AI, data privacy and confidentiality for all employees

For every employee who uses AI tools: decide what information can go into which tool, and protect people, clients and your organization.

For: All employees using AI tools

  • 2 contact hours
  • 8 modules
  • 8 interactives
  • 4 job aids
  • Updated October 11, 2026

What you will be able to do

  • Classify work information (personal, sensitive, PHI, financial, student, client-confidential, trade secret, credentials) before using it with an AI tool.
  • Explain how AI tools process, store and may train on inputs, and distinguish consumer, enterprise and embedded AI tools.
  • Apply never-paste rules and minimization techniques, including placeholders, aggregation and awareness of HIPAA de-identification.
  • Identify privacy-law, contract and professional confidentiality duties (HIPAA, GLBA, FERPA, CCPA, FTC Act, NDAs, ABA Opinion 512, trade secret law) that apply to AI use.
  • Handle AI outputs that contain personal data and report AI data incidents promptly with the right facts.

Learn the one AI skill every employee needs: deciding what information can safely go into which AI tool. You will practice classifying data, telling consumer and enterprise tools apart, stripping identifiers before you prompt, recognizing HIPAA, GLBA, FERPA, CCPA and contract duties, and handling AI outputs and mistakes the right way.

Built for all staff who use AI at work, from front desks and clinics to schools, finance teams, law firms and labs. Realistic cases follow a paralegal in Tucson, a loan officer in Fort Wayne, a medical assistant in Terre Haute, a school data clerk in Lafayette and an engineer in Peoria.

Most AI privacy failures are not hacks. They are ordinary people pasting the wrong file into the wrong tool under deadline pressure. This course gives you fast, practical rules (a classification check, a traffic light, a minimization routine and a same-day reporting habit) so you can keep using AI without putting anyone at risk.

What you’ll be able to do Monday morning

  1. Check that every AI tool you use for work is on the approved list and that you are signed in with your work account.
  2. Run the 60-second Before You Paste checklist on the next file you want to use with AI.
  3. Rewrite one of your regular prompts to use placeholders or a general question instead of real names or confidential details.
  4. Turn off AI note-takers or auto-summaries for meetings about people, health, legal or confidential matters.
  5. Save your privacy or security reporting contact so you can report an AI mistake the same day.

Curriculum

8 modules · 31 lessons · about 2 contact hours

01What information needs protection before it goes near an AI tool?Free preview14 min
  1. Which kinds of information need extra care?
  2. What is a data classification level, and why does it matter for AI?
  3. Why does AI change the privacy picture?
  4. How do you check a document before using AI with it?
  • Sort activity: What classification level is this?

Diagram · In practice checklist · 2-question knowledge check

02What happens to what you type into an AI tool?14 min
  1. What is the life cycle of a prompt?
  2. Can an AI model repeat what someone else typed into it?
  3. What do the provider's terms and privacy policy tell you?
  4. What should Lysander have done, and what now?

Diagram · In practice checklist · 2-question knowledge check

03Consumer or enterprise: how do you know a tool is approved for your data?13 min
  1. What is the difference between consumer and enterprise AI tools?
  2. What makes a tool safe enough for confidential or regulated data?
  3. How do you check whether a specific tool is approved?
  4. What about AI features that appear inside software you already use?
  • Decision tree: Can I use this AI tool with this data?

Diagram · In practice checklist · 3-question knowledge check

04What should never go into an AI tool, and what can?14 min
  1. What goes on the never-paste list?
  2. How does a traffic-light rule help in the moment?
  3. What hidden data hides in files, images and recordings?
  4. What can you safely use AI for?
  • Spot the issue: Spot the privacy problems in this prompt

Diagram · In practice checklist · 2-question knowledge check

05How can you get AI help without exposing personal data?14 min
  1. What is data minimization, and how do you apply it to a prompt?
  2. What techniques remove or mask identifiers?
  3. What does HIPAA de-identification require?
  4. When is minimized or de-identified data still not safe to share?
  • Spot the issue: What did the de-identification miss?

