I'm Marianne Kolbasek-Magee, Executive Editor at Information Security Media Group. Today, I'm speaking with Attorney Wendell Bartnick of the law firm Reed Smith. We'll be discussing President Biden's recently issued Executive Order on artificial intelligence and its impact on the healthcare sector. So Wendell, what parts of the executive order do you think could potentially have the biggest impact on the healthcare sector and its use of AI and why?
Clearly, healthcare was a focus of President Biden. There are several pages focusing on how AI is impacting healthcare and how we should think about it. What I found really interesting is, and great, is that the approach that the Biden administration took is that rather than try to just create rules, it asked HHS to create rules and to look at AI quality and to just really start thinking about a strategy for regulating AI. And I think that actually is a great approach here because there already is a lot of existing regulation.
And I really appreciate that President Biden is going to look to industry experts to help formulate AI policy and regulations as well. So I think to me, that was a really big win for the healthcare industry. More specifically, it was nice to see, of course, a focus on investment in this area. There were several ways in which the administration would like to see investment in AI and new facilities, research institutes with getting more experts, which we all need.
And so that was great. I think it also requires HHS to establish an AI task force to really build out the strategy I mentioned before. So thinking about what sorts of frameworks and policies are necessary to help ensure the use the responsible use of AI in healthcare. And I think that could really help direct what regulation might look like.
So I think that's really important. It also asked HHS to develop a program to collect information about the quality of AI tools right now. Now, of course, the difficult part with that is that AI is probably the goal is that an AI tool is better tomorrow than it is today, right? So if you've got a report that's six months old, in theory, the quality of the AI should be significantly better.
Now, so anyway, it'll be interesting to see how that works. But the obsolescence of these types of reports might make some of this a little bit more difficult. But but it's good to evaluate the quality anyway. Just have some a better baseline from which to measure in the future, if nothing else.
So I think that will be will be important. And then also, of course, the the executive order also really focuses on, say, bias and non-discrimination. And so you could see that there was a lot of effort towards driving compliance with existing non-discrimination laws, particularly with providers and health plans that receive federal funding. So the expectation is, is that they will be using AI in a way that doesn't sort of perpetuate existing biases.
And then, of course, there's the AI safety program. And so, again, this will this is another interesting sort of thought, is that we'd like to do a better job of tracking clinical errors that might have originated from AI. And then also, of course, HHS is supposed to look at them and then provide recommendations on how to reduce reduce those forms. So this is, you know, very similar to, you know, the FDA's existing program where they they've got the their adverse impact reporting.
Right. And so it's somewhat similar to that, I think. And so it'll be interesting to see how HHS actually tries to implement something like this. And then two other points I'll make is that we've got the HHS will be required to develop a strategy to regulate the use of AI in drug development.
So that'll be interesting. Of course, you know, FDA is already very active in this space. They're already they've issued guidance and white papers on the impact of AI in terms of clearing say software as a medical device, at least in that area. But clearly, you know, that same expertise will will be useful here in educating and then potentially regulating the use of AI in drug development.
And then finally, of course, there's the impact on privacy. And, you know, for the most part, there's a little bit in here about privacy, but for the most part, I think, you know, President Biden probably rightfully said, Hey, Congress, it's time to get serious on privacy. And one one nice thing, of course, is that HIPAA already applies. And there are detailed privacy and security requirements already applicable to a certain aspect of the healthcare industry.
But of course, HIPAA doesn't apply to everything. You know, there's a whole digital health space of actors, even those using AI that aren't subject to HIPAA. And so that's that's really where I think the concern lies is, you know, how are we regulating their use of of all of the data that's necessary to train and use these AI programs. So I think, you know, that's kind of a long list, but, but that's those are the big impacts I see.
So a lot of a lot of thinking ahead for HHS and hopefully, you know, some thoughtful strategic objectives will come out of this. So Wendell, with that said, what might be potentially most helpful for healthcare sector entities when it comes to an AI regulatory framework? What sorts of things still need to be sorted out that healthcare sector entities really need to know? Well, I think what would help or what's what's going to be important to consider with these frameworks is that they take a risk-based approach.
