthcare cluster around the unstructured text that dominates clinical work — documentation, training, communication, and research. McKinsey's survey found clinical productivity is the single most widely implemented use case, in production at more than half of care-organization respondents, and that the organizations getting the most value pursue end-to-end workflow redesign rather than narrow, one-off point tools.
Clinical Documentation
The single most widely deployed use case. Generative AI drafts visit notes, summarizes charts, and structures clinical documentation so clinicians spend less time in the EHR and more time with patients. Estimate the reclaimed hours with our clinical documentation efficiency calculator, and see the compliant, secure end of the workflow in our secure AI transcription tools roundup.
Medical Training & Simulation
Field manuals, triage guidelines, and treatment protocols become an instantly searchable, accurate knowledge base for training. The US military's medical training branch deployed Blockify and AirgapAI to process 1,100+ pages in six minutes with zero hallucinations — a pattern that transfers directly to nursing education, residency programs, and continuing medical education.
Patient Communication
Generative AI drafts patient-facing education, after-visit summaries, and correspondence in plain language and at the right reading level — with a clinician in the loop for review. Because this content is patient-specific, controlling where the PHI goes is non-negotiable, which is why the deployment model matters as much as the model itself.
Research & Protocols
Synthesizing literature, drafting protocol documentation, and answering clinical-guideline questions accurately. Grounding matters most here: link a model to curated clinical knowledge and it cites the right protocol; leave it ungrounded and it invents one.
Beyond the clinical front line, generative AI is moving into operational and administrative work — coding support, prior-authorization drafting, and correspondence — and toward the frontier of agentic AI that coordinates multi-step workflows. McKinsey found 19% of healthcare organizations already implementing agentic AI, with a further 51% pursuing proofs of concept. Model the payoff of specific administrative workflows before you build with our healthcare HIPAA compliance cost calculator.
Examples of Generative AI in Healthcare
Examples of generative AI in healthcare include clinical documentation drafting, prior authorization letters, patient communications, medical training content, clinical policy and protocol Q&A, and medical coding assistance. Each one is a drafting task built on protected health information, so where the model runs decides whether the example is deployable.
The six examples below are the ones health systems fund first, and they share a shape: a large volume of unstructured evidence at the front, a required written artifact at the end, and a named clinician, coder, or reviewer who owns the result. That shape is what makes them safe to automate at the drafting layer and unsafe to automate at the decision layer. Each entry notes how protected health information has to be handled in that workflow, because in healthcare that is the constraint that decides which examples ever reach production.
-
Clinical documentation drafting
The most deployed example, and the one with the clearest arithmetic behind it. A grounded model drafts the visit note from the encounter, summarizes a long chart before rounds, and assembles the discharge summary from what is already in the record, so the clinician edits and signs instead of typing from scratch. The time it reclaims is time the profession measurably loses: a time-and-motion study in the Annals of Internal Medicine found physicians spend 49.2% of the office day on electronic health record and desk work against 27.0% on direct clinical face time. Model the reclaimed hours with the clinical documentation efficiency calculator.
PHI handling: The note is PHI from its first word, so the safe pattern is drafting where the chart already lives — on the clinician's device or inside the hospital network — rather than pasting encounter text into a general-purpose cloud assistant.
-
Prior authorization letters and appeals
Authorization requests, letters of medical necessity, and appeal packets are written artifacts assembled from evidence a clinician has already gathered: the diagnosis, the tried-and-failed therapies, the guideline the request rests on. Generative AI drafts that packet in the payer's required structure and cites the chart passages behind each assertion. The pressure to shorten the cycle is now regulatory as well as operational — CMS's Interoperability and Prior Authorization final rule (CMS-0057-F) requires impacted payers to return decisions within 72 hours for expedited requests and seven calendar days for standard ones — while the American Medical Association's annual prior authorization physician survey continues to put the burden at roughly 12 to 13 hours of physician and staff time per physician each week.
PHI handling: The draft carries diagnosis, treatment history, and record excerpts, so the letter is PHI in motion: it has to be composed and stored inside the covered entity's controls, or under a Business Associate Agreement if a third party ever touches it.
-
Patient communications
After-visit summaries, portal message replies, pre-procedure instructions, and education handouts written at the reading level the patient actually has. A model drafts in plain language and in the patient's preferred language; the clinician reviews and sends. This is where tone and clarity compound — the same instruction, rewritten at a sixth-grade reading level, is the difference between a followed care plan and a readmission — and it is also where a clinician in the loop is non-negotiable, because the draft is clinical advice the moment it reaches the patient.
PHI handling: Every one of these messages is patient-specific by definition, so the deployment model decides the risk: on-device generation keeps the message and the chart context that produced it from ever entering a third party's systems.
-
Medical training and simulation content
Field manuals, triage guidelines, nursing competencies, and residency curricula become an answerable knowledge base rather than a shelf of PDFs, and the same corpus generates case scenarios and knowledge checks for simulation. The US military's medical training branch deployed Blockify and AirgapAI to process 1,100+ pages in six minutes with zero hallucinations, running fully air-gapped — the pattern that transfers to nursing education, residency programs, and continuing medical education. See the US military medical training case study for how that was built.
