GDPR, safety and your own prompt library
In this closing module we look honestly at what is and isn't allowed (GDPR, traffic light, EU vendors like Mistral), and you build your own prompt library. At the end you have a personal work document with 10–15 templates that fit straight into your work.
Time: ~60 minutes. At the end: short evaluation + assignment book with 15 extra assignments to practise at your pace.
Lesson 5.1: Traffic light in practice
Goal: in 10 seconds know whether a text belongs in a public chat.
We've used the traffic light since module 1. Now we make it permanent:
| Colour | What it is | What you do |
|---|---|---|
| Green | No personal data, no patient data, no confidential contracts. General information, your own text, fictional cases. | Public chat (ChatGPT, Claude, Gemini) is fine. |
| Amber | Internal but not identifying data: rosters without names, an idealised case, an email without patient context. | Anonymise or use dummy names before pasting. Or: only in an approved environment. |
| Red | Patient data (name, BSN/SSN, date of birth, diagnosis + location), letters from the EHR, confidential contracts or HR matters. | Don't paste. Period. For processing: hospital-approved environment (Copilot M365 Enterprise, Azure OpenAI, Claude Enterprise, or possibly an EU route). |
Question for lesson 5.1
1. A colleague asks if you can “quickly through ChatGPT” lay out a text for the department newsletter about “an 84-year-old patient from Sneek with a rare valve abnormality who's being operated on this week”. What do you do?
Lesson 5.2: What if a doctor still drops a patient case into a prompt?
Goal: don't secretly feel guilty, do react practically.
It happens: a doctor emails you a text containing a patient name, age, diagnosis and the question “Can you have ChatGPT rewrite this?” You are then at the choice point. The rule of thumb:
- Pause. Don't paste immediately “because it's urgent”. Ask the doctor whether it can go anonymous.
- Anonymise. Replace name, BSN, date of birth, region and specific diagnosis combinations.
- Check policy. Unknown? A short question to IT / privacy officer about which route is approved in your hospital.
- Document. Keep a brief record of what you asked and what answer you got. If a privacy question comes up later, it's on paper.
Support sentence for in the hallway
“I'd like to do this for you. May I anonymise it first? Then I can do it in a public AI. Otherwise we have to wait until the approved route is available.”, Honest, helpful, and it places the responsibility back where it belongs.
Question for lesson 5.2
2. What's the most professional reaction when a doctor has a patient name in their prompt and asks you to run it through ChatGPT?
Lesson 5.3: Mistral as the EU route
Goal: know where “the European variant” fits in your vocabulary, even if you don't use it yourself yet.
Mistral is a French/EU AI company that makes the “Le Chat” chat product and accompanying models. For healthcare institutions with a European preference (data residency, GDPR as starting point rather than later sticking point) Mistral is often on the shortlist. For you as a staff secretary it's important to know the name, IT/procurement may have questions about it.
Where Mistral becomes logical
When your hospital is looking for a vendor where “data within Europe” is a hard criterion. EU jurisdiction and GDPR are the starting point, not a later concern.
What it lags on
Integrations with M365 / Workspace / Outlook / Teams are still thinner. The ecosystem is smaller; most training materials and guidelines for secretariats are about ChatGPT and Claude.
Live exercise 5.3: Open Le Chat and ask a test question
Open Le Chat (Mistral's chat). Ask the same mail question as in module 1.
Compare with your version from module 1. Does Le Chat feel significantly different anywhere from ChatGPT/Claude/Gemini? For most secretarial tasks the differences are small, the main argument for Mistral is the EU base, not output quality.
Lesson 5.4: Build your own prompt library
Goal: 10–15 templates that carry you through a work year.
A prompt library isn't a secret art. It's a work document (Word, OneNote, Notion, or inside a Claude Project) with your best prompts. Without a library you start over every time; with a library you pluck the right prompt in 30 seconds.
Suggested structure:
- Mail (5 prompts): short internal email, polite refusal, onboarding email new staff member, email on behalf of department head / training supervisor, external email.
- Long text (3 prompts): minutes from transcript, agenda from mail thread, guideline on one A4.
- Excel/Office (3 prompts): invent table + formula, rewrite slide, document with track changes.
- Quick help (2-4 prompts): tone shift, summary of a conversation, brainstorm questions for a meeting.
Live exercise 5.4: Have Claude set up a library for you
Open Claude. Paste. Save the result as “My AI library.docx” (or into OneNote / Notion).
Don't forget: your library is a living document. Every time you improve a prompt (a better sentence, a new constraint), you update it. After three months you'll probably have 20–25 templates that click into your work.
Lesson 5.5: Automation bias: the creeping risk
Goal: know why after three weeks of AI use you read less critically, and how to counter that.
An unexpected risk most people underestimate: automation bias. The more often you see AI output that's good enough, the more you tend to accept it without conscious checking. “It said so, so it must be right.” This creeps in. A week after the course you're still critical, after three months less so, after a year you skim an email and forward it.
