Artificial Intelligence (AI) Policy
Scope
Artificial Intelligence (AI) tools can improve productivity, analysis, communication, and decision support, but they also introduce information security, data protection, accuracy, and responsible-use risks. This policy provides requirements for the safe and appropriate use of AI tools for Nixon Medical business purposes while protecting company, associate, customer, and other sensitive data.
What are AI tools?
AI tools allow users to enter prompts and receive generated, gathered, analyzed, or transformed responses. Different AI tools handle information in different ways. Public or unapproved AI services may retain, process, or use information outside Nixon Medical’s control, which can create a risk of data leakage or unauthorized disclosure.
Nixon Medical provides NM1 as its approved internal AI platform. NM1 and the tools available through it are designed for Nixon Medical work purposes and provide an approved environment for working with company information, subject to applicable access controls and company policies. NM1 is not intended for personal use. AI outputs can still be inaccurate, incomplete, or misleading, so associates must use AI responsibly and apply appropriate judgment.
Purpose
The purpose of this policy is to ensure that associates use AI tools securely, responsibly, and appropriately for business purposes. It establishes when NM1 should be used, how company information must be protected, the requirements for using other AI tools, and the associate’s responsibility to verify AI-generated results.
Policy Statement
Nixon Medical recognizes both the opportunities and risks of AI. NM1 is the company’s approved internal AI platform for business use and should be the default AI environment when working with Nixon Medical information. NM1 and its tools are provided for work-related purposes only and are not intended for personal activities or personal data. Associates must follow this policy, applicable company policies, and established security practices whenever using AI tools.
Security Best Practices
1. Approved AI tools and evaluation
- NM1 is Nixon Medical’s approved internal AI platform and should be used for work-related AI activities involving company information.
- NM1 and the tools provided through it are for Nixon Medical business purposes only. Associates must not use NM1 for personal projects, personal accounts, personal documents, or other non-business activities.
- AI tools or services outside NM1 must not be used with Nixon Medical confidential, proprietary, customer, associate, or otherwise sensitive information unless the tool has been reviewed and approved by IT for that use.
- Associates who have a business need for an AI tool that is not available through NM1 must involve IT before using the tool with company information so that privacy, security, terms of service, data handling, and third-party risks can be evaluated.
2. Protection of company and confidential data
- Company information may be used within NM1 for legitimate business purposes when the associate is authorized to access and use that information and the activity complies with applicable company policies.
- Confidential, proprietary, customer, associate, or personally identifiable information (PII) must not be entered into public or unapproved AI tools. Examples include names, addresses, phone numbers, email addresses, account numbers, government IDs, or combinations such as CUSTOMERNAME + CUSTOMERNUMBER.
- Financial information, contracts, HR records, pricing strategies, source code, customer service records, and other sensitive company information must not be shared with public or unapproved AI tools.
- When using an approved external AI tool, associates must follow the specific data-handling restrictions established by IT for that tool. Anonymizing information does not replace the requirement to use an approved tool.
3. Access control
- Access to NM1 and other company-approved AI tools is limited to authorized users and must not be provided to individuals outside Nixon Medical without prior approval.
- Associates must not share login credentials, authentication tokens, API keys, or other sensitive access information. Access controls and permissions must not be bypassed or used to expose information to unauthorized users.
4. Compliance with security policies
- AI use must comply with existing Nixon Medical security, privacy, records, confidentiality, and acceptable-use requirements.
- Associates must use company-approved accounts and access methods, protect credentials, apply required software updates, and follow the Computer Acceptable Use Policy and other applicable standards.
5. Data privacy and appropriate use
- Before entering information into an AI tool, associates must confirm that the tool is approved for the type of information being used and that the use serves a legitimate Nixon Medical business purpose.
- NM1 may be used with work information in accordance with company policies, user access rights, and any restrictions communicated for a specific NM1 tool or capability.
- Personal information or content unrelated to Nixon Medical business must not be entered into NM1. Associates should use personal AI services and personal accounts outside company systems for personal use, subject to applicable company policies.
- Public or unapproved AI tools must be treated as external services. Nixon Medical confidential, proprietary, customer, associate, or sensitive information must not be entered into those tools.
- When uncertain whether a tool, data type, or use case is approved, associates must consult IT before proceeding.
6. Safe use examples
- Allowed in NM1: Summarizing internal meeting notes, analyzing authorized work data, drafting business communications or marketing content, brainstorming work-related ideas, and using other NM1 capabilities for legitimate Nixon Medical business purposes.
- Not Allowed: Using NM1 for personal projects or personal data; entering Nixon Medical confidential, customer, associate, financial, HR, contractual, source code, or other sensitive information into public or unapproved AI tools; or using AI to bypass company access controls or policies.
7. Accuracy and bias
- Associates must recognize that AI outputs may contain inaccuracies, fabricated information (hallucinations), omissions, or bias.
- AI-generated content must be reviewed and verified to a level appropriate for its intended use before it is relied upon for business decisions, operational actions, or customer communications.
- The associate using AI remains responsible for the accuracy, appropriateness, and final use of the output. AI does not replace professional judgment, required approvals, or established business processes.
Enforcement
Violations of this policy may result in disciplinary action, up to and including termination. Serious violations may also lead to legal or regulatory consequences or breaches of customer, associate, or company trust.
Review
This policy will be reviewed at least annually, and sooner when significant changes occur in AI technology, regulation, company operations, or Nixon Medical’s approved AI capabilities. Updates will be communicated to associates as appropriate to maintain awareness and compliance.