As a medical doctor I extensively use digital voice recorders to document my work. My secretary does the transcription. As a cost saving measure the process is soon intended to be replaced by AI-powered transcription, trained on each doctor’s voice. As I understand it the model created is not being stored locally and I have no control over it what so ever.

I see many dangers as the data model is trained on biometric data and possibly could be used to recreate my voice. Of course I understand that there probably are other recordings on the Internet of me, enough to recreate my voice, but that’s beside the point. Also the question is about educating them, not a legal one.

How do I present my case? I’m not willing to use a non local AI transcribing my voice. I don’t want to be percieved as a paranoid nut case. Preferravly I want my bosses and collegues to understand the privacy concerns and dangers of using a “cloud sollution”. Unfortunately thay are totally ignorant to the field of technology and the explanation/examples need to translate to the lay person.

  • lorty@lemmygrad.ml
    link
    fedilink
    arrow-up
    0
    ·
    7 months ago

    This is really weird. Is it common in other countries for doctors to not input the data in the system themselves?

    • 520@kbin.social
      link
      fedilink
      arrow-up
      0
      ·
      7 months ago

      Not OP but if I were him/her: Leakage of patient data. Even if OP isn’t responsible, simply being tied to an incident like this can look very bad in fields that rely heavily on reputation.

      AI models are known to leak this kind of information, there are news articles all over

    • FlappyBubble@lemmy.mlOP
      link
      fedilink
      arrow-up
      0
      ·
      edit-2
      7 months ago

      My biometric data, in this case my voice. Training an AI, tailored to my voice, out of my control, hosted as a cloud solution.

      Of course there is an aspect of patient confidenciality too, but this battle is already lost. The data in the medical records is already hosted outside of my hospital.

      • SheeEttin@programming.dev
        link
        fedilink
        English
        arrow-up
        0
        ·
        7 months ago

        Sounds like a weak argument. They’re not going to be inclined to operate a local ML system just for one or two people.

        I would see if you can get a quote for locally-hosted transcription software you can run on your own, like Dragon Medical. Maybe reach out to your IT department to see if they already have a working relationship with Nuance for that software. If they’re willing to get you started, you can probably just use that for dictation and nobody will notice or care.

  • Boozilla@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    7 months ago

    Will they allow you to use your own non-cloud solution? As long as you turn in text documents and they don’t have to pay a person to transcribe, they should be happy. There are a number of speech to text apps you can run locally on a laptop, phone, or tablet.

    But of course, it’s sometimes about control and exercising their corporate authority over you. Bosses get off on that shit.

    Not sure which type of doctor you are, but there’s a general shortage of NPI people. I hope you can fight back with some leverage. Best of luck.

    • FlappyBubble@lemmy.mlOP
      link
      fedilink
      arrow-up
      0
      ·
      7 months ago

      It will not be possible to use my own software. The computer environment is tightly controlled. If this is implemented my only input device to the medical records will be the AI transcriber (stupidity).

      I’m a psychiatrist in the field of substance abuse and withdrawal. Sure there’s a shortage of us too but I wan’t the hospital to understand the problem, not just me getting to use a old school secretary by threatening gping to another hospital.

      • wizardbeard@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        0
        ·
        7 months ago

        my only input device to the medical records will be the AI transcriber

        I understand that you keep steering away from legal arguments, but that can’t be legal either. How could a doctor not have direct, manual access to patient records?

        Anyway, practical issues:

        You need some way to manually interact with patient records in the inevitable event the AI transcription gets it wrong. It only takes one time messing up transcription on something critical and you have a fucking body on your hands. Is your hospital prepared to give patients the wrong dosages because background noise or someone else speaking makes the AI mishear? Who would be held responsible in the case of mistreatment due to mistranscription? Is your hospital willing to be one of the first to try and tackle that legal rats nest?

        A secretary is able to do a sanity check that what they heard make sense. AI transcription will have no such logic behind it. It will turn what it thinks it heard into text and chuck it wherever it logs to. It thinks you’ve called for leeches when you said something about lesions? Have fun.

        Whenever there’s an issue with the transcription service you’d be screwed too. That could mean network outage, power outage, microphone breaks, any part of this equipment breaks, and this whole system falls apart.

        • FlappyBubble@lemmy.mlOP
          link
          fedilink
          arrow-up
          0
          ·
          7 months ago

          The problem with incorrect transceiption exists with my secretary too. In the system I work in the secretary write my recordibg, sends it to me, I read it. I can edit the text at this point and then digitally sign it with a personal private key. This usually happens at least a day after being recorded. All perscriptions or orders to my nurses are given inannother system besides the raw text in the medical records. I can’t easily explain the practical workings but I really don’t see that the AI system will introduce more errors.

