Goto

Collaborating Authors

 hipaa


Can I Trust This Chatbot? Assessing User Privacy in AI-Healthcare Chatbot Applications

arXiv.org Artificial Intelligence

As Conversational Artificial Intelligence (AI) becomes more integrated into everyday life, AI-powered chatbot mobile applications are increasingly adopted across industries, particularly in the healthcare domain. These chatbots offer accessible and 24/7 support, yet their collection and processing of sensitive health data present critical privacy concerns. While prior research has examined chatbot security, privacy issues specific to AI healthcare chatbots have received limited attention. Our study evaluates the privacy practices of 12 widely downloaded AI healthcare chatbot apps available on the App Store and Google Play in the United States. We conducted a three-step assessment analyzing: (1) privacy settings during sign-up, (2) in-app privacy controls, and (3) the content of privacy policies. The analysis identified significant gaps in user data protection. Our findings reveal that half of the examined apps did not present a privacy policy during sign up, and only two provided an option to disable data sharing at that stage. The majority of apps' privacy policies failed to address data protection measures. Moreover, users had minimal control over their personal data. The study provides key insights for information science researchers, developers, and policymakers to improve privacy protections in AI healthcare chatbot apps.


Towards a HIPAA Compliant Agentic AI System in Healthcare

arXiv.org Artificial Intelligence

Agentic AI systems powered by Large Language Models (LLMs) as their foundational reasoning engine, are transforming clinical workflows such as medical report generation and clinical summarization by autonomously analyzing sensitive healthcare data and executing decisions with minimal human oversight. However, their adoption demands strict compliance with regulatory frameworks such as Health Insurance Portability and Accountability Act (HIPAA), particularly when handling Protected Health Information (PHI). This work-in-progress paper introduces a HIPAA-compliant Agentic AI framework that enforces regulatory compliance through dynamic, context-aware policy enforcement. Our framework integrates three core mechanisms: (1) Attribute-Based Access Control (ABAC) for granular PHI governance, (2) a hybrid PHI sanitization pipeline combining regex patterns and BERT-based model to minimize leakage, and (3) immutable audit trails for compliance verification.


Implications of Artificial Intelligence on Health Data Privacy and Confidentiality

arXiv.org Artificial Intelligence

The rapid integration of artificial intelligence (AI) in healthcare is revolutionizing medical diagnostics, personalized medicine, and operational efficiency. However, alongside these advancements, significant challenges arise concerning patient data privacy, ethical considerations, and regulatory compliance. This paper examines the dual impact of AI on healthcare, highlighting its transformative potential and the critical need for safeguarding sensitive health information. It explores the role of the Health Insurance Portability and Accountability Act (HIPAA) as a regulatory framework for ensuring data privacy and security, emphasizing the importance of robust safeguards and ethical standards in AI-driven healthcare. Through case studies, including AI applications in diabetic retinopathy, oncology, and the controversies surrounding data sharing, this study underscores the ethical and legal complexities of AI implementation. A balanced approach that fosters innovation while maintaining patient trust and privacy is imperative. The findings emphasize the importance of continuous education, transparency, and adherence to regulatory frameworks to harness AI's full potential responsibly and ethically in healthcare.


Privacy Checklist: Privacy Violation Detection Grounding on Contextual Integrity Theory

arXiv.org Artificial Intelligence

Privacy research has attracted wide attention as individuals worry that their private data can be easily leaked during interactions with smart devices, social platforms, and AI applications. Computer science researchers, on the other hand, commonly study privacy issues through privacy attacks and defenses on segmented fields. Privacy research is conducted on various sub-fields, including Computer Vision (CV), Natural Language Processing (NLP), and Computer Networks. Within each field, privacy has its own formulation. Though pioneering works on attacks and defenses reveal sensitive privacy issues, they are narrowly trapped and cannot fully cover people's actual privacy concerns. Consequently, the research on general and human-centric privacy research remains rather unexplored. In this paper, we formulate the privacy issue as a reasoning problem rather than simple pattern matching. We ground on the Contextual Integrity (CI) theory which posits that people's perceptions of privacy are highly correlated with the corresponding social context. Based on such an assumption, we develop the first comprehensive checklist that covers social identities, private attributes, and existing privacy regulations. Unlike prior works on CI that either cover limited expert annotated norms or model incomplete social context, our proposed privacy checklist uses the whole Health Insurance Portability and Accountability Act of 1996 (HIPAA) as an example, to show that we can resort to large language models (LLMs) to completely cover the HIPAA's regulations. Additionally, our checklist also gathers expert annotations across multiple ontologies to determine private information including but not limited to personally identifiable information (PII). We use our preliminary results on the HIPAA to shed light on future context-centric privacy research to cover more privacy regulations, social norms and standards.


