The Prescription Label That Changed How I Use AI | CercaLabs

Insights › Health systems

Health systems

The Prescription Label That Changed How I Use AI

A compliant AI tool won't cover you if you sent more client data than the job needed. What I learned about minimum necessary before AEP.

By The CercaLabs team · Published September 8, 2026 · 5 minute read

I've been poking around at the AI tools being sold into our market, curious about what's actually shipping versus what's just a landing page. A line in one of the pitches stopped me.

Scan a prescription label with your phone. The app builds the client's medication list for you.

First reaction: clever. If you've ever sat at a kitchen table in October typing out eleven medications from a shoebox of orange bottles, you get the appeal immediately.

Then I thought about what's printed on a label. The client's name. Their address. The prescriber's name. The Rx number, the pharmacy, the fill date. Plus the drug and the dose.

What does a formulary check need out of all that? The drug. The dose. Maybe the county, so you pull the right plan set.

Two fields, maybe three. You just photographed seven.

The question I'd been asking was the wrong one

Here's what I got wrong, and I doubt I'm alone in it. Every conversation about AI and client data lands on the same question: is the tool HIPAA compliant? Reasonable question. Just not the first one.

HIPAA has a minimum necessary standard, at 45 CFR 164.502(b) with the implementation detail at 45 CFR 164.514(d). You disclose the least protected health information the job requires. Nothing more. And if you're an independent agent selling Medicare Advantage, you're generally a business associate or business associate subcontractor of the plan, so that standard follows you around. Not just the carrier.

Run it against the label again. You needed two fields. You sent seven, four of them direct identifiers. Do that inside a tool with a signed Business Associate Agreement and you're still offside.

A BAA makes the disclosure permissible. It doesn't make an unnecessary disclosure necessary. Took me longer to get to that sentence than it should have, and once I had it, it changed what I paste.

And your tier probably isn't covered anyway

The other thing I found surprised me more: most of us aren't on a covered tier to begin with. The tier matters way more than the brand name, and almost nobody checks.

Where it stood as of mid-2026, per each vendor's own compliance docs:

TierBAA available?
ChatGPT Free, Plus, Pro, Team, self-serve BusinessNo
ChatGPT Enterprise or Edu (sales-managed), ChatGPT for Healthcare, OpenAI APIYes, conditionally
Claude Free, Pro, Max, Team, self-serve EnterpriseNo
Claude API, HIPAA-ready Claude Enterprise (sales-assisted, HIPAA mode on)Yes
Consumer Gemini on a personal Google accountNo
Google Workspace with Gemini, Business or Enterprise tier; Vertex AIYes
Microsoft 365 Copilot: Family or Personal no; commercial tenant and Azure OpenAI yesDepends on tenant

Two traps in there I'd never considered. Even on a covered tier, particular features get carved out of BAA scope, so the whole product isn't automatically in. And this one's sneaky: if your agency has a covered enterprise account and you log in from home on your personal account, you're on the consumer surface. Same logo, no coverage.

This moves fast, so check the compliance page before you lean on any of it, mine included.

Where I've landed

I still use these tools constantly. What's left after you draw the line is most of the value anyway, roughly what an administrative person would've handled before a client group meeting:

  • Summarizing carrier documents so I understand them before I sit down with anybody
  • Building general presentation material, which I read and sign off on myself
  • Chewing through long CMS documents for my own comprehension
  • Drafting the reusable language in my templates

What stays out is anything with a person attached. Labeled medication lists, prior client sales data, somebody's ANOC. Not because the tool is bad. Because that data wasn't required for the work.

The test runs in my head in about two seconds: no client in the input, no beneficiary reading the output without me in between.

What's actually on the line

The personal piece first, since that's why you're still reading.

Realistically, the thing that ends a Medicare career isn't a regulator. It's the carrier. Plans have to report to CMS every for-cause termination of an agent or broker (42 CFR 422.2274(c)(3)), and that report follows you into every contracting packet afterward.

That road usually starts with a beneficiary complaint through the Complaint Tracking Module, then your carrier asking for your file. The Scope of Appointment, the recording, the materials you used. There's also a category of reputational and civil exposure nobody has mapped yet. A client finding out their prescription label got photographed into a chatbot isn't a regulatory conversation. It's worse.

For the agency, it's unapproved materials. Plan-specific marketing can't go out until CMS has approved it, deemed it approved, or accepted it under File and Use (42 CFR 422.2261), and AI doesn't shorten that clock by a day. Carriers also have a standing oversight obligation over you as a third-party marketing organization (42 CFR 422.2274(g)), which is why complaints roll downhill fast.

One fear I want to talk down, because I went looking and couldn't find it. There's no CMS rule governing agent use of AI. CMS floated AI guardrails in the CY 2026 rule and didn't finalize them (CMS CY 2026 Final Rule Fact Sheet, April 4, 2025). The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers is pointed at carriers, not producers, and as of Q1 2026 there were no reported state enforcement actions under any adopted version. This is ordinary data-handling risk at higher speed, not a new category of offense.

What I'd set up before October

Operational first, the part you can knock out on a Monday.

Do thisWhy it matters
Write down which tools are approved, and whether client data can appear in eachMost of us have never said this out loud
Confirm your tier is BAA-covered, not just the brandThe consumer tiers above aren't
Before pasting, name the minimum data the analysis needsThis is the whole control
Type the drug and dose instead of photographing the labelFifteen seconds, and four identifiers never leave the room
Keep a log: piece, AI-assisted or not, who reviewed it, dateSo you can show provenance in four minutes when a carrier asks

On redaction tools, I won't recommend a product. Vet your own against these:

  • It runs locally. Nothing leaves the device.
  • No telemetry, no cloud processing, no account required.
  • If you have to paste the data into a website to strip the identifiers, congratulations, you already made the disclosure you were avoiding. That one fails.

Legal second, where I stop and hand it off. Whether your E&O policy responds to a claim from AI-generated content, whether a vendor app calling an AI API gives you the full chain of BAAs you need, whether your downline's tool use flows through your own obligations. Counsel questions, all of them. Ask in writing. I'm not a lawyer.

Where none of this applies to you

If you've got an enterprise tool with a signed BAA covering that specific product and tier, and an FMO or carrier that's told you in writing what's allowed, you're fine. Follow their policy over mine. And if you never touch client data in these tools, the minimum necessary problem never comes up.

And here's the honest limit, which I'd rather say than pretend away. Redacting takes longer than pasting. During AEP nobody has time for admin tasks, and things with fuzzy penalties get skipped first. That's just true, and telling you to redact anyway isn't a plan, it's a lecture.

So run the trade before you paste. If stripping the identifiers costs more than the tool saves you on that task, don't use the tool for that task. Nobody's making you.

One last thing, and it's part of why I wrote this down. In all this digging I couldn't find one FMO that has put an actual AI policy in writing for its appointed agents. Not one. If yours has, I'd genuinely like to read it.

*None of this is legal advice.*