HIPAA Considerations for AI Tool Use in Healthcare Research episode artwork

EPISODE · Apr 20, 2023

HIPAA Considerations for AI Tool Use in Healthcare Research

from Info Risk Today Podcast · host InfoRiskToday.com

The potential use cases for generative AI technology in healthcare appear limitless, but they're weighted with an array of potential privacy, security and HIPAA regulatory issues, says privacy attorney Adam Greene of the law firm Davis Wright Tremaine.

Episode metadata supplied by the publisher feed · Published Apr 20, 2023

Embed this episode

NOW PLAYING

HIPAA Considerations for AI Tool Use in Healthcare Research

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

I'm Mary Ann Kolbasakmiki, executive editor at Information Security Media Group. I'm at HIMS, talking to privacy attorney Adam Green of the law firm Davis Wright, for Maine. Hi Adam. Hi Mary Ann.

Thanks for joining us. So Adam, we're hearing so much about artificial intelligence, especially technologies like chat, GPT. What are some of the most common and we're promising types of AI that you're seeing applied in healthcare these days, and what are your top privacy and security concerns? Well, at this point, it's just a matter of imagination as to what AI can do with healthcare.

I mean, we've now seen for a few years radiology images, for example, in AI being able to detect tumors, sometimes as good, if not better, than radiologists. We can see it in areas like coding, whether you're on the healthcare provider side, looking to better, more efficiently do coding, or whether you're on the health plan side, potentially using AI to review coding and detect abnormalities. So in chat GPT now, I think, is able to pass the medical exam to become a doctor. So we know where that's going.

So on the privacy side, the continuing challenge just tends to be that there's a need for health information to be able to build this. And ideally, you can use de-identified information, but sometimes that doesn't get the job done, and that's where navigating the privacy laws can be challenging. So with that said, what should carbon entities and business associates know about how HIPAA, for instance, applies to the use of protected health information to develop or improve AI tools? So there's the actual use, and that can be easy.

So you might use AI for treatments, and that's permissible under HIPAA. The development side is definitely more challenging. So there's a lack of clarity out there with respect to, for example, when developing AI may qualify as healthcare operations, and that may be based on whether it's primarily focused on improving the particular carbon density that is providing the protected health information that's being used. It could possibly be considered research to develop AI, but we don't have much clarity about if you're not publishing, but you're doing commercial R&D, whether that truly qualifies as a research under HIPAA.

And even if it does, it's not a get out of jail free card. You still either have to get individuals' authorizations, or an IRB, or privacy boards waiver of authorization, or there's just that none of the above, in which case you likely need individuals' authorizations to use their health information to develop AI. Now HIPAA has two different recognized ways of de-identifying PHI that can be used for research, and would that apply to using that data for AI, do you think? So yes, HIPAA has two recognized ways to de-identify information, and that can be for purposes of research or for any other purpose.

And so one of them is the safe fiber method, and that involves removing things like direct identifiers like name or so of a security number, but also indirect identifiers like dates related to treatment, or zip code and things like that. And if you've got a structured data set, that can be pretty easy. The only challenge might be whether the resulting data is good enough for the purpose that you're intending. It's where you get into unstructured data, that using a safe fiber method can be very challenging, because finding in free text every date that might be relevant or things like that can be very challenging.

The other method is the expert determination method, where you bring in a statistical expert to essentially document and determine a document that the risk is very small, and that holds a lot of promise. But it can be expensive and time-consuming to engage such an expert. Does it get even more complicated where there's this push for healthcare entities to share data and for patients to be able to access the data from everywhere, if you're an entity and you're sharing your patient's data with another entity because your patient answered due to that other entity, all of a sudden, decides they're going to use some of this data for AI purposes, is that allowed? Interoperability, more or less, treats the information as subject to the laws governing the recipients.

For example, if I'm a healthcare provider in Kansas, and I get a request for treatment through kind of a health information exchange to send information over to a healthcare provider in Texas, then it's really not going to be under hip at least my data anymore. Once it's been received by that other Texas healthcare provider for treatment purposes, and so it becomes likely part of their electronic health record and could feed into their own data sets that might be used for AI development and so interoperability really leads to a flow of data and at any point in that flow, it could potentially be scooped up hopefully for good purposes for AI development. And are there any other sorts of AI-related issues that we haven't touched upon that you think are worth noting that I didn't ask about? So a big one is sale of protected health information, so essentially a covered entity or its business associate may not disclose protected health information in exchange for any form of remuneration.

