Imagine a hospital emergency room ten years from now. Sam Brown, a car crash-victim, has come in with severe, life-threatening injuries. ER admissions staff enter Sam’s information into the hospital’s artificial intelligence (AI)-enhanced electronic health record (EHR) system. From this point forward, every medical device that interacts with the patient (e.g., vital signs monitors, surgical instruments, MRIs, etc.) records and uploads data to Sam’s visit account in the EHR. This is then synced with Sam’s broader EHR file–which includes all digitally available medical history for her prior to that moment. Pre-formulated and highly complex algorithms, the backbone of the system’s AI, compile this data and compare it to information gathered from millions of patients and hundreds of thousands of similar incidents. Dr. John Doe, an ER physician who is battling to keep pace with our patient’s ever- worsening condition while also working through the effects of chronic sleep deprivation, stress, and general burnout, sees an alert on a screen in front of him advising him on suggested next steps for treating the patient’s injuries and associated complications. Exhausted and short on time, Dr. Doe chooses to follow the system’s suggestions, instead of further evaluating the circumstances himself. Sam Brown dies soon after.
Several weeks later, the medical software vendor notifies all of its customer healthcare networks that the vendor’s programmers have identified an unanticipated outcome that can occur under certain conditions. As it turns out, when the AI’s algorithms interact with certain combinations of data from a patient’s current visit, medical history, and the data drawn from millions of other visits (which drive the AI’s machine learning), there is an unexpected output from the algorithm that provides faulty notifications to medical staff about suggested next steps in treating patients. The vendor’s programmers provide Dr. Doe’s hospital with detailed steps to reproduce the issue in their own simulation EHR (which is a mirror image of the real EHR used for patients) while the programmers work on coding a standard solution. Concerned, Dr. Doe asks the hospital’s healthcare IT staff to work through the steps to reproduce the issue, using a simulated version of Sam Brown’s medical record and account from the night she passed away. The IT staff determined that, the AI’s unanticipated output did indeed lead to the flawed medical suggestion that Dr. Doe acted upon—and which may have contributed to Sam Brown’s death.
Who, if anyone, should be legally responsible for the death of a patient like Sam Brown? This is a question lawyers and lawmakers should begin thinking about sooner rather than later. It is unlikely that Dr. Doe in this case will admit he relied solely on the system’s analysis. Because the EHR cannot track events that occur outside it, no audit log will exist that could say whether or not Dr. Doe personally contemplated Sam’s medical needs after seeing the system-suggested treatment. So, if relying on the AI’s diagnosis or proposed treatment plan becomes the de facto new standard of care for medical professionals, who (if anyone) is to blame when the system fails? Even if a human makes the ultimate treatment decision, AI may eventually become the effective decision-maker in many medical contexts, which then raises the further question of whether or not medical professionals will understand (or even be able to find out) how the software is generating a given conclusion about how to treat a patient. Both technical and human problems arising from AI may result in liability for various actors involved with the production and use of EHRs.
As the medical software industry gears up to implement AI and machine learning in ever more EHR applications, [1] judges, lawyers, and policy-makers would be wise to learn from the growing-pains that accompanied the rapid growth and adoption of EHRs in the United States over the last decade. Hospitals have been fundamentally transformed by the ever-growing use and complexity of EHRs that the Health Information Technology for Economic and Clinical Health (HITECH) Act stimulated beginning in 2008. [2] Companies like Meditech, Epic, Cerner, and Allscripts were forced to play catch up for years as hospitals across the United States scrambled to comply with HITECH’s Meaningful Use requirements
so that their client hospitals could qualify for government reimbursement. [3] At the same time, these companies also had to develop and implement new products to keep pace with both regulatory requirements [4] and customer demands for labor-saving technology. While the industry played this game of catch up, physicians, nurses, technicians, and healthcare IT staff struggled with an incredibly steep learning curve as many needed to learn new systems (sometimes several within a short period of time) [5] while still performing their normal functions in a high-stakes and high-stress environment. [6] This also meant that backlogs of hardcopy medical records often had to be scanned into EHRs manually, which is very laborious. [7] To further complicate matters, integration of electronic medical record systems between vendors was and remains a significant problem because of proprietary coding languages, competition, customized systems, and related factors [8].
At the March 2018 Healthcare Information and Management Systems Society (HIMSS) Global Conference & Exhibition in Las Vegas, Eric Schmidt (the Technical Advisor and former Executive Chairman of Alphabet, Inc. (Google’s parent company)) [9] warned that “for the discussions of AI and machine learning, the decision-maker should not be the computer because it makes mistakes. One of the problems we have with respect to AI right now, is not only do they make a small percentage of errors, but we as an industry cannot explain those errors.” [10] As Schmidt explained, despite training an AI system, developers do not inherently know why errors in judgment result within the system. This is often referred to as the “black box” problem and can result from (amongst other things) insufficient filtration of or control over datasets used in machine learning to calibrate AI; additional complexity resulting from the use of deep neural networks (which rely on multiple layers of filtration and calibration), [11] or simply the limits of the human mind to envision how an exceptionally complex system will work or what results it could generate. For example, even though a medical software AI may have been trained by a worldwide medical knowledge database, the AI has a chance of forming an incorrect conclusion without justification or reason. Because AI comes with a built-in error rate, but is still a major advance in medical efficiency, software service providers need clarity regarding liability. However, because AI systems make inexplicable mistakes, they should not be the ultimate decision-maker. Similar to how physicians may confer with other medical staff regarding a patient’s condition or a suggested treatment plan, medical staff should treat an AI as an additional tool or resource that they must control and monitor. As such, it may be unwise to treat the software companies as responsible when a random mistake occurs.
