Legal Marketing Radio
AI and HIPAA Compliance: Governance, Observability, and Human-in-the-Loop Safeguards On Legal Marketing Radio, the host interviews Steve Goulet, a healthcare technology executive with 20+ years' experience, about using AI in healthcare while staying HIPAA-compliant. Goulet emphasizes AI must remain a tool with a human in the loop and should not independently make clinical decisions due to hallucination risk and unclear regulatory alignment. He describes AVI's AI uses—operational AI, ambient listening scribes integrated with the EHR, and a custom support bot for the website and patient/support portals—plus moving to Claude Enterprise under a BAA for enterprise controls and observability. He stresses auditable monitoring, data retention, guardrails to limit PHI exposure, and minimizing third-party data sharing by hosting an open-source stack internally. The discussion covers prompt injection risks, system prompts, automated testing using prompt libraries and tools like LangFuse/LangSmith, DevOps-style release practices, and cautious, state-by-state regulatory engagement for emerging interfaces like digital human avatars. 00:00 AI and HIPAA Overview 00:11 Meet Steve Goulet 02:01 AI as Tool Not Clinician 07:08 Building Compliant AI Stack 09:50 PHI Control and Vendors 13:09 Auditability for Small Teams 16:35 Testing and Guardrails 20:13 Prompt Injection Risks 23:21 System Prompts and DevOps 27:26 Regulatory Caution and Litigation 29:43 Digital Human Avatar Plans 31:59 Wrap Up and Next Steps
51 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y forma parte de la comunidad de Legal Marketing Radio!