0:00
Physicians face challenges every day, from difficult patient encounters to changing regulatory requirements at Copic, our commitment to you goes beyond providing reliable medical liability insurance. What sets us apart is our proactive approach, a 24/7 hotline answered by physicians, specialty specific guidance and CME accredited education and unwavering dedication to help you thrive, C, o, p, i, c.com, we're Copic here for the humans of healthcare, here for you.
0:25
So just like anything, a provider in their healthcare organization needs to be conducting periodic auditing and monitoring of all billing documentation, whether or not it's aI generated or not to ensure the accuracy. There's no Get Out of Jail Free card if the AI recommendation is for a higher code than what was actually performed, welcome
0:51
to off the chart, a business and medicine podcast featuring lively and informative conversations with healthcare experts, opinion leaders and practicing physicians about the challenges facing doctors and medical practices. My name is Austin Luttrell. I'm the associate editor of medical economics. I'd like to thank you for joining us today in today's episode medical economics, managing editor Todd Shryock sat down with Dan silverboard, a healthcare attorney at the law firm Holland, and Kate. They discuss how AI and healthcare is currently being regulated and where the legal gaps are. Silverboard walks through the biggest liability risks that physicians and practices face when using AI assisted clinical and administrative tools. What happens legally when an AI generated recommendation contributes to patient harm, and why there's no Get Out of Jail Free card when an AI tool produces a higher billing code than what was actually performed. The Conversation also covers what to look for in vendor contracts, the HIPAA complications that arise when AI systems learn from patient data and the three questions that every practice should be asking before they deploy any AI tool. Dan silver board, thank you for joining us. Let's get into the episode.
1:53
I'm here with Dan silver board, health care attorney at the law firm of Holland, and Kate to talk about AI and health care. Dan, thanks for joining me.
2:00
It's great to be here. Thanks for
2:03
having me So Dan, from a legal standpoint, how is AI and healthcare currently being treated? Is it a simply a software decision support tool? Is it a medical device or something else?
2:17
It's a good question. I think you can look at that through the lens of the regulating entities, those those people out there who are passing laws and regulations that affect the use of artificial intelligence and healthcare. So states are regulating AI primarily as a unique technology that supports clinical decision making that supports medical records documentation by licensed healthcare professionals, not necessarily as a medical device. The FDA does not independently regulate AI. They are regulating medical devices and kind of indirectly regulate AI based on whether or not it's incorporated into the medical device or not.
3:09
So what are the biggest liability risks that physicians and healthcare organizations face when they're using AI assisted clinical decision tools?
3:19
So generally speaking, artificial intelligence in healthcare, it's still an evolving technology. We still have headlines out there of hallucinations taking place, things of that nature. So I would say there's, there's really two risks. The first risk is, is that 85% of all investment in a healthcare AI is going to startups. There's not a ton of vendors out there that have these very proven, historic track records of providing AI tools that pass the litmus test of HIPAA compliance, of having years and years of comfort, of 100% confirmation or validation testing or that are 100% accurate. So I'd say the first risk is just for the first thing I would say is that healthcare providers really need to be doing their due diligence as to the vendor they're contracting with to make sure that all of those protections, those compliance protections that I'm sure we'll talk about, are in place. The second key risk is, is that, with all of this new technology, that healthcare providers will simply sign off on whatever the recommendation of the AI program is, or if we're talking about an ambient listening program, that they'll just check the box and approve whatever the record is without verifying first, whether or not what's it what the ambient technology has recorded accurately reflect, reflects the encounter. So those are the, I think, the two key risks.
4:57
So, what happens if an AI generated? Recommendation contributes to patient harm. Who gets blamed for that? Clinicians, the health system, the technology vendor. How does that work?
