ChatGPT Health adds Epic integration for clinicians to import patient data

This is the company that runs the MyChart app/site, which of course many of my doctors use. I’m not a big fan of AI and definitely not of giving it this kind of access.

1 Like

Usually the biggest privacy breaches these days actually tend to be systems generated by small companies which haven’t invested in their infrastructure. This ChatGPT usage no doubt would be the enterprise version which would have very strict privacy controls.

I actually think this is a really good thing, specifically that article mentions “laboratory results, medications”. This is pure data which might flag a message to the doctor like “what the f#@ are you doing telling this person to take medication X and Y those are incompatible.” or something like “This value in their blood test is too high, look into it”.

Humans are not perfect (that includes doctors), and this may very well save someone’s life.

Also that article kinda gets a few things conflated for example.

“A few days before this rollout, a Florida-based pastor sued the company, alleging that ChatGPT gave him a near-fatal recommendation.”

A product of this kind would no doubt be trained on models specific to the domain medicine, so data about medications should come from the manufacturers. Not some random page on the internet.

2 Likes

I have to push back on you a little bit for this one. 3.6 million employee directory records swiped from Azure Entra ID hit the market just last month.

That article doesn’t say that Azure was hacked itself rather that it used “leaked credentials”. The real question is who’s credentials. My guess would be some smaller third party service that all these affected clients used.

Fair point, this article claims that the breaches were due to infostealer malware pulling saved browser passwords and session tokens. But a breach is still a breach.

Its not a breach in the sense of tenant cross contamination or anything like that. I would bet some company possibly a marketing company that these clients hired left the keys out for the poster to steal.

I guess the real question is how much data does Epic have and how securely is that being retained. I would put my money on them being hacked before OpenAI.

From what what I read chatGPT in this case has read only access to assist doctor. if this is how it is ultimately implimented it would be a a helpful tool for the doctors.

Also if it’s ChatGPT enterprise that’s quite different to ChatGPT consumer products. The data can live in a provider’s cloud with strict compliance controls and use Retrieval-Augmented Generation (RAG) to make special queries to information stored like about medications etc.

I dunno, there have been several incidents where AI has sent information out to the internet when it wasn’t supposed to, or even hacked other companies in the quest to fulfill instructions. Anyone can argue that maybe the humans should have been more specific, but entrusting a blunt / occasionally too-sharp tool without fully understanding it is folly.

And read-only access isn’t much comfort when all it has to do is read your PHI and send it to the wrong people.

The compliance controls are not requests given to the agent by the doctor, but rather strict overarching controls created by the provider (Epic). The real concern isn’t about AI it’s about how well Epic secures the data. Fortunately the medical industry (as are financial) in regard to data is quite tightly regulated in most countries.

From the description in the article I don’t think it sends any data to third parties. That would seem unnecessary anyway.

OpenAI said that it collected over 4,300 responses from physicians across 27 clinical use cases, including pre-visit review, clinical timelines, medication review, and handoff summaries, and found that 99.1% of responses were safe. However, even a few unsafe answers can lead to harmful results for humans.

This is my issue with AI use in the medical field, and really anywhere. Doctors may become to reliant on it and it makes a mistake they don’t catch and the potential results could be terrible.

People too easily trust the answers and summaries that AI puts out without double checking them and that is a recipe for disaster.

1 Like