{"id":299668,"date":"2026-02-24T11:34:10","date_gmt":"2026-02-24T11:34:10","guid":{"rendered":"https:\/\/www.newsbeep.com\/nz\/299668\/"},"modified":"2026-02-24T11:34:10","modified_gmt":"2026-02-24T11:34:10","slug":"hipaa-promised-to-keep-your-medical-data-secret-ai-threatens-to-reveal-it","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/nz\/299668\/","title":{"rendered":"HIPAA promised to keep your medical data secret. AI threatens to reveal it"},"content":{"rendered":"<p>In 1996, Congress enacted a law to assure Americans that their sensitive personal health data would never be disclosed without their consent.<\/p>\n<p>Lawmakers had never heard of AI.<\/p>\n<p>\t\t<img loading=\"lazy\" decoding=\"async\" class=\"wp-block-san-app-download__qr\" src=\"https:\/\/www.newsbeep.com\/nz\/wp-content\/uploads\/2025\/09\/app-download-block-qr-code.png\" alt=\"QR code for SAN app download\" width=\"80\" height=\"80\"\/><\/p>\n<p class=\"wp-block-san-app-download__title\">\n\t\t\tDownload the SAN app today to stay up-to-date with Unbiased. Straight Facts\u2122.\t\t<\/p>\n<p class=\"wp-block-san-app-download__subtitle\">\n\t\t\tPoint phone camera here\t\t<\/p>\n<p>Thirty years after passage of the Health Insurance Portability and Accountability Act, known as <a href=\"https:\/\/san.com\/cc\/misinformation-about-hipaa-health-violations\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA<\/a>, artificial intelligence is disrupting the patient privacy that the law created. Individuals\u2019 health information shared with <a href=\"https:\/\/san.com\/cc\/move-fast-and-heal-things-ai-tests-regulation-and-medicines-cautious-culture\/\" rel=\"nofollow noopener\" target=\"_blank\">AI chatbots<\/a> can be stripped of identifying details and sold to everyone from data brokers to pharmaceutical companies.<\/p>\n<p>Now, AI can be used to restore a patient\u2019s identifying data, circumventing HIPAA, a New York University research team found.<\/p>\n<p>HIPAA\u2019s protections \u201care rapidly becoming outdated,\u201d Lavender Jiang, a fifth-year data science PhD student at New York University, told Straight Arrow News. Jiang is part of a team that showed how AI can be used to examine anonymized patient notes to determine an identity.<\/p>\n<p>\u201cWe believe HIPAA needs urgent updates to offer more robust protections against the sale of this data and we should exercise care when handling clinical notes,\u201d Jiang said.<\/p>\n<p>In other words, a specifically trained AI could use health data collected by a doctor\u2019s AI receptionist to render HIPAA protections useless. Experts believe that updates to the law and strict regulations on AI\u2019s use are more needed than ever.<\/p>\n<p>Is AI HIPAA-compliant?<\/p>\n<p>Threats to medical data have long existed. <a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/05\/15\/276-million-patient-records-compromised---what-you-need-to-know\/\" rel=\"nofollow noopener\" target=\"_blank\">Hackers and data leaks<\/a> have exposed personal, sometimes embarrassing health care data.<\/p>\n<p>But as AI becomes <a href=\"https:\/\/san.com\/cc\/move-fast-and-heal-things-ai-tests-regulation-and-medicines-cautious-culture\/\" rel=\"nofollow noopener\" target=\"_blank\">increasingly integrated<\/a> into the health care industry, many people wonder whether AI-powered chatbots and automated receptionists used by doctors protect patients\u2019 private medical data.<\/p>\n<p>Whether HIPAA applies to medical data gathered by AI depends entirely on who is deploying the technology. Providers, organizations and agencies subject to the law\u2019s regulations are known as HIPAA-covered entities.<\/p>\n<p>Those entities include providers such as doctors and psychologists and their clinics or practices. Health plans \u2014 whether from health insurance companies, an employer or the government \u2014 are also covered.\u00a0<\/p>\n<p>More or less, HIPAA applies to any individual or entity that comes into contact with or processes protected health information.<\/p>\n<p>Given that a doctor\u2019s office is a HIPAA-covered entity, protections apply whether sensitive health data has been collected by a human or AI receptionist.