          But I agree that in the event of a system failure, there will be a catastrophic situation.

      • Boozilla@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        7 months ago

        I was afraid that might be the case. Was hoping they would let you upload the files as if you had typed them yourself.

        Maybe find some studies / articles on transcription bots getting medical terminology and drug names wrong. I’m sure that happens. AI is getting scary-good, but it’s far from perfect, and this is potentially a low-possibility-but-dangerous-consequences kind of scenario. Unfortunately the marketers of their software probably have canned responses to these types of concerns. Management is going to hear what they want to hear.

        • FlappyBubble@lemmy.mlOP
          link
          fedilink
          arrow-up
          0
          ·
          7 months ago

          Thaks fot he advice but I’m not against using AI-models transcribing me, just not a cloud model specifically trained on my voice without any control by me. A local model or more preferrably a general local model woulf be fine. What makes me sad is that the persons behind this are totally ignorant to the problem.

          • Boozilla@lemmy.world
            link
            fedilink
            English
            arrow-up
            0
            ·
            7 months ago

            I understand, and we’re basically on the same page. I’m not fully anti-AI, either. Like any tool, it can be used for good or evil. And you are right to have concerns about data stored in the cloud. The tech bros will mock you for it and then… oh look, another data breach has it been five minutes already. :)

            • FlappyBubble@lemmy.mlOP
              link
              fedilink
              arrow-up
              0
              ·
              7 months ago

              Yes I agree. Broadening the scope a little, I frankly just wait for a big leak of medical records. The system we use is a birds nest of different softwares, countless API:s, all sorts of database backends. Many systems syem from MS-DOS, just embedded in a bit more modern integrated environment. There are just so many flaws and I’m amazed a leak hasn’t happened (or at least surfaced) yet.

  • stevedidwhat_infosec@infosec.pub
    link
    fedilink
    arrow-up
    0
    ·
    7 months ago

    Simple jobs are going to continue to go away in favor of more efficient spending.

    You’re not going to get around the removal of simple jobs from the market in favor of newer concepts and more complex operations.

    All these people that said going to college to further your education was stupid and a waste of money are going to be the first to bitch and moan because the rest of us who spent the time and money to better ourselves would like to reciprocate that same logic into the world so you don’t have to worry about things like underpaid fast food workers spitting in your food, delivery drivers stealing your food, etc.

    Some people who can only do “simple” tasks are the ones who stand the most to be hurt by the world moving forward and becoming more advanced and complex, but I’m not sure what we can do to help them outside of seriously considering UBI. The wealth we are generating and saving through automation deserves to be equally spread amongst the people it replaced. That’s fair.

    • off_brand_@beehaw.org
      link
      fedilink
      arrow-up
      0
      ·
      7 months ago

      I think it was pretty clear the issue was one of privacy requirements and not any qualms with losing jobs, which isn’t even happening here.

      • stevedidwhat_infosec@infosec.pub
        link
        fedilink
        arrow-up
        0
        ·
        7 months ago

        They do pretty specifically mention the using their own voice thing, good point.

        However I’d like to remind everyone that recording you while in public is done and done so very frequently (look at all the whistle blower docs) so it’s really moot imo whether or not there exists recordings of your voice.

        And everything else I said still stands. Idgaf about the doctor who still goes home with some of the highest salaries in the public. Personally, I think medical practitioners should be a part of working for the state or the govt, and you basically become a servant to the public. Imo doctors should be held to the same public scrutiny but that’s a diff topic.

        • off_brand_@beehaw.org
          link
          fedilink
          arrow-up
          0
          ·
          7 months ago

          Not in public. This is a conversation with the healthcare provider, not with your partner while you’re at the grocery store. You have a legally recognized right to privacy (at least in the US) when it comes to your health details.

          Which is an unequivocally good thing.

  • BurningRiver@beehaw.org
    link
    fedilink
    arrow-up
    0
    ·
    7 months ago

    I would suggest that that first action item would be is to ask for (in writing) are 1) data protection and 2) privacy policies. I would then either pick it apart, or find someone who works in cybersecurity (or the right lawyer) to do that. I’ve done it a few times and talked my employer out of a few dodgy products, because the policies clearly try to absolve the vendor of any potential liability. Now, whether the policies truly limit liability would have to be tested in court.

    You could also talk about how data protection, encryption, identity and access management, and governance is actually really expensive, but I’d first start poking holes in the actual policies to create doubt.

  • 7heo@lemmy.ml
    link
    fedilink
    arrow-up
    0
    ·
    7 months ago

    I would have work sign a legal discharge that from the moment I use the technology, none of the recordings or transcription of me can be used to incriminate me in case of an alleged malpractice.

    In fact, since both are generated or can be generated in a way that both sounds very assertive but also can be adding incredibly wild mistakes, in a potentially life and death situation, they legally recognise potentially nullifying my work, and taking the entire legal responsibility for it.

    As you can see in the most recent example involving Air Canada, a policy has been invented out of thin air. Such policy is costing the company. In the case of a doctor, if the administration of the wrong sedative, the wrong medication, or if the wrong diagnosis was communicated to the patient, etc; all that could have serious consequences.

    All sounding (using your phrasings, etc) like you, being extremely assertive, etc.

    A human doing that job will know not to derive from the recording. An AI? “antihistaminic” and “anti asthmatic” aren’t too far off, and that is just one example off of the top of my head.

  • Bobby Turkalino@lemmy.yachts
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    7 months ago

    It would be worth finding out more about how exactly the training process works, namely whether or not the AI company stores the training audio clips after training has been completed. If not, then I would say you don’t have anything to worry about, because the model itself can’t be used to clone your voice to any useful extent. Deep neural networks aren’t reversible like that. Even if they were, it’s not just trained on you, it’s trained on hundreds of thousands of people then fine-tuned to you.

    If they do store the clips though, then maybe show them this article about GitHub to prove to them that there is precedence for private companies using people’s data to train AI without their explicit consent.

    • Adalast@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      7 months ago

      To expound on this, AI models are extremely narrow in scope. One which reproduces audio it is trained on is entirely different from one that understands what is being said. As Mr. Turkalino mentioned, the transcription AIs are built on a combination of speech recognition and incredibly specialized text data that is narrowly defined by your industry (medical in this case). In fact, they may have tuned specific models for separate disciplines. This included thousands of documents ranging from textbooks to scholarly journals along with thousands of recordings of professionals saying the words in a variety of accents and dialects so it can understand the difference between very important and very different sounding words, my wife is pregnant, so amnioitis and amniocentesis come to mind. They are close enough sounding that a general model might mistake them, and that being transcribed wrong could spell real problems when others may look at the patients chart if there are complications.

      Also, most models are run in the cloud because the calculations can he very taxing. I run Stable Diffusion and other AIs locally on my beast of a machine and it struggles at times. Realistically, the cloud machines are just bugger than you can get as a desktop. Also, under the most ideal circumstances, the audio of your notes does not live in the servers, it is transmitted, stored on a virtual machine (VM) while it is being processed, then after the results are completed the VM is destroyed and the audio recording goes with it. Nothing is kept. Of course, that is where you need to be sure to do the work, making sure that your situation is “ideal”. One of the biggest controversies in with AI right now is that data is being stored for doing reinforcement training on the AI models. Example, you send your recordings and the AI returns the transcript. You mark any corrections and go on with your day. The company takes those recordings and feeds them back into the general model with the corrections you made and tries to tell the AI what it got wrong. You are going to want to be sure that you are allowed to opt-out of your data being allowed to be used as training data (beyond the fine-tuning to help it learn your voice).

  • Boozilla@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    7 months ago

    I had another idea. You might be able to use something that distorts your voice so that it doesn’t sound anything like you, but the AI can still transcribe it to text. There are some cheap novelty devices on amazon that do this, and also some more expensive pro audio gear that does the same thing. Just a thought.

    • FlappyBubble@lemmy.mlOP
      link
      fedilink
      arrow-up
      0
      ·
      7 months ago

      Sure but what about my peers? I want to get the point across and the understanding of privacy implications. I’m certain that this is just the first of many reforms without proper analysis of privacy implications.

      • Possibly linux@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        ·
        7 months ago

        Honestly I would be way more concerned about your patients privacy. You shouldn’t just ship medical data to some third party. That leads to massive data breaches.

        • Boozilla@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          7 months ago

          I agree with you but that ship has sailed. I work with big medical data and it’s shocking the stuff that gets stored and passed around. The really big players like PBMs and major insurance providers are supposed to abide by HIPAA but they do not fear enforcement at all. Only the small fish like doctors, etc, need fear HIPAA.

    • Possibly linux@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      7 months ago

      Voice cloning is the least of your concerns honestly as you are sending people private information to the cloud.

  • Spyder@lemmy.ml
    link
    fedilink
    arrow-up
    0
    ·
    edit-2
    7 months ago

    Do your patients know that their information is being transcribed in the cloud, which means it could potentially be hacked, leaked, tracked, and sold? How does this foster a sense of distrust, and harm the patients progress?

    Could you leverage this information and the possibility of being sued if information is leaked with the bureaucrats?

  • small_crow@lemmy.ca
    link
    fedilink
    arrow-up
    0
    ·
    7 months ago

    I assume you’ll be using Dragon Medical One. Nuance is a well established organization, with users in a broad range of professions, and their medical product is extensively used by many specialists. The health system where I live has been in the process of phasing out transcriptionists in favor of it for a decade or so.

    The only potential privacy concerns a hospital would care about would be if they are storing your transcripts on their servers, because that will contain sensitive information about patients. It will be impossible to get any administrator to care about your voice data.

    This tide is unlikely one you will be able to stem, but you could stop dictating and type it yourself.

    • FlappyBubble@lemmy.mlOP
      link
      fedilink
      arrow-up
      0
      ·
      7 months ago

      I’m not sure what exact service will be used. I won’t be able to type as the IT environment is tightly controlled and they will even remove the keyboard as an input device for the medical records.

  • macniel@feddit.de
    link
    fedilink
    arrow-up
    0
    ·
    7 months ago

    Shouldn’t that be a HIPAA violation? Like you can’t in good conscious guarantee that the patient data isn’t being used for anything but the healthcare.

    • FlappyBubble@lemmy.mlOP
      link
      fedilink
      arrow-up
      0
      ·
      edit-2
      7 months ago

      My question is not a legal one. There probably are legal obstacles for my hospital in this case but HIPAA is not applicable in my country.

      I’d primarily like to get your opinions of how to effectively present my case for my bosses against using a non local model for this.

      • 520@kbin.social
        link
        fedilink
        arrow-up
        0
        ·
        7 months ago

        Look to your local health privacy laws. Most countries have that tightly controlled in such a way that this use of AI is illegal.

        Your question is not a legal one, but a legal argument can be a very persuasive one.

    • Szymon@lemmy.ca
      link
      fedilink
      English
      arrow-up
      0
      ·
      7 months ago

      It is until they prove it isn’t, which they might not be able to do. Many trusted 23andme only to see private data stolen. Make the company prove the security in an place and the methods ensuring privacy, because you’ll essentially be liable for any failures of the system from a lack of due diligence.

      • lewdian69@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        edit-2
        7 months ago

        Voice recognition dictation has been used in the medical field for over a decade, probably even longer. My regional health system of multiple hospitals and clinics has been using an electronic based, like Dragon dictation, solution since at least 2012. Unfortunately in this case op is being overly paranoid and behind the times. I’m all for privacy but the HIPAA implications have already been well sorted out. They need to either learn to type faster or use the system provided that will increase their productivity and save the health system an fte that used to be used on their transcriptionist which can not be used more directly to care for patients.

        • Boozilla@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          edit-2
          7 months ago

          It is true that Dragon and similar apps have been used for years. But I don’t think it’s fair to say OP is being paranoid and a luddite. Data breaches in the cloud are a weekly occurrence, and OP wanting to protect their voice / biometrics is not foolish it’s smarter than the average bear. You can change a compromised password. You can’t change your biometrics or voice.

          Also, those products were used on local networks for many years before they entered the cloud. They gradually reduce our privacy over time, getting people numb to it.

        • BearOfaTime@lemm.ee
          link
          fedilink
          arrow-up
          0
          ·
          7 months ago

          “Overly paranoid”, with the practically-daily breaches of clouds based systems today?

        • BolexForSoup@kbin.social
          link
          fedilink
          arrow-up
          0
          ·
          7 months ago

          Voice recording =/= training an algorithm that can simulate my voice and use whatever I say with impunity.

          The recording a doctor makes of a patient is a known quantity with known copies for a known purpose. It is a calculated decision from top to bottom that has been sorted. AI training off of doctors’ dictations is not.

          • Szymon@lemmy.ca
            link
            fedilink
            English
            arrow-up
            0
            ·
            edit-2
            7 months ago

            I think the issue is moreso that you’re sending confidential health data to a 3rd party, which is where you lose control. You don’t know the intentions of people looking to steal that data, and you need to consider the worst possible outcome and guard against those. AI training is just one option. Get creative, what could you do with a doctor’s voice and their patient’s private medical history?

