Guides

    AI for HEOR: What You Can and Can't Put in a Prompt

    The field's guidance says use AI carefully, keep humans in the loop, and be ready to defend it at HTA. Here is the piece it leaves open: what to do when the input itself is confidential.

    Published 2026-07-13

    The short answer

    AI is now mainstream in HEOR — ISPOR ranks it the field's top trend and has published a taxonomy of generative-AI uses across the workflow. The unresolved piece is confidentiality: unpublished results, pricing strategy, patient-level and sponsor data cannot go into public AI tools, and enterprise licences alone don't authorize it. Safe AI use in HEOR means public inputs, sponsor-authorized deployments, or cloaked inputs where the model never receives the confidential values.

    Where the field actually stands

    HEOR has moved past the "should we use AI" debate. ISPOR — the field's professional body — named AI the #1 trend in its 2026–2027 Top 10 HEOR Trends report, and an ISPOR Working Group has published a taxonomy of generative AI applications across the HEOR workflow (Fleurence et al., Value in Health): systematic literature review, evidence synthesis, economic modelling, dossier development and beyond. The same institutional literature is equally clear about the conditions: human oversight, transparency about AI involvement, and traceability that survives HTA scrutiny — with published guidance on when not to use AI at all.

    What the institutional guidance does not resolve is the input problem. The taxonomy tells you AI can help draft a dossier section; it does not tell you what to do about the fact that the dossier section is built on a sponsor's unpublished endpoint and confidential price. That gap is where day-to-day HEOR consulting actually lives.

    What can and can't go in a prompt

    InputPublic AIWhy
    Published literature, public HTA reports, guidelines✓ FineAlready public — no confidentiality obligation attaches.
    Your own general methods knowledge, synthetic examples✓ FineNothing owned by a client or sponsor is disclosed.
    Unpublished trial results, endpoints, subgroup analyses; economic, evidence-synthesis and NMA results based on unpublished data✗ NoSponsor-confidential under NDA/engagement terms; disclosure occurs at transmission.
    Pricing, discounting and market-access strategy✗ NoConfidential business information — confidential in substance, with or without names.
    Patient-level data (IPD), registries, RWE extracts✗ NoPrivacy law (HIPAA/GDPR/PIPEDA) and sponsor confidentiality both apply.
    Draft deliverables built on any of the above✗ NoThe draft inherits the confidentiality of its inputs — 'it's only a draft' is not a release.

    The uncomfortable arithmetic: the rows marked ✗ are most of the real work. A HEOR consultancy that restricts AI to public inputs has protected its NDAs by excluding AI from the deliverables that would benefit most — which is how quiet, unsanctioned AI use starts.

    57% of employees who use AI at work conceal it from their employer, and 48% have uploaded company information into public AI tools.

    Source: KPMG & University of Melbourne, “Trust, Attitudes and Use of AI: A Global Study 2025” (n ≈ 48,000 across 47 countries)

    Making the confidential step safe

    Three routes exist for the ✗ rows, in increasing order of usefulness:

    • Exclude AI from confidential work. Compliant and common — and it concedes the productivity gain everywhere it matters.
    • Sponsor-authorized enterprise AI. Valid where the sponsor approves a named deployment in writing. In practice: slow, engagement-by-engagement, and many sponsors decline — an enterprise licence is an agreement with the vendor, not the sponsor's consent. And even when authorized, you remain responsible for leaks and misuse, and the secrets are still shared with external vendors — which demands advanced audits and BAA certification.
    • Cloaked inputs. Replace every confidential value — endpoints, prices, identities, figures — with name cloaks and semantic/sequential flags on the consultant's own computer, before anything is transmitted. A drug name becomes a stable name-cloak identifier; a price becomes a semantic flag conveying its strategic posture; a response rate becomes a sequential flag the model can reference in context — all without the real values ever being sent. Real values are restored locally. No confidential value is disclosed, so no sponsor consent is required for the values, and output quality survives because the flags preserve meaning.

