The Need for Enhanced Data Oversight in AI Healthcare Applications

The Need for Enhanced Data Oversight in AI Healthcare Applications
Summary
Healthcare organizations must inventory data for HIPAA compliance amid AI integration challenges.
Failures in data usage can lead to breaches involving protected health information.
Critical practices include understanding data flow and safeguarding patient privacy in AI deployments.

Share

Bookmark

Newsletter

As healthcare institutions and their partners embark on the journey of integrating autonomous artificial intelligence and various AI technologies, it's vital for them to perform a comprehensive assessment of their data assets. Understanding the permissible uses of this data under HIPAA and associated regulations is crucial, stated attorney Jordan Cohen from Akerman LLP.

In an insightful discussion with ISMG, Cohen highlighted the implications of straying from legal data usage. He pointed out that if protected health information (PHI) is mishandled, it could result in a reportable breach.

Cohen emphasized that many of the essential strategies HIPAA-compliant entities should adopt during their implementation of autonomous AI are not exclusively tied to AI. A meticulous inventory of data flow is essential. He advised that organizations should map out and account for how data is collected, processed, stored, and transmitted, including how vendors interact with it. "If you lack clarity on what data exists, its location, and who has access to it, securing that data and ensuring patient privacy becomes a formidable challenge," he remarked.

While these data management practices have been promoted for years, their importance has grown exponentially in the era of autonomous AI deployments.

In his video interview with ISMG, Cohen further explored several topics, including:

- The prevalent applications of autonomous AI in clinical and administrative settings within healthcare, along with the types of PHI, electronic health records, and other data being commonly utilized. - Additional legal and regulatory considerations relevant to the deployment of AI technologies. - Key considerations for AI, such as implementing technical safeguards, effective incident response strategies, ongoing monitoring, and ensuring transparency and patient consent. - The potential for AI to enhance data privacy and security measures across healthcare and other industries.

Cohen serves as a partner at Akerman LLP and leads the firm’s digital health practice, where he provides legal guidance to clients regarding transactions involving healthcare providers and related platforms. His expertise encompasses issues of federal and state privacy compliance, including adherence to HIPAA's provisions regarding Privacy, Security, and Breach Notification, along with navigating state-specific breach notification laws. Additionally, he advises on a wide array of regulatory matters pertinent to healthcare, such as compliance with fraud and abuse regulations like the Anti-Kickback Statute and the Stark Law.

Loading comments...