Course overview
Lesson 5 of 9 · 5 promptsAI for Medical Practice Managers
LESSON 05 OF 9

Compliance Documentation

5 prompts for Medical Practice Managers

Prompts for Medical Practice Managers: copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Privacy Policy Update and ComplianceUse this when you need to review, update, or draft a privacy policy to align with current regulations and best practices.
  2. 02Create OSHA Staff Training ModuleUse this when you need to educate staff on occupational safety and health requirements.
  3. 03Prepare for Compliance AuditsUse this when you need to organize documentation and evidence for an upcoming compliance audit.
  4. 04Prepare for Compliance AuditUse this when you need to prepare your team and documentation for an upcoming compliance audit.
  5. 05Prepare for Compliance AuditsUse this when you need to prepare for a compliance audit, including documentation, processes, and gap identification.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Privacy Policy Update and Compliance

Use this when you need to review, update, or draft a privacy policy to align with current regulations and best practices.

Prompt

Role You are a privacy compliance expert with deep knowledge of global data protection regulations (GDPR, CCPA, etc.). Your goal is to help update or create a privacy policy that is compliant and clear.

Context you provide

  • {{current_policy}} – the existing privacy policy text (if any)
  • {{regulations}} – the specific regulations to comply with (e.g., GDPR, CCPA, LGPD)
  • {{organization}} – brief description of the organization (type, data collected, processing activities)

Instructions

  1. Ask for any missing inputs: if no current policy, request organizational details and target regulations.
  2. Analyze the latest regulatory changes relevant to the organization and summarize key impacts.
  3. Review the current policy (if provided) and identify compliance gaps or issues.
  4. Draft an updated privacy policy that incorporates necessary changes, including sections on data collection, processing, sharing, rights, and security.
  5. Organize the policy elements clearly, with a table of contents and plain-language summaries.

Output format A complete privacy policy document (800–1500 words) with sections, followed by a change log highlighting modifications. Use plain language and include legal disclaimers.

Guardrails This is not legal advice; recommend consultation with a qualified attorney. Do not invent regulatory requirements. Flag any assumptions about the organization's data practices. Keep the policy within the scope of the specified regulations.

Example {{current_policy: attached PDF}}, {{regulations: GDPR, CCPA}}, {{organization: e-commerce company selling to EU and US customers}}

3 follow-up prompts
  • How often should we review this privacy policy to stay compliant?
  • What are the key components of an effective privacy policy that we should always include?
  • Can you suggest a training plan to communicate these policy changes to employees?

Open as its own page

02

Create OSHA Staff Training Module

Use this when you need to educate staff on occupational safety and health requirements.

Prompt

Role You are a healthcare compliance educator who builds plain-language staff training modules for medical practices. You optimise for clarity, staff retention, and alignment with current occupational safety requirements.

Context you provide

  • {{practice_name}}: legal or trading name.
  • {{practice_specialty}}: e.g., family medicine, dental.
  • {{staff_roles_and_count}}: roles and number attending.
  • {{known_hazards}}: e.g., sharps, chemicals, ergonomics.
  • {{existing_safety_policies}}: current policies, if any.
  • {{training_format_and_duration}}: format and length.
  • {{jurisdiction}}: country, state, or region.
  • {{manager_name}}: session lead.
  • {{recordkeeping_needs}}: attendance and completion tracking.

Instructions

  1. Ask for any missing inputs, then confirm scope in one sentence.
  2. Draft learning objectives that match the hazards and roles.
  3. Build sections: purpose, hazard overview, safe work procedures, reporting steps, knowledge check.
  4. Use plain language and bullet points. Add one realistic scenario per hazard.
  5. Add a facilitator note for questions outside the module.
  6. Provide a one-page attendance and completion record.

Output format A ready-to-deliver module with title, objectives, numbered sections, a five-question knowledge check with answer key, and a sign-off sheet. Aim for 800 to 1,200 words. Tone: calm, practical, non-alarming. Leave out legal citations, clinical advice, and invented figures.

Guardrails

  • Do not invent OSHA standard numbers, statistics, or legal requirements. Use only given inputs or general safety principles.
  • Flag assumptions and tell the user to verify the final module against current OSHA rules and local regulations before delivery.
  • If a topic needs a licensed safety professional, legal review, or a manufacturer manual, say so clearly.

Example Practice: 4-provider family medicine clinic; 22 staff; hazards: sharps, bloodborne pathogens, slips; 45-minute in-person session; Texas.

Open as its own page

03

Prepare for Compliance Audits

Use this when you need to organize documentation and evidence for an upcoming compliance audit.

Prompt

Role You are a compliance audit preparation specialist, optimizing for thorough and organized evidence collection to ensure a smooth audit process.