PHI handling: Training content is usually built from de-identified or institutional source material, and when a real case is used for teaching it has to clear HIPAA's de-identification standard first — the constraint here is source fidelity rather than PHI exposure.
-
Clinical policy and protocol Q&A
Every health system runs on a library nobody reads end to end: infection-control policy, formulary, standing orders, coding policy, credentialing rules, and the change memos on top of them. An assistant grounded in that library answers “what is our protocol for this?” in seconds with the governing paragraph attached, instead of a page to the on-call supervisor. Grounding is the entire job — Blockify converts the library into governed IdeaBlocks so answers cite the protocol rather than paraphrasing a plausible one, which is what an Iternal medical-accuracy evaluation measured at a 261% average improvement over legacy chunking.
PHI handling: The corpus itself is institutional rather than patient data, which makes this the lowest-exposure place to start — though the question a nurse types can still contain PHI, so the assistant has to run somewhere that text is safe.
-
Medical coding and documentation integrity support
A model reads the documented encounter and proposes the ICD-10-CM and CPT codes it supports, flags the gaps a clinical documentation integrity specialist would query, and drafts the query itself. On the back end, the same capability reads denial letters and assembles the rebuttal from the record. The value is in preparation and consistency across a large volume of charts, not in autonomy: the codes submitted on a claim are an attested representation to the payer, so a certified coder or the clinician signs off on every one.
PHI handling: The chart is the input and the claim is the output, both PHI, so coding assistance belongs inside the revenue-cycle perimeter that already handles them rather than in a general-purpose external tool.
Generative AI for healthcare organizations pays off first where a person still signs the output and the data never leaves their control — which is why the deployment model is part of the use-case decision, not a downstream IT detail. AirgapAI runs these workflows on the device or inside the hospital network, and for the buying-side view of which tools qualify, see the ranked comparison of HIPAA-compliant tools.
Applications by care setting
The same six examples land differently depending on where care is delivered. An ambulatory clinic and a field medical team can run identical documentation workflows and still need different architectures, because one is constrained by staffing and the other by connectivity. The table below maps the applications of generative AI in healthcare onto the settings that fund them, with the constraint that shapes each.
| Care setting | Where generative AI lands first | The constraint that shapes it |
|---|---|---|
| Inpatient hospital and health system | Discharge summaries, chart summarization before rounds, shift handoff notes, policy and protocol Q&A | PHI crosses many roles and systems in a single stay, so the assistant runs inside the network and inherits the access controls the record already has |
| Ambulatory and primary care clinic | Visit-note drafting, portal message replies, referral and prior authorization letters | Small IT footprint and no appetite for a new data flow — on-device generation keeps chart text on the clinician’s laptop and adds nothing to inventory beyond software already inside the practice |
| Emergency, urgent care, and field medicine | Triage and protocol Q&A, rapid handoff summaries, after-action documentation | Connectivity is not guaranteed, so offline operation is a clinical requirement rather than a preference; air-gapped deployment is the only model that survives the setting |
| Payer and health plan operations | Authorization and appeal correspondence, member communications, coverage-policy Q&A, denial rebuttals | Member records are PHI under the same rules, and utilization-management determinations stay with the qualified reviewer — the model drafts the letter, never the decision |
| Home health, behavioral health, and long-term care | Visit and therapy documentation, care-plan updates, family communications | Documentation is produced in homes and facilities with variable connectivity, so the assistant has to work offline and store nothing outside the agency’s systems |
| Life sciences and clinical research | Protocol drafting, literature and evidence synthesis, regulatory and safety documentation | Source material is largely de-identified or study data, so the binding constraint is traceability — every claim in a regulated document has to point back to the source it came from |
Two things follow from reading the table across rather than down. First, the highest-volume examples — documentation and correspondence — appear in every setting, which is why they are the standard first pilot. Second, no row is solved by choosing a better model; every row is solved by choosing where the model runs. Training the staff who will use it is the other half of the work, covered in AI training for healthcare teams. For more information visit the healthcare and life sciences page.
The HIPAA Problem with Cloud AI
There is no AI-specific HIPAA rule — and that is exactly the problem. HIPAA is technology-neutral, so its existing Privacy and Security Rules already apply to any AI tool that touches PHI, without spelling out what "compliant AI" looks like. The moment you paste a patient's chart into a general-purpose cloud chatbot, that PHI has left your control and entered a third party's systems — usually without a Business Associate Agreement (BAA), and often with terms that permit the provider to retain or train on the data.
Regulators are closing that gap. HHS's Office for Civil Rights proposed the first major HIPAA Security Rule update in 20 years on January 6, 2025, which would require covered entities to maintain a technology-asset inventory that explicitly lists the AI software handling ePHI, and to assess — before deploying an AI tool — exactly what ePHI it can access and where its outputs go. The compliance gap this addresses is real: while a large majority of physicians now report using AI tools in practice, industry compliance-survey data suggests only about 23% of health systems have BAAs in place for the third-party AI they use.