5:12
So I think first you have to look at what the standard of care is around the use of AI in healthcare. There have been a number of states that have through their medical boards or statute have have basically posited the idea of the fact that a medical professional is ultimately responsible for approving or denying the recommendations of the artificial intelligence program. So I don't think you'd have a situation where an AI program of itself would be solely responsible for an adverse event, because, at least Legally speaking, the provider has to sign off, has to approve whatever the AI recommendation is right. If the question of whether a technology vendor could be liable. It comes back to a couple things. I think it comes back to whatever's in the vendor contract. Several those contracts actually require that a decision maker, a physician, sign off on whatever the recommendation is, and that there's broad disclaimers of liability, having said that they could potentially be liable if it's found that the AI program is wholly deficient from a technological standpoint, it was trained on bias data, for example, or data that was could was false data. More or less,
6:45
do physicians that are using AI tools, does they need to document that in the medical record to reduce their legal risk?
6:54
Yes, I think it comes back to whatever some of the states have actually passed legislation on this. Medical boards have passed guidance on this, like North Carolina, for example. But to answer your question, yes, physicians should be documenting if AI was used, whether or not they followed the recommendations of the AI and program, and why and if the AI is making a recommendation that the physician wants to deviate from or projects they should be noting that in the medical record.
7:28
What about for administrative AI tools? There's a lot of AI tools that help with coding, prior authorizations, documentation. Are there compliance or billing risks that practices need to be paying attention to, I think at the end of
7:43
the day, unbundling, unbundling up, coding down, coding anything like that, there was the responsibility from that, from a legal standpoint, falls on the shoulders of the provider. The provider is the person who is attesting to the accuracy the information that's being submitted to the health insurer as part of the claim. So just like anything, a provider in their healthcare organization needs to be conducting periodic auditing and monitoring of all billing documentation, whether or not it's aI generated or not to ensure the accuracy, there's no get out of jail. Free card if the AI recommendation is for a higher code than what was actually performed.
8:37
Hey, there. Keith Reynolds here, and welcome to the p2 management minute. In just 60 seconds. We deliver proven, real world tactics you can plug into your practice today, whether that means speeding up check in, lifting staff morale or nudging patient satisfaction north. No theory, no fluff, just the kind of guidance that fits between appointments and moves the needle before lunch. But the best ideas don't all come from our newsroom. They come from you got a club or workflow, hack an employee engagement win or a lesson learned the hard way, I want to feature it. Shoot me an email at K Reynolds, at mjh, lifesciences.com, with your topic, quick outline or even a smartphone clip. We'll handle the rest and get your insights in front of your peers nationwide. Let's make every minute count together. Thanks for watching, and I'll see you in the next p2 management minute.
9:27
How should healthcare organizations approach their vendor contracts for AI tools to ensure adequate legal protections around accuracy, data, use, liability, privacy, things like that.
9:40
That's a great question. Healthcare providers and organizations are going to want robust representations and warranties in their agreement that the AI vendor is HIPAA compliant, meaning that they have they have privacy and security policies. They conduct security risk assessments, for example. Example, they are also going to want reps and warranties that the AI vendor conducts on an ongoing basis, validation testing, bias testing that they report back to the healthcare provider if there's any sort of problems that emerge from that testing, also some basic reps and warranties that the vendor has a data governance plan and that their technology is free of any claims that the program or the data it's trained on is somehow biased or otherwise untrustworthy.
10:36
What about the privacy issues for systems that are continuously learning from patient data. Are there complications with those that practices need to be aware of?
10:50
So the interesting issue here is, is for whose benefit is the AI training its data for so that one interpretation under HIPAA is that a business associate ie the vendor, can really only train its data if it's benefiting, if it's if it's benefiting the provider that it's contracted for. It cannot train on phi protected health information for its own benefit to make general product improvements. So that is a complication that comes into place. However, if we're not talking about phi and it's just de identified data, that's a lot simpler. There's a lot more freedom on the part of the technology vendor, from a HIPAA standpoint, to train on that de identified data to improve its products or to improve the AI program. I think one other issue that comes up is that as AI becomes more advanced, and this comes in the realm of de identified data, there is this sort of fear that the AI vendor or somebody else down the line could re identify the data using AI. So the last question you asked me is about contracting provisions. There needs to definitely be prohibitions in the contract or the business associate agreement that prohibit the AI vendor or any other downstream contractors from taking any efforts to re identify, de identified data.
