I'm Mary Ann Coby, executive editor at Information Security Media Group, and I'm here at the HIMS Cyber Forum in Boston speaking with Dr. Eric Lederman, who is director of medical informatics at Kaiser Permanente. Hi, Eric. Hi, Mary Ann.
So, as you know, we've been hearing so much about chat, GPT, and generative AI this year. But, as you know, also AI has been used in healthcare for a long time, including to help radiologists with reading medical images, as well as for other use cases. With that said, what sorts of emerging use cases are you seeing and hearing most about right now involving generative AI or other sorts of AI applications in healthcare right now that you think are most promising, but yet at the same time pose certain risks that you're also worried about? Well, we've got some really exciting things going on.
You mentioned imaging. There's been such great developments in imaging. So, for example, with mammography, I've been some recent studies that I've seen, and we've been a lot of work on my organization as well, where we're reaching a point where the artificial intelligence machine learning tools may be as good as replacing one out of a pair of radiologists. So, AI plus radiologists may be as good as two radiologists reading images together.
That's amazing. Especially since we have workforce shortage. So, our sickest patients are patients who are sick with sepsis, which is the infection of the bloodstream affecting the whole body. We want to find and identify these people as early as possible because they tend to get really sick really fast and oftentimes die.
And then, in general, the whole idea of identifying patients in the hospital who are going to have what we call a code, a cardiac arrest or other life-ending event in the near future. We want to identify those as early as possible, even hours before it happens, and we have increasingly powerful tools that allow us to do all these things. And then, with large language models, which generate a lot of excitement, we have the opportunity to tackle the challenging and time-consuming, but necessary work of healthcare generating notes after patient encounters and visits, generating messages to patients. These are really important.
We have to get these right, and we have to do them, but sometimes it helps contribute to burnout amongst our clinical workforce, and these large language models hold promise there. But, of course, like anything else, all of this artificial intelligence also holds the possibility of peril, right? If the AI misses cancer or flags one where there isn't one, similarly with the septic patient or the patient who's going to code, and then with large language models, well, you know, what most people probably don't know is that if you're sitting there playing around with a publicly available large language model, like chat, GPT, GPT-4, Bard, and all these others, many of which are now increasingly incorporated into search engines, what you put in becomes part of the data set that's used to train the AI and therefore can come out somewhere else. And if what you put in is protected health information, person identifiable information, credit card information, or intellectual property, then you may have just sent it out there into the world.
And therefore, it's incumbent on us not only to focus on the promise, but also the risks and mitigating them. So, speaking of that, as you know, I'm sure, too, that AI is sort of becoming sort of a shadow IT. You know, people hear about it in organizations, and they kind of try things out, but they haven't really gotten the official green light to do so. And hopefully, PHI doesn't end up in any of these public, you know, LLMs, you know, so on and so forth.
What sort of guardrails do healthcare organizations need to be thinking about in order to not stifle innovation, but to make sure that, you know, patient data is protected as well as other sensitive information? I think the most important thing is to provide safe, trusted alternatives that are bound by contractual terms and business associates agreements, because if you don't, if organizations does not provide these kinds of alternatives to publicly available, large language models, then they can expect that their clinicians and employees are going to be using them. And so the step one is work as fast and as hard as you can to come up with trusted alternatives that perhaps use your own data, or at minimum, don't incorporate or send out any of the prompt data that's entered into them, and then direct your workforce to use those LLMs instead. The alternative approach, which would be to tell everybody they can't use anything and then try to block it, is a non-starter, water will find its own level, people will do what they feel they have to do, both in terms of their interest and curiosity, but also because, you know, they want to get home at night to see their family.
So in terms of AI and, you know, it's used in healthcare, what are some of the cybersecurity and privacy concerns on the downside, you know, other than, you know, perhaps somebody using AI in an organization and they really shouldn't be using it for whatever they're using it for, and they're worried about the patient data leaking out, what are some of the malicious sorts of things that maybe the outsiders might be able to do with AI that are threats to cybersecurity and privacy and healthcare do you think? Yeah, there's several that were in me. Let's start with phishing. So we're all used to what the cybersecurity folks call spray and pray general phishing campaigns.
So, you know, we get these by email, we get them by text, which by the way is called smishing, SMS, right, smishing, we get voice calls, you know, we get it through a variety of means, but they're generally kind of generic. I mean, if you don't have a Wells Fargo account or an Express account and you get something that tells you that it's been, you know, in some way canceled or infiltrated, you're just going to ignore it and believe it. But if you do have one, maybe you'll be tempted to click on it, maybe not. But the really dangerous, powerful, social engineering attacks are ones that are targeted just for you.
These are called spear phishing, or in the case of senior executives, they're called wailing, and there's currently, you know, prior to AI, they require a lot of investment of resources. You got to do a lot of research, looking at all kinds of publicly available, Intel, like LinkedIn, Facebook, you know, and do a lot of research, and it can really pay off for folks. I mean, you know, there have been a lot of recent attacks where it's specifically targeted to be individuals and allowed for the successful intrusion into large corporations. I'm not going to mention any, but spear phishing doesn't happen as often because it does take all these resources.
