In this episode, social work ethics and data privacy expert Dr. Allan Barsky, MSW, Ph.D. of Florida Atlantic University breaks down what everyone should know about how artificial intelligence is reshaping healthcare and putting sensitive medical and mental health records at risk.
Jeffrey Snyder, Broadcast Retirement Network
Well, Dr. Barsky, it’s so great to meet you. Thanks for joining us on the program this morning.
Dr. Allan Barsky, MSW, Ph.D., JD, Florida Atlantic University
Pleasure to be here, thank you.
Jeffrey Snyder, Broadcast Retirement Network
And as we were talking in the virtual green room, privacy is a big issue that’s being talked about across so many different industries. You recently took a look at it across the healthcare industry. First, let’s start with your perspective.
How secure is our data, yours, mine, every individual patient’s? Is it secured or do we need to do more individually and I guess as an industry?
Dr. Allan Barsky, MSW, Ph.D., JD, Florida Atlantic University
Sure, so my focus, first of all, is on mental health, but a lot of the laws that cover mental health professionals like psychologists and clinical social workers also cover physicians and nurses and occupational therapists and other health professionals. And most of the time when you are working with a licensed health professional, including those licensed mental health practitioners, they are using safe types of online services. So medical records are generally fairly safe, but we’ve also had numerous occasions where somebody has hacked into systems, including the systems of very large health and mental health organizations.
And a number of us, I know I think two or three times already, I’ve had a health organization say to me that there’s been some sort of breach and somebody may have hacked in and may have access to information like my name, my health insurance information and other identifying information like my address and things like that. So you never know, is somebody using this for nefarious purposes? How much actual information did they get?
But we should be aware of, first of all, trying to prevent unauthorized access to our health information. And then we should be informed consumers of healthcare, including mental healthcare. So my article was really asking people to talk to their professionals and find out what types of precautions that they’re taking, perhaps also what type of precautions that we can take.
A lot of services are being provided at a distance, so people are logging on from their home computers and may not realize that they may be adding to the risks instead of minimizing those risks.
Jeffrey Snyder, Broadcast Retirement Network
Yeah, you make a good point. You make a lot of good points, but the last point in particular, I think a lot of us use like a feature that whether you’re going to a mental health provider or just a general practitioner, you log into a website and you have your password and username. Maybe you have that new passkey feature or two-factor authentication, but you’re putting a lot of information is being entered from your computer.
And then through the magic of the internet, it’s flowing. I mean, that information, it’s yours, but in your estimation, I mean, it’s hard to stay ahead of these hackers because they are really ahead of everyone. It’s like whack-a-mole, doctor.
Dr. Allan Barsky, MSW, Ph.D., JD, Florida Atlantic University
There are constant challenges and there are constant improvements. And so when somebody has the opportunity to update the software on their cell phone or their computer or their tablet, it’s probably a good thing to do that because they’re trying to keep up on that, but just kind of like very basic things. So some people will log on to a website and start putting in personal information, but they’re using an unsecure internet service provider.
It may not be their home provider. It may be a public service. It may be somebody else’s service.
So you don’t know who’s hacking in there or people may use a public computer and not close it down or not close down the history. Some information that we provide, it’s required. If you’re submitting information about your health insurance because you want to have the insurance company pay rather than you, that’s not optional.
But there are some things that in the article that I wrote that are more optional. So service providers are supposed to provide you with different ways of communicating with them and different ways of assessing and providing interventions. And so if you’re not comfortable with something because it’s using AI or because it’s using a platform that you’re not familiar with, at least ask questions.
A lot of times we do things for convenience and it may save us time and may even be more effective services, but you want to know that. And so if they’re trying a brand new product, it’s worth you knowing that this is really an untested product or maybe it is a tested product and maybe it does have pretty good safeguards.
Jeffrey Snyder, Broadcast Retirement Network
It’s interesting you bring up artificial intelligence. I did a program about a week ago about EdTech. So that would be technology that is being used in K-12 schools.
Well, in the state of Utah, they did an audit and found that third-party data brokers were actually accessing the data. And it was not even obvious to the platforms that this was occurring. I wonder how pervasive…
Well, obviously AI is being used in a lot of different ways and not just your field, but other fields. It helps with clinical notes. It can help, I guess, with diagnoses instead of thumbing through the DSM, right?
I’m sure they have large language models. How does that change or does that change the equation about privacy and expectation of privacy?
Dr. Allan Barsky, MSW, Ph.D., JD, Florida Atlantic University
Sure. So one of the questions I encourage people to ask is when there’s a program that you’re being asked to use by your provider, is it HIPAA-compliant, H-I-P-A-A, Health Insurance Portability and Accountability Act? And that’s federal legislation.
And part of it is about protection of personal health information, including personal mental health information. And so if you’re being asked to submit information to AI, perhaps you’re engaged in a therapeutic interview and it’s being recorded and AI is going to do the original analysis of that information, maybe come up with clinical records or a preliminary assessment. All of these assessments should be reviewed by the professional and the professional should give the final opinion, not just rely on AI to provide a diagnosis, but they could be used within the tools that mental health professionals use for a diagnosis.
