Guide6 min read

Is It Safe to Use AI for Elderly Care?

Yes for care logistics, no with raw data: anonymise a vulnerable senior's name, health and finances before any prompt to a consumer AI.

By Pierre de ONYRI

The answer fits in one line. AI can help you organise an older relative's care, but not with their raw data. Helping a dependent parent means handling their most sensitive information. Their health status. Their medications. Their accounts. Often, that person can no longer consent for themselves. Health data is special-category data in the UK and the EU, protected by Article 9 of the GDPR. A consumer AI does not offer a clinic's protection. And a vulnerable senior's profile is exactly what scammers want. There is a clean method: anonymise the name, health and finances before you send.

You are handling someone else's data

This is the ethical and legal heart of it. Managing an elder's care means processing their data on their behalf. Their health. Their finances. The vulnerability itself. You are not the subject of this information. You are its guardian.

Health data is not ordinary data. In the UK and the EU, it is special-category data. Article 9 of the GDPR gives it extra protection. The ICO, the UK regulator, spells this out. It covers more than diagnoses. It covers anything that reveals a person's health status. A test result. An appointment reminder. A medication. A disability or a care need.

There is a second, harder hurdle. A person who has lost capacity cannot give the explicit consent this data normally requires. So you decide for them. That is a responsibility, not just a practical step.

Elder fraud is real and targeted

This risk is not abstract. The FTC, the US federal consumer-protection agency, measures its scale. Fraud losses reported by adults aged 60 and over roughly quadrupled in four years. They rose from about $600 million in 2020 to about $2.4 billion in 2024. A large share came from high-value losses to investment, romance and impersonation scams.

These figures are reported losses. The FTC notes that most fraud is never reported. So the true total is higher. The trend is what matters: older adults are a growing target.

A full profile is precisely what scammers want. A vulnerable senior's identity. Their health status. Their financial or power-of-attorney details. Together, these form the raw material of a scam. A leak here is not a vague risk. It can enable direct, targeted harm.

A consumer AI is not protected like a clinic

Many people assume health data is always protected. In the US, that is false outside the medical setting. The FTC explains this for health apps. HIPAA, the US health-data law, covers records held by hospitals, doctors and insurers. But many companies that collect health data fall outside it. Fitness trackers. Wellness apps. Direct-to-consumer tools.

The consequence is simple. What you paste into a general-purpose chatbot is not protected like a clinic's records. The same holds for consumer AI. It does not carry the safeguards of a regulated health provider.

You assumeThe reality
“It's my call, they can't consent anymore”You handle someone else's data — a duty to act in their interest
“Health data is always protected”A consumer AI generally isn't covered the way a clinic is
“A leak here stays an abstract risk”A vulnerable senior's profile is raw material for a targeted scam
“Medications aren't that sensitive”The ICO classes them as special-category data (Article 9)
The risk isn't asking an AI for help — it's the vulnerable person's data you leave behind in the prompt.

The fix: anonymise before you send

Good news: AI is still useful for care. It can help with logistics. A medication schedule. A checklist for an appointment. A draft letter to a service. For that, it needs no real identifiers. Ask the question on de-identified information.

Two-part diagram: at top, a care-profile card for an older person, with a health row and a finance row in the clear (amber) and a small vulnerability shield, travels toward an AI card that receives the exposed profile with an amber alert; at bottom, the same card anonymised shows only cobalt token chips under a larger shield, and the AI receives only tokens with a checkmark.
After the ICO's guidance on special-category data (Article 9) and the FTC's work on elder fraud and health apps outside HIPAA.

When you must describe a concrete case, anonymise it first. Replace the name, the health status and the financial identifiers with tokens. The AI reasons about the shape of the situation. It never sees the real values. You restore them afterwards, locally. Never paste a full medical or financial record. And if the person retains capacity, involve them and seek their consent.

  1. 1Spot the sensitive data: name, health, medications, finances, power of attorney.
  2. 2Replace it with reversible tokens, in the browser.
  3. 3Send only the anonymised text to the AI.
  4. 4Restore the real values in the reply, locally.
  • Keep medical records and financial statements out of the prompt.
  • Prefer vetted tools, not a random consumer chatbot.
  • Act in the person's interest — a duty under power of attorney.
  • If capacity or power of attorney is unclear, consult a legal adviser.

That's what ONYRI Sanitize is for. The engine detects sensitive data — name, health status, medications, amounts, contact details — and replaces it with reversible tokens before sending. Detection and the mapping stay in your browser. Only anonymised text reaches the model. The AI finds only tokens, never the person's real data. You get the logistics help, without exposing a vulnerable relative to the risk the ICO and the FTC ask you to rule out.

Frequently asked questions

Is it safe to use AI for elderly care?
Yes for care logistics, no with their raw data. AI can prepare a schedule, a checklist or a draft letter on de-identified information. But never paste a vulnerable senior's name, health status, medications or finances into a consumer chatbot. Health data is special-category data (Article 9), and a full profile feeds targeted fraud. Anonymise before you send.
Is a relative's health data protected inside a consumer AI?
Not like in a clinic. In the US, the FTC notes that HIPAA covers hospitals, doctors and insurers, but not most consumer health apps and tools. So what you paste into a general-purpose chatbot lacks a medical record's protection. In the UK and the EU, this data remains special-category data under Article 9 of the GDPR.
What if the person cannot consent?
You decide on their behalf, with a duty to act in their interest, including protecting their data. Share the strict minimum and anonymise the rest. If they retain capacity, involve them and seek their consent. Power-of-attorney and capacity rules vary by country: when in doubt, consult a legal adviser.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Anonymize my prompt

Read next