Victoria’s doctors are calling for greater accountability from OpenAI and clear answers from both the Victorian and Federal governments about how they will protect sensitive patient health information after it was recently disclosed that Medicare was breached in June of this year.
The breach involved an OpenAI agent gaining unauthorised access to a Services Australia Medicare statistics portal. While the Federal Government said no personal patient information was accessed, OpenAI inexplicably did not notify Australian authorities until September.
AMA Victoria President Dr Simon Judkins said the incident raised serious questions for both doctors and patients.
“Confidentiality remains absolutely critical to maintaining a trusted relationship between a doctor and their patient, and increasingly that depends on the security of the digital systems we use every day.
“While no personal patient data appears to have been accessed, the obvious question is what happens next time if an AI agent gains access to a system containing sensitive clinical information?
“Patients and doctors need confidence that unauthorised access will be detected quickly and reported immediately.”
Dr Judkins said it was incumbent on OpenAI, for the benefit of all Australians, to provide greater clarity about what happened.
“Why did it take nearly three months for Australian authorities to be notified? What safeguards failed, and what has changed to make sure this cannot happen again?
“These are reasonable questions for a company developing technology capable of acting autonomously and without real-time oversight.
While the Federal Government investigates the incident, including interactions with other government systems and the Victorian Department of Health, Dr Mukesh Haikerwal, a former AMA Victoria and Federal AMA President and longstanding advocate for responsible digital health, said governments must also consider what safeguards are needed to protect Australians’ health data from increasingly capable AI systems.
“The clear question to ask is whether the Federal and Victorian governments are satisfied that our health systems are adequately protected against unauthorised access by AI?
“What safeguards are in place for hospital records, My Health Record and electronic prescribing?
“How quickly would an intrusion be detected and reported? And are our current regulations strong enough to hold technology companies accountable when something goes wrong?
“These are questions that need to be answered with a sense of urgency before a future incident involves sensitive patient information.”
Dr Haikerwal said that while doctors supported the responsible use of AI in healthcare, appropriate safeguards needed to be put in place to protect sensitive and confidential patient information.
“AI has enormous potential to improve healthcare, but those benefits cannot come at the cost of patient confidentiality and privacy.
“Its use must be underpinned by clear standards for safety, confidentiality, clinical oversight and accountability.
“Patients need to know their information is safe, and doctors need confidence in the systems they rely on to care for them.”