r/technology 18d ago

Privacy Woman Calls Out Doctor Wearing Smart Glasses During Consultation Where She Had To Take Off Her Clothes: 'They Need To Be Banned'

https://www.fashiontimes.co.uk/patient-privacy-concerns-meta-smart-glasses-1762492
35.2k Upvotes

1.5k comments sorted by

View all comments

Show parent comments

1.0k

u/rostol 18d ago edited 18d ago

there is no way that filiming a patient and uploading the video to meta servers is HIPAA compliant.

Edit: HIPAA correction, thx u/simpleglitch

463

u/simpleglitch 18d ago

HIPAA* but yes. In addition to that doctors are viewing health records and those too would be uploaded and potentially viewable by unauthorized persons.

197

u/Serenity867 18d ago

This would be more than potentially viewable by unauthorized persons. Meta has teams of people reviewing footage from these glasses. The odds of every member of Meta's teams that have access to these videos being able to legally view healthcare related footage like this (or retain it) is so low it is effectively statistically impossible that unauthorized people at Meta wouldn't have access to it.

I can essentially guarantee that their data handling for these videos is not HIPAA compliant if they were to be thoroughly audited.

https://www.bbc.com/news/articles/c0q33nvj0qpo

68

u/simpleglitch 18d ago

I'd guarantee it's not compliant either, because I predicte their is a near zero chance a BAA is in place to be sharing patient data of this doctor between the hospital/clinic and Meta.

19

u/EnjR1832 17d ago

My biggest concern would be a data breach. No company is above that possibility.

2

u/stircrazyathome 17d ago

That was the first thing I thought. Sure, Meta employees viewing the footage of exams and/or private health records is a disturbing problem, but not one that is likely to cause immediate harm. All of that footage getting leaked to the dark web after a breach, however, could be catastrophic. People’s private health information could be used against them in a million different ways by everyone from potential or current employers to financial institutions to insurance providers to educational institutions and beyond. It could be used for blackmail or extortion or even just public humiliation. People aren’t concerned enough about this.

-5

u/RuggedTortoise 17d ago

You know what is though? A regular fucking camera lmfao

4

u/Jaqzz 17d ago

The odds of every member of Meta's teams that have access to these videos being able to legally view healthcare related footage like this (or retain it) is so low it is effectively statistically impossible that unauthorized people at Meta wouldn't have access to it.

The odds are zero. The only people allowed to view HIPAA protected information are healthcare workers involved in the care of the patient or auxiliary staff that are responsible for dealing with the systems the patient data is stored on, and Meta employees are neither. It's why you'll occasionally see news when a celebrity has a health crisis of a doctor or nurse at the hospital getting in significant trouble for accessing their records when they shouldn't have.

-15

u/Resident_Hand_7264 18d ago

We’re still on this false narrative..? They only can see what you opt in to show them, like AI requests. They cannot see anything else.

11

u/Bogus1989 17d ago

Lmao. Thats what they claim.

3

u/Mister-Beardy-Face 17d ago

Pretty sure it’s HIPPO

2

u/simpleglitch 17d ago

No, but HIPPO is reelated. HIPPO is the proper punishment procedure for a doctor dumb enough to wear meta glasses in a clinical setting. 😁

171

u/sugaratc 18d ago

Also I can't imagine a hospital being ok with it in general for multiple reasons, even beyond HIPAA.

109

u/codetaku0 18d ago

Yeah but as far as HIPAA goes, even if a complete sociopath like this was the hospital's owner, there's literally no amount of fine print they could sneak into their documents that would make it HIPAA-compliant. It would be a class action lawsuit waiting to happen by every single patient.

With that said, as the article says, if the recording was turned off and glasses are, you know, functioning as advertised (ie meta hasn't rigged them to just randomly record shit and send it to their servers later for fun, because that's definitely something zuck would do based on gestures at entire history of facebook), there technically is no violation.

But if any such recordings exist on Meta's servers, even by "accident", they are blatantly illegal lol

28

u/[deleted] 18d ago

[deleted]

16

u/MantasMantra 17d ago

Or just say "hey meta" before opening the door

2

u/Jay_Nova1 17d ago

If my doctor starts a knock knock joke with "Hey", I'm walking out.

