AI tools are everywhere: in your EHR, in your browser, in the platforms your team uses every day. Maybe you're already using them intentionally for notes or admin. Maybe you're not sure you want to. Either way, these tools are part of the landscape now, and they come with compliance implications that most therapists haven't had a reason to think about until now.
Think about how many AI tools touch your work in a given week. Now ask: which of those provide a BAA? Which ones store what you type? Which ones are training their models on your input? If you don't know the answer, you're not alone, but you may have a problem.
Potential risks get harder to track the more people you have on your team. Maybe someone left an AI assistant running in their browser during a session. Maybe there's a meeting bot on your video platform that's been recording and transcribing client calls without a BAA. In cybersecurity, this is called shadow AI, and it's one of the fastest-growing sources of data breaches in healthcare right now.
This is the follow-up to our May 15th session on HIPAA and cybersecurity fundamentals. This time, Burt Maben of Creative Cyber Management zeros in on AI: what makes a tool safe to use, what questions to ask before you adopt something new, what permissions you need from clients, how to think about AI across your team's workflow, and how to spot the shadow AI risks that may already be in yours.
Understand the security and compliance implications of using AI tools in clinical documentation, communication, and practice management.
Identify what distinguishes a safe, compliant AI tool from one that isn’t — including BAA requirements, data storage practices, and model training policies.
Recognize shadow AI and its risks: what happens when unapproved tools enter clinical workflows without oversight.
Discuss client consent and disclosure considerations when integrating AI into your practice.
Evaluate your current AI tools and workflows for security gaps.
Explore practical strategies for building an AI usage policy for your practice, whether solo or group.
Whether you’re actively using AI, cautiously exploring, or not interested yet — the compliance landscape around these tools is evolving fast, and most therapists haven’t had a chance to catch up. This webinar helps you understand where you stand and what to do about it.
Presentation (~45 minutes): AI-specific security and compliance considerations for private practice: evaluating tools, BAA requirements, shadow AI risks, client permissions, data handling, and building a compliant AI workflow.
Q&A : Bring your real questions about your practice setup, tools, and workflows.
This webinar is designed for mental health professionals in private practice who are using or considering AI tools in their clinical or administrative work. It’s especially relevant if you use AI for documentation, notes, scheduling, content creation, or any task that involves client information.
Professionals who will find this material valuable include: psychotherapists, counselors, psychologists, social workers, marriage and family therapists, psychiatric nurse practitioners, practice managers, and clinical directors.
No technical background is needed. Attendance at the May 15th HIPAA fundamentals session is helpful but not required.
Meet Your Presenter
Founder & Principal, Creative Cyber Management, LLC
Burt Maben knows what it’s like to be a small business owner on the wrong end of a cyberattack. After founding and growing the largest single-site martial arts and fitness organization in Louisiana, he and his wife experienced firsthand what happens when your website gets hijacked, your email gets spoofed, and your bank accounts get compromised. Instead of just recovering, they fought back — making operational changes that drastically reduced their exposure and building the expertise that would become their second business.
In 2010, Burt founded Creative Cyber Management, LLC to help other small business owners build cyber resiliency. Today the firm serves small and medium businesses, nonprofits, cultural institutions, and healthcare professionals with customized cybersecurity solutions aligned with best practices defined by CISA (the U.S. Cybersecurity and Infrastructure Security Agency). Burt doesn't deal in techno-babble — he speaks the language of business owners who want to protect what they've built.
FREE webinar
Date: 5/29/2026 12-12:45 EST
Access to the recording available for 90 days
No CEUs available at this time
This workshop will be recorded and shared with participants after the event ends. You will receive access to the recording even if you aren't able to attend live.