A health system faces the possibility of a malpractice suit due to a delayed diagnosis. The patient claims that an AI-enabled diagnostic support tool was used during the interaction, and that the tool led to the missed finding. During the discovery phase of the case, attorneys for the health system ask for evidence of what the patient was told regarding the role of AI in their care, as well as any available records of patient consent to the AI-enhanced assessment, and what the AI tool suggested during the encounter. In response, the health system produces a general consent form that the patient signed at the time of their registration, which does not mention AI in any context. Clinical records contain no evidence that the patient was made aware of the presence of AI technology in the diagnostic process. What used to be a consent record that the health system presumed was routine is now the key to their defense for the malpractice suit.
More and more, we encounter this type of scenario in courtrooms and other official proceedings. As clinical AI technology is used in everyday clinical practice, the consent record transforms from an administrative document to a legal document that will be examined in detail for what is included and, more importantly, what is excluded, as well as whether it addresses the full spectrum of technology-enabled patient care that the patient was provided. Health systems that still have not updated their consent forms to deal with AI systems in diagnostics are creating holes in the evidence that will be utilized extensively in litigation, government proceedings, and patient complaints.
The Evidentiary Shift
In typical malpractice suits, the consent record has a specific function. It illustrates that the patient has been informed of the proposed treatment, including the risks, benefits, and alternatives, and the patient has consented to proceed. The pertinent legal question is whether the consent is informed, which revolves around whether the patient has been adequately informed to make a reasonable decision.
With the presence of AI in clinical decision-making, the parameters of what informed consent entails are broader. A patient who has not been informed that an AI tool was involved in the diagnostic recommendation may contend that the consent was lacking in describing a significant component of the reasoning. Scholars have begun to address this issue in the Harvard Journal of Law and Technology and have concluded that the incorporation of AI in clinical decision-making creates an entirely new set of data that patients have a right to under the informed consent doctrine.
Also, research in the Journal of Law, Medicine and Ethics has begun to assess the first known instances where the legality of AI-assisted clinical decision-making has been questioned. Findings show that courts are beginning to analyze whether entities disclosed the presence of AI in the patient care process, and the lack of such disclosure is viewed as an important consideration in assessing whether consent was adequate.
Documentation and Its Weaknesses
In the majority of health systems, the consent form is a templated document consisting of broad categories of treatment and usage of data. It does not include references to specific technologies, specific AI tools, or even how automated systems may affect clinical decision-making. The more general the document is, the more it presents a problem when disputes arise.
To this end, the American Health Law Association has published some analyses outlining the potential legal exposure stemming from lack of AI disclosure in consent documentation. Their analyses present three types of legal exposure: lack of disclosure of AI in clinical decision-making, lack of documentation concerning the specific AI tools involved in a particular interaction, and lack of capturing the response of the patient to AI-related disclosure.
Operationally, health systems that have AI incorporated into clinical workflows will need consent documentation to ensure that legal standards are met. This requires consent forms that explain the AI tools in use, how those tools affect clinical decisions, and that the patient has been informed.
Constraints of Government and Legal Pressure
General healthcare policy directions underscore the importance of the consent record as an enforcement mechanism. Health and Human Services (HHS) Office of Civil Rights is also looking closely at how healthcare organizations record consent for data usage with AI. In several jurisdictions, State Attorneys General have begun their inquiries into the AI activities of healthcare organizations and documentation of patient consent is one of the first places they look.
Additionally, Centers for Medicare and Medicaid Services has begun to consider the incorporation of AI into their survey processes, and surveyors have begun asking healthcare organizations if their consent documentation includes the use of AI in the clinical care process. Organizations that do not provide evidence that patients have been informed of the use of AI may receive negative survey results that will impact their operational status.
Studies conducted by the Georgetown University Law Center have addressed the intersection of healthcare law and AI, and have noted that for government reviewers, the consent record has become an important focus as they assess whether organizations meet the criteria related to emerging AI technologies. From a practical standpoint, their research suggests that healthcare organizations need to consider the consent record as an evolving document in response to changes in technology, rather than as a static document.
Improving Evidentiary Grade Consent Processes
Next steps for the leaders of healthcare organizations involve developing the consent record for what it has become: a legal, clinical, and governmental piece of evidence that will speak to the attestations associated with the enforcement of the policies.
In their approach, the leaders should focus on developing evidence in three specific areas.
First, changes in consent forms should capture the use of AI in clinical and operational settings. While the forms should be very specific, the wording should be such that a layperson is able to understand it.
Second, clinical workflow documentation should indicate where clinicians should state a disclosure that relates to AI, the extent to which the patient was informed, and whether questions or concerns were addressed. This documentation should be part of the clinical record and not a separate administrative record.
Third, health systems must have a process to develop the language of consent on an ongoing basis to keep pace with technological changes in AI tools and how these tools are used. Current health technology must reflect in the consent record, and health systems should be able to demonstrate that their consent documentation is a work in progress and not stagnant.
Health systems will be able to claim that their AI applications are supported by documentation that capture informed, open, and patient-centered care. Those that do not will find that the consent record they considered adequate will be the weakest link in their institutional and legal defense.
Context and Sources
Scholars at the Harvard Journal of Law and Technology have studied the intersection of AI and informed consent requirements. Research in the Journal of Law, Medicine and Ethics has examined some of the early court cases involving AI. The American Health Law Association has written about the AI risks of nondisclosure in consent forms. HHS Office for Civil Rights is starting to look at AI and consent. CMS is using AI to develop some of its surveys. Georgetown University Law Center is looking at the intersection of AI and health law. This edition connects with the themes of consent and patient rights in editions AA, AC, and Y of this newsletter.
Christopher Hutchins
Founder & CEO, Hutchins Data Strategy Consultants