Module 5 · safety & library

GDPR, safety and your own prompt library

In this closing module we look honestly at what is and isn't allowed (GDPR, traffic light, EU vendors like Mistral), and you build your own prompt library. At the end you have a personal work document with 10–15 templates that fit straight into your work.

Time: ~60 minutes. At the end: short evaluation + assignment book with 15 extra assignments to practise at your pace.

GDPR, safety and prompt library

Lesson 5.1: Traffic light in practice

Goal: in 10 seconds know whether a text belongs in a public chat.

We've used the traffic light since module 1. Now we make it permanent:

ColourWhat it isWhat you do
GreenNo personal data, no patient data, no confidential contracts. General information, your own text, fictional cases.Public chat (ChatGPT, Claude, Gemini) is fine.
AmberInternal but not identifying data: rosters without names, an idealised case, an email without patient context.Anonymise or use dummy names before pasting. Or: only in an approved environment.
RedPatient data (name, BSN/SSN, date of birth, diagnosis + location), letters from the EHR, confidential contracts or HR matters.Don't paste. Period. For processing: hospital-approved environment (Copilot M365 Enterprise, Azure OpenAI, Claude Enterprise, or possibly an EU route).

Question for lesson 5.1

1. A colleague asks if you can “quickly through ChatGPT” lay out a text for the department newsletter about “an 84-year-old patient from Sneek with a rare valve abnormality who's being operated on this week”. What do you do?

Lesson 5.2: What if a doctor still drops a patient case into a prompt?

Goal: don't secretly feel guilty, do react practically.

It happens: a doctor emails you a text containing a patient name, age, diagnosis and the question “Can you have ChatGPT rewrite this?” You are then at the choice point. The rule of thumb:

  1. Pause. Don't paste immediately “because it's urgent”. Ask the doctor whether it can go anonymous.
  2. Anonymise. Replace name, BSN, date of birth, region and specific diagnosis combinations.
  3. Check policy. Unknown? A short question to IT / privacy officer about which route is approved in your hospital.
  4. Document. Keep a brief record of what you asked and what answer you got. If a privacy question comes up later, it's on paper.

Support sentence for in the hallway

“I'd like to do this for you. May I anonymise it first? Then I can do it in a public AI. Otherwise we have to wait until the approved route is available.”, Honest, helpful, and it places the responsibility back where it belongs.

Question for lesson 5.2

2. What's the most professional reaction when a doctor has a patient name in their prompt and asks you to run it through ChatGPT?

Lesson 5.3: Mistral as the EU route

Goal: know where “the European variant” fits in your vocabulary, even if you don't use it yourself yet.

Mistral is a French/EU AI company that makes the “Le Chat” chat product and accompanying models. For healthcare institutions with a European preference (data residency, GDPR as starting point rather than later sticking point) Mistral is often on the shortlist. For you as a staff secretary it's important to know the name, IT/procurement may have questions about it.

Where Mistral becomes logical

When your hospital is looking for a vendor where “data within Europe” is a hard criterion. EU jurisdiction and GDPR are the starting point, not a later concern.

What it lags on

Integrations with M365 / Workspace / Outlook / Teams are still thinner. The ecosystem is smaller; most training materials and guidelines for secretariats are about ChatGPT and Claude.

Live exercise 5.3: Open Le Chat and ask a test question

Open Le Chat (Mistral's chat). Ask the same mail question as in module 1.

You are an experienced staff secretary of a cardiology department. Write a short internal email (3-5 lines) to five professors to collect availability for an MDT in two weeks. The email must: - ask about two slot options (Tuesday or Thursday); - ask for a reply within three working days; - close friendly. No patient data, no external links. Deliver subject + body.

Compare with your version from module 1. Does Le Chat feel significantly different anywhere from ChatGPT/Claude/Gemini? For most secretarial tasks the differences are small, the main argument for Mistral is the EU base, not output quality.

Lesson 5.4: Build your own prompt library

Goal: 10–15 templates that carry you through a work year.

A prompt library isn't a secret art. It's a work document (Word, OneNote, Notion, or inside a Claude Project) with your best prompts. Without a library you start over every time; with a library you pluck the right prompt in 30 seconds.

