AI may already be part of your health care practice, whether you realize it or not. In this episode, Partner Jay Reyero explains what “shadow AI” is and how it can quietly enter a practice behind the scenes. Tune in to understand the privacy and compliance risks of AI, unexpected ways employees and patients may use AI, and what practice owners can do to bring AI “out of the shadows.” Learn how to recognize AI in your practice and create a plan to protect your patients, employees, and business.
Listen to the full episode using the player below, or by visiting one of the links below. Contact ByrdAdatto if you have any questions or would like to learn more.
Transcript
*The below transcript has been edited for readability.
Intro: [00:00] Welcome to Legal 123s with ByrdAdatto. Legal issues simplified through real client stories and real-world experiences. Creating simplicity in three, two, one.
Brad: [00:13] Welcome back to Legal 123s with ByrdAdatto. I’m your host, Brad Adatto. My co-host, Michael Byrd.
Michael: [00:19] As business attorneys for health care practices, we meet a lot of interesting people and learn their amazing stories. This season’s theme is AI In Health Care. We’re bringing in people a lot smarter than the two of us to help decipher the business risk of using AI in a medical practice.
Brad: [00:36] And remember, audience members, because AI is so new, we don’t really have those kind of client stories we typically like to use. So we’re going to have a lot of interactive conversations with how it works and with this once in a lifetime shift in the world with the use of AI.
Michael: [00:53] Yes, and after speaking of bringing in people smarter than you, Brad, in particular, we welcome for the first time and right off the bat in season 25, our partner and series regular, Jay Reyero.
Brad: [01:07] All right. Well, okay, hold on. First off, wait, no client stories?
Michael: [01:11] Yep.
Brad: [01:12] No client stories, no changing the names, no need to protect the innocent, just pure focus on AI.
Michael: [01:18] All right. Well, okay, I don’t know if I can do this. I came in prepared today. I had great characters for my stories. I had Skynet Aesthetics the medical practice. They were owned by Dr. John Connor, Dr. Miles Dyson. They specialize in the Terminator Facial, and it was done by the device that’s the T-1000. I mean, I worked on this really hard.
Brad: [01:41] If your target audience is Brad then well done.
Michael: [01:45] If you notice tier audience members coming down, I was so happy hearing all these Terminator movie references, so I think we should just make up a story just for that, Jay.
Brad: [01:55] Yeah. All right. Well, I’ll just get over it, and then the show must go on. But have you guys ever heard the saying, “What’s old is new again”?
Michael: [02:04] I think Brad has that tattooed on his back. Michael, I don’t even want to know how you know that, okay? It’s kind of gross. But what I like about what old is new again is most of my fashion. Just stick with an outfit, and eventually it’ll all come back around.
Brad: [02:20] Well, it’s not about fashion, but I do have news for you. In a recent documentary, a couple of guys named Chris and Tim Vanderhook said they had plans to relaunch one of the OGs of social media, Myspace.
Michael: [02:35] Yes. And believe it or not, audience members, this is not the first time a group has tried to relaunch Myspace. And if you don’t want people to know about your tattoo, Brad, quit wearing those half shirts that the small of your back shows.
Brad: [02:46] Crop tops.
Michael: [02:47] Yes. It’s so bad. All right. Okay. I did see this about Myspace and immediately thought about Brad and how many times Brad has said Myspace when we talk about social media, but you finally have a chance to be an influencer now, Brad.
Brad: [03:04] So excited.
Michael: [03:04] You can just dust off your old account.
Brad: [03:06] Well, I never had Myspace, so I never knew that the site was credited with helping the careers of musicians like Adele. Did you know in the heyday of 2006, it was the most visited website in the US, making up almost 5% of all browser traffic?
Michael: [03:24] I did not, even though I have always claimed to have Myspace, my face, space, place. I don’t think I went as deep as Michael Byrd did, though. Yeah, Brad, in psychology, they call this mirroring. That you take what’s true about you, and you’re trying to put that on me.
Brad: [03:42] Oh.
Michael: [03:42] I was actually an early adopter of LinkedIn back in 2006. I actually got a letter from LinkedIn for being one of their first 150,000 users. Of course, the only reason I did that was because of a client, that tech client we had back then.
Brad: [03:56] Well, Brad, I do have some bad news for you.
Michael: [03:59] Okay.
Brad: [04:00] Apparently, the original co-founder, Tom Anderson, who’s remembered as “Myspace Tom” the automatic first friend on every single account, he’s not going to be part of the relaunch. So Brad, you’re going to have to work hard, really hard to get that first friend.
Michael: [04:16] Not again. Oh, man. I can’t believe Myspace is coming back. All right. Well, let’s get into our conversation today. So to reset, last episode, we kind of did the AI regulation framework, and we actually touched on what we’re going to talk about today, but we’re going to go a little bit deeper, and it’s just going to kind of help unfold throughout the season. There’s going to be a little bit of overlap as we go from episode to episode, but this stuff is so complicated that I think it’s important that we make sure everybody understands the interplay. Today, let’s talk about shadow AI and where it can show up in a medical practice.
Brad: [04:59] Totally agree with you that this might feel a little bit repetitive since we just talked about it, but for those who missed the first episode of the season, Michael, maybe you can kind of help out and remind the audience what is shadow AI?
Michael: [05:13] The basic premise is that AI is in a practice even if the practice doesn’t realize it. There are third-party software products that have AI tools that exist in the practice, and I think, Brad, you can speak to the bigger culprit, employees using AI for work without the knowledge of the employer.
Brad: [05:35] Yeah, and shadow AI really is the new shadow IT. Employees are using AI tools without approval from leadership, obviously opening up compliance and legal issues or even IT issues, and their intent, I think, usually is good, but the risk could be significant.
Michael: [05:51] Okay. So now that we have this broadly defined, I think it’s important to talk about some of the common situations where this can arise in a practice. And so Jay, I’d love your take.
Jay: [06:03] Yeah, I think it definitely starts with the employees and what, where we’re seeing it is on the common things of helping them do their job, and so it comes probably with some good intention. So you think about using ChatGPT, whether it’s to get some information, help answer a patient inquiry in a certain way, help make their writings and emails a little bit more professional or toned down. We’re seeing it a lot with note-taking, helping capture information and then not just recording it like the old ways of just putting your phone out and recording it, but then helping summarize and keeping things up to date. And I think one of the things that we’re also seeing just from an employment side of things is this almost becoming a lawyer. Like you might see office managers who start developing contracts because the physician owner says, “Hey, we need to hire someone,” so they go to ChatGPT to say, “I need a contract for this person,” or developing policies and procedures or your informed consent. So almost kind of doing some of the jobs that we’ve seen of attorneys to be able to be a little bit more advanced in their role, not just helping them do what they need to do.
Brad: [07:24] Yeah. I’m going to completely agree with you, Jay. I think what happens, especially with the shadow AI, is as you kind of said, they’re finding shortcuts in productivity. They’re finding ways to do things faster, emails and summarize notes or write policies, everything you just kind of said, spreadsheets or create marketing content even, but that doesn’t always mean better. I think that’s the scary part of all that.
Michael: [07:50] I’ve actually had clients share with us a somewhat surprising way they’ve discovered shadow AI in their practice. So a lot of enterprise AI tools, or some of them I’ll say, you as the employer can kind of see what the inquiry history is of the employees. And so one of those is OpenEvidence, which is really popular in medical. And this employer discovered that the employees didn’t use these types of platforms because they were afraid of being found out that they were asking dumb questions, that it was something they were supposed to know. So they go to their own personal tools to get the information that they need.
