* Total Points: 0
Back to Lessons Trust, Verify, and Use Safely 0 pts Module 2 · Lesson 4
Introduction

Trust, Verify, and Use Safely

Turning what you now know into a point-of-care habit

Where We've Landed

You know an LLM predicts tokens (L1), samples from uncertainty (L2), and that retrieval vs. reasoning are different strategies with different failure modes (L3). This lesson converts all of that into a small set of habits you can use Monday.

The goal isn't to use these tools more, or less. It's to use them where their strengths fit and your verification covers their weaknesses.

Green-Light vs. Red-Light Uses

Sort tasks by one question: is the model working from information you gave it, or recalling specifics from memory? The first is safe; the second needs verification.

Green light

Rephrase & restructure

Turn your op note into a discharge summary; simplify a consent explanation. It's working from your text.

Green light

Explain established concepts

Mechanisms, definitions, widely-taught principles. Densely represented in training; usually reliable.

Green light

Brainstorm & draft

Differential lists, talk outlines, first drafts. You supply the judgment; the model supplies breadth.

Green light

Summarize text you provide

Condense a paper you pasted in. Grounded in the source, not memory.

Red light

Specific citations & numbers

References, doses, p-values, trial figures from memory. Highest fabrication risk -- verify every one.

Red light

Direct patient decisions

Letting the output decide management. It can't examine the patient and reflects the average case.

Red light

Recent, post-cutoff facts

Last month's trial or guideline, asked from memory. It guesses unless it retrieves.

Red light

Anything with patient identifiers

PHI into a non-approved tool is a privacy breach, full stop. Covered next.

Five Habits That Cover the Weak Spots

You don't need to verify everything equally. You need to verify the checkable specifics and prompt in ways that reduce error.

!

The mental flip that does the most work

Stop asking "Is this answer right?" and start asking "What would make this answer wrong, and have I checked that?" For a citation: does it exist? For a recommendation: does it fit this patient? For a recent claim: is it past the cutoff? The failure mode is usually predictable from the task.

The Non-Negotiable: Patient Privacy

Everything above is about accuracy. This is about not breaking the law or your patients' trust.

Do not paste protected health information into a consumer AI tool. Public ChatGPT, Claude, Gemini, and most consumer apps are not HIPAA-compliant by default. Names, MRNs, dates, and identifiable details entered there may be retained, used for training, or exposed. De-identification is harder than it looks -- a rare diagnosis plus a date can re-identify a patient.

Safe pattern

Generic, de-identified questions

"What's the workup for an acutely ischemic limb?" carries no patient data. Asking about mechanisms, definitions, and general management is fine.

Only on approved tools

Anything touching real patient data

Drafting a note from a real chart, summarizing a real patient's course -- only inside an institutionally-sanctioned, BAA-covered environment. Many systems now offer these; use them, not the consumer app.

Get approval first

Research on patient data

Feeding clinical datasets to any AI for a study needs IRB review and data-governance sign-off -- even de-identified. Loop in compliance before the data moves.

Simple rule of thumb: if you'd hesitate to post it on a public forum, don't paste it into a consumer AI tool. When in doubt, strip the identifiers or use your institution's sanctioned system.

Exercise: Green Light or Red Light?

For each real-world use, decide whether to proceed, verify, or stop -- and why.

Scenario 1 of 7

Module Complete!

0
Total Points Earned
Scenarios (0/7 correct) +0 pts
Lesson Completed +100 pts

Trust, Verify, and Use Safely

Module 2 - Lesson 4 complete · You finished the LLM module

Key Takeaways

  • Sort by source of truth: if the model works from text you gave it, it's green-light. If it's recalling specifics from memory, it's red-light.
  • Green light: rephrasing, explaining established concepts, brainstorming, summarizing text you provide.
  • Red light: citations and numbers from memory, direct patient decisions, post-cutoff facts, anything with identifiers.
  • Five habits: make it cite then open the source; paste in real material; ask it to show reasoning; re-ask to probe certainty; verify anything that drives a decision.
  • Ask "what would make this wrong?" -- the failure mode is usually predictable from the task.
  • Never paste PHI into consumer tools: they aren't HIPAA-compliant by default. Use institution-approved, BAA-covered systems; research needs IRB sign-off.

You can now explain, to a skeptical colleague, how these tools actually work, why they fail, and how to use them without getting burned. That's the whole goal of this module.