4 ms·
Is it legal in the US to send patient data to a third party service? In the context of a scientific study, with explicit patient agreement things are different
by jspdown 4y ago
Is it legal in the US to send patient data to a third party service?
In the context of a scientific study, with explicit patient agreement things are different of course. But I haven't seen any of that in the article.
- amai 4y agoThe author writes in the article: „I anonymized my History of Present Illness notes for 35 to 40 patients — basically, my detailed medical narrative of each person’s medical history, and the symptoms that brought them to the emergency department — and fed them into ChatGPT.“
- aix1 4y agoDoing this sort of thing would typically require approval from an ethics committee (called IRB = Institutional Review Board). From my experience of going through IRB reviews, I would guess that an IRB review for what's described in the blog post would be focussed on the privacy of subjects whose data is to be entered into a non-HIPAA-compliant third-party system. My understanding is that privacy requirements can typically be met either by de-identifying the data to a certain standard, or obtaining patients' consent. The following doc is about a different type of thing (case reports in medical journals) but gives a good idea of the required standard of de-id: https://hipaa.yale.edu/sites/default/files/files/Case%20Reports%20and%20Patient%20Privacy.pdf https://hipaa.yale.edu/sites/default/files/files/Case%20Repo...