Exploring Consequences of Privacy Policies with Narrative Generation via Answer Set Programming

arXiv.org Artificial Intelligence

Informed consent has become increasingly salient for data privacy and its regulation. Entities from governments to for-profit companies have addressed concerns about data privacy with policies that enumerate the conditions for personal data storage and transfer. However, increased enumeration of and transparency in data privacy policies has not improved end-users' comprehension of how their data might be used: not only are privacy policies written in legal language that users may struggle to understand, but elements of these policies may compose in such a way that the consequences of the policy are not immediately apparent. We present a framework that uses Answer Set Programming (ASP) -- a type of logic programming -- to formalize privacy policies. Privacy policies thus become constraints on a narrative planning space, allowing end-users to forward-simulate possible consequences of the policy in terms of actors having roles and taking actions in a domain. We demonstrate through the example of the Health Insurance Portability and Accountability Act (HIPAA) how to use the system in various ways, including asking questions about possibilities and identifying which clauses of the law are broken by a given sequence of events.


Healthcare AI Use Cases and Trends - An Executive Brief

#artificialintelligence

Matthew is Senior Editor at Emerj, focused on enterprise AI use-cases and trends. He previously served as podcast producer with CrossBorder Solutions, a venture-back AI-enabled tax solutions firm. Prior, Matthew served three years at the World Policy Institute as a news editor and podcast producer. Healthcare is an increasingly complex sector of the global economy, and AI is playing an active role in the worldwide evolution of the industry throughout its many disciplines. In a Deloitte study released earlier this year, 85% of respondents among healthcare business leaders said their enterprise was increasing AI spend before 2023.


AI in healthcare: navigating uncharted territory

#artificialintelligence

AI is undoubtedly changing the healthcare industry, making it more efficient and driving better outcomes for patients. COVID-19 has served as an accelerator of adoption โ€“ a catalyst in helping the industry catapult itself forward, taking advantage of the best technology has to offer. Barriers to adoption persist, however, as many applications of AI in healthcare remain uncharted territory. The vast majority of the world's health systems are not using their data and AI to make helpful predictions that inform decision making, creating tremendous opportunity to use data and AI to help make more insightful healthcare decisions. But the challenge is in finding common, replicable use cases. To start, healthcare providers are looking to understand how the disparate clinical data they gather can be organised better into an efficient pipeline that can be used to tap into accurate, predictive data intelligence.


HiPaaS Artificial Intelligence AI - HiPaaS

#artificialintelligence

Easy integration with Epic, eCW, Athena or any EHR Bi-direction interface with Epic or any EHR Interface various HL7 messages Dashboard capability to view messages. HiPaaS Go Live with ML/AI Model for leading Cancer Research Hospital to reduce in-hospital mortality rate. HiPaaS used for Population Health Management by leading Medical Group. HiPaaS collects following events from various sources โ€“ 1. CCDA information about Patient History 2. Client required a scalable and highly available solution for connectivity to multiple EHRs and payers, with interface for patient management and document services (OCR). HiPaaS is used by leading Cancer Research firm to collect genomics data which is then used for Prediction scoring.


Researchers examine the ethical implications of AI in surgical settings

#artificialintelligence

A new whitepaper coauthored by researchers on the Vector Institute for Synthetic Intelligence examines the ethics of AI in surgery, making the case that surgical procedure and AI carry related expectations however diverge with respect to moral understanding. Surgeons are confronted with ethical and moral dilemmas as a matter in fact, the paper factors out, whereas moral frameworks in AI have arguably solely begun to take form. In surgical procedure, AI purposes are largely confined to machines performing duties managed completely by surgeons. AI may also be utilized in a medical determination help system, and in these circumstances, the burden of accountability falls on the human designers of the machine or AI system, the coauthors argue. Privateness is a foremost moral concern. AI learns to make predictions from giant knowledge units -- particularly affected person knowledge, within the case of surgical programs -- and it's usually described as being at odds with privacy-preserving practices.


Researchers examine the ethical implications of AI in surgical settings

#artificialintelligence

A new whitepaper coauthored by researchers at the Vector Institute for Artificial Intelligence examines the ethics of AI in surgery, making the case that surgery and AI carry similar expectations but diverge with respect to ethical understanding. Surgeons are faced with moral and ethical dilemmas as a matter of course, the paper points out, whereas ethical frameworks in AI have arguably only begun to take shape. In surgery, AI applications are largely confined to machines performing tasks controlled entirely by surgeons. AI might also be used in a clinical decision support system, and in these circumstances, the burden of responsibility falls on the human designers of the machine or AI system, the coauthors argue. Privacy is a foremost ethical concern. AI learns to make predictions from large data sets -- specifically patient data, in the case of surgical systems -- and it's often described as being at odds with privacy-preserving practices.