Suggested structure:

  1. Mail (5 prompts): short internal email, polite refusal, onboarding email new staff member, email on behalf of department head / training supervisor, external email.
  2. Long text (3 prompts): minutes from transcript, agenda from mail thread, guideline on one A4.
  3. Excel/Office (3 prompts): invent table + formula, rewrite slide, document with track changes.
  4. Quick help (2-4 prompts): tone shift, summary of a conversation, brainstorm questions for a meeting.

Live exercise 5.4: Have Claude set up a library for you

Open Claude. Paste. Save the result as “My AI library.docx” (or into OneNote / Notion).

Role: you are an experienced prompt coach for staff secretaries. Context: I work at the cardiology staff secretariat and learned in a course to work with ChatGPT, Claude and Gemini. I now want to set up my own prompt library. Task: produce a workable library template in 4 sections: 1) Mail (5 prompts); 2) Long text (3 prompts); 3) Excel/Office (3 prompts); 4) Quick help (3 prompts). For each prompt: - Short title; - One sentence when to use it; - The full prompt text (role + context + task + format + constraint), with placeholders like "[subject]" and "[deadline]" where it makes sense. Requirements: - English, cardiology context, no patient data examples; - Suitable for copy-paste to Word/Claude Project; - No disclaimer fluff; straightforward; - At the end: a list of 3 tips on how to maintain this library over time. Deliver in clean formatting with headings.

Don't forget: your library is a living document. Every time you improve a prompt (a better sentence, a new constraint), you update it. After three months you'll probably have 20–25 templates that click into your work.

Lesson 5.5: Automation bias: the creeping risk

Goal: know why after three weeks of AI use you read less critically, and how to counter that.

An unexpected risk most people underestimate: automation bias. The more often you see AI output that's good enough, the more you tend to accept it without conscious checking. “It said so, so it must be right.” This creeps in. A week after the course you're still critical, after three months less so, after a year you skim an email and forward it.

Research on healthcare professionals shows this really happens: the first time an AI gets something wrong it's noticed, by the tenth time it isn't. For your work this means you need a few light structural habits:

  • Reading pause. Between “AI done” and “you send” there's at least 30 seconds in which you read the output. No other tab, no phone, just reading.
  • Specific check questions. For every email: do the facts match? do the names match? does the tone match? is there something in there I didn't say?
  • “What would you write differently?” Once a week, ask a colleague to read one random AI email from that week. That's your second pair of eyes.
  • Mail on behalf of a manager double-checked. The impact is biggest there, tone and facts in someone else's name. Write down for yourself the rule: no AI-generated mail going out on behalf of the department head or training supervisor leaves without me, or the manager themselves, having explicitly read it.

Small experiment

Write on a sticky note on your monitor the sentence: “Have I read this myself?”. Three weeks. Then you'll know if you still need it. (Often: yes.)

Question for lesson 5.5

What's the best countermeasure against automation bias?

Lesson 5.6: What do you do when something really goes wrong?

Goal: a calm step plan for the rare time an AI mistake reaches the outside.

It happens: an email with an invented patient detail, minutes with a meeting decision that wasn't taken, a referral that was a Claude hallucination. The course is meant to prevent this, but nobody prevents 100%. What do you do if it still happens?

  1. Breathe in. Don't hide. Sweeping it under the rug is tempting and always leads to bigger problems later. AI mistakes are collective learning material for the department.
  2. Determine the scope. Who has seen the mistake? What is the factual error? What needs to be corrected in a follow-up?
  3. Short rectification. Email a quick short message: “In my earlier mail/minutes [date] it said [X]; this is not correct. Correct is [Y]. Apologies for the confusion.” Not too long, not rambling. Acknowledge, correct, move on.
  4. Discuss it once. Tell your manager and fellow secretariat what happened and how you'll prevent it next time. Not for punishment, for learning.
  5. Update your prompt. Which rule would have prevented the mistake? “Don't invent patient names”? “When in doubt: write ‘not specified’”? Add to your library.

Live exercise 5.6: Write a short rectification email

Open Claude. Paste.

Role: staff secretary cardiology. Context: yesterday I sent an internal email announcing that Friday's MDT was moved to Monday 11:00. This wasn't correct, I hadn't properly checked the AI draft, the MDT stays on Friday, only the start time has been moved from 8:30 to 9:00. Task: write a short rectification email. Requirements: - Max 5 lines. - Open with one sentence naming the mistake without heavy drama. - Give in one sentence the correct info (Friday, 9:00 instead of 8:30). - End with one sentence of apology (short, not overdone). - Subject line clearly containing "correction". No reference to AI (not relevant internally); no patient data. Deliver subject + body.