12:30
There's a lot of interest in what's called ambient AI, especially with automated note generation. We did a story in medical economics last year. It was like the most popular use of AI by primary care physicians. But what are the legal concerns if clinicians rely too heavily on automatically generated documentation? I mean,
12:55
I think it comes back to the standard of care and just ensuring that providers, even if, even if they're like heavily on it, that they're still checking to make sure that whatever is in the medical record is is accurate. I mean, Texas, for example, has a statute that has that as a requirement for all providers that use use AI to record patient encounters. So that's still the, I would say, the number one concern.
13:24
So with the proliferation of AI and all these new incredible tools that are coming out, what questions should medical practices be asking before deploying them?
13:36
So I think again, it's early days. There's a plethora of AI companies out there. I think the first question the providers need to be asking is, who are they going to partner with? And again, doing their diligence to make sure that the vendor that they do partner with has a proven track record of compliance, including compliance with HIPAA. The second thing I would say is, is that I think the recent polling shows that it's still 5050 as to patients who are comfortable with the AI and healthcare. So I think understanding from a physician standpoint, understanding their patient base and what they're comfortable with can help dictate how they want to implement AI, whether it's back office or whether it's patient facing technology, such as an ambient listening device, if that makes sense. And then third, how are they going to disclose AI to patients? There's certain states, again, that require that disclosure happens, but in the states that don't require that something they want to do any regardless of the law, just for customer, patient, physician relationship, to safeguard that, or is it something they want to put into a Notice of Privacy Practices? Is that we utilize artificial intelligence. So those are, those are some of the questions that I think physicians should be at least talking about before rolling out AI into their clinical operations,
15:13
looking ahead to five years. Do you expect AI related malpractice or compliance litigation to increase significantly, and what would be driving that?
15:25
So if you believe the Department of Health and Human Services, the the implementation of artificial intelligence and healthcare is going to decrease adverse patient events, so we have to wait and see on that in five years. If that's true, then maybe litigation risk goes down. I think where you're going to still see a continuing amount of litigation has to do with the use of artificial intelligence and algorithms by health insurance companies to deny or down code claims or to deny requests for prior authorization. There is a healthy amount of that litigation that's out there currently, and I would expect that to keep going.
16:16
Is there anything else that you would like to mention about AI for medical practices that we haven't talked about.
16:23
I think artificial intelligence holds great promise for the future of healthcare. I do think for now, it's early days, and that healthcare providers need to be vigilant about the vendors who they're contracting with to provide those services and to conduct periodic auditing and monitoring, especially around programs that generate billing codes, for example, and clinical recommendations and have those sort of compliance checks in their compliance programs.
16:57
Dan, thanks for joining me.
16:59
Thanks for having me. It's great being here once again.
17:15
That was Dan silverboard, a healthcare attorney at Holland, at night, speaking with medical economics Managing Editor Todd trial, on behalf of the whole medical economics and physicians practice teams, I'd like to thank you for listening to the show and ask that you please subscribe so you don't miss the next episode. As always, be sure to check back on Monday and Thursday mornings for the latest conversations with experts, sharing strategies, stories and solutions for your practice. You can find us by searching off the chart wherever you get your podcasts, and if you'd like the best stories that medical economics and physicians practice published deliver. Practice published delivered straight to your email six days of the week. Subscribe to our newsletters at medical economics.com and physicians practice.com off the chart, a business in medicine podcast is executive produced by Chris mazzolini and Keith Reynolds and produced by Austin Luttrell. Medical economics and physicians practice are both members of the mjh Life Sciences fam. Thank you. Applause.
We recommend upgrading to the latest Chrome, Firefox, Safari, or Edge.
Please check your internet connection and refresh the page. You might also try disabling any ad blockers.
You can visit our support center if you're having problems.