My doctor violated my privacy by using AI (in a very disturbing way)

TL;DR:

My doctor sent me a detailed AI generated infographic of my symptoms which contained my full name and multiple illustrations of a character with my likeness.

This is the same doctor I complained about weeks ago in the different post.

What I forgot to mention was that at the end of that same consultation, my doctor told me they would send me an infographic explaining the symptoms I had described to her. While she was telling me this, she was typing on her phone. I expected a generic medical infographic that one might find on the internet and that explains the symptoms of specific ailments. Something like the one below:

However, I was shocked to discover when I got home that the infographic, which was sent over WhatsApp, contained my name and multiples images of a character with my quasi-exact likeness in different positions. This is how I discovered that my doctor uses AI.

I’m using this AI infographic below that I found online to make my point.

This was the final straw and why I intend to have a serious talk with her about privacy at our next consultation.

WHY I’M CONFIDENT IT WAS AI

I have little doubt that the infographic was created with AI. If my doctor were a graphic designer, which I’m sure she is not, I could believe it possible that she could create an infographic within hours from scratch. But she is not a graphic designer.

Also at our last consultation, I was expecting her to reveal the results of a test I had taken the week prior. To my surprise, she had not reviewed the results yet and literally looked at them in front of me for the first time while I sat silently. It was very uncomfortable because I was nervous for days about getting bad news.

All this is to illustrate that my doctor seems to be the kind of person that is so busy that she does not have time to review test results she has received days in advance. Hence, she does not have the time nor the skills to manually create infographics for patients, which means she almost certainly used AI.

I am so upset. This is the final strike.

  1. The first was that her medical forms did not contain any privacy policy, which, to my understanding, is mandatory by law.

  2. The second was the discovery that she uses Gmail and WhatsApp to communicate with patients and doesn’t seem to think it’s a big deal.

  3. The third was the use of AI by putting my full name and symptoms into some LLM.

I am preparing for our next meeting for that serious talk.

3 Likes

Your own statement proves you are not certain, therefore you cannot claim to know.

1 Like

I am 99.99% certain. The 0.1% is just the couteous benefit of the doubt that I will grant my doctor when I will ask her if she used AI. I will ask her if it was AI before any mention of my concerns over privacy, to not influence her answer.

The simple fact that my name is in the infographic is evidence enough. It was literally produced within 2 hours. My appointment was in the morning. After I left my doctor’s office, I went to have brunch in a coffee shop. My doctor had many patients after me and probably finishes her day between 5 and 6pm. I got the inforgraphic during my brunch.

4 Likes

Good luck with your confrontation.

2 Likes

If you’re in the US you can complain to HHS about a HIPAA violation. I would recommend this over confronting them directly. They won’t understand and think you’re just crazy if you confront them personally. You can also complaint to your state’s medical licensing authority, though they may just respond advising you to submit a HIPAA complaint to HHS.

https://www.hhs.gov/hipaa/filing-a-complaint/complaint-process/index.html

I do believe this would constitute a HIPAA violation, assuming they just used a standard generative AI service and not something specifically tailored to the medical industry, and that’s almost certainly what happened based on my experience with doctors and HIPAA (they usually have good intentions but no idea what kinds of IT things they shouldn’t be doing)

However, you do not need to know for a fact that a violation occurred to submit a complaint, you just need to believe in good faith that one did based on the information available to you.

If you’re in Europe, there may be a similar medical information specific recourse available, but I am not familiar with the process so I can’t provide details. It might just be GDPR though.

5 Likes

Perhaps it is better to ask “how did you create the infographic?” rather than ask if she used AI. Assuming she already knows about your privacy concerns, mentioning “AI” may raise her guard. Don’t use the word “generate” because that may imply you believe AI was used. Alternatively you could complement her graphic design skills and see if she discloses she used AI and not [insert graphic design application name here].

Like @lyricism recommended it may be better to take legal action rather than confront the practice. The only purpose of the above would be to verify AI was used to generate the infographic, and if so, you can add to your complaint the fact that she said she used AI.

Are there any disclosures or obvious signs of AI use evident in the infographic? Sometimes AI generated outputs disclose which AI was used.

4 Likes

You may want to speak to them directly if you have concerns. There are HIPAA requirements healthcare providers are required to follow. AI itself is not necessarily a privacy violation; there are healthcare-focused and HIPAA-compliant AI tools available. The same is true of Google Workspace (in reference to your other thread) and, in some circumstances, WhatsApp.

