
Vendor contracts, staff training and patient consent: How practice leaders can reduce AI legal risk
Health care attorney Tatiana Melnik, J.D., says practices adopting artificial intelligence tools should reread their vendor contracts, train staff every week and plan for patients who decline an AI scribe.
Two proposed class actions in California accuse health systems of recording patient visits with an artificial intelligence (AI) scribe without consent.
A patient sued
Tatiana Melnik, J.D., an attorney with
She presented "Privacy and Security Legal Issues in the Age of Artificial Intelligence" on Sept. 28 at the Medical Group Management Association (MGMA)
Her advice to practices starts with the
She also said the Health Insurance Portability and Accountability Act (HIPAA) applies to AI tools for scheduling, prior authorizations and visit notes the moment they can reach protected health information.
Our conversation, lightly edited for length and clarity, follows.
Your session description says a lot of practices are putting AI tools in place without fully understanding the legal risks. For someone who couldn't make it to MGMA this year, what are they missing?
Tatiana Melnik: A couple of things from that session. One is to review your vendor contracts, with both your existing vendors and your new vendors. Make sure you actually understand the consents you're granting to these companies and how they're using your information, and make sure your indemnity clause reflects that.
The other is to train your staff for change. This technology is coming. It's not going away, and technology isn't new. Health care practices have been willing and able to adapt to new technologies since electronic medical records (EMRs) and even before that. So this is not new, but you should work with your staff to prepare them for the changes.
How does HIPAA apply when a practice uses AI tools for things like scheduling, prior authorizations or writing up visit notes?
Same as it does to every other technology. When you grant these technologies access to protected health information, HIPAA automatically kicks in, and this is why it's really important to understand the consents you've granted to your vendors. Before AI, allowing your vendors to de-identify information may have been a low-risk issue. Now, in the age of AI, you might decide it's high risk because re-identification is so easy.
When a practice signs a contract with an AI vendor, what should it look for when it comes to who owns the patient data and whether the company can use that data to train its AI?
Explicitly for those things. There are also other kinds of gotcha clauses. For example, there might be clauses about how the vendor is allowed to collect information on how you use the technology, which they often will call something like usage data. Normally that'll be the things you click on as you're using the application, so the vendor can look for problems with the technology. But now, with AI, is an AI prompt usage data?
I think practices have to take an additional step to really think through what the vendor means when they're using some of these terms: usage data, confidential information, the grant to keep information post termination of the contract. What are the obligations to actually delete the data? Can the vendor do that? And if they can't do that, then you should look at the indemnity and the damages cap clause.
It's standard, I think, in a lot of these contracts that the damages clause will say something along the lines of, "Our liability is capped to 12 months of fees that you paid prior to whenever the incident arose." Well, if the incident arises three years after the contract because you've allowed them to keep your data post termination, then the damages cap is zero. Then you, as the practice, are responsible for all those liabilities because, under HIPAA, it's the covered entity that bears the majority of the risk.
More patients are showing up to appointments having already used AI to diagnose themselves. Does that create a legal risk for the physician, and how should practices handle those scenarios?
I think they should handle those issues the same way they currently handle a patient who shows up having consulted Doctor Google. This is not a new issue for medical practices. They already have tools to handle it. They should apply the same processes they have for Doctor Google to Doctor ChatGPT.
How are regulators and plaintiffs' attorneys starting to approach AI cases, and where do you expect the big problems to show up for practices?
That's a really terrific question. We're already seeing consumer class actions out of California against medical practices and hospital systems using AI scribes, where the patients are saying they did not consent to those uses, and that's a big issue. So I expect that to follow.
I also expect medical malpractice carriers to start denying coverage when a medical malpractice issue arises where AI has been used. For example, if you have a physician not reviewing the notes that are submitted because they're using AI scribes, and that then leads to a medical malpractice case, you might have the medical malpractice carrier say, "Hey, that's a technology issue. That's not a malpractice issue."
But again, this is not a new phenomenon for medical practices. We saw the same thing when medical practices started to adopt EHRs, when plaintiffs' attorneys started to see all of the audits from the technologies and saw, "Hey, you modified this patient note two months after you saw the patient. Why would you do that?" You're really creating a lot of exposure for the practice when you're doing things like that, but practices already have the tools to deal with these issues.
To follow up on AI scribes, I've seen cases where patients say they didn't consent to the AI recording. Is there anything a physician or practice can put in place? Is it as simple as a sign on the wall saying the visit is being recorded, or is it asking the patient ahead of time?
My general recommendation to practices is to ask the patient and get their affirmative consent, and in part that's because I generally think it's the right thing to do to have people be comfortable with these technologies. The caveat is the practice then has to have a process in place for what happens when the patient says no.
Not everybody is comfortable with those technologies, and so you, as the practice, have to decide: Can we accommodate the patients who are not comfortable? Can we just turn these technologies off? Or is it going to be like what practices did with EMRs, where a lot of them said, "Look, our process now is to use EMRs, and if you're not comfortable having your records stored electronically, then you simply can't be our patient"?
But in my view, the best place to put some of these disclosures and address these consent issues is the notice of privacy practices, which is something practices are already supposed to do and use as part of HIPAA. There is no reason why they can't add AI terminology to their existing notice of privacy practices.
Physicians Practice is all about tips for practice administrators. What's one tip you would give a practice administrator that they can put into place first thing tomorrow?
Train your team. Spend the money necessary to actually train your staff. Do weekly five-minute sessions on best practices, weekly reminders on your existing policies and weekly notices, and just do ongoing training. The biggest risk in a lot of these technologies is the people using them, and the best way to minimize those risks is to spend time training your staff.
It's uncomfortable. It takes time. No one wants to do it. People don't remember, and that's why you've got to do it anyway.
We're at the MGMA conference here in San Antonio. What has been the highlight of your conference so far, or what are you looking forward to the rest of the week?
I'm looking forward to the sessions. I love seeing the sessions about how practices are actually running their businesses, what challenges they're encountering and how they're thinking about them. As an attorney, that really gives me a lot of insight into legal issues that may be coming down the line and how I should be thinking about them for my clients.
Physicians Practice was in San Antonio at the MGMA Annual Conference, Sept. 27-30, celebrating 100 years of MGMA, attending sessions and speaking with industry leaders. Follow our coverage on our
Related to this article









