Live data from Hacker News

Zoom terms now allow training AI on user content with no opt out

explore.zoom.us

451–460 of 538 posts

Re: Zoom terms now allow training AI on user content with no opt out

#451

Earlier quoted context omitted.

IANAL, but I did health tech for 10 years and had my fair share of interactions with lawyers asking questions about stuff I built. HIPAA applies to the provider. Patient have no responsibility to ensure the tech used by their care provider is secure or that their medical records don't wind up on Twitter. HIPAA dictates that the care providers ensure that happens by placing both civil and sometimes criminal liability…

I don’t think the question is about Zoom’s safeguards which are audited, and as you say almost certainly stronger than HIPAA requirements, but rather whether they can use the stored PHI for product development where the law appears ambiguous.

Imo the law basically says you can do this with PHI:

-De-identify it then do whatever you want with it -use it to provide some service for the covered entity, but not for anyone else -enter a special research contract if you want to use it slightly de-identified for some other specific purpose

Re: Zoom terms now allow training AI on user content with no opt out

#452

Tangentially related, but a number of telehealth operations with hospitals/therapists/etc... use Zoom -- I suspect because their clients can connect without an app or an account over a browser. When you join a Zoom session over the browser, you don't sign a TOS. And I assume that actual licensed medical establishments are under their own TOS provisions that are compatible with HIPPA requirements. Training on voice-to…

Looks like they have a separate offering, Zoom for Healthcare that presumably has different terms and conditions. https://blog.zoom.us/answering-questions-about-zoom-healthca...

What if you discuss sensitive health-related details with someone other than your doctor, for example your attorney?

The privacy issues here are bottomless, and so are the legal issues.

Re: Zoom terms now allow training AI on user content with no opt out

#453
post #442

Tangentially related, but a number of telehealth operations with hospitals/therapists/etc... use Zoom -- I suspect because their clients can connect without an app or an account over a browser. When you join a Zoom session over the browser, you don't sign a TOS. And I assume that actual licensed medical establishments are under their own TOS provisions that are compatible with HIPPA requirements. Training on voice-to…

Related to this, anyone know if Zoom has a separate offering for education (universities, schools, etc)? I teach at a university, and not only do we use Zoom for lectures etc, but also for office hours, meetings, etc, where potentially sensitive student information may be discussed. I'm probably not searching for the right thing; all I found was this: https://explore.zoom.us/docs/doc/FERPA%20Guide.pdf (FERPA is to hi…

Both my undergraduate and universities have free Zoom under .zoom.us, so I assume it's separate

Re: Zoom terms now allow training AI on user content with no opt out

#454
post #338
post #326

This is very much like the Black Mirror episode Joan Is Awful. By using modern services we consent to our data, including our likeness, being used in any way the service can extract value from it. User data is such a gold mine that most services should be paying their users instead. Even giving the service away for "free" doesn't come close to making this a fair exchange. Not to sound pessimistic, but we are already…

Balaji talks a lot about the state losing power in the future, but I don't think this is how he was envisioning it.

As far as I can tell he's not only pretty sure he'll be part of the class that holds power like this without accountability to any state, he consistently makes manipulative statements which function to move things in that direction.

Re: Zoom terms now allow training AI on user content with no opt out

#455
post #342
post #334

Earlier quoted context omitted.

In the US I don't know a single person that has access to POTS. Discord (with paid nitro) is the gold standard for quality and latency, followed by all the free VoIP apps

I live in the US, and I'm pretty sure everyone I know has a landline, though a good number of them are now digital/fiber/whatever. Some people I know still have multiple landlines, as it's cheaper than paying multiple cell bills if necessary. I know at least one person who used to have call forwarding set up to get calls on their cellphone, but with the current state of marketing calls they probably don't do that any…

The only people I know who still have a landline are my grandparents who are in their 70s

Re: Zoom terms now allow training AI on user content with no opt out

#456

Earlier quoted context omitted.

Looks like they have a separate offering, Zoom for Healthcare that presumably has different terms and conditions. https://blog.zoom.us/answering-questions-about-zoom-healthca...

What if you discuss sensitive health-related details with someone other than your doctor, for example your attorney? The privacy issues here are bottomless, and so are the legal issues.

The law doesn't protect it. HIPAA doesn't apply in that setting.

Attorney client privilege is an interesting case.

"Privacy issues" is a meaningless phrase to me when divorced from the law. Do you mean, like, ethically concerning? This term in the contract is neither uncommon nor illegal.

Re: Zoom terms now allow training AI on user content with no opt out

#458

Earlier quoted context omitted.

I don’t think the question is about Zoom’s safeguards which are audited, and as you say almost certainly stronger than HIPAA requirements, but rather whether they can use the stored PHI for product development where the law appears ambiguous.

Imo the law basically says you can do this with PHI: -De-identify it then do whatever you want with it -use it to provide some service for the covered entity, but not for anyone else -enter a special research contract if you want to use it slightly de-identified for some other specific purpose

One note is that the act of deidentification itself requires accessing PHI when done retroactively, this may be institutional policy or specific to covered entities but per the privacy office lawyers such access (apart from a small dataset) requires a permitted use to be accessible in order to then deidentify and use freely.

As with all things HIPAA, this only becomes a problem when HHS starts looking and I’m sure in practice many people ignore this tidbit (if in fact this is the law and not Stanford policy).

Re: Zoom terms now allow training AI on user content with no opt out

#459

Earlier quoted context omitted.

IANAL but “Zoom for Healthcare” is a business associate under HIPAA and treated as an extension of the provider with some added restrictions. Covered entities (including the EMR and hospital itself) can use protected health information for quality improvement without patient consent and deidentified data freely. Where this gets messy is that deidentification isn’t always perfect even if you think you’re doing it righ…

Haha wow this is a great post. I am a lawyer and you may have solved a problem I recently encountered. So you think this is saying that generic language in the Zoom BAA constitutes permission to de-identify? Are there examples of healthcare ai chatbots trained on de-id data btw? If you're familiar would love to see. What's your line of work out of curiosity?

> Haha wow this is a great post. I am a lawyer and you may have solved a problem I recently encountered. So you think this is saying that generic language in the Zoom BAA constitutes permission to de-identify?

Not that I’m an expert on the nuance here but I think it gives them permission to use PHI, especially if spun in the correct way, which then gives them permission to deid and do whatever with.

My experience has been that it’s pretty easy to spin something into QI.

> Are there examples of healthcare ai chatbots trained on de-id data btw? If you're familiar would love to see.

https://loyalhealth.com/ is one I’ve recently heard of that trains on de-id’d PHI from customers.

> What's your line of work out of curiosity?

Previously founded a health tech startup and now working primarily as a clinician and researcher (NLP) with some side work advising startups and VCs.

Post reply on HN