Every long-term care facility runs reports. But reports are built for the general case, and staff needs are never that general. A DON wants to see falls broken down by shift and unit. A biller wants to reconcile a batch of claims against a specific payer. An administrator wants a number that no canned report was built to produce. So staff take what the system gives them and start reshaping it by hand, or worse, they export it and turn to a tool that can actually answer questions on demand: ChatGPT, Claude, or whatever AI assistant they already use on their phone.
That instinct makes sense. It’s also a HIPAA violation waiting to happen. Once resident data leaves a system with a signed Business Associate Agreement and lands in a consumer AI account, the facility has no assurance about how that data is stored, retained, or used to train future models. Most staff doing this aren’t trying to cut corners. They just don’t realize that pasting a spreadsheet into a chat window is fundamentally different from running a report inside their EMR.
There are a few ways facilities try to solve this, and it’s worth being clear-eyed about what each one actually costs.
Enterprise AI accounts.
Some organizations sign up for healthcare-tier accounts with AI vendors that offer a BAA and proper data handling. This works, but it adds a real line item, and staff still have to download data out of their software and upload it somewhere else before they can ask a single question.
Wraparound add-on tools.
Others buy a separate AI layer that connects to their existing software through an API, which at least removes the download-upload step. But these tools tend to be expensive, and they usually only cover one narrow slice of the workflow rather than the full system. And every add-on is another login, another vendor, another invoice, another thing IT has to maintain and secure. That overhead adds up fast across a multi-facility organization.
Software with AI built in.
The more direct answer is choosing a system where the AI already lives inside the platform staff use every day, with the BAA, data retention terms, and PHI handling already worked out at the vendor level. There’s nothing to export, nothing to reconcile between two systems, and nothing for staff to figure out on their own about what’s safe to paste where. The AI has direct access to the data it’s answering questions about, because it never left the system in the first place.
None of these approaches are complicated once you see them side by side. The real risk isn’t that staff want better answers from their data. It’s that, absent a safe way to get them, they’ll find an unsafe one. The facilities that get ahead of this are the ones asking their software vendors a straightforward question: is AI already