UnitedHealth's Optum Secures Exposed AI Chatbot Handling Claims Procedures

Optum restricts access to an internal AI chatbot after a security researcher discovers it is publicly accessible online. The tool helps employees navigate health insurance claims procedures but does not contain protected patient health information.

Optum, a subsidiary of the healthcare giant UnitedHealth, restricts access to an internal AI chatbot after cybersecurity researcher Mossab Hussein discovers the tool is publicly accessible online. The chatbot, dubbed "SOP Chatbot," allows users to ask questions about handling patient health insurance claims and disputes based on the company's standard operating procedures. Although the tool resides on an internal Optum domain, its public IP address exposes it to anyone with a web browser without requiring a password.

The inadvertent exposure occurs at a time when UnitedHealth faces intense scrutiny over its use of artificial intelligence tools to allegedly override doctors' medical decisions and deny patient claims. However, Optum confirms the demo chatbot does not contain or produce sensitive personal or protected health information. The AI tool instead relies on a small sample set of internal documents to generate answers about claims eligibility and reimbursement procedures.

Optum locks down the chatbot soon after TechCrunch contacts the company for comment. A company spokesperson states the tool is merely a proof-of-concept demo that is never put into production and does not make any actual decisions regarding patient care. Despite the company's assertion that the technology is never scaled or used in any real way, the incident highlights the ongoing security challenges healthcare organizations face when deploying artificial intelligence tools on their corporate networks.

Read More at the original source →