Is it possible they are using personal Google, WhatsApp, or AI accounts in a way that would violate HIPAA? Certainly. But based on what you’ve described, there isn’t enough information to determine that. Most medical practices make at least some effort to use systems designed to comply with applicable privacy requirements.

The better question may be to ask what software or service was used to generate the infographic and how patient information is handled within that system.

2 Likes

First, it IS entirely possible that the doctor is using some “secure AI” systems. There are many HIPPA-Compliant vendors.

https://openai.com/index/openai-for-healthcare/

So it’s very, very possible that this isn’t actually even a HIPPA violation. If that eases your mind at all…(it shouldn’t).

First step, ask how it was made, and ask specifically about your personal data and how it’s being used. As for distinctions like “is this regular ChatGPT? Or a special HIPPA-compliant version?”

Second, check that the infographic is actually 100% accurate. If it’s not, and I mean if there’s a single errant point of data, or something omitted that is critical, ask your area’s most intense ambulance chaser lawyer for a (free!) consult on an “interesting” medical case. A HIPPA violation alone (if that’s even happening) isn’t enough to bother wasting your time with a lawyer. But a doctor using AI to dispense inaccurate and potentially harmful information without a cross-check is 100% a malpractice suit waiting to happen. I’m not a fan of being litigious, but at some point this doctor is going to let ChatGPT tell someone to do something that will harm them, and that’s worth making a stand about now while the stakes are low.

Best of luck!

3 Likes

I don’t live in the US. I have reached out to my local data protection authority (DPA), to inquire about the legality of using Gmail and WhatsApp in healthcare, and their response was disappointing legalese.

I did not ask them about AI though, but I am not sure if it’s worth it, given how it has gone so far. Even though I may get the same answer it may be a good idea to ask anyway, just to have an answer on the record.

Contacting a medical licensing authority may be a good idea, but similar to your point, they may redirect me to the DPA. I would like to think a medical authority could answer a simple question on the legality of using AI, WhatsApp and Gmail. However, again, because the use of these tools is so rampant, they may decline to give a straight answer.

This is what I suspect too. When I filled out my medical form, there was no mention of a privacy policy or any mention of AI.

Though I am confident in my claim, that is a good thing to know.

In the EU there’s the GDPR, but on top of that, most EU countries have local DPAs and may have specific privacy laws on top of EU laws.

That is an excellent point, and I will definitely do that.

I don’t think my doctor knows about my privacy concerns. I only mentioned them to her secretary as I was filling out medical forms.

As I commented in my update in a different post, I cannot afford to sue, and even if I could, I do not wish to do that. Right now, all I want to know is if the law is on my side, and it is, confront my doctor before taking any legal actions. And my goal with my doctor is not to have an altercation, but for them to understand that they are violating patient privacy and I would like that to change

3 Likes

As far as I can tell, there is no indication on the infographic about which AI was used. It doesn’t have any watermarks. However, you made me realize it had more information about me than I thought.

Not only does it have my full legal name, and multiple illustrations of my likeness, but it also has my age, address, profession, marital status, and parental status… It also has the date of my visit.

This makes me wonder if these infographics are more for the doctor than the patient.

I am aware of that. Earlier this year, was in touch with a different doctor, who admitted to me she used AI, and told me exactly the name of the software and company, and it was one that catered exclusively the the medical field.

Although I don’t believe that is the case for my current doctor, even if it was, I cannot be sure that my privacy is protected. Also, I think that that kind of information needs to be disclosed in advance.

Moreover, as I mentioned in my original post, the use of AI was not the first privacy violation I noticed. My doctor didn’t have a privacy policy in her medical forms, and her practice uses Gmail and WhatsApp.

Based on my research, WhatsApp is unequivocally NOT HIPAA compliant and cannot be. And by default neither is Google.

Signal is also not HIPAA compliant despite being very private. My understanding of HIPAA compliance is that one of the requirements is that you have to have a contractual relationship with the medical field that binds your to legal responsibilities and obligations.

What do you mean by this?

Are you asking if the information about me in the infographic is accurate, or if the scientific information presented is generally sound?

I don’t believe the doctor was using AI to diagnose me. She was using it purely to illustrate the information I had given her and her diagnosis so far.

That’s a real danger, but it’s not the situation I am in.

In the past, I have seen doctors use Google in front of me to search about my symptoms. At first I thought that was concerning, but then I came to realize that it’s normal and doctors don’t know everything. In my case, it was a GP who looked up my symptoms on Google, and then referred me to specialist based on her understanding. She made the right move.

