---
title: "AI \"Vibe Coding\" Policies and Defenses"
description: "Learn about the legal, policy, and technical implications of \"vibe coding\" AI products that offer to integrate with AngelTrack via your browser."
---

[Skip to content](https://support.angeltrack.com/help/vibecoding.htm#main-content)

English

Show submenu for translations

![A.400x400.png\]](https://support.angeltrack.com/hs-fs/hubfs/A.400x400.png?height=40&name=A.400x400.png)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- Go to angeltrack.com

 Go to angeltrack.com

 AngelTrack Knowledge Base

- There are no suggestions because the search field is empty.

1. [AngelTrack Knowledge Base](https://support.angeltrack.com/help?hsLang=en)
2. [IT](https://support.angeltrack.com/help/it?hsLang=en)
3. [Data Protection](https://support.angeltrack.com/help/it?hsLang=en#data-protection)

# AI "Vibe Coding" Policies and Defenses

## Some AI products now allow users to build their own browser integrations, but these cause difficulties for EMS and fire data.

### What is "Vibe Coding"?

"Vibe Coding" is the practice of telling an AI in plain language what you wish to do, and the AI then tries to write a program to perform that task.

Vibe Coding is relevant to AngelTrack and the EMS and fire sectors because vibe coding products are now available which allow the user to write a program to automatically click buttons and menus in a web page. This is accomplished via a tool known as a "headless browser", intended to be driven by an AI-written program.

### HIPAA and PHI

Remember that even if you paid for it, *your AI does not work for you*. It will help you, but it serves a different master.

To that end, it will upload copies of all your data to its servers, for use training its next generation. The goal of this constant training is to eventually underbid you for your job... and copying your data is the way to accomplish that.

Even if the AI runs *entirely locally*, it will still attempt to train on your data and then discreetly phone it home.

This ubiquitous AI behavior is incompatible with HIPAA regulations, because PHI in the training data will end up in the next generation of AIs trained using that data. For example, researchers recently demonstrated that the full exact text of the Harry Potter books could be extracted from frontier AIs who at the time were claiming they a) never trained on such copyrighted works, and b) could not in any case ever regurgitate raw training data in the manner the researchers demonstrated.

The Harry Potter book experiment proved that -- contrary to their public claims -- AIs permanently store all information fed into them, including patient names, SSNs, MBIs, medical history, and billing data, all of which can be readily extracted later.

![Danger.large](https://support.angeltrack.com/hs-fs/hubfs/Imported%20images/Danger.large.png?width=120&height=120&name=Danger.large.png)

For these reasons, do not utilize any AI product on any computer which contains or routinely accesses PHI data, without first clearing it with your compliance officer.

### Bugs and Floods

A vibe-coded AI that interacts with AngelTrack's *user-facing* web pages creates interesting risks, because AIs can easily make mistakes which no human ever could, against which user-facing web pages are not defended. Such mistakes include:

- Entering an infinite loop and clicking a "create new record" button ten million times, creating a quantity of records that violates AngelTrack's design assumptions and thus causes other systems to being failing or timing out;
- Setting filters to perform a large expensive query and then requesting it ten times a second while ignoring the results, causing all other users to experience slowdowns; or
- Clicking a menu or button at the maximum permitted rate, thus causing all others users at the same IP address (i.e. at the same office) to receive a "Too Many Requests" error message.

Further, AngelTrack LLC has observed real-world vibe-coded AIs behaving inconsiderately, including:

- Not caching static files, thus uselessly re-requesting dozens of megabytes of files for each page interation;
- Not sending a session cookie, thus consuming server resources re-establishing the session on every request;
- Disguising its identity as an AI running a headless web browser;
- Ignoring the directives in robots.txt;
- Probing the AngelTrack server for its maximum permitted request rate, and then running requests at that rate without considering the needs of other users; and
- Impersonating its user's authentication cookie, thus issuing requests for HIPAA data in the user's name but not necessarily with the user's permission and consent.

Such activities violate the AngelTrack Terms of Use and are grounds for immediate termination of service without cooldown period.

### Defenses

To reduce their attack surface against such risks, AngelTrack's user-facing pages impose request throttles per-IP and per-user. The throttles are set to allow ample room for anything a normal human would ever do, while preventing an AI from issuing a dangerous rate of requests.

If you have an outside biller where all of the employees share a single user account named "Billing Agency" or some such, they might run afoul of the per-user throttle, since they have many humans all making requests under the same user account. If that occurs, please tell the billing agency that HIPAA requires all PHI requests to be traceable to a specific human, and therefore a billing agency's employees must never share a user account.

AngelTrack has unlimited seats, so there is no reason why a billing agency would ever need to share user accounts.

### Alternatives

AngelTrack has a variety of API endpoints which are designed for such integrations, and already have the necessary documentation, standardized formats, and appropriate throttles.