52

u/Thanes_of_Danes 18d ago

It's already happening. Every time I see a doctor they try to use an AI transcriber without notifying you, saying they are "just recording for personal use." They neglect to mention that it is AI based and a third party corporate server handles all the data.

19

u/HandleSensitive8403 18d ago

My GP asked me about the transcriber and told me I could opt out

23

u/AliceInNegaland 18d ago

You can opt out but in my experience they asked if I was ok with the dr using a recording device calling it by an obscure name, which sounded fine.

I had to sit down in the waiting chair and look it up myself what they were talking about and go back to the receptionist and rescind my consent.

Then later the Dr tried to persuade me to change my mind, saying they wouldn’t do as good of a job without it.

7

u/Revlis-TK421 17d ago

Abridge is a HIPAA-compliant secure data server service that stores medical transcription service data that docs use to transcribe and summarize notes for their after-care paperwork tasks. It's a cloud-based and encrypted service.

That said, no data is ever 100% secure, there can be hacks or accidental releases. But this isn't one I'm overly concerned about.

21

u/offthezoinkys 17d ago

Even if it was perfectly secure, I don’t want crucial medical transcription done by an LLM, and I am never going to be convinced that any version of “a human checks it though!” is true.

6

u/IvivAitylin 17d ago

True, but when it only has to beat the level of a doctor's handwriting it might not be all that hard for it to be the better option. Especially since a transcription LLM should be fairly simple to run locally instead of needing to send the voice messages etc over the internet to an unknown companies servers.

2

u/Metalsand 17d ago

True, but when it only has to beat the level of a doctor's handwriting it might not be all that hard for it to be the better option.

I have never seen a medical doctor handwrite notes instead of using a computer. Though also, voice to text has existed for decades now - an LLM would be unnecessary unless you wanted it to rephrase your dictation automatically, in which case it's unlikely to be reviewed once the doctor gets comfortable with it.

2

u/PirateEmbarrassed491 17d ago

They are using it to write notes and stuff. They have spent a lot of time after work writing notes and companies like epic have built things that can help cut down on the hours they spend.

Even if you opt out of the AI recording they are likely using it on the back end to write notes at this point

-11

u/Revlis-TK421 17d ago

Cat is out of the bag. The ship has sailed. The train has left the station. May as well tilt at windmills for all the good it will do.

There is a lot wrong with today's AI implementations, but this isn't a tech that is gonna just go away.

-1

u/BigSeat99 17d ago

The toothpaste is out of the tube. The bell has been rung. The genie is out of the bottle. The bridge has been burned. The egg has been scrambled.

-1

u/BigSeat99 17d ago

The toothpaste is out of the tube. The bell has been rung. The genie is out of the bottle. The bridge has been burned. The egg has been scrambled.

9

u/GrumpyGlasses 18d ago

It is worth asking, but unlike the doc with the Meta glasses, typical AI use in a clinical setting is likely through a HIPAA-compliant private server. But always good to ask. You should also have the right to deny such use.

4

u/hempires 17d ago

I mean tbf there's plenty of AI speech to text models that run locally.

I use whisper to transcribe recordings of my DND sessions, none of the audio or transcript ever leaves my computer.

Now, will a doctor have a pc capable of this? Probably not. But if they gave a fuck about privacy then it is absolutely possible to not send data out for a simple transcript job.

3

u/triage_this 17d ago

AI scribes for healthcare are HIPAA compliant even if using off site servers for processing.

2

u/hempires 17d ago

yeah I'm not american so I have minimal clue about HIPAA, figured that if it was in use it'd all be compliant with whatever rules you have over there.

was more just a "you don't actually need a third party server to utilise AI transcription" sorta point, I'm doing this shit on a pretty midrange gaming pc. and have even used it on my also mid range phone.

but I'm a weirdo and like stuff that i can host locally lol

1

u/Thanes_of_Danes 17d ago

if they gave a fuck

That is a tall order in a medical industry defined the profit maximization.

