Dental professional writing patient response with AI tools and considering GDPR risks

AI Risks in Dentistry: What Dentists Must Know Before Using AI

Why Dentists Must Exercise Extreme Caution When Using AI to Respond to Patient Letters

Introduction

AI writing tools are now part of everyday professional life. They can draft emails, summarise documents and save valuable time. For a busy dental practice, using AI to help respond to patient letters or complaints may seem like a sensible shortcut. However, dentists and practice managers need to understand the legal, ethical and clinical risks before they do so.

1. The GDPR Risk: It’s Not Just About Clinical Records

The most immediate concern for any dental practice using AI tools is data protection. A person or organisation that makes decisions about the purposes for which personal data is processed, and how it is processed, is a data controller. This includes dental practices and means that under the UK General Data Protection Regulation (UK GDPR), and the Data Protection Act 2018, they are legally responsible for how patient data is used, stored, and shared.

If a team member copies and pastes a patient’s letter or even selected details from it into an AI tool such as ChatGPT, Microsoft Copilot or Google Gemini, that information may be:

Transmitted to and stored on external servers outside the practice’s control

Used to train future AI models depending on the platform’s terms of service

Retained in server logs or prompt histories accessible to third parties

Potentially subject to data breaches on those external platforms

That creates a clear data protection risk. UK GDPR requires personal data to be handled lawfully, fairly and transparently. It also requires practices to keep data within secure and agreed processing environments unless proper safeguards are in place.

2. A patient who is not identified may still be identifiable

A common mistake is to assume that removing a patient’s name and date of birth makes the information safe to share. It often does not.

Firstly, information does not need to include a name or NHS number to count as personal data. Where information does not identify a patient but the patient is nonetheless identifiable by the controller (including by means of other information), the information will be that patient’s personal data and all the usual data protection rights requirements will apply to that information.

Secondly, while someone outside the practice might not be able to identify a patient from a single piece of information, several pieces of information, each harmless on its own, can be combined to identify a person. This is known as the “jigsaw effect” or “mosaic effect”.

For example, a practice may remove the patient’s name before pasting a letter into an AI tool. The letter may still include:

A reference to the patient’s unusual dental condition

A mention that the patient is a primary school teacher

A detail that they attended the practice on a specific date

A note that they live in a small village near the practice

Individually, these details may not identify the patient. Taken together, they may be enough for someone to work out who the patient is particularly after a data breach or where the information is seen by someone with local knowledge.

This is particularly significant in smaller, rural, or specialist dental practices where the patient population is limited and details are more easily traced.

3. Special Category Data and Heightened Risk

Dental records regularly contain special category data, including information about a patient’s health. This type of data attracts the highest level of protection under UK GDPR.

Mishandling it can have serious regulatory and financial consequences.

A short description of treatment, dental anxiety, medication or medical history is still health data. Entering that information into a third-party AI platform is a form of processing. Without a clear lawful basis and a proper Data Processing Agreement, a practice is taking a significant risk.

4. Incorrect or Misleading Clinical Information

Data protection is not the only concern. AI tools can produce confident, professional-looking answers that are clinically wrong.

AI language models do not understand the patient’s full clinical history and do not review the records in the way a dentist would. They generate text by predicting likely wording. As a result, an AI tool might:

Suggest incorrect timeframes for treatment or healing

Provide inaccurate advice about medications, contraindications, or post-operative care

Misinterpret the clinical context of a complaint and respond inappropriately

Use confident, authoritative language even when the information is wrong

If that response is sent without careful clinical review, the result may be confusion, distress or genuine clinical harm. From a medico-legal perspective, the dentist remains responsible for any advice sent under their name or on behalf of the practice. “The AI wrote it” is not a defence.

5. Complaints and Legal Correspondence: A Higher Bar

Formal complaints and letters before action require particular care. AI tools are not a substitute for knowledge of the NHS complaints procedure, GDC fitness to practise processes or civil litigation. An AI-generated response could:

Inadvertently make an admission of liability

Fail to comply with required timescales or formal procedures

Include statements that contradict clinical records

Misstate the law or miss critical legal or regulatory nuances

In these situations, practices should seek guidance from their indemnity providers like All Med Pro. Where appropriate, they should also obtain legal advice. AI should not be used to draft these responses unless there is close expert human oversight.

6. Consent and Transparency

Patients have not usually agreed to their information being shared with AI platforms, even where that information appears in correspondence rather than the clinical record. UK GDPR’s transparency principle requires patients to be told how their data is used. If a practice’s privacy notice does not clearly explain AI-assisted processing, and the legal basis has not been properly established, using AI in this way may breach that principle.

Regulatory expectations are also developing quickly. The Information Commissioner’s Office expects organisations to be able to show accountability for how personal data is processed, including when AI is involved.

7. Practical Recommendations for Dental Practices

Dental practices do not need to avoid technology altogether. They do, however, need clear rules for using it safely. The following steps are strongly recommended:

  1. Never input identifiable patient information into a public or unverified AI tool. This includes names, dates, specific conditions, treatments, locations, or any combination of details that could identify a patient.
  2. Review your Data Processing Agreements. If you use any AI-powered software within your practice management system, ensure the supplier has a signed DPA in place.
  3. Update your privacy notice to reflect any AI-assisted processing and ensure there is a clear lawful basis for it.
  4. Use AI only for generic tasks such as drafting a template structure or improving grammar on anonymised text never for substantive clinical or legal responses.
  5. Always have a qualified clinician review and approve any letter going to a patient before it is sent.
  6. Train your team. Reception staff and practice managers must understand what constitutes personal data, including the jigsaw effect.
  7. Consult your dental defence organisation before responding to any formal complaint or legal correspondence.
  8. Seek specialist data protection advice if you are considering integrating AI tools into your workflow at a systemic level.

Conclusion

AI can help dental practices work more efficiently, but it should never be treated as a risk-free shortcut. GDPR duties, the jigsaw effect, clinical accuracy and complaint handling all point to the same conclusion: AI must be used carefully, with clear governance and proper human oversight.

Patient trust sits at the heart of dental practice. Protecting that trust means protecting patient data wherever it appears and however it is handled.

This article is intended for general informational purposes and does not constitute legal advice. Dental practices should seek specialist data protection and medico-legal guidance relevant to their specific circumstances.

For peace of mind that you and your business reputation are protected, contact All Med Pro for all your insurance needs.

Share this post: