logoalt Hacker News

burnteyesterday at 8:26 PM1 replyview on HN

That article is from 8 years ago, accuracy is dramatically better today. We see a few percent error rate.

From the 2025 study: Conclusions The CAISs demonstrate high levels of summarisation accuracy. However, there is great disparity between the currently available CAIS products and, while some perform well, none are perfect. Clinicians should therefore maintain vigilance, particularly checking omitted psychosocial details and medications, and scrutinising plausible-sounding insertions. Purchasers and regulators should be aware of the significant performance disparities identified, reinforcing the need for careful evaluation and selection of CAIS products.

This is exactly what I say and how we teach our people to use it. At the end of the day the human is responsible for the accuracy. We do have providers who decline to use AI because they don't want to double check it, and that's fine by us.

> On the gripping hand, people who work in the management end of the US healthcare industry can't be trusted with healthcare or information security to begin with.

No, this blanket statement is far to overly broad. Health insurers are by far the least trustworthy. Provider organizations are a very, very different group. In my 12 years I have never had a PHI breach or leak that wasn't a human making a mistake. No hacks, no credential breaches, no backdoors or zero days, no network infrastructure penetrations. Two former employers had breaches years after I left which I think speaks well to my track record. I take security incredibly seriously. Our patients are the most important part of my job.


Replies

EvanAndersonyesterday at 9:53 PM

I'm glad your organization hasn't had a PHI breach. I'll see your anecdata and raise you mine:

The two biggest hospital providers in my geography have both had breaches in the last 5 years, both involving exfiltration of PHI (and one involving ransomware). (My family's data was in both, too!)

https://www.hipaajournal.com/premier-health-partners-2023-da...

https://www.hipaajournal.com/kettering-health-ransomware-att...

I have a background in IT security and systems administration (including working as a contractor for healthcare providers). Since medical records have become "electronic" I've assumed medical data is de facto public.

If there was a diagnosis or treatment I felt others knowing about would compromise me I would avoid bringing it up to a medical professional or seeking treatment. I'm certain there are people who avoid mental health services, for example, for exactly that reason.