    Semantic cloaking retained 94–98% of baseline AI writing quality (~95% typical); censoring-style redaction retained roughly 37% and random crypto-tokenization roughly 32%.

    Source: Tremblay & Harricharan (2026), “Comparing De-identification Methods on AI Writing Quality in HEOR and Market Access,” Zenodo, doi:10.5281/zenodo.21343321. Internal benchmark, 30 tests per technique.

    Traceability: the requirement HEOR keeps naming

    The recurring theme in ISPOR-adjacent guidance is that AI-assisted work must be defensible after the fact — to sponsors, to HTA reviewers, to a client's compliance function. That is an evidence problem, not a policy problem: when a question comes eighteen months later, "our policy prohibited confidential data in prompts" reconstructs nothing. What answers it is an audit trail generated by the tooling itself — every submission recorded with what was cloaked, which model received it, and what came back, with the confidential values never appearing in the record. That artifact is what turns "we used AI carefully" into something you can hand over.

    The bottom line for HEOR teams

    Follow the field's guidance on when AI belongs in the workflow — ISPOR has done that work. Then hold your tooling to the standard the guidance implies but doesn't specify: the model never receives sponsor values that are confidential, secret, sensitive or unpublished, and every submission is auditable. If a tool can't meet both, the safe uses are the public-input rows of the table above — and nothing else.

    Frequently asked questions

    Is AI use accepted in HEOR?

    Increasingly, yes — ISPOR named AI the top HEOR trend for 2026–2027, and an ISPOR Working Group has published a taxonomy of generative AI applications across the HEOR workflow (Fleurence et al., Value in Health). Acceptance comes with conditions the field keeps repeating: human oversight, transparency about AI involvement, and traceability that survives HTA scrutiny.

    What HEOR data should never go into a public AI tool?

    Anything confidential to a sponsor or client: drug names, specific mutations and targets, the target product profile (TPP), unpublished trial results and endpoints, unpublished economic and statistical results, pricing and market-access strategy, patient-level data, draft dossier content, and the sponsor's identity where the engagement itself is confidential. Under a standard NDA or engagement terms, sending these to a public AI service is an unauthorized third-party disclosure — regardless of how useful the model would be.

    Can I use AI on patient-level data (IPD) in HEOR work?

    Not by sending it to a model. Patient-level data carries both privacy obligations (HIPAA, GDPR, PIPEDA) and, in most engagements, sponsor confidentiality obligations. The workable pattern keeps the real data on your side: derive what the analysis needs locally — cloaked summaries or pseudo-IPD that preserves statistical structure — and let the model work on that instead.

    What does 'traceability' mean for AI-assisted HEOR deliverables?

    That every AI contribution to a deliverable can be reconstructed and defended afterwards: what was submitted to which model, when, what came back, and what a human accepted or changed. HTA bodies and sponsors increasingly expect this. In practice it requires an audit trail generated by the tooling itself — a policy document cannot reconstruct a submission after the fact.

    How do HEOR consultancies use AI without breaching sponsor confidentiality?

    Three routes: restrict AI to public inputs only (safe but excludes most real work); obtain sponsor authorization for a specific enterprise AI deployment (valid but slow, and many sponsors decline — and it demands serious precautions with the BAA, privacy tooling and auditability, cutting no cost on advanced traceability); or cloak confidential values on the consultant's own computer so the model receives semantic and sequential markers instead of the sponsor's data. The third route preserves roughly 95% of output quality (Tremblay & Harricharan, 2026) while transmitting no confidential values at all — which is what cloaking is all about, so only you see the truth.

    This guide is general information about how AI tools interact with confidentiality obligations. It is not legal advice, and it does not create any professional relationship. Confidentiality agreements vary — review your own agreements with qualified counsel before relying on any framework described here.

    Work with AI on data you can't share with it.

    Untraceable cloaks confidential values on your computer before any AI model sees the text — the model never receives the secret at all.