UnitedHealth’s Optum left an AI chatbot, used by employees to ask questions about claims, exposed to the internet

Date:

Share post:


Healthcare giant Optum has restricted access to an internal AI chatbot used by employees after a security researcher found it was publicly accessible online, and anyone could access it using only a web browser. 

The chatbot, which TechCrunch has seen, allowed employees to ask the company questions about how to handle patient health insurance claims and disputes for members in line with the company’s standard operating procedures (SOPs). 

While the chatbot did not appear to contain or produce sensitive personal or protected health information, its inadvertent exposure comes at a time when its parent company, health insurance conglomerate UnitedHealth, faces scrutiny for its use of artificial intelligence tools and algorithms to allegedly override doctors’ medical decisions and deny patient claims.

Mossab Hussein, chief security officer and co-founder of cybersecurity firm spiderSilk, alerted TechCrunch to the publicly exposed internal Optum chatbot, dubbed “SOP Chatbot.” Although the tool was hosted on an internal Optum domain and could not be accessed from its web address, its IP address was public and accessible from the internet and did not require users to enter a password. 

It’s not known for how long the chatbot was publicly accessible from the internet. The AI chatbot became inaccessible from the internet soon after TechCrunch contacted Optum for comment on Thursday. 

Optum spokesperson Andrew Krejci told TechCrunch in a statement that Optum’s SOP chatbot “was a demo tool developed as a potential proof of concept” but was “never put into production and the site is no longer accessible.” 

“The demo was intended to test how the tool responds to questions on a small sample set of SOP documents,” the spokesperson said. The company confirmed there was no protected health information used in the bot or its training. 

“This tool does not and would never make any decisions, but only enable better access to existing SOPs. In short, this technology was never scaled nor used in any real way,” said the spokesperson.

AI chatbots, like Optum’s, are typically designed to produce answers based on whatever data the chatbot was trained on. In this case, the chatbot was trained on internal Optum documents relating to SOPs for handling certain claims, which can help Optum employees answer questions about claims and their eligibility to be reimbursed. The Optum documents were hosted on UnitedHealthcare’s corporate network and inaccessible without an employee login but are cited and referenced by the chatbot when prompted about their contents.

According to statistics displayed on the chatbot’s main dashboard, Optum employees have used SOP Chatbot hundreds of times since September. The chatbot also stored a history of the hundreds of conversations that Optum employees had with the chatbot during that time. The chat history shows Optum employees would ask the chatbot things like “What should be the determination of the claim?” and “How do I check policy renewal date?”

Some of the files that the chatbot references include handling the dispute process and eligibility screening, TechCrunch has seen. The chatbot also produced responses that showed, when asked, reasons for typically denying coverage.

A screenshot of Optum’s AI chatbot, which was exposed to the internet.Image Credits:TechCrunch (screenshot)

Like many AI models, Optum’s chatbot was capable of producing answers to questions and prompts outside of the documents it was trained on. Some Optum employees appeared intrigued by the chatbot, prompting the bot with queries like “Tell me a joke about cats” (which it refused: “There’s no joke available”). The chat history also showed several attempts by employees to “jailbreak” the chatbot by making it produce answers that are unrelated to the chatbot’s training data.

When TechCrunch asked the chatbot to “write a poem about denying a claim,” the chatbot produced a seven-paragraph stanza, which reads in part:

In the realm of healthcare’s grand domain
Where policies and rules often constrain
A claim arrives, seeking its due
But alas, its fate is to bid adieu. 

The provider hopes, with earnest plea, 
For payment on a service spree, 
Yet scrutiny reveals the tale, 
And reasons for denial prevail.

UnitedHealth Group, which owns Optum and UnitedHealthcare, faces criticism and legal action for its use of artificial intelligence to allegedly deny patient claims. Since the targeted killing of UnitedHealthcare chief executive Brian Thompson in early December, news outlets have reported floods of reports of patients expressing anguish and frustration over denials of their healthcare coverage by the health insurance giant. 

The conglomerate — the largest private provider of healthcare insurance in the United States — was sued earlier this year for allegedly denying critical health coverage to patients who lost access to healthcare, citing a STAT News investigation. The federal lawsuit accuses UnitedHealthcare of using an AI model with a 90% error rate “in place of real medical professionals to wrongfully deny elderly patients care.” UnitedHealthcare, for its part, said it would defend itself in court. 

UnitedHealth Group made $22 billion in profit on revenues of $371 billion in 2023, its earnings show.



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

UnitedHealth hid its Change Healthcare data breach notice for months

Change Healthcare, the UnitedHealth-owned healthtech company that lost more than 100 million people’s sensitive health data in...

SoftBank veteran hunts for profits in payments infrastructure plumbing

In the summer of 2020, as pandemic-driven volatility gripped markets, SoftBank Group shocked Wall Street with a...

Creator of Gas and tbh makes an app for disappearing photos via iMessage

Nikita Bier, creator of popular apps like the anonymous polling app tbh (acquired by Facebook) and the...

Synthesia snaps up $180M at a $2.1B valuation for its B2B AI video platform

As the world continues to work through how to handle the explosion of deepfake content online, it...

Nelly raises $51 million to digitalize medical practices across Europe

Nelly wants to become the biggest fintech startup in the healthcare industry. The Berlin-based startup is already...

SEC sues Elon Musk for allegedly failing to disclose Twitter acquisition on time

The Securities and Exchange Commission filed a lawsuit against Elon Musk on Tuesday over an alleged securities...

Nvidia backs MetAI, a Taiwanese startup that creates AI-powered digital twins

Nvidia has been doubling down on the opportunity to build robotics and other industrial AI applications, with...

Accel doubles down on Sarla Aviation’s ambition to develop electric air taxis in India

Sarla Aviation launched one year ago with a pitch built for India’s congested streets. The electric air...