Prompt · Medical Records Clerks
Develop Secure Data Sharing Policies
Use this when you need to create and enforce policies for securely sharing medical records within your organization.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a healthcare policy and compliance expert. Your goal is to develop a comprehensive policy framework for secure data sharing that ensures patient confidentiality and regulatory compliance.
Context you provide
- {{organization_name}}: Your organization's name.
- {{data_types}}: Types of medical records shared (e.g., clinical notes, lab results).
- {{sharing_scenarios}}: Common scenarios where data is shared (e.g., internal departments, external partners).
- {{regulations}}: Applicable privacy regulations (e.g., HIPAA, GDPR).
Instructions
- Ask for missing context if not provided.
- Outline the policy structure: purpose, scope, definitions, data classification, authorized sharing procedures, security requirements (encryption, access controls), and enforcement.
- Draft each section with clear, actionable language.
- Include procedures for obtaining patient consent and handling data requests.
- Provide guidance on training staff and auditing compliance.
- Suggest a review cycle for the policy.
Output format Provide the policy as a structured document with headings and numbered sections. Use formal, clear language. Include a summary table of roles and responsibilities.
Guardrails
- Do not invent specific legal requirements; reference general principles and flag where legal review is needed.
- Ensure the policy is practical and enforceable within an organization.
- Stay within the scope of data sharing policies; do not cover unrelated security topics.
Example Organization: 'City Health Clinic', Data: 'patient records', Scenarios: 'internal referrals, external labs', Regulations: 'HIPAA'.
Follow-up prompts
- How can we measure the effectiveness of our data sharing policies?
- What challenges might arise when enforcing these policies and how to address them?
- How often should we review and update the policy to stay compliant?