Diagram · In practice checklist · 3-question knowledge check

06Which privacy laws apply when you use AI with personal data?14 min
  1. Which federal privacy laws matter most for AI use?
  2. How do state privacy laws affect AI use?
  3. What do these laws have in common?
  • Matching activity: Match the law to what it protects

Diagram · In practice checklist · 2-question knowledge check

07What about client confidentiality, contracts and trade secrets?14 min
  1. How do NDAs and customer contracts limit AI use?
  2. How do trade secrets lose protection?
  3. What do professional rules say about AI and client confidences?
  4. What should you do when you are not sure?
  • Ethics dilemma: The client wants you to use their AI tool

Diagram · In practice checklist · 2-question knowledge check

08What if AI output contains personal data, or something goes wrong?15 min
  1. How can AI outputs contain personal data?
  2. How should you handle outputs before you use or share them?
  3. What counts as an AI data incident, and how fast should you report?
  4. What should a good report include, and what happens next?
  • Branching scenario: The summary that went to the wrong inbox
  • Self-assessment: How safe are my AI data habits?

Diagram · In practice checklist · 2-question knowledge check

Final assessment: 23 questions, 70% to pass, then your certificate

Try it now, no account needed

The summary that went to the wrong inbox

A branching scenario from this course. Your choices are not saved.

Free sample activity

The summary that went to the wrong inbox

You are an office manager. At 3:10 p.m. you notice an AI note-taker emailed a summary of an internal meeting, including an employee's medical leave, to all invitees, one of whom is an outside vendor.

Inside the course

Practice activities

  • Sort activity1
  • Decision tree1
  • Spot the issue2
  • Matching activity1
  • Ethics dilemma1
  • Branching scenario1
  • Self-assessment1

Job aids you keep

  • Before You Paste: AI Data ChecklistChecklist
  • AI Output Privacy and Verification ChecklistChecklist
  • Privacy-Safe Prompt SheetReference sheet
  • AI Data Use Standard StarterPolicy starter

Credit and approval status

Certificate of completion

This course awards a certificate of completion for 2 contact hours of instruction. It is not approved or accredited by any licensing board, state agency or continuing education accreditor. Employers decide what counts toward their own privacy and AI training programs, so check with your employer, licensing board or certifying body whether this course meets your specific requirement.

Pathways we may pursue include review by a training accreditor and by accountancy continuing education sponsors. None of these approvals exists today; the course page will show an approval only after it is granted.

Our full approvals list

Questions about this course

Who should take this course?

Anyone who uses AI tools at work: office staff, clinicians and care staff, educators, financial services staff, legal and professional services teams, and managers. It focuses on one practical skill, deciding what information can go into which AI tool, so it suits every role and assumes no technical background.

Will this course tell me which AI tools are safe?

No course can list safe tools for every organization, because safety depends on your employer's contracts and settings. This course teaches you how to tell consumer and enterprise tools apart, what makes a tool suitable for sensitive data, and how to check your organization's approved list before you use any tool.

Does it earn continuing education credit?

You receive a certificate of completion for 2 contact hours of instruction. The course is not approved or accredited by any licensing board or accreditor today. Check with your employer, board or certifying body whether they accept it for your requirement.

Does it cover HIPAA, FERPA and state privacy laws?

Yes, at the level everyday AI users need: what each law protects, what it means for AI tools (such as business associate agreements, the FERPA school-official exception and CCPA service-provider rules), and HIPAA de-identification awareness. For full HIPAA training, see our HIPAA course for healthcare workers.

How long does it take, and how is it assessed?

Plan on about 2 hours: eight short modules with scenarios, a decision tool, spot-the-issue exercises and knowledge checks, then a 23-question final assessment. You need 70 percent to pass. Spaced reminder questions follow at 3, 10 and 30 days.

What can I download?

A Before You Paste checklist, an AI output privacy and verification checklist, a privacy-safe prompt sheet with before-and-after examples, and an AI data use standard starter your organization can adapt with its privacy and legal teams.

This course is general education and training awareness from CE Courses Hub on AI, data privacy and confidentiality. It is not legal, medical or professional advice and does not replace your employer's policies, your licensing board's rules, or advice from a qualified professional. Completing it earns a certificate of completion for the stated contact hours; it is not approved or accredited by any licensing board, state agency or accreditor unless an approval is shown on the course page. Check with your board, employer or state agency whether this course meets your specific requirement.