Gorgon Zee
Hero
Only approved tools can be used for data that is private, sensitive or restricted (includes PHI/PII, financial, etc. -- basically anything not public). Approval is by a committee including me, our VP for compliance and our VP for security. In general, to be approved a tool must:How are you dealing with any privacy concerns? In my org we are bound by FIPPA and anyone who fed private data to a public LLM would get roasted alive, for the legal exposure we would face.
- Secure our data subject to HIPAA and other requirements.
- Not use our data to train a model. Or if they do, secure that model so we are the only ones with access to it.
- We typically (always?) require a contract that defines these requirements.
I am not a lawyer: The above is my understanding of the law and I believe that others may have a different / more lenient view. So do not take the above as fact, but simply as the interpretation that I use in my daily work.