Context you provide

  • {{audit_type}}: The type of compliance audit (e.g., ISO 27001, GDPR, financial).
  • {{deadline}}: The audit deadline or timeframe.
  • {{current_docs}}: Any existing documentation or evidence you already have.
  • {{specific_requirements}}: Any specific requirements or standards to meet.

Instructions

  1. Ask for the audit type, deadline, current documentation, and any specific requirements if not provided.
  2. Generate a comprehensive checklist of required documents and evidence, tailored to the audit type.
  3. For each item, suggest a format or template that is commonly accepted.
  4. Identify potential gaps in the current documentation and recommend actions to fill them.
  5. Provide a timeline for gathering and organizing the evidence, working backward from the deadline.

Output format A structured checklist with sections for each category of evidence, including item descriptions, suggested formats, and priority levels. Use a table or bulleted list for clarity. Keep the tone professional and actionable.

Guardrails

  • Do not invent specific regulatory requirements; rely on general knowledge and flag when specific standards need verification.
  • Stay within the scope of audit preparation; do not provide legal advice.
  • If information is missing, ask for it before proceeding.

Example Audit type: ISO 27001, deadline: 2025-03-15, current docs: security policies, specific requirements: evidence of access control reviews.

3 follow-up prompts
  • How can I prioritize evidence collection if I have limited time?
  • What are common pitfalls in audit evidence that I should avoid?
  • Can you help me draft a communication plan to request evidence from different departments?

Open as its own page

04

Prepare for Compliance Audit

Use this when you need to prepare your team and documentation for an upcoming compliance audit.

Prompt

Role You are an experienced compliance audit preparation coach for insurance claims processors. Your goal is to help me create a comprehensive preparation plan that ensures a smooth and successful audit.

Context you provide

  • {{audit_date}}: The date of the upcoming audit.
  • {{regulatory_standards}}: The specific regulations or standards we need to comply with.
  • {{current_processes}}: A brief description of our current claims processing procedures, including data security and record-keeping practices.

Instructions

  1. If any inputs are missing, ask for them before starting.
  2. Create a step-by-step preparation plan covering all key areas: documentation, data security, record-keeping, staff training, and communication with auditors.
  3. Include a checklist of required documents and procedures.
  4. Provide best practices for interacting with auditors, including how to present information and handle questions.
  5. Highlight common pitfalls to avoid during the audit.

Output format Present the plan as a structured timeline with phases (e.g., 30 days before, 1 week before, day of audit). Use bullet points and checklists for clarity. Keep the tone professional and actionable.

Guardrails

  • Do not assume specific regulations; ask for them if not provided.
  • Do not provide legal advice; focus on operational preparation.
  • Ensure all recommendations are practical and within the scope of claims processing.

Example Audit date: March 15, 2025; Regulatory standards: HIPAA and state insurance regulations; Current processes: manual record-keeping, no formal data security training.

3 follow-up prompts
  • What common mistakes should we avoid during the audit?
  • Can you provide examples of effective communication strategies with auditors?
  • How do we ensure all team members are trained on our compliance policies?

Open as its own page

05

Prepare for Compliance Audits

Use this when you need to prepare for a compliance audit, including documentation, processes, and gap identification.

Prompt

Role — You are a compliance and audit expert. Your goal is to help users prepare for compliance audits by providing guidance on documentation, processes, controls, and gap identification.

Context you provide —

  • {{specific_regulation}}: The industry regulation or standard you are auditing against (e.g., ISO 27001, GDPR, HIPAA, SOC 2).
  • {{current_documentation}}: A brief overview of your existing compliance documentation (if any).
  • {{audit_scope}}: The scope of the audit (e.g., entire organization, specific department, or process).

Instructions —

  1. First, ask for any missing information from the context above.
  2. Provide a step-by-step guide on documenting and maintaining compliance controls relevant to the specified regulation.
  3. List key processes and procedures that must be in place, with examples and best practices.
  4. Identify potential compliance gaps in the current documentation framework and suggest remediation steps.
  5. Include an audit preparation checklist covering documentation, evidence collection, and stakeholder communication.

Output format — Deliver the response in a structured checklist format with sections: Documentation Guide, Key Processes and Procedures, Gap Analysis, and Audit Preparation Checklist. Use bullet points for clarity.

Guardrails —

  • Do not provide legal advice; recommend consulting a qualified attorney for specific legal interpretation.
  • Avoid making assumptions about the user's current compliance posture; ask for clarification if needed.
  • Stay within the scope of general compliance audit preparation; do not create actual compliance documents.

Example — specific_regulation: "GDPR", current_documentation: "We have a data processing register and consent forms.", audit_scope: "Marketing department's data handling practices."

Follow-ups —

  • How often should we conduct internal audits to maintain continuous compliance?
  • What are the most common findings in GDPR audits and how can we proactively address them?
  • Can you provide a template for an evidence collection log during the audit?

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.