What Should You Not Give the Model?
This Part
The six chapters before this, for all their differences, were about one direction: what comes out of the model. Whether its answer is right or not, whether its source is real or invented, and how you are supposed to judge it. There is one question we did not ask in all that time, because its place was here: where does what you give the model go?
What sets this part apart from the rest of the book is that here, even if the model answers flawlessly, something wrong may still have been done.
An Ordinary Night, an Ordinary Job
It is late at night and you have to write a letter to the cardiologist of one of your patients. You copy the record and paste it into the chat box: first and last name, 62 years old, prosthetic mitral valve, warfarin, a plan to extract several teeth and fit an immediate denture, the date of the visit, the file number. You attach the panoramic as well and write: “Write a formal consultation letter for the treating physician.”
The letter is ready in a few seconds, and it is a good one. By the criterion of Chapter 5 it is on the right side of the line too: you hold the information, the treating physician makes the decision, and the model has only tidied up the text. From the output’s side there is nothing wrong with it.
The problem is on the input side. The medical information of one specific person, with a name and an image, left your practice for the server of a company in another country. The patient does not know about it and nobody asked them. And keeping a patient’s secrets is not merely professional ethics for us; we are legally bound to it as well.
The Chat Box Is Not Your Notebook
A chat window feels like a private space, the way writing something in your phone’s notes does. But everything you send is stored on the servers of the company that built it. On personal accounts it may be used to train later versions of the model, unless you have switched that option off in the settings yourself. Some of the conversations are read by human reviewers, and you will never find out whether yours was among them. Deleting a conversation from your own list does not mean it is immediately deleted from the server either. And in this respect a paid personal subscription is not much different from a free account: the money you pay buys a stronger model, not a confidentiality agreement. Those commitments belong to the enterprise versions, which are effectively out of reach for an ordinary practice in Iran.
The real danger is not that tomorrow the model will write out your patient’s record for somebody else. That is highly improbable. The danger is simpler: the patient’s information is stored somewhere you have no control over, and people may see it whom the patient never gave permission to.
A Problem That Is Specifically Ours: Shared Accounts and Middlemen
A large share of Iranian users did not get their subscription directly from the company that makes it. There are two common arrangements, and from the standpoint of a patient’s privacy both are worse than the ordinary case.
The first is the shared account: one account a seller has handed to several people so the cost is split. In these accounts the conversation history is shared. That is, the letter you wrote for that patient, with their name and their panoramic, is also visible in the conversation list of several strangers — plus the seller, who has the password.
The second is intermediary services: websites and Telegram bots that say “the same ChatGPT, without a VPN.” They take your message, send it to the model themselves and hand the answer back. That is, a third party is sitting in the middle of the conversation, seeing everything you send and able to store it.
If you use the model in either of these two ways, this part’s rule is stricter for you: nothing that traces back to one specific patient.
Why “I Removed the Name” Is Not Enough
The first solution that occurs to everyone is removing the name. It is the right thing to do, but it protects less than it appears to.
The first problem is the combination of details. Consider this text: “47-year-old man, sports teacher, congenital absence of both upper laterals, history of a motorcycle accident and a mandibular fracture in 1398.” There is no name in it. But in a mid-sized city, anyone who knows this person will know who it is about from reading that one sentence. None of these details is an identifier on its own; their combination is. And the more unusual the case — which is usually the very reason you went to the model — the harder it becomes to anonymize.
The second problem is the file itself. On most panoramics and cephalograms the patient’s name, date of birth and the name of the radiology center are printed in the corner of the image. The file name is very often the patient’s name as well. DICOM and CBCT files carry the patient’s full details in their accompanying data, even when nothing is visible on the image. And the portrait you take for a smile design is the face itself.
The third problem is specific to our field. In forensic medicine, when a body cannot be identified, one of the most reliable ways of establishing identity is comparing dental radiographs against dental records, because the combination of restorations, root canal treatments, missing teeth and root shapes is unique in every person. That is, a dental radiograph — even when you have cropped the name out of its corner — is itself an identifier, something close to a fingerprint. The claim that “this image is anonymous” is fundamentally untrue of a dental radiograph.
A Patient Record Does Not Belong in the Knowledge Base
In Chapter 6 I said to build a fixed workspace, with a fixed prompt and a few files in the knowledge base. Anyone who learns this sooner or later thinks of putting their patients’ records in the knowledge base too and having a practice assistant. This is worse than pasting them into a chat once, because the file stays there, is processed again in every later conversation, and if you one day share that workspace with a receptionist or a colleague, the records go with it. The knowledge base is for papers, protocols and your letter templates.
So How Do You Get Help Without Handing the Patient to the Model?
Almost everything this book recommends can be done without the patient’s identity. You only need to change one habit: separate the question from the patient.
It does not matter to the model who the patient is. What it needs in order to answer is the clinical situation, and the clinical situation can be written without a specific person. Instead of the record text, write: “A patient with a prosthetic heart valve who takes warfarin is due to have several teeth extracted. Write a consultation letter for a cardiologist asking about the following.” Age, if it is needed, comes as a decade rather than an exact number. Occupation, city, date, file number and every detail irrelevant to the question are removed. The model writes the same letter, with blanks for the name and the date and the details, and you fill those blanks in on your practice’s own system. If you write this kind of letter often, that same template goes into the knowledge base and next time you do not need to type anything about the patient at all.
To work out whether your text is anonymous enough, you have a simple test: if a colleague in your own city read this text, might they work out who it is about? If the answer is “maybe,” it still carries excess detail.
For radiographs the cost-benefit arithmetic is clear. In Chapter 5 we saw that language models read radiographs badly. That is, what you gain by sending the patient’s image is small, and what you lose is a permanent identifier of that patient, which cannot be taken back.
Get the settings right as well: switch off the option to use conversations for training the model, and for more sensitive work use temporary chat mode. These reduce the risk but are not a substitute for anonymizing, because the data has still left the practice. And if a case comes up where you genuinely cannot work without the image or the patient’s details — preparing a case presentation, for instance — the rule is the same one you apply to showing a patient’s photograph at a seminar: the patient’s own consent.
What Is the Next Part About?
This part was about the information you give the model. The next part is about the text you get from the model and want to hand to a patient or a colleague. The model has several behaviors that make you think that text has been checked, when it has not. The simplest example: you ask “are you sure?” and it answers “yes, I am 92 percent sure.” That number puts your mind at ease, but there is no calculation behind it. You saw three more of the same kind in Chapter 6 and I deferred explaining them. The next part goes after exactly these.