Live data from Hacker News

Show HN: Using GPT-3 and Whisper to save doctors’ time

news.ycombinator.com

131–140 of 141 posts

Re: Show HN: Using GPT-3 and Whisper to save doctors’ time

#131
post #126

This is the scariest real life attempt to use the bullshit machine I’ve seen so far. Nothing like “subtly wrong” clinical notes to affect positive medical outcomes. And time pressed medical professionals are certainly well suited to vigilance tasks like correcting machine generated errors. /s. I sincerely hope this never sees the light of day.

If you think this is scary you should see how it's done today without AI. Doctor's handwriting is notoriously bad. Now try putting that into an EMR. Good luck with that! You think you're going to get someone who gets paid $2000/hr to type shit up? Yeah, guess again.

We don’t get paid even close to $2k/hr. Where is that number from? Many physicians type notes, others use dragon dictation, or medical assistants/scribes.

I used to type, now I dictate.

Quality of note is provider dependent though. If an LLM can improve quality of notes across the board through simple summary that’s interesting. But the input matters - is the provider actually asking the right questions? Did they look at past relevant history and other notes and put it in their current note?

The LLM should be in a HIPAA compliant environment and have access to the EMR. Then it provides a tidy summary for that. Second it should have relevant questions for the provider to ask during the interview but also a real time/dynamic component which generates relevant follow up questions dependent on patient responses.

Lastly it should put together the old and the new and generate a new note which can then be edited by the provider. Editing notes is much easier than generation of a new high quality note.

Re: Show HN: Using GPT-3 and Whisper to save doctors’ time

#132
post #97

Earlier quoted context omitted.

Thanks for looking into our legal documents. The ones related to the Nabla Copilot product are different from the website T&C and privacy policy, and can be found here: https://www.nabla.com/legal-documents/ Our product is GDPR compliant.

I read the French legal documents and your notices regarding GDPR. What I don't understand from those, and statements made by your team in this thread, is how some claims can be compatible. - That the product is GDPR compliant. - That you don't store the PII or health data. - Yet all data is stored at Google servers. - Also, you reserve the right to re-use said data. (Which, since this is for R&D purposes, should pro…

You're absolutely right, we should have been much more upfront with the privacy/security aspect of the product and add this link to the post: https://www.nabla.com/blog/privacy-security/

I hope this link will clarify our position.

Here are additional answers related to your points. - We do use Google Cloud to host our backend in EU or in the US but also the data for the Care Platform product. For the Copilot product, we don't host any data. They are hosted locally on the practitioner browser. - Our T&C reserves the right to re-use data in the event we will store the data in future versions of Nabla Copilot. In any case, the reuse of data, even health data, is allowed by GDPR for the improvement of the service provided if the data controller (practitioner) authorizes us and if they have informed the patient. - We did not say that "none of the data is sent outside the EU". Actually we say the opposite in the Copilot APD Annexe 1. We specifically mention Google and OpenAI and we comply with GDPR with a data protection agreement with both these companies.

Re: Show HN: Using GPT-3 and Whisper to save doctors’ time

#133
post #16

I feel uncomfortable knowing doctor would use anything like this. How are 2 party consent states handled? Is this HIPPA compliant?

This! No mention of HIPAA on their site at all. Would be a total non-starter for any providers not in private practice.

Kindly reminder that HIPAA is a particular law applicable only in a single particular country.

Re: Show HN: Using GPT-3 and Whisper to save doctors’ time

#134

Pretext: My wife is a psychiatrist. Via her, I'm am close friends with many doctors. Also, I know it's super easy to be critical, but I'm going to save you an insane amount of effort and heartache. This is actually a solved problem in medicine, already. Maybe not solved, but absolutely "good enough". M-Modal, Dragon, and Telephone services (yes, call someone and have them translate) all exist. They all translate note…

Right now I am working on an MVP of a product just like this one for a private psychiatry practice.

> HIPAA - You absolutely, 100%, without a doubt need to be HIPAA compliant

This is incorrect: kindly reminder that HIPAA is a specific law applicable only to a single particular country. The vast majority of the world does not need to be compliant to it. Although similar laws exists elsewhere, they are not at all insurmountable.

> More tactically, most EHR access occurs via remote access

I have never seen a system where EHR access is used via remote desktop. (Although I admit that would be a good security measure). But then again, I'm not in the US.

> can this system differential between prednisone and prednilisone

Whisper is nothing short of magic in this regard. Yes it can - out of the box. Even more: it can easily differentiate lots of medical terms in languages other than english. Even more: it can easily parse compound terms like "hypothalamic–pituitary–gonadal axis" in other languages where first two words sounds very very similar.

I reckon that differentiating prednisone and prednisolone in doctor's writing is a harder problem than differentiating those from voice.

--

Having said that, your concerns and remarks are very valid. This is why we are not focusing on replacing written records/EHR fill out. There are other ways AI and large language models could deliver help for psych practice and the patient. And safer.

Re: Show HN: Using GPT-3 and Whisper to save doctors’ time

#135

Earlier quoted context omitted.

