When “Notice” Isn’t Enough: AI Transparency in Multilingual Healthcare

A privacy notice can be visible but meaningless. AI governance should account for whether patients can actually understand what is happening to their information.

By John Keenan, CISSP

The sign in the lobby is where the question begins

Working in medical interpretation has made one problem with healthcare AI unusually visible to me. A healthcare organization can post a notice explaining that artificial intelligence may be used, yet some people walking past it may not be able to read the language in which it is written. Others may understand the words but not what the technology actually does.

That creates a deceptively simple question: if a patient sees an AI disclosure but cannot understand it, has the organization achieved transparency?

This is not an argument that every use of AI requires individual consent, nor is it a legal conclusion about whether a particular sign satisfies HIPAA, state law, or another requirement. Those questions depend on the technology, the data, the organization, and the applicable law. The narrower cybersecurity question is whether the communication control accomplishes its intended purpose.

Security professionals are accustomed to making that distinction. A control does not become effective merely because it exists. It must work in the environment in which it is deployed.

AI makes invisible data processing easier

Ambient clinical documentation illustrates the problem. A clinician may use software that listens to an encounter and helps generate a draft note. To a patient, nothing about the room necessarily looks different. There may be no keyboard interaction or obvious recording device. The technology can disappear into the workflow, even as the data processing becomes more complex.

Depending on the system and configuration, information may move through audio capture, transcription, speaker identification, summarization, model processing, logging, storage, and the electronic health record. The final clinical note is only one possible artifact in that chain.

That makes transparency more important, not less. Patients cannot infer the data flow by looking around the room. If an organization chooses a notice as part of its transparency strategy, the notice must communicate across the population the organization actually serves.

Language access is a governance issue

It is tempting to classify multilingual disclosure as a translation problem and hand it to the language-services department. That is too narrow.

The NIST AI Risk Management Framework treats AI risk as a lifecycle and governance problem. Its core functions - Govern, Map, Measure, and Manage - encourage organizations to identify context, affected parties, risks, responsibilities, and controls rather than treating AI as a stand-alone technical product. NIST's Generative AI Profile likewise emphasizes risks that can emerge across design, development, deployment, and use.

Language belongs in that context. If a hospital regularly serves patients who speak Spanish, Arabic, Vietnamese, Amharic, Korean, or other languages, those patients are not unusual exceptions to the operating environment. They are part of the environment.

The same reasoning applies beyond language. Health literacy, disability, cognitive limitations, and unfamiliarity with AI can all prevent a technically accurate notice from producing meaningful awareness.

Privacy starts with understanding the data

The disclosure question also exposes a deeper asset-security issue: organizations need to understand what information the AI system actually handles.

Healthcare data may include structured records, free-text narratives, images, audio, demographic information, and metadata. HHS guidance on HIPAA de-identification recognizes two methods - Expert Determination and Safe Harbor - and makes clear that de-identification is a defined process rather than a casual assertion that names were removed. HHS also acknowledges that even properly de-identified data carries a very small residual risk of identification.

AI can create additional representations of information: transcripts, summaries, embeddings, prompts, model outputs, logs, or derived datasets. A sound governance program therefore asks what is created, where it goes, how long it exists, who can access it, and for what purpose it may be used.

Only after answering those questions can an organization explain its practices clearly to patients.

From posted notice to meaningful awareness

A better operational test is straightforward: could a reasonable patient understand when AI is being used in the encounter and, at a basic level, what that means for the patient's information?

That does not require turning a waiting room into a graduate seminar on machine learning. It may require something as practical as multilingual notices, plain-language explanations, a clear point-of-use disclosure, and an established process for answering questions. In an interpreted encounter, it may mean giving the interpreter an approved explanation rather than expecting the interpreter to improvise the organization's AI policy.

The distinction matters because privacy programs depend on trust. A patient who later discovers that technology was listening to an encounter may react very differently depending on whether the organization made a serious effort to explain the practice beforehand.

Cybersecurity has learned repeatedly that you can't bolt human factors onto a system at the end. AI transparency deserves the same treatment. A notice should not be evaluated by whether it was posted. It should be evaluated by whether the people affected by the technology had a reasonable opportunity to understand it.

Sources

·       NIST AI RMF

·       NIST GenAI Profile

·       HHS De-identification

Previous
Previous

Patient Data as AI Training Data: A Cybersecurity Risk-Lifecycle Problem

Next
Next

Language Access Is Risk Management