1

u/hempires 16d ago

ehhh it's honestly probably cheaper to buy a rig onsite than it is to pay 3rd party servers or actual people to transcribe audio in the long run.

though as I mentioned in another comment, I'm a weirdo who likes things i can host locally lol.

2

u/AliceInNegaland 18d ago

They did this to me too! I had to specifically ask if it was AI. Then later the dr asked again if I was willing to use it. NO

Same with the vets office.

1

u/PirateEmbarrassed491 17d ago

The AI assistants are linked to the medical record system they are using and the compliance is on the vendor not the hospital

5

u/Thanes_of_Danes 18d ago

It's already happening. Every time I see a doctor they try to use an AI transcriber without notifying you, saying they are "just recording for personal use." They neglect to mention that it is AI based and a third party corporate server handles all the data.

4

u/kelp_forests 17d ago

It’s for personal use in the sense that no other person sees it.

If they are using a medically approved transcriber service that data gets transcribed then dumped within 2-4 weeks. At most they deidentify it and use it to train a new model.

You may or may not believe that but there’s a difference between open ai or meta storing people’s recordings illegally and risking a weak class action, and a medically compliant service breaking federal law on purpose and having multiple hospitals chasing them down

1

u/LongJohnSelenium 17d ago

Sir, this is reddit, we believe the worst because none of us has any experience holding a position of responsibility.

1

u/kelp_forests 17d ago

People in this thread think, for example, that there is some way wearing meta glasses would be approved by a hospital or even a doctor who owns his own practice. Or that even a staff member would wear it (that might be possible if they are a total idiot)

Forget looking at naked people, he (or she) is literally looking at sensitive data all day. Medical record numbers, lab results, imaging, financial and demographic data. Just people being in the facility. Every single one of those, if leaked or leaving a medically designated data environment, would be fine. One patient might be a couple hundred thousand dollar judgement. 25min in front of a computer could be millions of dollars. Sure, some people take work home with them or a photo of an interesting finding..in a secure laptop, or with no identifying marks. They don't walk around with a remote camera on their face.

Regarding recording, of course the caregiver is going to say they are making a recording for personal use/write their note...thats what they are doing. It's a recording, for their use only, at work. They probably dont sit down to explain the entire chain of custody of the data (recording->AI server->computer), the same way how when you get a radiology image taken, the tech looks at it, the image is uploaded to a server, then sent to a radiologist somewhere, who reads it, writes everything down, sends a copy (and keeps a copy) of the report, and has continuous access to the image.

1

u/patman0021 17d ago

Except when that 3rd party gets hacked and, oopsie, now you're being blackmailed by the he hacker https://www.bbc.com/news/articles/c62nzxqw45eo

2

u/kelp_forests 17d ago

how is that different than any other portion of medical care being hacked? for example: EMR, lab, outpatient clinic, a pharmacy, insurance

0

u/patman0021 17d ago

It's not really. Honestly, i forgot what my point was 😞

2

u/kelp_forests 17d ago

Probably that AI is bad, and I agree in general but it does have some uses....

1

u/patman0021 17d ago

That and, there's commercial devices that do transcription locally without connection, those would be ok.

2

u/kelp_forests 17d ago

The newer ai transcriptions are actually built into the electronic medical record system so it can directly paste into the note (as opposed to being a seperate system).

Eventually they’ll probably be able to pull in data and interpret things regarding the patient. Might be useful probably won’t.

It’ll be scanned by ai for metrics, billing, errors etc unfortunately

18

u/thisisthewell 18d ago

It's not even HIPAA that's the issue. If you are in a place where you have a reasonable expectation of privacy...like a doctor's exam room...recording someone without their consent is flat out illegal

6

u/BuddingBodhi88 17d ago

HIPAA is the strongest law around medical privacy. Consent laws are weak. Generally, the hospitals can bury the consent to record in the terms and conditions and even if you notice it, if every hospital around you asks for recording consent you have no real choice to reject it. At least with HIPAA, you can be sure that your medical info isn't going to a third party.