            Simplest solution is to stop the arrangement until the company can prove data security on their end or implement an offline solution on local servers not connected to the internet.

  • MajorHavoc@programming.dev
    link
    fedilink
    arrow-up
    0
    ·
    edit-2
    7 months ago

    Your voice-print is worth protecting.

    There’s already retirement funds activating “my voice is my password” by default, now. (You can, and absolutely should opt-out, if yours does.) And you can’t change your voice-print if it gets leaked. (Maybe with a professional voice coach, you could…)

    Personally, I would change employers over this, if I had the option.

    I think we’re heading towards having a group of citizens with compromised voice-prints leaked to the dark web, who have a harder time day to day through no fault of their own. Like the early SSN breach sufferers, history tells us that society says “it’s a shame”, and tries to protect the next generation properly, but doesn’t recompense those hurt by the early bullshit.

    While job searching, I would also request an accomodation, and not use the voice system. It’s much easier for the employer to retain a secretary for you, than to deal with the legal hassles that will come up if they try to fire you for not using their legal-gray-area solution.

    Even granted the accommodation, I would be looking for my next job though.

    • PM_me_trebuchets@lemm.ee
      link
      fedilink
      arrow-up
      0
      ·
      7 months ago

      Most places use this sort of software (at least, larger companies). I have worked with doctors who refused to use it and instead developed templates for common items they copied + pasted into the MAR software / PACS, etc., and they just type what they need. That’s what they did before dictation software existed anyway. It’s not as efficient, but it’s basically the only way to avoid this.

  • umami_wasabi@lemmy.ml
    link
    fedilink
    arrow-up
    0
    ·
    7 months ago

    So what’s your concern? I’m a bit confused.

    1. Using cloud to process patient data? Or,
    2. Collecting your voice to train a model?
    • DessertStorms@kbin.social
      link
      fedilink
      arrow-up
      0
      ·
      7 months ago

      Yeah, I’d be sooooo confident and reassured if I knew my doctor was prioritising the security of their voice of the security of my information… /s

      (yes, it can be both, but this post doesn’t seem at all concerned with one, and entirely with the other)

  • privsecfoss@feddit.dk
    link
    fedilink
    arrow-up
    0
    ·
    edit-2
    7 months ago

    I don’t where you live. But almost all of bigtec US cloud is problematic (Read: Illegal to use) for storing or processing of Personal information according to the GDPR if you’re based in the EU. Don’t know about HIPPA and other non-EU legislation. But almost all cloudservices use US bigtech as a subprocessor under the hood. Which means that the use of AI and cloud is most likely not GDPR-complaint. Which you could mention to the right people and hope they listen.

    Edit: It’s illegal to use for the processing of the patients PII, because of transfer to insecure third countries and because bigtech uses the data for their own purposes without any legal basis.

    • FlappyBubble@lemmy.mlOP
      link
      fedilink
      arrow-up
      0
      ·
      7 months ago

      I agree and I suspect this planned system might get scuttled before release due to legal problems. That’s why I framed it in a non legal way. I want my bosses to understand the privacy issue, both in this particular case but also in future cases.

    • pearsaltchocolatebar@discuss.online
      link
      fedilink
      arrow-up
      0
      ·
      edit-2
      7 months ago

      You don’t have to use a cloud service to do AI transcription. You don’t even need to use AI. Speech to text has been a thing for like 30+ years.

      Also, AWS has a FedRAMP authorized Gov Cloud that’s almost certainly HIPAA (and it’s non-us counterparts) compliant.

      Also also, there are plenty of cloud based services that are HIPAA compliant.

  • DontMakeMoreBabies@kbin.social
    link
    fedilink
    arrow-up
    0
    ·
    7 months ago

    You’re going to lose this fight. Admin types don’t understand technology and, at this point, I imagine neither do most doctors. You’ll be loud minority because your concerns aren’t concrete enough and ‘AI is so cool. I mean it’s in the news!’

    Maybe I’m wrong, but my organization just went full ‘we don’t understand AI so don’t use it ever,’ which is the other side of the same coin.

    • FlappyBubble@lemmy.mlOP
      link
      fedilink
      arrow-up
      0
      ·
      7 months ago

      I understand the fight will be hard and I’m not getting into it if I cant present something they will understand. I’m definetly in a minority both among the admin staff and my peers, the doctors. Most are totally ignorsnt to the privacy issue.