Important: the prompt itself contains the acknowledgement “I hadn't checked properly”. That blocks the AI from talking you into a “technical problem” or “external cause” framing. It's your responsibility, that's professional.

Lesson 5.7: Colleagues and team onboarding

Goal: be able to transfer the course you took to a colleague in five minutes.

An often underestimated opportunity: you've been through this course, and there are probably two, three or five colleagues at your secretariat doing the same work. A short team onboarding (~15-30 minutes) can be enough to give everyone the same basis, with the bonus that you all work the same way.

Proposed content for a short team handover:

  1. (2 min) The three tools: ChatGPT, Claude, Gemini, what they do for our work.
  2. (3 min) Traffic light: what you do and don't paste in a public chat. Short exercise with three examples from your own work.
  3. (5 min) Four building blocks: role + context + task + format. First live demo with one real email.
  4. (5 min) Template prompt: together you can grab your prompt library.
  5. (5 min) What we do when it goes wrong: rectification, learning, moving on. Everyone may know this.
  6. (5 min) Questions.

Live exercise 5.7: Make your own onboarding cheatsheet

Open Claude. Paste.

Role: experienced staff secretary cardiology preparing a short AI onboarding for the secretariat team. Task: produce a one-A4 cheatsheet for my colleagues with this structure: 1) "The three tools in one sentence each" (ChatGPT, Claude, Gemini). 2) "Traffic light in one paragraph" (green/amber/red). 3) "Four building blocks of a good prompt" in one box. 4) "Three example prompts from our work" (short internal email / onboarding email new staff member / minutes from transcript). For each: title + the full prompt text. 5) "What we do on an AI mistake" in 3 steps. 6) "Who handles which contact question?" (privacy officer for patient data, IT for licences, manager for tone agreements). Requirements: - Max one A4. - No jargon colleagues don't know. - No invented facts. - In English. - Suitable to print or send round as PDF. Deliver in clean formatting with headings.

Tip: Print the cheatsheet and pin it on the noticeboard. It's not secret material, the more colleagues know it, the faster you all work in sync.

Lesson 5.8: Short check questions for IT/privacy officer

Goal: in one short email get the right information from IT.

The course has given you a feel for what's possible. The definitive boundaries are set by your hospital. Below is a short, neutral email you can send to IT or the privacy officer to clarify the basic route.

Live exercise 5.8: Draft a mail to IT

Open Claude. Paste.

Role: staff secretary cardiology. Context: I've just finished a course on working with ChatGPT, Claude and Gemini. I want to ask our IT/privacy officer briefly which routes are approved within our hospital. Task: write a short email (max 10 lines) in which I politely ask: 1) Which AI chat products are approved within our institution for public use at the secretariat (logging, training, data residency)? 2) Do we have Claude/Gemini/Copilot in a licence with M365 or Workspace add-in that is carefully bounded? 3) What is the advised route when a doctor asks me to process something with patient context via AI? 4) Who is the contact within our institution for such questions in the future? Tone: friendly, business-like, not investigative. Make clear I want this information to be able to work within policy, not to push boundaries. Deliver subject + body.

Send or not? You decide. Many hospitals appreciate that secretariats think along, you prevent many grey-zone incidents.

Take-home of module 5 (and the course)

Traffic light is your compass

Green / amber / red. When in doubt: anonymise or don't paste. Ask IT if policy is unclear.

Mistral is in your vocabulary now

The EU route exists. For you it's mainly a name to recognise when procurement/IT discuss it.

You have a library

10–15 templates to carry you a year. Living document; update as prompts improve.

Checking policy is professional

The short mail to IT/privacy officer isn't fussing, it's part of professional work with AI.

Automation bias is real

After three months you read AI output more carelessly. The sticky “Have I read this myself?” works surprisingly well.

On a mistake: short rectification

Don't hide. Short rectification email, ownership, and update your prompt library with the rule that would have prevented the mistake.

Share with your team

A one-A4 cheatsheet and 15 minutes of team handover put your colleagues on the same basis. Works faster, learns faster.

Done, fill in the short evaluation

Two minutes, anonymous. Afterwards you'll get access to the assignment book: 15 extra assignments at level to keep practising at your pace with ChatGPT, Claude and Gemini.

Go to the evaluation