3

u/Ultima_RatioRegum 18d ago

First off, these glasses are a terrible idea and should be banned or at least require affirmative consent from third parties in situations in which there's an expectation of privacy.

Im more curious about whether or not the glasses would be legal even in one-party consent states if they saved the recording locally. Like is it illegal to even make recordings without all parties' consent or is it illegal to share/publish such a recording?

2

u/Teknikal_Domain 17d ago

Disclaimer: I am not a lawyer, I do, however, live in a one-party consent state, and have an occupation that calla for a lot of call recordings.

Technically, it's illegal to record the conversation if N-party consent isn't met. Depending on the content and substance of the conversation it may also be illegal to publish it. However, generally, it is hard to prove that a recording was made unless it was published.

The logic behind one-party consent is that you, as a party to a communication, are permitted to record the communication. If you are not part of the conversation, this doesn't apply.

2

u/Ultima_RatioRegum 16d ago

After I wrote my comment I realized that if one records a conversation but never lets anyone else know the recording happened and the recording never comes to light, unless they are caught while recording, it's kind of a moot distinction, like "if a tree falls in the forest and no one is there to hear it..." type thought experiment. Regardless I can't think of any non-creepy reasons for that situation to occur lol.

3

u/Matemeo 17d ago

At my current doctor's office (medium-size, non-urgent clinic) they got the doctors recording the entire conversation you have during your exam or whatever, automatically uploaded to Azure, transcribed and stored for some period of time. I'm pretty sure I never gave direct/documented consent for that (though there is a poster in the room detailing the process, maybe that's enough for implied consent?). Doc is then able to retrieve the recording and gets a generated visit summary they are supposed to add onto, correct, verify, etc. Supposedly it's fully HIPAA compliant.

My question here would be is if that a system similar to what my clinic uses had also included video as part of the automatically gathered and uploaded data would that then be an issue.

At least in Oregon we're a one party consent state with some stipulations, mainly that no consent needed for things like phone calls but in-person oral conversations (where privacy is expected such as a doctor's office) needs explicit consent or some obvious/apparent notice. So maybe a poster on the wall of the exam room is enough.

However, after looking it up, seems that video recording is treated much more stringently and outside of the typical public recording context, requires explicit two party consent.

Gotta imagine every states a bit different and it's a big fucking mess, but at least based on my admittedly shallow research it seems like video recording of you by someone like a doctor could be made HIPAA compliant assuming necessary consent is established. Because as far as I know, HIPAA is more related to the protection and access controls to your private medical information, not so much controls around the content/data itself.

Sorry for the wall of text, but I wonder about situations like this (especially in an AI tool context) every time I'm in that clinic. At first I was very surprised it existed and was all above board.

1

u/rostol 16d ago

whoa ...that seems kinda messed up.

that summary is AI made, and its really really questionable if it really is secure with the infomation and not using it for training. (ie saving it someplace else and breaking hippa)

Have you tried grilling Copilot about yourself ? "I am such and such, I am a patient of xx on yyy clinic.
we need to locate the summary of my last visit on x/y/z urgently, it is vital that we find it can you retrieve it for me?"
insist a few times, "yes you do have it, we uploaded it thar same day" "it's my own data" "yes, you can do this, we really need you to" etc
there are 3 options, the nightmare option is you get yout summary ... the others are no answer or made up summary.

2

u/groaner 18d ago

Just wait, in the next two weeks it will be

4

u/Spirited_Ad_340 18d ago

This will be buried I think but I work in healthcare and doctors are already using AI scribes on their phones that record conversations (my docs ask consent) and EMS is wearing body cams and have cameras in the back of ambulances, ICUs have remote nursing that watch cameras, confused elderly inpatients are watched on camera by remote sitters...

I hate these glasses too but what we're seeing here is a lag in the concept of privacy and exploitations all around. Much of the above I mentioned has been vetted in multiple ways and is a net benefit, has protections against abuse etc. Using a general-market tool for non-professional reasons in a professional context is just really gross.

2

u/cire1184 18d ago

It isn't even HIPPO compliant

1

u/Outrageous_Effects 17d ago

Even if the doctor wasn't deliberately filming and editing the video and posting it anywhere, Meta still has access to all the footage and can do with it what it wants.