One solution to the issue of whether or not software companies should be liable when an AI errs may come from a products liability-approach. The learned intermediary rule would function well in this context, as exemplified in Taylor v. Intuitive Surgical Inc, where the court explained that “under the learned intermediary doctrine, the manufacturer satisfies its duty to warn the patient of the risks of its product where it properly warns the prescribing physician.” [12] This places an additional duty on the doctor in relation to the product, as the court noted:
Where a product is available only on prescription or through the services of a physician, the physician acts as a “learned intermediary” between the manufacturer or seller and the patient. It is his duty to inform himself of the qualities and characteristics of those products which he prescribes for or administers to or uses on his patients, and to exercise an independent judgment, taking into account his knowledge of the patient as well as the product. [13]
The learned intermediary doctrine is worth particular consideration in the case of AI-enhanced EHRs (far more so than in the case of physical medical devices) because the doctor is unlikely to be able to fully explain to their patient the potential risks associated with using an AI-driven EHR. Indeed, the closest analogy, from the patient’s point of view, would be the presence of a medical assistant in the room who read the patient’s medical record and made suggestions to the physician. Although the patient might ask such a medical assistant where they went to school, what they specialized in, how many years of experience they have, or whether they have seen similar cases before, they can neither ask this question of the AI nor is the physician likely to be able to speak to the qualifications of the programming team who designed it (much less the integrity of the datasets that the AI’s machine learning relied upon). Nonetheless, manufacturers would still have a duty to inform and warn the hospitals and/or physicians of any risks associated with their AI-enhanced products so they can make informed decisions about when and how to use those products, and can potentially advise patients as well. [14]
Although medical software in general is not yet classified as a medical device, regulations are moving in that direction. In December 2017, the FDA issued its Guidance for Industry and Food and Drug Administration Staff, which endorses such a position. [15] While this is not binding upon the industry, nor does it create any rights for the public (including patients), [16] the idea that medical software should be viewed as a device is one that will become ever more relevant as medical software moves from merely collecting and displaying readings from instruments and past medical documentation, to one where it actively suggests courses of care for the patient based on the same. In such a world, manufacturers can escape strict liability so long as they provide adequate warnings regarding the “inherently dangerous” nature of the software. [17] However, in the meantime, courts and judges may continue to operate under current liability regimes, such as relying heavily on a fact-based approach to determine whether software is a “good” or a “service,” for purposes of (1) establishing liability under Article 2 of the Uniform Commercial Code; [18] (2) evaluating whether there was a breach of implied warranty; [19] or (3) determining whether there was a manufacturing defect in a particular copy of the software. [20]
In the medical professions, where burnout is a chronic problem, companies are marketing AI-powered EHRs as a way to alleviate physician workload. [21] However, this is also precisely why they are a potential stimulant for medical malpractice suits: time-starved and sleep-deprived medical staff will be more likely to rely on the suggestions and projections of such systems over time, especially as they become a normal part of their workflows. Just as it would now seem redundant for a medical professional to use a mechanical blood pressure-cuff and stethoscope to take a patient’s blood pressure immediately after doing so with a digital monitor; and just as many physicians have come to rely on EHRs rather than paper charts to view patient lab test-results, medication administration records (MARs), and physician documentation, among many other examples. Medical staff will inevitably come to rely on machine learning-informed AI-driven medical suggestions.
Proving a malpractice claim in this instance would be difficult. Absent proof to the contrary, practitioners will likely disclaim complete reliance on a diagnosis software–making it potentially impossible to prove a deviation from a standard of care. But if the software companies successfully shift all liability risk onto the physicians, then an over reliance on the system by the doctor may be the future for medical liability. One potential fix may be to require medical professionals to express their reasoning for their decisions within the patient’s record. This could alleviate the proof issue and protect both doctors and patients from false assertions. If, however, a medical professional simply denies solely relying on the AI system, and a plaintiff cannot find proof to the contrary, then the plaintiff will have suffered a wrongful injury without a means to recover from a defendant. However, this approach comes with additional policy concerns, because time spent charting is time not spent with patients, which has become so problematic that vendors are directing new efforts to assist specifically with charting. [22]
As the medical profession embraces tools using AI, lawyers should begin thinking how medical malpractice claims may change. In the described scenario where an actionable harm is caused, in part, by a faulty AI system, there should be a means for plaintiffs to recover. The utilization of AI in analyzing patient health records, however, presents a potential gap in the fault system where legitimate claims will go uncompensated or place additional pressure on already overworked physicians. In the case of predictive analysis, the AI advising the doctor may become akin to a physician’s assistant, though without the accountability of a human professional. As AI becomes more proficient and widely used in successfully predicting illness and suggesting treatment plans to medical staff, this may force the creation of new rules and precedents for dealing with a system that mimics or takes the place of human judgement and experience. Under current law, it may be impossible for plaintiffs to recover. If the medical software industry continues down the path of treating medical software as a “device,” then the learned intermediary rule would shield the software developer and yet secure the liability upon the doctor and hospital so long as the developer provided adequate warning. Nonetheless, this is but one possible solution, and we as legal professionals may find that still further legal innovation is required to keep pace with ongoing technological innovation.
Though the old stereotype–that the medical and legal professions are both slow to change their ways–may often be true, the world is nonetheless running into an AI-driven future. Whether we like it or not, we have to try and catch up.