Research on healthcare professionals shows this really happens: the first time an AI gets something wrong it's noticed, by the tenth time it isn't. For your work this means you need a few light structural habits:
- Reading pause. Between “AI done” and “you send” there's at least 30 seconds in which you read the output. No other tab, no phone, just reading.
- Specific check questions. For every email: do the facts match? do the names match? does the tone match? is there something in there I didn't say?
- “What would you write differently?” Once a week, ask a colleague to read one random AI email from that week. That's your second pair of eyes.
- Mail on behalf of a manager double-checked. The impact is biggest there, tone and facts in someone else's name. Write down for yourself the rule: no AI-generated mail going out on behalf of the department head or training supervisor leaves without me, or the manager themselves, having explicitly read it.
Small experiment
Write on a sticky note on your monitor the sentence: “Have I read this myself?”. Three weeks. Then you'll know if you still need it. (Often: yes.)
Question for lesson 5.5
What's the best countermeasure against automation bias?
Lesson 5.6: What do you do when something really goes wrong?
Goal: a calm step plan for the rare time an AI mistake reaches the outside.
It happens: an email with an invented patient detail, minutes with a meeting decision that wasn't taken, a referral that was a Claude hallucination. The course is meant to prevent this, but nobody prevents 100%. What do you do if it still happens?
- Breathe in. Don't hide. Sweeping it under the rug is tempting and always leads to bigger problems later. AI mistakes are collective learning material for the department.
- Determine the scope. Who has seen the mistake? What is the factual error? What needs to be corrected in a follow-up?
- Short rectification. Email a quick short message: “In my earlier mail/minutes [date] it said [X]; this is not correct. Correct is [Y]. Apologies for the confusion.” Not too long, not rambling. Acknowledge, correct, move on.
- Discuss it once. Tell your manager and fellow secretariat what happened and how you'll prevent it next time. Not for punishment, for learning.
- Update your prompt. Which rule would have prevented the mistake? “Don't invent patient names”? “When in doubt: write ‘not specified’”? Add to your library.
Live exercise 5.6: Write a short rectification email
Open Claude. Paste.
Important: the prompt itself contains the acknowledgement “I hadn't checked properly”. That blocks the AI from talking you into a “technical problem” or “external cause” framing. It's your responsibility, that's professional.
Lesson 5.7: Colleagues and team onboarding
Goal: be able to transfer the course you took to a colleague in five minutes.
An often underestimated opportunity: you've been through this course, and there are probably two, three or five colleagues at your secretariat doing the same work. A short team onboarding (~15-30 minutes) can be enough to give everyone the same basis, with the bonus that you all work the same way.
Proposed content for a short team handover:
- (2 min) The three tools: ChatGPT, Claude, Gemini, what they do for our work.
- (3 min) Traffic light: what you do and don't paste in a public chat. Short exercise with three examples from your own work.
- (5 min) Four building blocks: role + context + task + format. First live demo with one real email.
- (5 min) Template prompt: together you can grab your prompt library.
- (5 min) What we do when it goes wrong: rectification, learning, moving on. Everyone may know this.
- (5 min) Questions.
Live exercise 5.7: Make your own onboarding cheatsheet
Open Claude. Paste.
Tip: Print the cheatsheet and pin it on the noticeboard. It's not secret material, the more colleagues know it, the faster you all work in sync.
Lesson 5.8: Short check questions for IT/privacy officer
Goal: in one short email get the right information from IT.
The course has given you a feel for what's possible. The definitive boundaries are set by your hospital. Below is a short, neutral email you can send to IT or the privacy officer to clarify the basic route.
Live exercise 5.8: Draft a mail to IT
Open Claude. Paste.
Send or not? You decide. Many hospitals appreciate that secretariats think along, you prevent many grey-zone incidents.
Take-home of module 5 (and the course)
Traffic light is your compass
Green / amber / red. When in doubt: anonymise or don't paste. Ask IT if policy is unclear.
Mistral is in your vocabulary now
The EU route exists. For you it's mainly a name to recognise when procurement/IT discuss it.
You have a library
10–15 templates to carry you a year. Living document; update as prompts improve.
Checking policy is professional
The short mail to IT/privacy officer isn't fussing, it's part of professional work with AI.
Automation bias is real
After three months you read AI output more carelessly. The sticky “Have I read this myself?” works surprisingly well.
On a mistake: short rectification
Don't hide. Short rectification email, ownership, and update your prompt library with the rule that would have prevented the mistake.
Share with your team
A one-A4 cheatsheet and 15 minutes of team handover put your colleagues on the same basis. Works faster, learns faster.
Done, fill in the short evaluation
Two minutes, anonymous. Afterwards you'll get access to the assignment book: 15 extra assignments at level to keep practising at your pace with ChatGPT, Claude and Gemini.