Amazon’s Health AI: A Privacy Look

When I first heard of Amazon’s rollout of Health AI, I had an inner cringe. Something about the concept of providing medical records to Amazon and having an AI chatbot provide services bothered me. This was back in January when Amazon’s One Medical members were given access. Around March of this year, Amazon expanded that access even further.

Health AI launched earlier this year exclusively for One Medical members in the One Medical app, and the response has been overwhelmingly positive—from patients and providers. We want to bring Health AI to even more people, so we’re expanding access to Amazon.com and the Amazon app. We’re rolling this out to customers starting today and will continue expanding availability in the coming weeks, with a goal of making it available to all U.S. customers soon. – Amazon News

I have been seeing and hearing more advertisements now for Health AI, and with the recent news regarding AI therapist privacy concerns, right in the same bucket as an AI personal assistant, I wanted to look into the topic a bit more. With Amazon, there’s the urge to provide full access to a user’s medical records for more tailored care. Therefore, it could be argued there’s a greater chance for risk there.

HIPAA Protections, Multiple Policies

The Health Insurance Portability and Accountability Act (HIPAA) sets the standards for protecting medical information, and it is one of those frameworks that has enforcement and teeth behind it. This is a good thing, because it ensures your medical records are protected from disclosure without your consent. If you want to dig into HIPAA, you can do so here.

The thing I noticed about Amazon though, likely because they are a tech company who participate in advertising and selling goods, is that there are numerous policies that Health AI references in how it handles your data. The Terms of Use for Health AI are supplementary to Amazon’s Conditions of Use and Privacy Notice. Plus, Health AI also falls under Amazon Health Services Notice of Privacy Practices. Instead of dealing with a healthcare provider directly and having a very health-focused relationship, this is one where the user must consider and account for the business side of Amazon too.

A part of the direction to additional notices is how Amazon handles data that is not considered Protected Health Information (PHI). This is important to understand. When a user interacts with Health AI, there is PHI data and non-PHI data. What bucket the data is considered is how it gets protected.

  • PHI (health/medical info): governed by this Notice of Privacy Practices, under HIPAA, tied to Amazon Pharmacy and One Medical as a joint “Affiliated Covered Entity.”
  • Everything else (account info, app usage, device data): governed by the general Amazon.com Privacy Notice, which explicitly allows use for advertising and for training Amazon’s generative AI models.
  • Please refer to the Amazon Health Services Notice of Privacy Practices to learn how Amazon Pharmacy and One Medical collect, use, share, and protect your Protected Health Information (“PHI,” as defined under the Health Insurance Portability and Accountability Act of 1996 or “HIPAA”).

-Health AI Terms of Use

I am by no means a lawyer, but I did not see any reference to how the conversation data within Health AI is classified. If the conversation data is not considered PHI, then the data would theoretically fall under Amazon’s Privacy Notice and could be used for other purposes. These sorts of distinctions matter, and having to deal with separate policies in how data is used is confusing at best.

Data Disclosures

The Amazon Health Services Notice of Privacy Practices provides a number of situations where Amazon can disclose your health information without your consent. Many of them were situations in which law enforcement was involved, or obvious situations in which it was necessary to provide treatment. Two that stood out to me were Business Associates and Research.

We may contract with other entities to perform certain services for us, such as accounting, billing, or information technology services. If these entities need access to your PHI to perform these services, they are called Business Associates, and they are required by law and by contract to comply with HIPAA and protect your PHI. -Amazon Health Services Notice of Privacy Practices

While the above notes complying with HIPAA, it’s important to keep in mind these are other entities who now have access to your PHI, and they are additional avenues of data compromise. Many times it isn’t the primary company that gets their computer network breached, but a smaller firm providing a service that may not have the same security standards or practices.

The part about Research was more concerning though.

We may use your PHI to conduct research or disclose it to researchers as authorized by law. For example, we may use or disclose your PHI for a study approved by an authorized review body that establishes processes to ensure the privacy of your information. -Amazon Health Services Notice of Privacy Practices

In my opinion, ensuring the privacy of a user’s PHI is irrelevant here as it is disclosure without consent. It would be like a friend sharing secrets they know about you without asking, but defending it by saying it was a private conversation. I am not sure what the standard is regarding research across the medical community and whether this is common, and maybe it is. But this is something to be aware of when using Amazon for medical efforts.

There were other situations where Amazon may require authorization and consent like in marketing. Even so, all of these situations again fall on the determination of what is considered PHI and what is not considered PHI. If the data collected is not considered PHI, like the ambiguity in the AI conversations, the use of the data is far more liberal.

Changes in Terms

Reviewing the terms in all of these policies sets a standard in that Amazon can change the terms whenever they wish and that change will apply to PHI already collected. Amazon makes the promise, however, to “never materially change our policies and practices to make them less protective of customer information collected in the past without the consent of affected customers.” I believe this should be at the discretion of the user though on whether they put trust in Amazon to uphold a promise to never be less protective. It’s been my experience that perspective matters and what a company believes is in keeping in line with user protections might not be the same perspective the users have.

Health AI: Final Thoughts

Just for me personally, I do not have enough faith and trust in Amazon to provide my medical records to their AI personal assistant. The lack of clarity in AI conversations being PHI or not, the business and marketing background of Amazon and the release of PHI for research are all important points of consideration before opening up medical records and detailed medical history with an AI agent. These points are in addition to the fact AI has been known to provide inaccurate information or expose data it should not. Hopefully the above review and some key points here help you understand how information is used with Health AI.