Free Medical AI Chatbots: Are They Safe With Patient Information?

Feb 09, 2023 · Alex Blau MD (Doximity Medical Director)


Physicians and other healthcare professionals are expanding their digital toolstacks to streamline workflows and improve the patient care experience. And when it comes to healthcare tooling like AI chatbots, is free too good to be true? Here are the differences between free and paid medical AI chatbots, and how DoxGPT differs from both while blending accessibility with patient security.

What Is a Medical AI Chatbot?

A medical AI chatbot, or a healthcare chatbot, is a conversational program that uses artificial intelligence to simulate human-like conversations with users about healthcare. It can perform a range of tasks, from symptom assessment and drug recommendations to offering initial guidance and treatment for non-critical scenarios.

Although it should be noted that these products should be treated as a guide rather than a definitive source of truth, they’re still helpful in a consultative context. These tools can provide 24/7 assistance and support for virtually any healthcare prompt, making them helpful to doctors, nurse practitioners, and PAs who are stretched thin at their practices.

Public-Facing Versus Clinician-Facing Products: What’s The Difference?

As you might expect, a public-facing chatbot is available to the public, whereas a clinician-facing chatbot is exclusive to certified physicians and other healthcare professionals. Clinician-facing chatbots also, of course, have a narrowed-down scope for the industry. Many of these products build their tools on more reliable clinical health data, with stronger safeguards.

Why Public-Facing Chatbots Might Not Be Safe Or Secure

Public-facing chatbot products like ChatGPT are undeniably handy, but that doesn’t mean they’re always safe and secure. Here’s why they aren’t well-suited in a healthcare context:

  • They aren’t HIPAA-compliant: Most general-use chatbots aren’t developed with regulations like HIPAA in mind. That means they lack the necessary technical and administrative safeguards required to protect sensitive patient information.
  • Sensitive data is inadvertently leaked: When healthcare professionals enter patient details and other sensitive information into a public-facing chatbot, the prompt data becomes part of the provider’s database and can be recycled to train the underlying model. This exposes patient information to unintended audiences and violates their privacy.
  • They lack transparency: General AI tools lack transparency into how data is collected, stored, and used, eroding patient trust and preventing users from controlling sensitive information as effectively as possible.
  • They’re vulnerable to cyberattacks: Like any digital tool, public-facing chatbots are susceptible to data breaches. A single attack could compromise vast amounts of historical patient health information.
  • The algorithm is biased: Public-facing chatbots are trained on massive datasets from the broader internet, and may contain biases or inaccurate medical information. In a healthcare context, relying on these recommendations could lead to the use of false information, potentially threatening patient health and safety.

Free Versus Paid Medical Chatbot Products

Now that you understand the difference between public-facing and clinician-facing chatbots, it’s time we break down why “paid” doesn’t always mean “more secure.” Here are three things to keep in mind.

  1. Not all paid tools are healthcare-appropriate. Many paid AI products were never designed to keep patient healthcare information secure and shouldn’t be used for clinical data.
  2. Security is a product design choice, not a price point. A free tool could be highly secure if it’s transparent about its practices and is well-maintained.
  3. Some chatbots upsell features unrelated to security. You might actually be paying for performance or functionality, rather than for safety, security, or compliance.

The long and short of it is that paying for a medical chat product increases the likelihood that the tool is compliant, but it’s never a guarantee. The decisive factor in whether the tool is suited to your practice should be how it’s made, not whether it’s available for a fee.

How DoxGPT Is Different: Free Meets Secure

At Doximity, we pride ourselves on being a reputable, secure, and accessible platform for healthcare professionals across the United States. While not a chatbot, our workflow assistant DoxGPT can be used in place of one while being completely free. With prompt answers rooted in medical evidence that physicians can trust as a handy guide, DoxGPT is more secure than a chatbot in a few ways.

DoxGPT Is HIPAA-Compliant

DoxGPT is fully HIPAA-compliant, with appropriate Business Associate Agreements (BAAs) in place. Tools like ChatGPT are not HIPAA-compliant and run the risk of leaking patient data in the event of a cyberattack or security breach.

DoxGPT Is Secure And Private

DoxGPT prompts and responses are entirely private for each clinician and are not used to retrain the underlying model. In contrast, public-facing chatbot products are not private, and anything entered as a prompt (including personal information) can be reused for training unless the user explicitly opts out in their settings.

DoxGPT Has Better Data Management

DoxGPT manages all data within a secure, private infrastructure, with data encrypted in transit and at rest. Public chatbots, on the other hand, lack specialized data management capabilities, and sensitive medical data is always at risk of being exposed.

The Full Suite Of Doximity Products

Doximity is the largest platform of healthcare professionals in the United States, with over 80% of physicians and 50% of NPs as verified members. We’re passionate about addressing workflow pains and needs across practices of all sizes, which drive our product development. Our “clinician first” mentality means we listen to the pain of healthcare professionals on the front lines, so we can build safe, effective products that solve complex problems. Doximity’s other digital solutions include:

  • Doximity Dialer: Users can use Doximity Dialer to connect with patients by text, phone, and video anywhere, while keeping their personal phone numbers private. There are no sign-ins or downloads required for video calls, and users can even have their staff initiate calls and hand off to the right clinician when ready.
  • Doximity Scribe: The HIPAA-compliant, clinical documentation tool Doximity Scribe uses AI to live-generate notes during patient visits. It’s designed to ease clinician administrative burden, boost note and template quality, and free up more valuable time for patient care.

Much like DoxGPT, Doximity Dialer, and Doximity Scribe are completely free. Getting started is as easy as creating an account, and users can use the full suite of products on desktop or mobile devices.

Try DoxGPT Today

If you’re looking for healthcare guidance that’s safe, secure, and rooted in medical evidence, try DoxGPT today. It’s the convenience and speed of a public-facing AI tool, without the guesswork and risk of patient data being used to train the model.

Sign up today

and simplify workflows at your practice with Doximity.


Back to Blog