Any of the programs that they use should be HIPAA-compliant. So that means that they have a certain level of encryption, that they’ve got a business associates agreement and this business associates agreement BAA includes things like they won’t sell information to third parties for commercial purposes, to train the AI or for other purposes that you’re not familiar with. Now you may actually agree in some circumstances that you want your information to be used for research purposes, but perhaps get assurance that you’re not providing identifying information.
And I know that when I’m training professionals, one of the things that I say is when you’re using AI, maybe one of the ways to limit those risks to personal privacy is put in information about the patient without putting in information about the identifying information. So no names, no addresses, nothing that can link these facts with the individual. So AI might continue to learn based on the information, but it doesn’t know that it’s your particular information.
So use the consumer of services should be able to agree to or reject certain of those uses of information.
Jeffrey Snyder, Broadcast Retirement Network
So it sounds like, I guess, let’s talk to IT professionals, the people that, because it’s not just a practitioner that’s using the technology, it’s there’s people installing it. They work usually in healthcare organizations. They support all the, you know, from billing to some of the subsystems that we’re talking about.
That’s a tough job because you’re playing, as I said earlier, you’re playing whack-a-mole. There’s always security updates. What’s the best thing they can do?
And I know you’re not a systems professional, but I think it’s just kind of common sense, doctor, right? I mean, what are the things that they can do to kind of protect their organization, but also their consumers, their patients?
Dr. Allan Barsky, MSW, Ph.D., JD, Florida Atlantic University
So, you know, what I would encourage the IT people to do is to work with the professionals so that they know what’s, you know, considered to be okay and not okay, especially from an ethics perspective. So what did confidentiality and privacy mean? How can we minimize certain types of risks?
What types of situations are, you know, particularly risky situations? If you’ve got therapists who are working with survivors of domestic violence and you don’t want their exes or sometimes even current partners to have access to information, you know, there are life and death issues at stake. And so you want to be particularly concerned in those types of situations.
Or if you’ve got vulnerable populations like children or older adults with dementia or people who are from backgrounds that, you know, are receiving a lot of discrimination and could have that information used against them in really horrible ways. You know, it can affect their careers, can affect their livelihoods, can include even things like death threats. So for particular types of situations, you want to be more careful, more risk averse.
And, you know, by IT people and health and mental health professionals working together, they can kind of come up with what’s the best combination of services or can people opt out of things? So rather than requiring everybody to do an online portal for intake, is it possible for some people to opt for, you know, in-person or telephone or other forms of, you know, lower tech types of intake processes?
Jeffrey Snyder, Broadcast Retirement Network
You mentioned the federal law HIPAA and that’s an important law. Are there things that our federal regulators and legislators should do? Because I feel like HIPAA was written many years ago, maybe a decade or more.
So it’s an important law, but maybe it needs to be updated. But are there things that they can do in terms of their oversight? Because a lot of times they have oversight, they have regulatory oversight over some of these healthcare bodies.
Are there things that they should be thinking about when it comes to not just privacy, but healthcare privacy in particular?
Dr. Allan Barsky, MSW, Ph.D., JD, Florida Atlantic University
Okay, so personal opinion, not my employer, not speaking of any association. I really think that states and the federal government need to work together on this. And I don’t really see this happening so much.
So there are, you know, updates of the HIPAA laws. There’s one called HITECH, H-I-T-E-C-H, and there’ve been some executive orders and other things that affect, you know, AI and the use of technology in various fields. But we need something that’s really comprehensive.
And in the United States, the states have responsibility for regulation of the professions, including the health professions. So there are laws at state levels as well. It would be nice if we could have some common things across the entire nation.
I know like Illinois and some other states have passed some laws, but if health professionals are using AI, they can’t rely on it solely for their diagnosis or their assessment purposes. So you have to keep the professional in the process, use their critical thinking, their knowledge, their review of the process. But that’s not, you know, the law everywhere.
So let’s say you’ve got a client who’s in Illinois, but you’ve got a practitioner who’s in Florida whose law applies. So it really would be helpful to have at least national standards and perhaps even international standards. And there are some other countries in, you know, Europe and Asia that are ahead of us in this.
It’s difficult sometimes to legislate. As you said before, you’ve got a constantly moving target and things are changing and we don’t necessarily know what’s best. I don’t believe that we should, you know, be so risk averse that we never use new, you know, technology, but there are risks and we should be aware of those to balance the risks with the benefits of the tech.
Jeffrey Snyder, Broadcast Retirement Network
Well, if that was the case, we’d still all be using abacuses. I don’t know what the plural is. Well, Dr. Barsky, we’re gonna have to leave it there. It’s a great piece. I think it’s very thought provoking. A lot of people should read it, but also regulators, legislators, people of importance should read it, help codify some of the things that you mentioned.
Great to see you. Thanks for joining us. And we look forward to having you back on the program again very soon, sir.
Dr. Allan Barsky, MSW, Ph.D., JD, Florida Atlantic University
Thanks for the great questions. Take care. Bye-bye.