Likewise the [Data Hub](https://support.angeltrack.com/help/reporting/adhocreports.htm?hsLang=en) has an enormous number of datasources which provide well-formed data with regular column names, in standard .CSV format, ideal for use in building a data warehouse or custom metrics. 

- [General Topics](https://support.angeltrack.com/help/general-topics?hsLang=en#main-content)

    - [Configuration](https://support.angeltrack.com/help/general-topics?hsLang=en#configuration)
    - [Integrations](https://support.angeltrack.com/help/general-topics?hsLang=en#integrations)
    - [State and County Uploads](https://support.angeltrack.com/help/general-topics?hsLang=en#state-and-county-uploads)
- [Dispatch](https://support.angeltrack.com/help/dispatch?hsLang=en#main-content)

    - [Basic Dispatch](https://support.angeltrack.com/help/dispatch?hsLang=en#basic-dispatch)
    - [Schedules and Recurrences](https://support.angeltrack.com/help/dispatch?hsLang=en#schedules-and-recurrences)
    - [Connections to Billing](https://support.angeltrack.com/help/dispatch?hsLang=en#connections-to-billing)
    - [Advanced Topics and Tips](https://support.angeltrack.com/help/dispatch?hsLang=en#advanced-topics-and-tips)
    - [Vertex AI Dispatch Planner](https://support.angeltrack.com/help/dispatch?hsLang=en#vertex-ai-dispatch-planner)
- [Supervisors](https://support.angeltrack.com/help/supervisors?hsLang=en#main-content)

    - [Fleet](https://support.angeltrack.com/help/supervisors?hsLang=en#fleet)
    - [Compliance](https://support.angeltrack.com/help/supervisors?hsLang=en#compliance)
- [Billing](https://support.angeltrack.com/help/billing?hsLang=en#main-content)

    - [Invoicing](https://support.angeltrack.com/help/billing?hsLang=en#invoicing)
    - [Pricing and Contracts](https://support.angeltrack.com/help/billing?hsLang=en#pricing-and-contracts)
    - [Coding, Claims, and Clearinghouse](https://support.angeltrack.com/help/billing?hsLang=en#coding-claims-and-clearinghouse)
    - [Prior Authorization and PCS](https://support.angeltrack.com/help/billing?hsLang=en#prior-authorization-and-pcs)
    - [Billing Workflow](https://support.angeltrack.com/help/billing?hsLang=en#billing-workflow)
    - [Payments and EOBs](https://support.angeltrack.com/help/billing?hsLang=en#payments-and-eobs)
    - [Facility and Patient Records](https://support.angeltrack.com/help/billing?hsLang=en#facility-and-patient-records)
- [QA Review](https://support.angeltrack.com/help/qa-review?hsLang=en)
- [Salesperson](https://support.angeltrack.com/help/salesperson?hsLang=en)
- [Human Resources](https://support.angeltrack.com/help/human-resources?hsLang=en#main-content)

    - [Timeclock](https://support.angeltrack.com/help/human-resources?hsLang=en#timeclock)
    - [Schedules and Vacations](https://support.angeltrack.com/help/human-resources?hsLang=en#schedules-and-vacations)
- [Crew Members](https://support.angeltrack.com/help/crew-members?hsLang=en#main-content)

    - [Report Completion](https://support.angeltrack.com/help/crew-members?hsLang=en#report-completion)
    - [Documents](https://support.angeltrack.com/help/crew-members?hsLang=en#documents)
- [Fire](https://support.angeltrack.com/help/fire?hsLang=en)
- [IT](https://support.angeltrack.com/help/it?hsLang=en#main-content)

    - [Data Protection](https://support.angeltrack.com/help/it?hsLang=en#data-protection)
    - [Troubleshooting](https://support.angeltrack.com/help/it?hsLang=en#troubleshooting)
- [Miscellaneous](https://support.angeltrack.com/help/miscellaneous?hsLang=en#main-content)

    - [Articles for patients and facilities](https://support.angeltrack.com/help/miscellaneous?hsLang=en#articles-for-patients-and-facilities)
- [Report Builder](https://support.angeltrack.com/help/report-builder?hsLang=en#main-content)

    - [Walkthroughs](https://support.angeltrack.com/help/report-builder?hsLang=en#walkthroughs)
    - [Built-In Reports](https://support.angeltrack.com/help/report-builder?hsLang=en#built-in-reports)

[![Chill listening crop-3](https://support.angeltrack.com/hs-fs/hubfs/A.400x400.png?width=40&height=40&name=A.400x400.png "Chill listening crop-3")](https://support.angeltrack.com/help/index.htm?hsLang=en)

AngelTrack Support Home

Copyright © 2026, AngelTrack LLC