Jay: [08:40] Yeah, and I think going beyond just kind of the administrative side, with the OpenEvidence, I think you look at the provider side, you also see using AI to potentially help diagnose. There’s a lot of tools out there that will help kind of supplement that diagnosis piece. We’re seeing some AI in the help of coding when you’re doing insurance and submitting claims for reimbursement, and so the billing and the coding aspect. So from a provider side, you’re also seeing it kind of morph into that, which is obviously a really big risk.
Brad: [09:14] Yeah, and especially if they’re using it from a shadow AI perspective. I know this season we’ll have two different guests come on and talk about utilizing AI platforms that are built for medical organizations to help with billing and coding and stuff like that. But in reality, we’re talking about health care organizations here, and they’re more vulnerable, I think, than most businesses because there’s, we’ve talked about this before, tons of different information out there on patients. And the patient data, the PHI, protected health information, if it’s being utilized, it could be exposed through these AI tools if they’re not correct. And HIPAA is also obviously a big concern. Staff may unknowingly adopt some type of PHI into a public AI platform, creating obviously regulatory contractual risk and obviously potential breach of privacy policies.
Michael: [10:08] We talked last week about how difficult it is to quantify the risk with evolving new AI laws and an already complicated compliance infrastructure that affects medical practices.
Jay: [10:22] Yeah, and I think, Michael, one of the things you mentioned earlier was this embedded nature of AI in other software, and while you might know about the software, you might not necessarily know the capability of the AI built within it, so then you don’t really understand how the employees are utilizing that AI within that software platform.
Michael: [10:44] Yeah. I mean, we know that physicians, physician owners, they’re busy. They’re operating. They’re often involved in making the decision to buy a software product. They get excited with the presentation. They may have gone to a booth at a trade show, and then they hand it over to the staff for implementation, and they’re really oftentimes not in the software that much. And so they may have this vague awareness sometimes that there’s an AI component to it, but sometimes they don’t even know that. And so there is this concept that there’s AI happening in the software they bought some time ago, and they have no idea.
Brad: [11:29] Well, and I think with AI what’s so confusing here, it’s, I guess with software, I mean, if you’re buying something new, you might assume that there’s some type of AI component in it. It seems like AI tools are embedded in everything now. So it’s not just ChatGPT or other software out there. It could be your browser. It could be some type of transcription tool, note-taking tool, scheduling assistant, SaaS applications, or they’re just certain autonomous AI agents. You know, I feel like the next time I go buy a box of cereal it’ll have AI as a part of it. And so all these different things are there, and so that’s the big struggle is that these businesses may have no idea. They may think, “We don’t have any AI here,” and it’s being used day to day in their tools, even though they don’t have that software that has that AI in it.
Jay: [12:17] Yeah, and I think kind of in a similar vein, kind of switching gears from the employee being using it within the practice, I think the other aspect that we’ll see it and that practices will experience is patients. So patients are coming in with all of these AI tools at their disposal, and they’re coming in with the note-taking, the meta glasses, the recording devices, which has historically been something that’s happened with phones, but it’s taken it up another level, especially when you can be wearing your glasses and walk in, no one can notice. But then also a more advanced level of the old school WebMD, the self-diagnosis. You can put a picture of yourself and ask it to conduct a skin analysis and generate a report. And so you’re basically doing the consultation yourself and coming in kind of already with something in mind.
Jay: [13:18] And so when they’re coming in with that kind of level of education and information, now you’re not just trying to do your job, but you’re also trying to somewhat go and either argue against or validate whatever this AI platform is that they were using when they’re coming into that first, that initial consultation.
Michael: [13:38] So you could be a practice resistant to AI or thinking that you are going to adopt it in a controlled manner, and the entire patient journey has this shadow AI component, to your point. And fundamentally, the communication and relationship building between the physician and the patient is altered because of that use of AI. Is that really a question of the patient that they’re asking, or is that what their ChatGPT told them to ask? Do they really want that particular procedure or believe that they have that diagnosis? And are they just giving you this information and you’re trying to communicate? So it really creates a friction to connecting to what the patient really wants. And then kind of adding onto all of that is that they’re using AI to price shop now. And so for elective medicine in particular, but you see it in insurance-based care as well, they’re coming into the practice with a new set of expectations.