<\/p>\n<p>Importantly, however, medical information handed over to chatbots used by companies outside the health care industry do not appear to receive the same protections.\u00a0<\/p>\n<p>Even as companies such as OpenAI and xAI <a href=\"https:\/\/www.cnbctv18.com\/technology\/elon-musk-promotes-grok-for-medical-advice-despite-privacy-warnings-just-take-a-picture-ws-l-19852550.htm\" rel=\"nofollow noopener\" target=\"_blank\">tout the ability<\/a> of chatbots to respond to health-related inquiries, <a href=\"https:\/\/cyberscoop.com\/ai-healthcare-apps-hipaa-privacy-risks-openai-anthropic\/\" rel=\"nofollow noopener\" target=\"_blank\">experts warn<\/a> that data protections outlined in terms of service agreements are not the same as those from HIPAA.<\/p>\n<p>De-identifying \u2014 and re-identifying \u2014 data<\/p>\n<p>Regardless of where it\u2019s collected, health data can be altered to remove HIPAA protections. Protected health data is regularly stripped of identifying information, such as a patient\u2019s name, in a process known as de-identification.<\/p>\n<p>De-identified health data <a href=\"https:\/\/san.com\/cc\/health-insurance-companies-are-selling-your-data-to-big-pharma\/\" rel=\"nofollow noopener\" target=\"_blank\">can then be sold<\/a> to everyone from data brokers to pharmaceutical companies. This industry, currently valued at over $9 billion, has existed for decades. In the case of the pharmaceutical industry, prescription and insurance information can be purchased to in turn target doctors for marketing purposes.<\/p>\n<p>While such sales may seem trivial given that the data has been anonymized, a team of researchers recently reported on the ease of <a href=\"https:\/\/www.unite.ai\/increasingly-hipaa-cant-stop-ai-from-de-anonymizing-patient-data\/\" rel=\"nofollow noopener\" target=\"_blank\">re-identifying health care information<\/a>, raising serious questions over HIPAA\u2019s validity in the age of AI.<\/p>\n<p>The New York University research team found re-identifying data to be trivial.<\/p>\n<p>In one example they cited in a research paper, de-identified notes from a hospital that only mentioned a pregnant woman who enjoyed horseback riding allowed AI to single out a specific patient \u2014 correctly inferring the patient\u2019s gender, socioeconomic class and the type of neighborhood she lived in.<\/p>\n<p>Even when industry best practices are followed, de-identified clinical notes \u201cremain statistically tethered to identity through the very correlations that confirm their clinical utility,\u201d the <a href=\"https:\/\/arxiv.org\/pdf\/2602.08997\" rel=\"nofollow noopener\" target=\"_blank\">research paper<\/a> says. \u201cThe conflict is structural instead of technical.\u201d<\/p>\n<p>However, Jiang said tools exist to help patients keep their data secure.<\/p>\n<p>\u201cFor many personal health care uses,\u201d she said, \u201cpatients may be able to achieve satisfactory performance using open source models running on secure, local hardware, ensuring the data never leaves the patient\u2019s control.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"In 1996, Congress enacted a law to assure Americans that their sensitive personal health data would never be&hellip;\n","protected":false},"author":2,"featured_media":299669,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34],"tags":[134,527,111,139,69],"class_list":{"0":"post-299668","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-healthcare","8":"tag-health","9":"tag-healthcare","10":"tag-new-zealand","11":"tag-newzealand","12":"tag-nz"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts\/299668","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/comments?post=299668"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts\/299668\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/media\/299669"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/media?parent=299668"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/categories?post=299668"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/tags?post=299668"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}