The AI translation is free. Where is your patient data going? 

Your patient data was secure…until someone pasted it into AI. 

Data security and data governance are huge concerns for most businesses, especially in the healthcare, medical, clinical research, and medical device sectors. 

The risks are real: regulations such as the U.S.’s Health Insurance Portability and Accountability Act (HIPAA) and the European Union’s General Data Protection Regulation (GDPR) set the standard for protection of electronic healthcare information. Pasting patient data into a public AI engine is a direct and serious violation of these regulations. Even the paid versions of consumer-grade AI tools (ChatGPT, Gemini, Claude) do not sign Business Associate Agreements, often use chat inputs to train their public models, and lack the technical security safeguards required for Protected Health Information (PHI). 

AI and medical data security is a hot topic. A recent paper in the Journal of Law, Medicine, and Ethics, titled “AI chatbots and challenges of HIPAA compliance for AI developers and vendors,” highlighted numerous risks. Some of these are at the developer level, while others are harder to control because they happen in everyday situations. A physician seeking to explain a complex medical concept in simpler terms may paste a block of text into a public AI engine, not realizing that the input contains protected health information. 

Translation is a particularly vulnerable link in the data security chain 

“What does that say in English?? Just paste it into ChatGPT!” 

For healthcare, medical, and clinical research organizations that work in multiple languages, translation is an integral component of the technical work. And the international landscape is growing:

All of these sectors require translation, both to and from English. And translation represents a particular data security risk, for several reasons: 

  1. Public AI tools don’t feel risky. Your organization has probably invested in secure IT systems, access controls, and workflows that comply with applicable regulations. Employees know this, and they follow your procedures…until they “just need to know what this says in English,” and paste protected information into Google Translate. One unsanctioned shortcut can bypass all of the safeguards you’ve so carefully set up. 
  2. Employees aren’t thinking about where the data goes. The point of public AI tools is to make translation feel fast and frictionless; they can translate thousands of words in seconds. But most of your employees don’t know how the information is processed, stored, or used. While they’re focused on whether the translation is accurate, the real issue is what happens to the data behind the translation. 
  3. Without a translation, work can come to a halt. Employees often feed information into an AI translation tool because they’re faced with an obstacle: text that they can’t read. Already short on time and facing a tight deadline, the employee thinks they’re using the right tool for the problem. Let’s say that text is in Japanese; it may not be until the employee sees the English result that they realize the problem: the text contains the patient’s name, ID number, and diagnosis. 

To manage the risk, you have to know where the data goes 

“If you share sensitive information in a dialogue with ChatGPT, Gemini, or other frontier models, it may be collected and used for training, even if it’s in a separate file that you uploaded during the conversation,” warns Jennifer King, PhD, a privacy and data policy fellow at the Stanford Institute for Human-Centered AI. 

Medical translation often involves multiple layers of sensitive or confidential information: 

  • Protected health information: patients’ names, addresses, birthdates, contact information, health insurance ID numbers, full-face photos, etc. 
  • Clinical trial information: details about the research study, including medications and devices used, preliminary results, patients assigned to control and experimental groups, etc. 
  • Regulatory documents: clinical protocols, investigator brochures, study reports, and technical documents. 

 All of these may need to be translated, but they require an auditable redaction process to remove confidential information. Your organization needs transparent visibility into where this information is transmitted, who can access it, and what happens after it is processed. None of this is possible if you use a public AI tool for translation. 

Free translation…costly consequences 

When it comes to data security, most organizations have robust policies and procedures in place. But translation often gets left out of that equation, or employees under deadline pressure choose the quickest available tool, inadvertently pasting confidential information into Google Translate or ChatGPT. 

“Free” AI translation Hidden data security riskPotential consequence
Employee pastes confidential or protected information into a public AI tool Sensitive data leaves your organization’s controlled IT environment and is transmitted to a public server Privacy breach or HIPAA violations; these can carry steep fines 
Clinical documents are translated with a free AI platform Your organization may not know how the data is stored, retained, or used. Even the paid versions of many AI engines do this. You’ve lost control of your confidential information; once it’s uploaded to an AI company’s server, it can’t be removed 
Your organization uses public AI engines to save time or cut translation costs You’re bypassing your established security reviews and approved workflows Regulatory exposure, reputation damage, and loss of patients’/customers’ trust 

In the end, these risks aren’t worth the potential impact. If you’re working with a reputable language services company, you’ve already established a procedure for processing confidential information and identifying what needs to be redacted, or handled only within a secure system. 

Time and cost constraints make it tempting to bypass the translation workflows you’ve already established, but the potential HIPAA violation, and having your confidential information stored on a public server forever, are simply not worth the risk. 