But AI holds the promise for the attackers of mass attacks, mass spear phishing, mass attacks that are just for you, right? And those are much more powerful, much more likely to be clicked through and to generate successful attacks. What the phishing does, it opens the door and allows folks in. So that's one.
Another is that AI can help attackers, perhaps ones with limited skills identify vulnerabilities and even create code to exploit those vulnerabilities, maybe even folks with limited or no coding skills themselves. This opens the door to a whole much larger workforce, if you want to think of that way, of attackers to attack us. And the last thing I would say is deep fix. So AI is increasingly allows creation of audio and video effects that appear increasingly real.
And so imagine a business email compromise campaign which combines an email, it says to the CFO, immediately that appears to be from, let's say, their boss, like the CEO or a vendor, right? Send money to this account. And then it's followed up five minutes later by a phone call that sounds like it's from that same person using the deep fix voice. That's going to be much more likely to succeed than our current situation.
So now you're also speaking at the conference about cyber security and privacy concerns that can even, that can either strengthen or potentially weaken patient trust. What do you see in terms of what patients are most concerned about regarding the privacy and security of their health data and what are the top worries that you hear related to this from patients? There have been some recent surveys that show in recent years as healthcare in particular has been increasingly targeted by cyber attack and variety of reported breaches that patients understand what's going on. We read the news just like we in my field do and they're not happy.
In fact, several recent surveys I've seen have the same finding, which is that approximately two thirds of patients report that A, they'll consider leaving their healthcare organization if they don't trust it anymore and B, have already started or would start withholding medical information from their own doctor if they don't trust the protection of the healthcare information. These are both incredibly insidious and dangerous for the patients and for the healthcare field and in those organizations they have to take patient privacy protection and security extremely seriously, tackle it and communicate about it to their patients if they want to keep and maintain trust. That would seem to be patient safety issue if a patient has some sort of sensitive ailment they don't like talking about and they don't trust that the data or the information that they're providing to their doctor will be secure, the hackers might get it, whatever they're afraid of, they may not ever mention it to the doctor because they don't want to document it any way and the doctor is missing a big part of maybe what the care plan should be for that patient. What's happening today or it's probably happened on paper too but do you think these cybersecurity threats that the patients here about are making them even more resistant to telling the doctor exactly what's going on with them?
So I looked at surveys over the years of this and I take 2015 as a watershed year for healthcare in terms of cyber attacks. That was a year that in effect cyber attacks greatly ramped up against healthcare organizations and against health insurers. There was a huge attack against Anthem for instance but not only they don't want to call them out specifically but all of these things changed the game. Prior to that there were very few attacks against healthcare.
In most cases cyber attackers the culture generally was that you don't go after hospitals because you might kill patients. But that changed after 2015. So if you look at surveys from just before that to the years after that you see a dramatic shift in what patients say about this and it shows that about prior to that about 10% say withhold information after that it's the majority of patients saying they withhold information and maybe leave their healthcare institution. And finally as you look ahead to next year what are some of your top privacy and security predictions and priorities for that matter?
Well in general I mean I'm not a cyber security professional. I work closely with our cyber security professionals. Our CISO, our other you know hard working folks to risk management and assessment, identity and access management and also compliance folks you know working hard on protecting privacy including from folks who work for the healthcare organization and periodically tempted briefly to look up information they really shouldn't look up for all human and you know so my role is to help all of them and work closely with all of them to do the following first. Make their functions cyber security in particular and enabling function not a blocking function.
All too often cyber security is perceived as a preventing or blocking function because cyber security in many healthcare organizations is divorced or disconnected from healthcare operations and physician leadership and creates controls to mitigate against vulnerabilities in a vacuum not understanding the realities and excisiones of care delivery and in fact throws them over the wall and gums up the works of care delivery. In fact the opposite is not only possible but desirable and the idea being make cyber security effective but as invisible to the frontline clinician as possible and as much as possible have cyber security be built in to the way people access systems and the way data is protected so that it's just part of how it all works smoothly. The most sophisticated HIMS level 7, HIMS conference, HIMS level 7 organizations if they get attacked by ransomware they'll be reduced to HIMS level 1 in a matter of seconds and they'll say that way for weeks that is not an outcome that is in anybody's interest. That's the first thing.
The second thing I say is that privacy protection is one that people think about but not as much as the cyber security risks but it's just as important. The people we employ who have logins to our systems and should have logins to our systems need to deter themselves from overusing or abusing their logins to look at information they shouldn't look at. We cannot achieve this. They're trying to put in access controls and turn all of our data into a bunch of walled off pieces because we never know who's going to need to take care of a patient either directly or indirectly at any moment in time.
Instead we need to create an enduring culture of self-deterrence, safety and not snooping and the way to do that is straightforward. You need to have create and maintain a function where you look for examples and evidence of people snooping. You let everybody know you're doing that and now people know gee I'd really like to look at the CEO's record just got hospitalized but you know what I'm going to get busted for that and so I'm not going to do it. Now that allows our highly skilled and highly trained experienced people to keep their jobs, keep their licenses and keep delivering care for us and get past that temporary temptation and it protects everybody's sense of safety.
Thank you very much, Eric. I've been speaking to Dr. Eric Letterman. I'm Mary Ann Cobissak-McGhee of Information Security Media Group.
Thanks for joining us.