Critical Considerations for Generative AI Use in Healthcare episode artwork

EPISODE · Sep 15, 2023

Critical Considerations for Generative AI Use in Healthcare

from Info Risk Today Podcast · host InfoRiskToday.com

Generative AI holds great potential for many amazing applications in healthcare, but it's critical to establish a strong framework before deploying it, said Barbee Mooneyhan, vice president of security, IT and privacy of Woebot Health, a provider of AI-driven online mental health services.

Episode metadata supplied by the publisher feed · Published Sep 15, 2023

Embed this episode

NOW PLAYING

Critical Considerations for Generative AI Use in Healthcare

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

I'm Mary Ann Kolpasek McGee, Executive Editor at Information Security Media Group, and I'm here at the Hymn Cyberform in Boston speaking with Barbie Woonihan, who is Vice President of Security, IT and Privacy at Robot Health, an AI-powered mental health application. Hi, Barbie. Hello. So, Barbie, for starters, for those who are not familiar with Robot Health, please briefly describe what the company provides in terms of mental health services and what does it mean for the company's services to be AI-driven?

Yeah, I think that's a fantastic question. Thank you. So, Robot Health at its core is a mental health ally and chatbot form. So what we do is we take a natural language processor and we pair it with curated content with clinical oversight and that engages in experience with patients and with users that allows them to be able to have someone to have conversations with and to be able to go through some of those methods for improvement of their mental health, whether it be at 2 a.m.

or if it's at 4 p.m. So, it's just always their mental health ally in your pocket. So, with that said, what steps will this will provide help taking to protect individuals privacy and security? And how does AI change that in terms of the risks?

I think that's a really good question because we are AI-based. So, there is the natural language processor, but we are incredibly thoughtful in what methods that we take when it comes to how we utilize AI. First and foremost is when we select our vendors, the vendors have to be a very specific relationship. Our contracts are very thoroughly looked over.

We make sure that from a partnership perspective, we know exactly where our data is, where it's going to go, how it's going to be used, and then we also know that internally. And so, we move through the process of architecting our infrastructure and architecting our AI services so that the user experience is sound, but also we're able to control each element of it. So, we don't have outputs that we don't know what they are. And from a privacy perspective, what you say to Wobot is what you say to Wobot is considered to be a privileged conversation.

And so, while yes, there are some indicators that we utilize to make sure that the experience is appropriate for the user, there's also a lot of things that go into place that prevent the exposure of that information, like what we call transcripts. We have a lot of conversations internally about transcripts and the appropriate usage of them and the appropriate, like who can view them and who can't. And so, we do have least privileged, we have role-based access, and the user data is actually in a separate environment than all the other environments so that we can keep good, deep controls on the user's information while also being able to run the application appropriately, and it really reduces the attack potential on user information. And then we are very, very protective of the conversations themselves.

So now you're using AI in your mental health sorts of services, but what other sorts of emerging use cases are you seeing or hearing most about right now when it involves generative AI in healthcare in terms of promising sorts of applications that you think could benefit patients and maybe the healthcare providers themselves that have to wait against what the risks are? First, I just want to cover that Wobot currently does not perform generative AI. Like I said, it is strictly curated content that is served back depending on our natural language processor. So we do actually, we've just released our first study on generative AI and the fantastic work that's being done there, but we just have so much testing to make sure that what we're doing is going to make sense, especially with the conversation that's very prevalent to the industry right now.

And so some of those components I guess for the future state of potentially use cases would be anything, right? We just talk on stage about using it to be able to take physician notes, using it to be able to create where your imagery could be in three months, so if you have a disease and then you do generative imaging for where it's going to be in three months. And so there's the use cases are endless. We could really just insert it into so many different operations and anything that you can do five times, you could probably automate and if you could automate it, you could probably automate it with a generative text component and the use cases are endless.

However, I do think it's incredibly important, like I said before, that we can't just implement into healthcare because we're working with patients' lives and I think that's an important thing to consider in all of this is that we have to have good guardrails, we have to understand what it's doing. We have to understand the outputs. We have to verify and test the outputs and we have a lot of testing to do in the environment before major, major changes can be made. And in terms of the good and the bad for generative AI and healthcare, when it comes to data security privacy and potential breaches looking ahead, what do you see?

Well, I think I kind of covered that a little bit already. There's obviously amazing things that we can do with it. It's an innovative, fast forward for us. I mean November hit, we got a new, much improved abilities and then just seeing the environment go wild since then everybody trying to get the front of the line and trying to figure out how to use generative AI.

So there's a lot of good that can happen, but like you said, there's also a lot of bad. And so one of the things that we try to keep in mind, so there's different pieces. There's outside threats and then there's the potential of insider threats. And insider threats doesn't have to be malicious, it can be completely unintentional.

So we have to make sure that in the long run, the security privacy components of it is well defined, so those insider threats have good policies in place and then you're able to identify if you're training the awareness of everything, if you're training them appropriately and you're training your workforce appropriately and you have good policies in place and you're saying, these are the things that you can do. These are the things that you can't do. And this is how you appropriately use it in our environments. We do reduce the risks around security and privacy, a big piece of it is privacy, right?

We don't want to put our business intelligence information. We don't want to put RPI or PHI into these and then we have a privacy implication, but we also want to be able to support the innovations. So a lot of it is just being prepared for it and being able to address it appropriately as it comes up and to proactively understand what the potential ramifications are and training our workforce for it. So it goes through some of the guardrails.

Finally, what is your top security and privacy advice for healthcare entities deploying general of AI efforts in their organizations right now? Anything that you haven't mentioned that you think is important for them to consider? Oh, absolutely. Again, the most important is we have to understand it first.

We have to test it. We have to validate it. We have to understand it. Without that, we could be potentially putting things into place that we don't know what's going to happen because we don't understand the technology just yet and we are still understanding it.

But I do think that we have protective controls if you're thinking through the protective controls. It's going to be making sure that you don't really have the text going out to a user without a clearance area. So whether or not you never have the user talk to AI or if you have just a buffer in there that has a validation verification that has those good check marks in place and it will stop the prompt before it goes back out. Being able to implement those and again testing them to make sure that they work appropriately is going to be a big difference between putting generative AI into place that could potentially harm versus putting AI into place that has those safeguards and guardrails already in place.

Well, thank you, Barbie. I've been speaking to Barbie, Munihan, and I'm Mary-Ann Kopasek McGee of Information Security PQ Group. Thanks for joining us. Thank you.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on September 15, 2023.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!