Brad: [14:55] Yeah, and I want to jump back real quick. There’s some things that Jay said that I want to go back to. First, I would be terrified about that whole body scan thing because I would be the person I’d like to scan, and they’d say, “System error.” Like, it would just not work.
Jay: [15:09] No hope.
Brad: [15:10] No hope. Like, “Sorry, just kill yourself.” All right. But I think real quick, going back to something Jay was talking about, he was talking about the physician-patient relationship, and that’s the key component here when talking about now we’re introducing a third party to this conversation, because it’s no longer just the physician and the patient talking to each other. And now, and to the point you were kind of getting to, Michael, is that there’s this communication that’s happening that AI is taking and interpreting what it believes the encounter was. It doesn’t mean, it’s not like a pure transcript anymore where it actually says it. It may give you a summary of what it believes happened in that room. And again, if it’s the patient doing it, the patient may be then relying on that summary, is kind of what you’re leaning into, Michael. And so that recap could be inaccurate, it could be incomplete, it could be completely taken out of context. And then there starts becoming either a distrust or misunderstanding between that patient and the physician because the AI is giving the patient a different belief as to what should be that treatment plan.
Brad: [16:08] And I’ve actually had many conversations with physicians where someone is coming in with that kind of idea in their mind where they’ve already self-diagnosed, and that’s going back to the story you were leaning into earlier, Jay, about the office manager with no legal background is now creating contracts. Well, now you have patients with no medical training self-diagnosing, and then they’re, based on AI, believing this is the course they should do without ever even seeing a physician.
Jay: [16:40] Yeah, and I think if we give credit to those that know how to use AI, we’ve always talked about with AI, you always think about garbage in, garbage out. The output tends to be only as good as the prompts, and so one of the exercises is to kind of understand how that individual, when you identify that they’ve utilized AI, how did they get to that output? Because then you’re really going to have a better framework on what it is that you do to talk with them through that process. You don’t want to just dismiss it out of hand, because there could be some valuable information in what they were doing or what they were trying to do, but you also don’t want to just accept it as true in fact, because they may not have any indication of how to write a proper prompt and the information that they put in, and it was very superficial, and it doesn’t get to the heart.
Jay: [17:28] So part of what providers are going to have to do is kind of understand how they got there and then be able to put that into context for them to get them to where they need to be in just the regular consultation in person.
Michael: [17:51] Let’s go to break and talk legal application, and here are some practical steps that every practice can start taking today.
Access+: [17:58] Many business owners use legal counsel as a last resort, rather than as a proactive tool that can further their success. Why? For most, it’s the fear of unknown legal costs. ByrdAdatto’s Access+ program makes it possible for you to get the ongoing legal assistance you need, for one predictable monthly fee. That gives you unlimited phone and email access to the legal team, so you can receive feedback on legal concerns as they arise. Access+, a smarter, simpler way to access legal services. Find out more. Visit byrdadatto.com today.
Brad: [18:33] Welcome back to Legal 123s with ByrdAdatto. I’m your host, Brad Adatto, with my co-host Michael Byrd and series regular, Jay Reyero. Now, Michael, for those that don’t remember, this season our theme is AI in health care. And before we really go crazy, we gave the audience some kind of oversight of what was happening. Maybe you can kind of give a recap where we left off.
Michael: [18:54] Yeah, so if you think about the season as a whole, these first two episodes are setting the framework, and today we’ve been talking about shadow AI, which is how AI shows up in the practice where the practice owners may not be aware of it. And so we spent some time just kind of highlighting various ways that it shows up. We will have specific guests throughout the season where we may really dive deeper into some of the specific scenarios we talked about. Jay, for you, kind of as we go into application, what should a practice do specifically to deal with shadow AI?