That being said, with AI forced on people in search engines, Google searches can become dangerous because information might not be accurate if you are no willing to look at direct sources.

1 Like

Sorry poor language on my part. I meant raise the issue with with other parties like lawyers and authorities but not necessarily sue practices. If you can demonstrate the law is in your favor, that may influence practices to lift their game.

I suggested the above earlier but forgot to say relying on legal arguments/systems is demoralizing and distasteful. Practically, laws are outdated and serve the elite, legal approaches will fail unless the practices are in violation of the law, and even the winners of a lawsuit ultimately lose. Further, relying on legal approaches relegates people as subordinate to states and further entrenches states’ dominion of people.

Instead I suggest using logic, moral arguments (both in general and medical ethics) and amicable communication with practices. I assume the practices are run by humans who have morality and can decipher right from wrong, and have some understanding of patient confidentiality.

However I’m not optimistic you will get a good outcome. It’s with deep sadness I say, most people are thoroughly conditioned into using and submitting to intrusive digital technologies, and increasingly, becoming brainwashed by and subservient to corporate/government AI gods.

1 Like

This seems like the most key, indisputable point IMO - AI or not, your doctor/her office’s behavior makes patients feel like they spend more time on fancy one-pagers than on medical care.

1 Like

Yes, this is my intent. I just want to know that the law is on my side so I can refer to it when speaking to my doctor. I do not want to make my doctor think that I intend to sue her because I don’t. I hope to have an amicable conversation, even if my doctor ends up not agreeing with me. At the very least, I want to feel heard and not dimissed out of hand.

Yeah, this is my fear too. But I have to try and keep trying even if I fail.

You make a valid point. If I was going to receive terrible medical news, I would want my doctor to have prepared for it, and not find out literally right in front of me when they’ve had the results for days. Bedside manners count for something.

I belive my doctor cares, but I can appreciate that her job can be stressful. I could be wrong about this, but to me, the fact that so many of her appointments are delayed and don’t actually happen at the time they were scheduled with her patients, suggests to me that she cares enough to spend time with her patients and not rush them out to ge to the next patients.

That being said, I took the day off for my appointment, so I did not mind that it started 2 hours late. I can understand that for someone who just took 2 hours off work, that would be extremely frustrating. I always wonder, how people who work in an office full time, find the time to go to therapy every week. It’s not like therapists work weekends or evenings.

2 Likes

My doctor was openly transparent when I went in for a consultation. Quite explicitly stating “I will be using AI to make notes for me as we both speak so that I can dedicate more time to you

I said no and to tell me what “AI” it is first before I agree to anything. He knew nothing about it!

I’m all for progress but, in the U.K., I don’t think the NHS have any clue whatsoever about privacy. The same doctors surgery are now suggesting using WhatsApp to notify me about appointments/to review consultations etc.
I haven’t had WhatsApp on any device for at least 8 years. I don’t intend to start now!

2 Likes

As many people here said, I’m not sure which country you are from but you can and should report your Doctor to the responsible Government Department. Both for doctors and data privacy.

In I think most countries around the world, health data is protected really strictly. What your doc did could pretty certainly considered a crime/felony

1 Like
Off-topic

Wow… Nowadays not just in the medical area but for everything WhatsApp is used. How do you manage to keep yourself up without it?

3 Likes
Off topic

Signal. And only Signal. For proper two way communication (messages and calls), anyway.

I was fairly content with the odd iMessage here and there until Nanny Starmer forced Apple to make the choice it made for the U.K. and Apple’s Advanced Data Protection. Now, as quite a lot of folk in the U.K. do not have ADP, the backups are no longer private (and why I do not back up my iPhone to iCloud)! Those on Android were recently bleating on about RCS and encryption etc but I’ve still point blankly refused and have RCS switched off in any case.

If I do receive any message outside of Signal, I have turned off all notifications so I check periodically. I was doing this every other day but I’ve since forgotten and check every few weeks or a month or so. This tends to irk people, which is fantastic as they then get to hear from me and learn how to contact me on Signal :wink:.
On the occasions that I do respond via iMessage or SMS, I tend to only reply with brief answers and using a pastebin like EntePaste or CloakBin. I.e. I will send them the link to whichever bin to view my reply once and once only.

(That reminds me - I’ve just checked for the first time this month - and the oldest message is from middle of May. The newest from Thursday. I’ve made a note in my calendar to reply to those next week).

Adding ‘Friction’ works both ways. Some people do express their annoyance/irritation that I’m “making them” download an app they don’t want/need (Signal), however, frankly, I cannot express how much I do not give a hoot. You don’t have to do anything and no one is making you!

