Artificial Intelligence (AI) is the use of computer technology to perform human tasks such as reasoning and decision-making. The increasing reliance on AI raises the question of whether the use of AI within the health care industry creates privacy risks for patients and whether privacy protections and physician-patient confidentiality rules are adequate under the current framework.
The Department of Health and Human Services (DHHS), through the implementation of the Health Insurance Portability and Accountability Act of 1996 (HIPAA), established such privacy practices. Rule 45 CFR §164.308 sets regulations for HIPAA security standards known as administrative safeguards. These provisions regulate the standardization of electronic health information requiring health plans to “implement policies and procedures to prevent, detect, contain, and correct security violations [by] conduct[ing] an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronically protected health information (PHI) held by the health plan.
However, HIPAA does not regulate health data provided by AI generated health systems with cloud services. HIPAA laws apply to more static human driven situations where one can easily extract PHI and identify patients from databases. Individual states determine how privacy protections are applied for the secure exchange of electronic health data. These laws support what HIPAA lacks in privacy protection.
The court case Dinerstein vs Google raised the issue of whether the sharing of electronic health records violated patient privacy rights. Google in conjunction with the University of Chicago and the University of Chicago Medical Center developed AI tools to predict patient health care needs and assist with clinical decision-making. The University provided Google with de-identified patient electronic medical records for AI research and development governed by a Data Use Agreement. The Data Use Agreement limited the sharing of data to research purposes and prohibited re-identification of patient records. The plaintiff, a patient whose medical records were shared, claims the data sharing practices violated privacy laws and breached contractual obligations.
In 2019, plaintiff filed a class action suit against Google and University of Chicago based on Illinois state privacy violations. The district court dismissed the case for failure to state a claim and for lack of standing. The appellate case focused on whether the injuries claimed amounted to Article III standing and whether any viable claim is at issue. Article III standing is found when (1) there is an injury in fact, (2) causation and (3) remedy.
The appellate court dismissed the case for lack of jurisdiction. The court held that based on the facts none of the injuries claimed were concrete, only theoretical. The appellate court concluded there was no actual harm, no economic injury, no invasion of privacy and no deceptive practices. As a result there is no viable claim the plaintiff could recover from.
The facts of this case show the plaintiff’s health data from the University of Chicago was used for development of an AI tool by Google to assess the likelihood of a given health outcome. Development was based on a risk prediction model. This process is called model training. According to IBM, model training is the process of “teaching” an AI model to optimize performance on a training dataset by learning its patterns and correlations relevant to the model’s eventual use cases so to make reliable predictions on new data. AI models are designed to rely on large volumes of sensitive patient data to predict patient outcomes.
Dinerstein vs Google is significant because it views privacy laws in a context that is blurred because precedent is challenged by the rise of AI and raises important policy questions of what rights patients have over non-HIPAA health information. Stronger safeguards are needed to ensure regulatory compliance of how health data is collected, stored and shared during the process of AI model training and development.