The problem
Policy binders go stale. The exposure control plan was last updated three managers ago, the emergency procedure still lists a staff member who left, and the handbook doesn't mention the new phone system. Updating them means a quiet afternoon with templates and regulations, which never comes.
Keep out of the AI
- Incident reports, exposure reports or anything about a specific patient or employee's health
- Real cases used as examples; use made-up ones
- Audit findings that include patient records
Every dental and medical idea here is designed so no protected health information (PHI) ever goes into Claude. Anthropic offers HIPAA only on Enterprise plans; Team plans can’t enable it. Under the HIPAA configuration, Cowork runs in local mode on a desktop and Cowork in the cloud (including cloud scheduled tasks) isn’t available. Anthropic’s documentation says connectors and MCP servers aren’t covered by its BAA. Nothing here makes a practice HIPAA compliant; ask your privacy officer before you start.
What Cowork does
- The practice saves its current policies, any templates from its consultant or association, and the public regulator pages it relies on (OSHA, CDC, state board) into a Drive folder.
- The manager picks a policy to update and lists what changed: new equipment, new staff roles, a new location.
- Cowork drafts an updated version that marks every change, cites which saved source each requirement came from, and lists questions it couldn't answer.
- It adds a review date and a sign-off block for the compliance lead.
Where the draft lands
A redlined draft in Drive with sources and open questions.
What stays with you
Deciding what the policy says, compliance review, staff training and sign-off. A draft is not a compliant policy until your compliance lead says so.
Exposure Control Plan, draft 2026-10
Changed: Section 3, job classifications now include the new sterilization tech role (source: saved OSHA bloodborne pathogens page). Section 7, updated sharps container locations for the second operatory hallway.
Questions for compliance lead: 1) Who is the new designated exposure contact? 2) Confirm the hepatitis B vaccination declination form is current.
Review by: Oct 2027.
Watch-outs
- HIPAA note: Cowork can help draft your privacy and security policies, but writing a policy doesn't make the practice compliant, and nothing here should be read as compliance advice.
- Regulations differ by state. The draft is only as current as the sources in the folder.
- Keep the sign-off and review dates in the document so the next update starts from a known point.
Questions owners ask
Can it write our HIPAA policies?
It can draft them from templates and official guidance you provide. Your privacy officer or compliance consultant has to review and adopt them.
What about OSHA training?
It can draft training outlines and sign-in sheets. Training itself is done by a qualified person.