Jay: [19:35] Yeah, I mean, as corny as it sounds, I think you have to bring it out from the shadows. And really, I mean, it starts with a mindset. You’ve got to acknowledge and accept the fact that it exists, that it’s there. Because only then can you start having the strategy discussions on, what type of AI practice do I want to be? Do I want to be one that embraces it and have it utilized in certain ways? Do I want to resist it and not have it show up in my practice and have strict policies to keep it out? Really just doing some kind of self-assessment by saying, “It exists, so I need to do something about it, and so which side of the fence am I going to be on?” Because only then can you really have the conversations on what policies to have to be able to govern all that.
Brad: [20:26] You know, we were jokingly saying in the first episode, shadow AI is something sounds scary, but you’re correct. You’re talking about shining a light on the shadow, right? That’s what we’re trying to do. And what happens is shadow AI creates this governance blind spot that you don’t know, where the leaders aren’t aware what tools are being used, how the data’s being shared, who has access to this output of what’s going on. And unfortunately, unlike in the movie “The Matrix,” ignorance is not bliss, Michael, in these kind of moments. And so the goal, as Jay was kind of pushing, is visibility. And it shouldn’t be punishment, it should be an organization’s trying to learn what are employees already using AI, and then figuring out, is that a tool they can continue to use, and then build governance around those real-world usage patterns. Obviously, we can talk about it all, but with the protections that are needed, especially in a health care practice.
Michael: [21:23] Yeah, and so taking it the next step, you’ve got to have that awareness and governance, but it becomes important to have a commitment to training on AI use in a practice. The repetition through the ongoing trainings is actually what integrates these policies or this governance that Brad mentioned into the day-to-day operations and brings it to life.
Jay: [21:51] Yeah. And I mean, look, what are the consequences if you just kind of put your head in the sand? I mean, they can actually be quite significant. Brad, you mentioned protected health information, privacy. If an employee puts patient information into a non-enterprise, personal level AI platform, we have real HIPAA breach issues because those platforms don’t protect that data. It’s the same as posting to the outside world. And so you get into really big privacy concerns by dumping that kind of stuff in there. Let’s take just the business stuff. You have a lot of things internally that are confidential, and the moment that they start plugging that stuff away into those same things, you create a lack of protection and whether you have trade secrets or something, that protection could be lost forever. I’ve had conversations with IP attorneys who have said that people have been developing patents and they’re using
Jay: [22:52] ChatGPT, regular edition, to do that, and there’s no coming back from that. I mean, you have basically lost that ability. And then let’s not, I don’t know, we’re not litigators, but what if a patient has a bad outcome and your provider goes home and in their personal ChatGPT history starts trying to figure out did they or did they not do something wrong? Is that discoverable? Is that protected? What are the discovery requests going to look like? Give me all your chat histories for all your AI platforms, both personal. It’s real consequences that you just have to get a handle on upfront.
Michael: [23:31] One of the culprits, the biggest culprits of how all this that Jay just talked about shows up is the employees’ cell phones. So, they’re at the office. They want to input something for whatever reason, maybe the reason of not looking dumb, or it’s just convenient. They open up their free version of ChatGPT or Gemini or whichever they use and start asking these questions or plugging in confidential information or patient health information. And to your point, Jay, at that point, it’s too late.
Brad: [24:08] Yeah, and if HIPAA taught us anything, it’s been around for 20-something years now, is good intentions don’t eliminate liability. The same goes with shadow AI. Most violations won’t come from bad actors. They actually could be really good employees who are just trying to work faster. But let’s get back to HIPAA. HIPAA exposure. If this exposure occurs, a simple copy and paste could happen that, as Jay’s mentioned before, entering patient information, photos, treatment plans, intake forms. If it has any of the PHI, protected health information, and it’s on an unapproved AI platform, there’s an exposure, and the practice may lose visibility and control over how this information is stored and processed or used. And health care organizations really need to ensure that the AI vendors are properly vetted and appropriate contractual protections, including business associate agreements.
