Thanks for sharing. My thought is that I’ve presumed at this point that a TON of medical information is using non-HIPAA compliant services.
So many medical shops are so tiny that the “IT person” is also the janitor: those folks don’t know HIPAA. And then add in “shadow IT”. And the reality I’ve presumed for years (ever since Gmail really) that stuff is floating around where it shouldn’t be.
I’m sure with ChatGPT and Claude and others it’s even worse. I fully expect to be hearing about peoples’ PHI showing up in those soon.
