Hi, Marianne Kolbasek-McGee, Executive Editor at Information Security Media Group, and I'm here at the HIMSS Cyber Forum in Boston speaking with Lee Kim, who is Senior Principal of Cybersecurity and Privacy at HIMSS. Hi, Lee. Hey, Marianne. So, Lee, a few months back at the HIMSS annual conference in Chicago, you and I chatted a bit about AI in healthcare and some of the privacy and security concerns.
What have you been seeing in the last few months in terms of how these privacy and security concerns might be evolving, changing, growing? Thanks, Marianne. So, I've seen a few things. Of course, I think we'd be amiss to not first start off with AI.
A lot more healthcare organizations are adopting the ChatGPTs and MidJourneys and other things in terms of this generative AI kind of thing. They're starting to adopt acceptable use policies. They're starting to figure out ways in which they can automate their processes to make up for staffing shortfalls, etc. But I have to say, the threats are still there.
In fact, it's perhaps a little bit more prevalent as, for example, because of a changing nation-state landscape, unfortunately, we are seeing a lot more ransomware activity. And that's kind of a shame because that does tend to disrupt patient operations. When you look on the horizon from a regulatory and or a legislative perspective when it comes to AI use in healthcare, what are you seeing? How might any of the regulatory or legislative issues that are being discussed affect healthcare and do you think they'll go anywhere?
So the number one thing in my mind, at least, is the SEC cybersecurity disclosure rules. As you know, they just became effective a little bit earlier this month in September. And in terms of compliance states, they start as early as December 15th. And if you are a U.S.
publicly traded company, and that includes some for-profit institutions in healthcare, that certainly includes a lot of vendors in healthcare, and now you have to start reporting things like what your cybersecurity strategy is, what your management looks like in terms of overseeing the cybersecurity, and how you're informing the board in terms of their oversight with cybersecurity. So that's a major change. And that aside, even though we haven't really had major changes to HIPAA recently, I think you well know that given the AI and given things such as online pixel tracking and all those other things, HIPAA always is adapting and evolving in terms of its interpretation, according to OCR. So I think that we need to be cognizant of actually what I foresee and what I'm analyzing currently, which is a confluence seemingly between healthcare and what HHS is recommending and interpreting, and also similarly FTC from a privacy watchdog standpoint, because they certainly regulate false and unfair, deceptive trade practices.
And I think that that's a good rule of thumb to abide by in healthcare, even if you're a not-for-profit, just in terms of being squarely within what's there and what's private and secure in terms of patient information. And going back to generative AI in healthcare, when it comes to data security, privacy, and potential breaches looking ahead, what are you concerned about most? I am concerned about our adopting this bright and shiny cool toy that we know is AI, and yet we aren't necessarily pushing back against these companies in terms of how they may be using our information, in terms of oversight of them, in terms of transparency about what their models are doing and what they're sharing with others. That's a real concern of mine, because if something isn't necessarily regulated or there isn't sufficient oversight, you can kind of predict that outcome, right?
And my concern is that automation or even AI left unchecked, it could be a real problem. It's human nature, for example, for humans to basically be a little bit lazier or complacent about things, to assume that these AI systems are inherently intelligent and or that they would make the right decisions. So, for example, I could say the coming wave in terms of healthcare is AI-based clinical decision support. And right now, I think that clinicians, for example, are comfortable with things like ensuring that what comes out of the system is likely legitimate in line with clinical protocols.
But that kind of laziness is kind of creeping in already. I've heard from clinicians, for example, that they no longer may keep in their heads drug-drug or drug-allergy interactions because the clinical decision support system pops it up automatically, right? Also, in terms of common medications, shall we say, that are frequently prescribed for A, B, C, and D in terms of health conditions, no longer do they have it in their head and they kind of trust the machine. So that's a bit of a slippery slope, don't you think?
I would agree. It's a lot of patient safety issues coming up. And we're all patients at some point. Let me emphasize too, in terms of AI, of course, there's generative AI like ChatGPT and MidJourney and Stable Diffusion and BARD and Llama and all kinds of things.
But also, radiologists, I think rightly so, use AI in terms of diagnosis, in terms of computer-assisted detection, such as when women have mammograms. I mean, it's absolutely life-saving. But I have to say that I would plead with people that we should always have some kind of human oversight and review. Otherwise, the patient safety and values and judgments and the intimate connection that healthcare professionals have with their patients, that human element will be gone.
And who wants to do that? Who wants to buck the trend of how medicine has evolved? And I think that we're so much better today, but we shouldn't go backwards by not adding in human compassion and judgment. And finally, Lee, you mentioned looking backwards.
How about looking ahead to 2024? Any regulatory issues or just privacy, security, and healthcare issues in general that you're kind of keeping an eye on that you haven't already mentioned? Yes. I think that we will see a lot more deepfakes that are convincing that will fool people.
I think that we will see a lot more attacks, even as to multi-factor authentication. I think that our increasingly virtual world will mean that there will be less checks and balances. And we, of course, need to think of ways in which we could compensate for that, Marianne. Well, thank you so much, Lee.
I've been speaking to Lee Kim of HIMSS. I'm Marianne Kolbesec-McGee of Information Security Media Group. Thanks for joining us. Thank you.