Michael: [25:01] When needed, if you’re touching PHI.
Brad: [25:03] Yeah, and I think one of the other aspects is in the marketing area, the medical advertising kind of liability issues. I mean, we’ve heard hallucinations. It likes to make things up and create fluff, and so you have the false, deceptive, misleading aspects. And just because you use AI, that’s not going to be an excuse. You’re still ultimately liable for it.
Michael: [25:24] Yeah, so again, picture the employee who’s doing social media for the practice, and they hear of a cool AI tool and they put something out there. Well, the advertising rules have been in place. We’ve done many episodes talking about it, and those haven’t changed. It’s federal and state laws that protect against misleading the patient. The problem is that when you start using AI tools, you compound that risk at scale because you’re pushing out so much content that could have that false and misleading information in it.
Brad: [26:04] Yeah, and we’ve talked about it, as Michael said, the medical advertisement rules. False, deceptive, misleading are the easiest things to fall back onto. That’s the FTC rules. That’s most state board rules. And if you’re using AI to help enhance results, generate images that look better but actually don’t reflect the patient’s results, again, regulators, FTC, state medical boards, nursing boards will see that as deceptive. I think, Michael, you said this too, it’s not even if you’re using AI frequently a lot, it actually can be worse because the more you use it, the AI might be more creative and update your website or other aspects of it and develop all this content, but that doesn’t necessarily guarantee that it’s actually good content as far as medical advertisement rules. So as such, AI can create amazing marketing content in seconds. The problem is that you can’t create misleading marketing content just as fast. I mean, I think we’re talking about AI and technology, and one of the industries that’s been kept busy is the cybersecurity area. So obviously, I think without a doubt, cyber liability risks are increasing and increased significantly with AI presence.
Michael: [27:20] Yeah. There’s a whole new window for bad actors to enter the practice and employees to inadvertently open that window, and obviously we’ve been talking about HIPAA and other privacy laws that it’s so important to recognize that security just got that much more difficult with AI that’s present.
Brad: [27:42] Yeah. And Michael talked about this in the last episode, but going back to check with your cybersecurity, check with your cyber insurance because AI can grab stuff so fast, you wouldn’t even realize that every single patient information could be uploaded instantaneously. But I think we’re almost out of time, so Jay, I’d love your final thoughts.
Jay: Yeah. I think to all the practice owners out there, it exists, and the moment that you accept and acknowledge it, you’re going to be in a better position because there’s no more shadow to protect the practice.
Michael: [28:16] I’ll be back.
Brad: [28:18] Well, and I’ll say this, the practices that succeed with AI will not be the ones that use the most technology. They’ll be the ones that govern it the best. So Michael, final thoughts.
Michael: [28:28] Yeah, don’t be like Brad. He sticks his head in the sand thinking that those half shirts are going to come back around and that it’s going to be in style, and sticking your head in the sand in this case for AI is not going to work.
Brad: [28:44] All right, everybody, next Wednesday we’ll return and explore. We have our first guest of the season that’s not Jay Reyero, as we explore AI use in plastic surgery practices with Dr. Akash Chandawarkar.
Brad: [28:55] Thanks again for joining us today. And remember, if you liked this episode, please subscribe. Make sure to give us a five-star rating and share with your friends.
Michael: [29:04] You can also sign up for the ByrdAdatto newsletter by going to our website at byrdadatto.com.
Outro: [29:10] ByrdAdatto is providing this podcast as a public service. This podcast is for educational purposes only. This podcast does not constitute legal advice, nor does it establish an attorney-client relationship. Reference to any specific product or entity does not constitute an endorsement or recommendation by ByrdAdatto. The views expressed by guests are their own, and their appearance on the program does not imply an endorsement of them or any entity they represent. Please consult with an attorney on your legal issues.
