Can care home staff use ChatGPT to write care notes?
Short answer. Yes — but only under three strict conditions:
- No personal data of a person you support goes into a ChatGPT prompt without a lawful basis and a DPIA.
- A named human reviews every AI-generated draft before it enters the care record.
- A written policy exists and staff have read and signed it.
Everything else in this article explains why each condition matters and what happens on inspection when one is missing.
Why this question keeps coming up
Registered managers across England are asking the same question in 2026: staff are using ChatGPT to speed up care notes, and nobody knows if this is permitted. It's rarely a decision anyone formally made — it's a habit that spread quietly, one carer showing another, without a policy to catch it.
The Care Quality Commission published its position on AI in health and social care on 21 May 2026. It "encourages the use of innovative technologies, including AI, where the technology benefits people and results in more effective and efficient services." That's a green light. But the same document says CQC will consider sector-specific guidance for 2026–27 — which means the specific rules for care providers aren't written yet. Providers have to work from first principles, and first principles is what this article is.
Condition 1 — Personal data cannot go into a prompt without a lawful basis and a DPIA
This is where most providers unknowingly cross the line today. A carer types "Rewrite this note about Mrs Smith who fell in the corridor" into ChatGPT. Mrs Smith is now identified data flowing to an American company's servers.
Under UK GDPR, this is processing of personal data by a new sub-processor. It requires:
- A lawful basis under Article 6 (usually consent or legitimate interests — with a documented Legitimate Interests Assessment)
- For health data, a further condition under Article 9 (Special Category Data)
- A Data Protection Impact Assessment (DPIA) under Article 35, because the processing is likely to result in high risk to individuals
- A Data Processing Agreement with OpenAI (or Microsoft for Copilot) with UK-compliant international transfer clauses
In practice most providers don't have any of these in place for ChatGPT. That means the lawful, honest instruction to staff is never put a person's name, initials, date of birth, room number, condition, medication, or any identifying detail into a general AI tool prompt. The prompt should describe the situation in general terms and the staff member writes the note themselves.
What the CQC will look for
Under the "Safe" key question and Regulation 12 (Safe care and treatment), an inspector who asks about AI use will expect to see a written policy that draws this line clearly and a way to check that staff are following it. If there is no policy, the provider is exposed.
Condition 2 — A named human reviews before the note enters the record
AI outputs are plausible-sounding but not always accurate. In care records this matters more than in most contexts: an inaccurate note becomes evidence in a safeguarding investigation, a coroner's inquest, a family complaint. Any AI-generated text that becomes part of the record must be read, corrected where necessary, and approved by a human before it is saved.
This is the practical meaning of the emerging supervision standard. It doesn't require special software — it requires a workflow rule that says the person entering an AI-assisted note has read it, understood it, and takes responsibility for its accuracy. The best form of evidence is a two-column log: what the AI proposed, what the human decided.
Condition 3 — A written policy that staff have read and signed
This is the cheapest condition to meet and the one most providers are missing. A one-page policy covers:
- What is permitted. Using ChatGPT to draft general text (not about specific people). Using approved care-planning software that includes AI features. Using AI for translation with de-identified content.
- What is prohibited. Any prompt containing identifying details of a person you support. Any AI output entering a record without human review. Using AI for safeguarding decisions or Mental Capacity Act assessments.
- What is required if something goes wrong. If an AI output contained an error that reached a record or was acted on, staff must report it as an incident and notify the named accountable person.
Every member of staff should have read this policy, signed it, and had it explained during induction. Repeat annually.
The MCA and safeguarding line — non-negotiable
AI must never be used for Mental Capacity Act 2005 assessments, best-interest decisions, Deprivation of Liberty Safeguards applications, or safeguarding referrals. These are legally reserved for human decision-makers. Any policy that doesn't state this is missing the most important sentence in the document.
What about the "AI features" already in your care-planning software?
Many care-planning systems (Nourish, Log My Care, PASS, and others) have added AI-adjacent features — auto-suggest, summarisation, risk flags. These are different from ChatGPT because the vendor has (usually) done the DPIA and holds the DPA with the underlying model provider.
But you still need to:
- Ask each vendor in writing which of their features use AI, what data is processed, and where
- Confirm they have a DPIA and can share the executive summary
- Add the vendor's AI features to your internal AI inventory
- Include the human-review-before-save rule in your policy for these features too
What to do this week
- Ask your team informally: is anyone using ChatGPT for care notes right now? (Yes-answers are the starting point, not a reason for discipline — punishing honesty here means the practice will continue but you'll stop hearing about it.)
- Draft the one-page policy above. Circulate to staff for reading and signing.
- Email your care-planning software vendor asking which of their features use AI.
- Take the free readiness check below to see where the rest of your AI-related exposure sits.
See where your service stands
The 15-question AI Readiness Check takes four minutes. You get a score, three priority gaps, and a PDF report — free, no obligation.
Take the readiness check Read the full standardSources
- Care Quality Commission — Artificial intelligence in health and social care: CQC's role, expectations and plans (21 May 2026)
- Information Commissioner's Office — Guidance on AI and data protection
- Mental Capacity Act 2005 (sections 1, 3, 4)
- Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 — Regulations 12, 17, 18