AI output may soon carry its own digital paper trail 

As of August 2, 2026, the transparency provisions in Article 50 of the European Union AI Act came into force. This includes a requirement for generative AI providers to make AI-generated and AI-manipulated output (text, images, etc.) detectable as AI-generated. The obligation is on the AI providers, and they’re taking it seriously. 

On August 14, 2026, Anthropic announced that “Future Claude models will generate text that contains a watermark. This is a way of determining the likelihood that Claude was involved in writing the text, and we, along with several other major AI providers, are implementing this change to comply with the EU AI Act.” 

If your organization uses AI for medical translation, it’s becoming increasingly important to not only validate the quality and accuracy of the translation, but to maintain an audit trail that includes:

  • Which AI system generated or edited the translation 
  • Whether the output complies with EU AI Act watermarking, if your organization does business in the EU
  • Who reviewed the translated text, and what level of human oversight was applied 
  • Whether your end clients can distinguish raw AI output from human-verified content 

This means that once an employee pastes confidential or protected medical content into a public AI engine, they may have simultaneously created two data security issues: loss of control over the data itself, and the obligation to document the origins of the AI output. 

As AI expands into healthcare, regulators are demanding human review 

Across the medical and healthcare sectors, organizations are (understandably) trying to leverage the speed and scale gains that AI offers, while maintaining data security and quality. Until recently, AI has often been implemented in a haphazard way, as regulations struggled to keep up with the pace of innovation. 

This situation is changing, with the pendulum swinging toward human-in-the-loop requirements and prohibiting the use of unreviewed AI, particularly in decision-making situations. In 2026 alone, seven U.S. states have passed laws specifying how health insurance companies can use AI when making decisions about what their policies cover.

These laws have a variety of provisions. Some (Alabama) require insurance companies to disclose the use of AI in their claims review processes. Others (Colorado) go much further, targeting not only insurance companies, but pharmacy benefit managers and managed care entities, requiring that a “qualified professional” (not an AI tool) must review a coverage denial before it is communicated to the insured party. Illinois has outright prohibited AI-based “downcoding,” where the insurance company unilaterally changes a billing code to a lower-cost service than what the provider originally submitted. A new law specifies that a human must review every downcode against the American Medical Association’s guidelines. 

Human-in-the-loop: pluses and minuses

When we talk about AI versus human workflows, human-in-the-loop, or expert-in-the-loop, often seems like a good balance between the two. Human-in-the-loop also formalizes a principle that Language Scientific has followed since the advent of machine translation several decades ago: automation can assist with high-stakes work, but it should not have the final word. 

Human-in-the-loop systems have a number of advantages:

  • Most importantly, they create accountability. An identifiable expert is responsible for validating the automated system’s results, combining automation’s speed and scale benefits with human accountability. 
  • They provide safeguards around unusual cases. Algorithm-based systems work best when they’re dealing with predictable or recurring patterns. Humans are better at identifying and handling cases that don’t fit the pattern, whether that’s a patient’s medical record or a tricky translation. 
  • They catch errors that sound correct, but aren’t. This is particularly important for translations: AI translation mistakes are difficult to catch because they usually don’t sound incorrect to a human who doesn’t know the subject matter.

It’s also important to acknowledge the limitations of human-in-the loop systems:

  • They can quickly become “human as rubber stamp.” If the human expert is simply reviewing and approving what the AI system generated, “approval bias” can quickly creep in, especially if the human is reviewing large volumes of data. 
  • They can recreate the bottlenecks that AI was supposed to eliminate. If the automated system is “iffy” enough that the human has to review every word, any speed or cost gains may be eliminated. 
  • The quality of the human matters. Review by a human isn’t the same as review by an expert. Review of a translation by a bilingual employee is fundamentally different from review by a qualified medical linguist with subject-matter expertise. For this reason, Language Scientific uses only bilingual medical professionals with translation experience, or highly specialized medical translators.  

AI-related regulations are evolving quickly, and the best way to stay in compliance is having an experienced, ISO-certified medical translation company on your side. Language Scientific closely tracks these changing requirements so that you don’t have to. We provide medical-grade accuracy in translation, and we make sure that you know where your data is going and how it’s used. 

Related Posts

Pharmaceutical Translation

Does your pharmacy provide the same standard of care in every language?

Language barriers mean millions of patients can’t safely take their own medications

pharmacy dessert

AI translation: A hidden liability for pharmacies

ai translation

Why AI Alone Isn’t Enough for Medical, Scientific and Technical Translation

How Technology and Subject-Matter Expertise Improved International COA Validation

Clinical Trial Translation Services: Ensuring Accuracy from Protocol to Publication

Secure, On-Time Medical Package Translation for Endpoint Adjudication