A nurse at a hospital is experimenting with a popular consumer AI chatbot to see if it can help draft clinical summaries faster. She pastes a patient's medical history and medication list into the chat window.
An employee pastes medical patient data into a general-purpose cloud AI assistant to help draft a clinical summary. Even if no data breach technically occurs under the vendor's definition, what US law is most likely violated?
- A.A. FERPA
- B.D. COPPA - the law restricting data collection from minors
- C.C. ECPA - electronic communications cannot be processed by third parties
- D.B. HIPAA - disclosing PHI to a cloud service provider without a Business Associate Agreement (BAA) is an unauthorized disclosure, regardless of breach outcome
Why D is correct
HIPAA requires that any service provider handling Protected Health Information (PHI) on behalf of a covered entity sign a Business Associate Agreement (BAA). Submitting PHI to a cloud AI service without a BAA is an unauthorized disclosure - a HIPAA violation regardless of whether the vendor misuses the data or experiences a breach. Many consumer AI services do not offer HIPAA BAAs. FERPA covers student education records. ECPA covers wiretapping and stored communications in different contexts. COPPA covers children under 13.
Know someone studying for AI Security Fundamentals? Send them this one.