Obviously, the classic image is, here's my PHI and you get back bags of money in exchange, but more challenging might be things like, you know, here I'm providing you access to my protected health information and in exchange you're going to give me IP rights or a license to use the AI that you develop. And we've already had at least one case where a court found that that sort of exchange would qualify likely as a sale of protected health information and so structuring these arrangements in a way that doesn't trigger sale of PHI prohibitions can be pretty challenging. So what are you predicting in terms of the regulatory offices, whether it's OCR or other offices that might get involved with AI but also PHI and being misused for AI purposes? How soon might we see either guidance or enforcement actions related to that?

Well, it's a tough area because generally regulators only get glimpses into what's going on through certain avenues, so there might be a breach, there might be a patient complaint, there might be a whistleblower, or there might be kind of a randomly selected audit. And of those, most of them are not going to lead down the road towards a regulator scrutinizing AI development. I mean a patient has no idea if their information is ultimately being used to develop AI. Now we did see one case where Project Nightingale involving Google where there was a whistleblower and brought that to the media's attention and we did see that OCR indicated that they were opening up an investigation response, but that's the last we heard of it as far as I know and so I've not heard anything on the horizon about AI guidance or anything like that and there's limited visibility for the regulators and frankly the regulators have their hands full right now and other things.

Speaking of them having their hands full, what are you watching most when it comes to the HHS OCR world? There's a lot to see, so we had back in January 2021, I know it's a proposed rulemaking and that's frankly the least interesting thing out there, it has a lot of things related to coordination of care that frankly I think were permissible even without the regulatory clarification. I think much more interesting is the recent I think December proposed rule on revising 42 CFR part two, the regulations governing substance use disorder information and that's going to have huge implications because amongst other things it creates breach notification requirements related to that rule, it brings the HIPAA enforcement mechanisms into play, creating a much higher risk of enforcement in that area and even though SAMHSA has traditionally been associated with that rule, OCR has taken a lead role on that rulemaking and then more recently we have a proposed rule on supporting reproductive health care privacy, obviously OCR stepping into a field of landmines on this one but they're not afraid to do so, I mean this is a big priority of the administration and they struck a very interesting middle ground where essentially they're respecting state law on the most part in that if it is, if a particular procedure for example is unlawful in a state then they will not get in the way of disclosures of protected health information to law enforcement and to courts related to that procedure unless it's required or authorized under federal law like Intala. In contrast if it's lawful in one state they are willing to preempt state laws in other states where those other states might try to get a hold of that information, so for example Idaho passed a law where if you take a minor to another state and they get an abortion in that other state where it may be legal you could be found in violation of Idaho law for doing so and so if you're in Washington for example you would not need to disclose under the proposed rule to an Idaho court who might be looking to prosecute someone for bringing a minor over state lines in that case.

Typically HHS, OCR kind of takes its time when it has proposed rule, you know their comments they read the comments and then you sort of wait and wait for a final rule, do you think they'll move faster on this one just because it's such a hot area right now? I do, I think that of the different rulemaking my guess is that the reproductive health privacy is their top priority, that being said they're going to probably get a whole lot of comments on this it's going to take time to go through those comments but it may significantly delay, we were expecting the rulemaking with respect to the 2021 notice of proposed rulemaking to be finalized in March but that may get delayed based on them really focusing their efforts on having put out recently this reproductive health rule and you know those other efforts and there is a requirement so a prohibition I should say in HIPAA that you may not amend the same HIPAA standard or implementation specification more than once every 12 months and all these rules actually affect one implementation specification in particular, the notice of privacy practices and so they either have to bring them all at once in finalization or snagger them quite a bit. Thanks Adam, I've been speaking to Adam Queen, I'm Mary Ann Kolpasek McGee of Information Security Media Group, thanks for joining us.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on April 20, 2023.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!