That said, the ones who have downloaded Signal actually do use it more and more to speak with others. They have got used to it for basic communication. They will likely never get rid of WhatsApp because Signal purposefully doesn’t like too many features so, naturally, people find WhatsApp more useful and gravitate towards.
Signal will never dominate the market and be the top messenger app with their stance, but it will always be a great contender and at least people will know about it.

This shift towards privacy has been particularly noticeable since that buffoon Nanny Starmer - utterly bereft of any common sense - has been so overtly eroding privacy for U.K. citizens at an alarming pace. People are talking about it. People are not happy. People are now starting to see how dangerous the government is. In fact, I should be congratulating The Buffoon for highlighting how much of a shambles the government’s ideas are relating to ending e2ee under the absolutely ridiculous guise of “child safety” which is, quite literally: “incredible”.

I should be commission based for the amount of sign ups I’ve got privacy focussed apps like Ente, Proton, Astermail, Mullvad etc.

When the U.K. end e2ee next year and force app stores to ban apps like Signal and also ban VPNs or make them KYC - because that will happen with this current heinous lot in power - I will revert to the Stone Age and relinquish my smartphone and people will have to contact me via the postal system only. I have a Nokia 8310 for emergencies.

They can also go swivel for any national ID card regime nonsense, too.

[EDIT]: Between my rambling, I forgot to mention business and WhatsApp! Yes, so many more are funnelling people through it. There was a company some months ago who said I had to contact them via WhatsApp. It was a mobile network provider as I had an issue with an eSIM. Anyway, they told me to message them on “WhatsApp”. Err: no. That won’t be happening.
Long story short I ported out elsewhere. No big deal really. I certainly wouldn’t have any loyalty to any company using WhatsApp as their contact method in any case!

3 Likes

While health data is often considered more sensitive than other types of sensitive data, unfortunately it is not as well protected as it should be nor as you claim it is. This thread and the predecessor thread discusses how health data is not protected but being exposed to Google, WhatsApp, AI etc, and what action OP (and others) should take to improve health privacy. There are numerous types of health privacy violations (not just by practices/doctors), for instance, secondary use of health data for research and insurance purposes, national electronic health records systems, coercing people to disclose their own health status, data sharing that’s permitted under HIPAA, etc, all (generally speaking) perfectly legal.

2 Likes

If you this doctor has been rubbing you the wrong way, why haven’t you looked for another? If not this or the other occurrence, it’s only a matter of time before something else egregious happens.

3 Likes

Either, really. I’m asking if any inaccurate data: AI hallucinations or wrong data or ommitted data, about you has occurred (if you know). It’s entirely possible that any AI system will forget or omit or hallucinate bits of information, so if your doctor is using this for their own information, and it’s not the full picture, that’s just as bad as it being diagnostic data because it’s the information your doctor uses to treat you. if you have an underlying medical condition that can complicate your treatment, and that’s NOT on the infographic, that’s a potentially harmful problem.

I do want to say thanks for being so forthcoming with the info you have here. It’s helpful to know legally, morally, and ethically what your concerns are and what your options might be. This is a complicated area of privacy and ethics, plus your own health and wellbeing. This seems like an especially frustrating and problematic situation.

I can see how this might be possible, and for someone with a learning disability like dyslexia, important. But if your doctor needs a printed infographic about their own interactions with you, that seems like it might also be a medical LLM company’s version of a chart/patient record. So it’s possible that’s just the template your doctor chose (or the default), and it has a lot of stupid things added in to make it visually appealing, rather than just a block of text.

To me, it seems like your only real question here is to find out if your doctor is using just regular ChatGPT, or a medically-approved version that is intended to handle patient records. Then also to assess if anything is not 100% fully accurate on the infographic itself. If it’s a medically-approved vendor, then other than your personal preference, there’s not much you can do other than find a new doctor.

If you think the doctor is using this for themselves as a refresher before they see you, then if you ask them to stop using it, all you’re doing is asking them to look at your record in a format that they don’t like. That doesn’t change your privacy situation at all. It seems like you might actually want a discussion with the doctor’s office manager rather than the doctor, to find out their technical processes.

I still wouldn’t trust any system that’s just a wrapper over ChatGPT as data leaks and theft happen all the time, and you only find out after the fact. Similarly, would a doctor like this know to use added security to protect against ransomware? or just find out the hard way, like many, many medical and legal offices around the world.

3 Likes