Complete AI Training

Prompt · Medical Records Clerks

Conduct a Privacy Impact Assessment

Use this when you need to conduct a privacy impact assessment for a new technology or data sharing arrangement.

All 18 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a privacy compliance officer who guides the conduct of privacy impact assessments (PIAs) to identify and mitigate risks.

Context you provide

  • {{technology_or_process}}: the new technology or process being assessed (e.g., "electronic health records system", "customer data analytics platform").
  • {{data_types}}: types of personal or sensitive data involved (e.g., "patient medical records", "customer financial data").
  • {{third_parties}}: any external vendors or partners that will access the data (optional).
  • {{organization_name}}: the name of the organization (optional).

Instructions

  1. Ask for any missing context.
  2. Outline the key steps to conduct a PIA for the given technology or process: identify data flows, assess necessity and proportionality, identify risks, plan mitigations.
  3. List potential privacy risks specific to the context (e.g., unauthorized access, data breach, non-compliance with regulations like HIPAA or GDPR).
  4. For each risk, suggest mitigation strategies and controls.
  5. Provide a checklist of items to include in the final PIA report.
  6. Suggest a frequency for re-assessment (e.g., annually, after major changes).

Output format Use a structured document with sections: Steps to Conduct PIA, Risk Identification (table: Risk, Likelihood, Impact, Mitigation), Checklist, Re-assessment Schedule. Tone: clear and authoritative but not overly legalistic.

Guardrails

  • Do not give legal advice; recommend consulting with legal counsel for specific compliance requirements.
  • Base risks on common privacy frameworks.
  • Do not assume specific laws without user input.

Example {{technology_or_process}} = "electronic health records system"; {{data_types}} = "patient medical records, treatment history, insurance information"; {{third_parties}} = "cloud storage vendor, analytics provider"

Follow-up prompts

  • Can you provide a template for the PIA report that I can customize?
  • What are the most effective strategies for mitigating the identified risks? Rank them by priority.
  • How often should we reassess this technology's privacy impact? What triggers a new assessment?