And I think we've seen that, you know, the NIST AI framework, I think is an excellent source and resource. And, you know, that very much focuses, you know, it takes a risk-based approach. So absolutely, if it's, if the AI has the potential to cause real harm, you know, that should be regulated. And we should make sure that, that those types of tools are at, you know, meet a higher bar than other uses of AI in the healthcare context that won't have that same potential to cause harm.
So I think keeping that in mind, I mean, I'm hopeful that that's, that's what's going to happen, but I think that's critical to, to regulating this. And we've seen that again also in the EU with the AI Act, they are also attempting to take a risk-based approach. That seems to be the trend. So I'm hoping that that continues.
And I think that's, again, that's going to be critical to a workable framework for the healthcare industry. I think what's also going to be important is, you know, clear definitions. So commonly artificial intelligence is defined and might even be defined here in a manner that's, you know, overbroad, or you could read into the definition many uses of technology and computer algorithms that already exist and have been used for, you know, decades. And so we'll always want to be careful with these regulations to not pull in things, you know, technologies and, and, you know, systems that, that we're already using and, and, you know, haven't created the, you know, the concern, I guess that AI is creating.
So I think clear definitions are, are important so that we can, again, our clients know how to comply because it's always difficult when that's not the case. And then third, I think what's important is that HHS and other regulators, right, they really participate in nuanced thinking and not, and not taking a one size fits all approach to how we regulate AI. It's related to the risk-based piece, but, but it's also a little bit different. And, you know, for, for example, one reason why, like I said, I really like the executive order's approach is that we need to recognize that the healthcare sector is already heavily regulated.
There's a, this is just a new technology. And so let's not try to plop on a bunch of generic AI rules and regulations on top of an already complex regulatory regime. So, so that's why I like the fact that, you know, we're looking at this point, at least at industry sector experts who can now become experts in AI through this process. And then we can start looking at, okay, where are the gaps?
And let's focus on those gaps and let's focus on the real harms we're worried about and then take a risk-based approach to really, you know, focusing on them and trying to prevent the harm we want to prevent. So those are the three, I think key, key items I would like to see. And I think hopefully, is where what we're going to see from HHS as they think about a regulatory framework for AI. Wendell, as we know, AI seems to really be moving fast.
At least now it is. And even though it's been used in healthcare for a while. Aside from this presidential executive order on AI, do you think Congress also needs to pass an AI bill that addresses any of the issues that are either contained or maybe not contained in the executive order? And why would such legislation around AI be potentially more lasting than a presidential executive order, for example?
Yeah, no, that's a good question. And I'll give you the lawyer answer of it. It kind of depends. So, you know, I think most people would agree that there should be certain safeguards in place around AI.
And I think, you know, a lot of people would agree that broad brush, a broad brush AI law passed by Congress is probably not the right solution. We will see how that's going to impact the EU when they pass their AI law or AI Act, which is, you know, not industry specific. It doesn't even only focus on AI that handles personal data, for example, it's all AI. So that's a very, very generic law.
And we'll see, we'll see how that impacts the innovation in the EU, because typically laws, generic laws applicable to technology do not age well. And so if you were to ask me, you know, should Congress just pass an AI law like the EU? I the person won't be able to recognize that is a bad result. And then also what we're not seeing here is issues around transparency and explainability.
So by transparency, I mean, you know, being transparent about the use of AI. How informed should patients be about providers and plans using AI? And also transparency about proper use, so we can prevent misuse. And I think this is actually where there's going to be a lot of litigation between developers and employers of AI, is they're going to argue about what was proper use of the AI.
And so, having more clarity or better accountability for proper use, I think, needs to be addressed. And then also the explainable AI piece, we've seen just a lot on that, where, you know, we need to know how the AI works. How is it coming up with its recommendations? Is it reliable?
And if there is a government investigation, or if there is a bad patient outcome based on a result from an AI model, can we go back and look at that and figure out exactly why? What happened here so that we understand, you know, and can fix what happened. So I think those are other items that, you know, the executive order doesn't really address in detail. And I think also, you know, which I think HHS will address in their strategic plan, or at least hopefully will address those things.
But those are other topics that companies in the healthcare sector need to also consider. Well, thank you so much, Wendell. I've been speaking to Wendell Bartnick. I'm Marianne Kolbesec-Magee of Information Security Media Group.
Thanks for joining us.