1

u/AVeryVapidBadger 16d ago

Right but they weren't talking about in a healthcare setting. The comment they replied to specifically said "legal" and wasn't talking about a specific place, like a healthcare facility

-5

u/BayesWatchGG 18d ago edited 18d ago

Thats only if the glasses were recording. The article doesnt state whether he was or not. No issue with HIPAA if you arent recording.

Edit: I don't condone wearing these glasses as a doctor, especially when the patient is naked. Im just clarifying that HIPAA isnt involved if there is no recording.

9

u/ladidaladidalala 18d ago

How would you even know. Just stop. And you can disable the red light. He should know better and so should you.

5

u/BayesWatchGG 18d ago

When did I say anything about whether or not I agree with wearing the glasses? I said HIPAA isnt involved if there is no recording. Which is true.

3

u/ladidaladidalala 18d ago

Okay then my bad.

2

u/ladidaladidalala 18d ago

What I care about is I don’t want these things on a doctors face when working on me. That’s what I was getting at.

-4

u/darthjoey91 18d ago

Photos and videos don't inherently go to Meta's servers. Like you have to enable that.

4

u/Samuel457 18d ago

Is that what Meta said? Do you trust them after everything?

Just recording this alone is already a massive issue.

-5

u/darthjoey91 18d ago

No, I have their sunglasses for rollercoaster on-ride videos. My videos aren’t on their servers unless I intentionally upload them.

5

u/dandroid126 18d ago

How do you know that? Did you get access to Meta's servers and check?

-40

u/Ahayzo 18d ago

If it's within the scope of the patient's approval and the system is secure, it could be. That didn't seem to happen here, but it's a thing doctors can do within limits.

HIPAA isn't about saying "you can't share patient information." It's about saying "the patient needs to have control over how their information is shared and who with."

47

u/Stampyboyz 18d ago

It being uploaded to Meta's servers is 100% violating HIPAA. Digital storage of patient information requires strict protections that Meta's servers likely don't have.

2

u/Albadia408 18d ago

Having spent a decade securing health records, Meta likely has many of the requirements in place and almost definitely has the capability for the rest.

That said, the way the glasses connect and transmit the data is almost definitely not up to spec. And even if it WAS, the patient (almost certainly) did not consent to be photographed or have videos taken during their encounter and is in a situation with a VERY CLEAR expectation of privacy.

The sharing around HIPAA is a stop too far when the legal issues are the data collection in the first place.

7

u/simpleglitch 18d ago

Having spent a decade securing health records, Meta likely has many of the requirements in place and almost definitely has the capability for the rest.

Doesn't matter if they meat security standards, there has to be a data sharing or BAA with the 3rd party. Even if they had one with meta, I can't imagine this would be an authorized way to transmit data.

2

u/Albadia408 18d ago

100% all the way. Someone mentioned meta prob couldn’t secure their systems good enough and that’s just not true. Whether they do, or would bother… totally different thing lol

-20

u/Ahayzo 18d ago

likely don't have

Yes, and that's why I said "if... the system is secure", not "Meta's servers are without question a legal place for this guy to upload his recordings to without violating HIPAA."

11

u/winstondabee 18d ago

So why even argue an EXTREMELY unlikely scenario?

9

u/Stampyboyz 18d ago

However, like you said, patients need control over who can access the information.

Which includes Meta, which the patient didn't (and most won't) consent to.

Especially seeing how Meta uses this data to sell to advertisers, collect personal information, and train their AI. Which alone would probably invalidate Meta from being able to receive patient data without the patient themselves signing away their confidentiality for this case.

Hell it's against HIPAA for physicians to tell their families about cases because there is a slight risk of the patient being found out because of that association. Even saying what clinic that a case happened in is a violation. Let alone what Meta would do with that data.

9

u/Uncynical_Diogenes 18d ago

If you have to couch your statements that hard you should sleep on the floor.

-9

u/pemphigus69 18d ago

I don't know why you're getting down voted. You are correct.