Your Doctor May Be Using AI During Your Appointment. Is That a HIPAA Violation?
What happens when you’re in your doctor’s office? From physical examinations to simple discussions about your health, you might talk about medications, test results, symptoms, family history, and other information you probably would not share with many people.
What would you do if you notice a sign declaring that an AI tool is listening to the conversation and taking notes?
It sounds like a privacy nightmare.
Surprisingly, though, it does not necessarily violate HIPAA.
Doctors and other healthcare providers can use AI tools to help document patient visits, summarize conversations, and reduce the amount of time they spend typing notes. So does that mean that AI can read your medical information?
Intertwining AI with healthcare can happen safely. It just depends which AI receives it, why it receives that information, and how the data gets protected.
What Is an AI Medical Notetaker?
Doctors spend a significant amount of time documenting their patient visits.
AI notetakers, sometimes called ambient clinical documentation tools in the medical field, can listen to a conversation and turn it into clinical notes. Instead of your doctor repeatedly looking away to type information into a computer, the technology quickly and easily creates a draft for the doctor to review.
This introduces several obvious benefits. Most importantly, your doctor can spend more time talking with you while the AI starts the paperwork in the background.
So when does that conversation, translated automatically by artificial intelligence, cross the line and become a data privacy concern? It all depends what happens after the AI hears that information.
HIPAA Does Not Ban Technology
A common misconception is that HIPAA prevents healthcare providers from sharing your information with any outside company. That’s not exactly how the law works, however.
Doctors already rely on outside companies for billing, data storage, laboratory services, software, and other necessary functions. HIPAA allows healthcare organizations to work with outside companies that handle Protected Health Information (PHI), provided they follow requirements specified under the law.
HHS refers to these organizations as “business associates.” According to HHS guidance, healthcare providers can disclose PHI to a business associate when they receive appropriate assurances that the company will safeguard that information. In other words, you have to prove to auditors that your data privacy regulations adhere to HIPAA.
An AI notetaking program that receives patient information on behalf of a medical practice may fall into this category. That means the doctor cannot simply sign up for any AI app and start feeding it patient conversations, but it can record them with the proper tools and for the right reasons.
How The Rules Keep Your Data Protected
Healthcare providers generally need a Business Associate Agreement, commonly called a BAA, whenever an outside service handles PHI on their behalf. That agreement establishes what the company can do with the information and requires appropriate protections.
For example, the agreement can restrict the AI provider from using your medical information for unrelated purposes. The business associate must also use safeguards to prevent unauthorized use or disclosure and ensure applicable subcontractors follow the same restrictions.
This is an important difference between a healthcare-approved AI system and a random AI tool that somebody found online. A doctor entering identifiable patient information into an unapproved consumer AI chatbot would constitute a very different situation under HIPAA.
AI Should Not Get a Free Pass
Using a healthcare-specific AI tool does not make every use compliant automatically. The medical practice still has the responsibility to protect its PHI.
It needs to understand where patient information goes, who can access it, how the provider protects it, and what happens when the service no longer needs it.
HIPAA’s Security Rule also requires appropriate protections for electronic PHI, including safeguards designed to protect its confidentiality, integrity, and availability.
In other words, saying, “It’s an AI tool,” does not excuse poor cyber-hygiene.
This Goes Beyond Doctors
The same principle applies whenever AI encounters confidential information: Data privacy is paramount.
Imagine an attorney using an AI meeting assistant during a conversation with a client. An accountant might use AI to summarize a meeting containing financial information. Even one of your coworkers might invite an AI notetaker into a staff meeting where people discuss customer records or internal business plans.
HIPAA may not apply to all of those situations, but other privacy laws, professional confidentiality obligations, contracts, or company policies might.
The important question is not simply, “Can AI listen to this?” but, “Have we approved this AI tool to receive this information?”
What Should You Do When an AI Notetaker Appears?
If you notice an AI assistant in a medical appointment or another sensitive meeting, you do not have to quietly wonder what it is doing. Just ask.
Find out whether the conversation is being recorded or transcribed. Dig into why the AI is there and what happens to the information afterward.
At work, do not invite your own AI notetaker into confidential meetings unless your organization has approved it. Just because a tool has good reviews online does not mean you have permission to listen to company information.
AI Can Be Useful Without Ignoring Privacy
AI notetakers have the potential to solve a very real problem. If technology handles some of the documentation, doctors can spend more of an appointment looking at their patients instead of their screens. That’s a worthwhile benefit.
We just have to be careful not to mistake convenience for permission.
HIPAA does not say that AI can never access medical information. It creates rules around how protected information can be used, disclosed, and safeguarded.
The same basic lesson applies outside healthcare, too. Before allowing an AI tool into any confidential conversation, ask what information it will receive, where that information will go, and whether the tool actually has permission to be there.
Sometimes the least noticeable listener in the room hears the most information.