Best practices for PHI-safe generative AI
- Control where PHI goes. Prefer deployment models where PHI is processed on your hardware or inside your network — on-device or air-gapped — so there is no third-party data flow to govern in the first place.
- Inventory every AI tool touching ePHI. Get ahead of the proposed rule: maintain a living inventory of AI software, what data it accesses, and where outputs land.
- Require a BAA for any cloud AI service. If PHI must reach a third party, no BAA means no deployment — full stop.
- Ground the model to reduce hallucination risk. Clinical accuracy is a patient-safety issue; grounding retrieval in curated knowledge is not optional.
For the full HIPAA-and-AI checklist, BAA guidance, and a ranked comparison of compliant tools, see the buyer's guide to HIPAA compliant AI. To pressure-test your own readiness, take the free Healthcare AI HIPAA Readiness Assessment, and estimate the budget and breach-risk side with our HIPAA compliance cost calculator.
Healthcare AI Consulting: What to Expect
Healthcare AI consulting turns the constraint above into a plan: it helps a health system pick the right use cases, deploy them in a HIPAA-safe way, and prove value before scaling. The best engagements leave your team more capable, not more dependent — and they lead with the security question, because in healthcare it decides which use cases are even viable.
A well-run healthcare AI consulting engagement moves through four stages:
| Stage | What happens | Typical duration | Outcome |
|---|---|---|---|
| 1. Assess | Diagnose data readiness, PHI exposure, and candidate use cases against clinical and compliance risk | 1–3 weeks | Prioritized, risk-scored use-case backlog |
| 2. Roadmap | Sequence use cases by value and feasibility; choose a PHI-safe deployment model | 2–4 weeks | Funded roadmap + HIPAA-aware architecture |
| 3. Pilot | Stand up the highest-value use case with governance and evaluation from day one | 30–90 days | Proven clinical/operational value |
| 4. Scale & enable | Industrialize what works; train clinical and admin staff for real adoption | Ongoing | Operating AI safely at scale |
Iternal delivers healthcare AI consulting as an engagement grounded in a real, deployable product line rather than slideware — strategy from the team behind The AI Strategy Blueprint, plus AirgapAI for on-device deployment and Blockify for clinical accuracy. The change-management layer — AI training for healthcare teams — is where adoption is won or lost, so it is part of the plan, not an afterthought.
What the Data Says
The evidence points the same direction: adoption is real and returns are being realized, but oversight and privacy remain the gating concerns. The numbers below make the case for moving now — and for moving in a way that keeps PHI in your control.
- Generative AI implementation reached 50% of payers, providers, and health-tech firms by the end of 2025, up from 25% in 2023 and 47% in 2024, with 82% of adopters anticipating a positive ROI and 45% already quantifying returns in the 2–4x range (McKinsey & Company, 2025).
- 19% of healthcare organizations are already implementing agentic AI, with a further 51% pursuing proofs of concept — and high performers pursue end-to-end workflow redesign, not narrow point solutions (McKinsey & Company, 2025).
- Just two years ago, fewer than 5% of healthcare institutions worldwide were deploying AI at any level, per HIMSS — a baseline that has since given way to widespread deployment, even as governance and oversight frameworks become the top executive concern (HIMSS, 2026).
- HHS's Office for Civil Rights proposed the first major HIPAA Security Rule update in 20 years on January 6, 2025, which would require organizations to inventory the AI software handling ePHI and to document what PHI it accesses and where outputs go (HHS OCR, proposed rule, 2025).
- Oversight has to be lifecycle-long. The GAO, jointly with the National Academy of Medicine, argued for predictable, lifecycle-long oversight mechanisms to keep healthcare AI safe and effective after deployment — guidance that predates the generative-AI wave but frames why governance matters (GAO-21-7SP).
On-Device AI for Healthcare
The cleanest answer to the HIPAA problem is architectural: run the AI where the data already lives. When a generative AI assistant runs entirely on the clinician's device or inside the hospital network, PHI is processed locally and never transmitted to a third-party cloud — which means there is no external data flow to govern, no BAA gap to close, and nothing to inventory beyond the software already inside your walls. That is how on-device, air-gapped AI turns "compliant by exception" into "compliant by design."
AirgapAI is Iternal's on-device AI assistant, built for exactly this: a full generative AI experience running on standard AI-capable laptops and on-prem hardware with no internet connection required. Paired with Blockify — which converts clinical documents into patented IdeaBlocks for far more accurate retrieval — health systems get accurate answers grounded in their own trusted knowledge, without the data ever leaving the building. For the architecture options behind local deployment, see the private LLM guide and the primer on what air-gapped AI is.
- PHI never leaves your control. Local processing removes the single largest HIPAA exposure of cloud AI.
- Works offline. Rural clinics, field settings, and secure facilities get the same assistant with no connectivity dependency.
- Grounded for clinical accuracy. Blockify keeps answers tied to your protocols and source documents, not a model's guesswork.