Skip to main content

Your Trial Data is Probably Not Private

2 min read

At this point, no one is unfamiliar with the convenience of modern AI tools. We use it everywhere, outsourcing tedious tasks so that we're unlocked to do bigger, better things. The ROI is obvious, but the risks are not.

Most of the vendors we know and love - OpenAI, Anthropic, Perplexity - all actively incentivize users to switch to their more commercially viable plans by insisting on using any data in their lower tiers as fodder for training future models. If your CRAs or coordinators go visit ChatGPT today and upload sensitive trial or patient details, those details are essentially changing hands and being used to train future publicly accessible models. What's worse, even if you do have a higher tier with these services, they may still retain your data for 30 days or longer.

The unapproved usage of potentially risky tools is called shadow AI. It's a very real risk - some studies say up to 45% of life sciences professionals use unauthorized tools on a weekly basis. But the dangers of data privacy in AI tools goes beyond just the chatbots: it's critical to ensure that the vendors you work with also treat that data with care. Ask the tough questions: "where is my data going?" and "are my details being used for training models?".

Typical data flow through a cloud AI wrapper — showing how clinical trial data passes through third-party servers, is retained, and may be used to train future public models

Because clinical trial data is both protected health information (PHI) and intellectual property, it is critical that organizations are aware of how it is being exposed in AI workflows. Most large enterprises solve the shadow AI problem by directly onboarding onto an enterprise AI account with a Business Associate Agreement (BAA) in place - ultimately, a costly process with immediate vendor lock-in. Others go the hyperscaler route and leverage their cloud providers (Google GCP, Amazon AWS, Microsoft Azure), which is subject to their agreements with AI providers and their own data training and retention policies.

The solution is not to avoid AI, but to use it the right way to minimize risk and maximize ROI. There is a better way.

How Rightview handles sensitive data

At Rightview, we're taking a completely different approach to maintain trust, security, and privacy. We've adopted open-source models that run in an encrypted, protected environment through our partnerships with trusted vendors who practice zero data retention (ZDR) - they don't even store the data, much less use it to train models. We're CFR Part 11 compliant and are trusted by sites and sponsors alike. Reach out to us at research@rightview.ai to learn more about how we're powering AI-applications across the life sciences space and get a copy of our data security brief.