Privacy & Security
Privacy:
Personal health, student, and sensitive information are safeguarded via a student data privacy agreement and business associate agreement between ISMMS and OpenAI.
No data, prompts, or responses will be used to train OpenAI's models.
Security:
OpenAI successfully completed a SOC 2 audit, confirming that their controls align with industry standards for security and confidentiality. OpenAI has also successfully completed Mount Sinai's cybersecurity assessment.
Data encryption at rest (AES-256) and in transit between ISMMS and OpenAI and between OpenAI and theirs service providers (TLS 1.2+). More here.
Our IT teams configured ChatGPT.Edu with enterprise-level authentication through SAML SSO to enhance IT security.
End User Guidelines:
The Icahn School of Medicine at Mount Sinai (ISMMS) provides access to OpenAI ChatGPT to all students and select faculty, researchers, and staff. Users of the ISMMS-provided ChatGPT service agree to adhere to all Mount Sinai Health System policies, including but not limited to, the ISMMS Appropriate Use of Technology policy IT-10A generally and, specifically the section, “Use of Artificial Intelligence (AI) Tools” and the Mount Sinai Health System (MSHS) Acceptable Use of Technology Policy IT-10B. Users will comply with ethical, copyright, and academic guidelines and adhere to standards of integrity as outlined in department handbooks and institutional policies.
Authorized users of ISMMS ChatGPT agree that they:
Will not send OpenAI Student Data associated with children under the age of thirteen (13)
Will not send OpenAI Personally Identifiable Information (PII), Protected Health Information (PHI) or Family Educational Rights and Privacy Act (FERPA) protected data.
Will not connect ChatGPT to external apps such as Google Drive, Microsoft OneDrive or Amazon Web Services.
Will not share their GPTs externally, which could result in protected data being transmitted to third parties outside of the workspace
Will not enable Third-Party GPTs, which may enable transmitting information to external third parties.
User understands that ChatGPT.EDU licenses are limited and accounts with little or no activity may be reassigned as needed.