From their main page ( https://www.nabla.com/ ), the mention HIPAA: Secure and HIPAA-eligible Audio, transcripts, and notes are not stored by Nabla HIPAA-eligible and GDPR compliant SOC 2 and ISO 27001 certifications in progress Digging deeper ( https://www.nabla.com/blog/privacy-security/ ): This data processing is done on Nabla's servers, which are powered by the HIPAA and GDPR compliant Google Cloud Platform (GCP)…

What does "HIPAA-eligible" mean? EDIT: I was very curious about this and did a bit of research. The answer to it is squishy. It seems to be mostly a marketing term. The best definition I found was this: "A service that is HIPAA eligible is one that is capable of being configured in a way that could meet HIPAA compliance requirements, but you have to know how to do it, it doesn’t happen ‘out of the box.’" https://www.…

Hi everyone! We’re of course well aware of the importance of HIPAA for all organizations operating in the US. To clear up any confusion: HIPAA-eligible means in our case that we’re ready to sign BAAs.

Re: Show HN: Using GPT-3 and Whisper to save doctors’ time

#136
post #129
post #124

Earlier quoted context omitted.

Many practices today have a transcriber with every doc, and that person is their personal scribe. You trust them, right? In any case HIPAA will protect you. Your provider will have a business associate contract with them, so they're subject to huge fines if they violate that. This is a demo. In real life this'll be wrapped with a whole lot of legal contracts.

I trust a scribe because they are a person with years of specialised training and experience who can be held accountable. > in any case, HIPAA will protect you It protects you insofar as it disincentives honest actors from doing sketchy things with your data. It's punishment for orgs, not protection for patients, like how laws against murder punishes the murderer rather than protecting the victim. The best thing a pa…

"I trust a scribe because they are a person with years of specialised training and experience who can be held accountable."

They can be held accountable, but it's unclear how much specialized training or experience they actually have. They could have had a 6-month course, an online course, etc.

And of course you're assuming their EMR is actually secure. In a small office you can usually find the passwords you need stuck to the monitor or under the keyboard.

Re: Show HN: Using GPT-3 and Whisper to save doctors’ time

#137
post #125

Earlier quoted context omitted.

What that really means is: * they may be HIPAA-compliant (ie: they fulfill the requirements), * they haven't gone through a HIPAA-certification (no third-party cert), * they aren't using services that aren't HIPAA-certifiable The latter point is important, because there are some services (ie: firebase) that apparently won't be HIPAA compliant. Some services are HIPAA-compliant if configured correctly. AWS has a list.…

HIPAA is a self certification. You can claim compliance simply by following the rules. Therefore, you’re either HIPAA compliant or your not. I have never heard anyone describe it as being HIPAA-eligible. HITRUST is a third party audit with higher standards than HIPAA. That is not a self-attestation. I’ve spent a bunch of time in this space. Most of the major players offer HIPAA compliant services and sign BAAs. As of…

Well, HIPAA can be self-certified, but that probably won't stand up in court so most organizations will pay a third-party provider to perform the certification for them. That also lets you see the gaps, because HIPAA is big.

Here's AWS's list of HIPAA-eligible services. HIPAA-eligible is technology provider specific:

https://aws.amazon.com/compliance/hipaa-eligible-services-re...

Here's google's:

https://cloud.google.com/security/compliance/hipaa-complianc...

In general it means that the service may not be HIPAA compliant by default, but can be configured to be HIPAA compliant.

HITRUST is something else and it outside the scope of this discussion IMO. Not sure why you brought that up.

Re: Show HN: Using GPT-3 and Whisper to save doctors’ time

#138
post #137

Earlier quoted context omitted.

HIPAA is a self certification. You can claim compliance simply by following the rules. Therefore, you’re either HIPAA compliant or your not. I have never heard anyone describe it as being HIPAA-eligible. HITRUST is a third party audit with higher standards than HIPAA. That is not a self-attestation. I’ve spent a bunch of time in this space. Most of the major players offer HIPAA compliant services and sign BAAs. As of…

Well, HIPAA can be self-certified, but that probably won't stand up in court so most organizations will pay a third-party provider to perform the certification for them. That also lets you see the gaps, because HIPAA is big. Here's AWS's list of HIPAA-eligible services. HIPAA-eligible is technology provider specific: https://aws.amazon.com/compliance/hipaa-eligible-services-re... Here's google's: https://cloud.google…

> Well, HIPAA can be self-certified, but that probably won't stand up in court

The is no certification requirement, so there is nothing to ”stand up in court”. Straight from the horse's mouth:

Are we required to “certify” our organization’s compliance with the standards of the Security Rule?

Answer: No, there is no standard or implementation specification that requires a covered entity to “certify” compliance.

https://www.hhs.gov/hipaa/for-professionals/faq/2003/are-we-...

Re: Show HN: Using GPT-3 and Whisper to save doctors’ time

#140
I'm a medical student and one of my main takeaways from spending time in clinical environments is that a lot of doctors and other staff seem to either not realise or not care about how much time is wasted due to slow, inefficient processes and technology. I was wondering to myself about what it might take to train a model to recognise medical jargon to help doctors rapidly transcribe audio recordings of their consults/spoken recounts of their notes. Not surprised that somebody is looking to make a commercial product of it, there's definitely space for it.
Post reply on HN