29 Comments
User's avatar
Flatulus Maximus's avatar

How interesting! I wondered how you could be as prolific as you are. I have a neurological problem with my hands. $800 is certainly not in my budget, but maybe I'll look into it if typing becomes more difficult for me. It isn't pretty now!

Jeff Bell's avatar

The comments about security risks are interesting. I am not a security expert, so this may be a not-so-bright question: If one uses Wispr Flow, or similar technology, just for dictating things that one intends to make public, but then does more private work on the same computer, does that put the private work product at risk?

To be more specific, I would love to use Wispr Flow or something like it to save a ton of time writing my articles, but I would never use it for client charting or anything like that. Is this feasible, from a security standpoint, or do a need to set up a completely separate computer for just the dictating work in order to maintain good privacy and security?

I am hoping that someone in this community can answer that for me.

Fed up's avatar

That’s fantastic that you found a voice recognition system that works well.

I did medical transcription for many years, the last type being radiology. In the end, the hospital brought in a several million dollar voice recognition system and we all got laid off. However, this new system came with many lawsuits (anticipated) since the docs did not have time to proof and the editors were few as well. Lots of reports where tumors were there when they were not and not there when they were. A real mess.

Glad this new system works well. I always got a kick out of reports from the voice recognition.with bologna amputation. 😝

Tracy Sanders's avatar

Accuracy of the product is definitely one thing to evaluate. I did a third-party risk assessment at a very high level on Wispr Flow.

Sensitive content is fed to it based on what you dictate. There is likely screen/context leakage from other active apps on your computer at the time. Your data is used to improve their LLM. It could function as a keylogger because it has endpoint agent trust level. It is a global input layer device since it is functioning as a keyboard replacement.

Wispr does have some privacy settings, but those are almost always a risk since the vast majority of people are not IT security specialists. Therefore, the settings are usually not configured in a hardened manner.

I looked at some independent analysis on the platform and it lists screenshot and context capture concerns.

Good that it is performing well, but be aware that it is not as secure as it could or should be. The AI that I use is completely restricted to my data control plane and I have governance audit controls over it. External data exfiltration risk must always be considered in the total cost of ownership of a product. Acquisition cost is not the entirety of the cost.

Randy's avatar

Most people have no thought or concern for security, to their detriment. Most people don’t even own a Faraday bag. It’s good that you are counterbalancing this trend. But remember that most people, including Dr Yoho, do not create “Eyes Only, Burn After Reading” documents in a SCIF. He’s creating documents that will be released to the public on Substack. I’m pretty sure he doesn’t care that his posts are being used as LLM fodder to train various AIs.

Tracy Sanders's avatar

Emails, research documents, confidential sources, none of these are expected to be published publicly, but all of these are likely being sent to the cloud processed AI. I've met countless individuals who think that their stuff is not important enough to be kept private and confidential. However, consumers need to select their providers based on the degree to which the provider protects their information.

Back in the early days of HITECH, doctors were supposed to only be using corporate email and certainly never using unprotected, public services for transmitting or storing anything deemed patient information. Doc after doc would do their dictation and then email it to their staffer using the doc's personal unprotected gmail account that did not even have MFA enabled.

On the same computer, the doc had access to their corporate, compliant email and their personal unprotected gmail account. They would choose to use their insecure gmail account every time. Their gmail account accumulated copies of all the patient dictation. Personal health records that were supposed to be protected. The docs were 100% in violation of not only law, but the trust the patients had placed in them to keep their treatment information secure.

The choices that people make have a direct adverse impact on the data about other people that they have in their possession.

I don't create burn after reading documents either. But I guarantee you that everyone I do business with or interact with is interested in knowing that I'm not allowing the contents of our interactions to be uploaded into a cloud processed AI. Even if the only component of the interaction is the presumption that it is a private conversation, that means don't upload it or process it through cloud processed AI.

Proper tool selection should include a properly scoped list of factors that accumulate a real total cost of ownership instead of the naiveté of perceived acquisition cost. Consumers can fight back by asking questions and going elsewhere when they don't get proper answers.

Randy's avatar

Thanks for the prompt reply, Tracy. My wife and I owned a medical transcription/ documentation service in the 1980s and 90s. This was before HIPAA, but patient privacy was paramount back then. We employed people working from home -- a cutting-edge practice at the time -- and we required that their transcription equipment be located in a room where they could close the door while they were working, to prevent a family member from wandering by and looking over their shoulder while they typed. Mini cassette tapes containing the doctors' dictation were hand-delivered to them by our runner, who also picked up floppy disks with their completed reports. The same runner also hand-delivered printed medical reports to our hospital and doctor clients. Neither voice dictation nor written documents were ever transmitted from/to our office by modem over the phone line (this was before the Internet was a big thing).

With the advent of the electronic medical record (EMR) in the HIPAA era, all communication to/from EMR databases was encrypted. That was fine as far as it went, but at that point, the system broke down. Doctors, who were used to speaking into a hand-held tape recorder and having their perfectly typed reports "magically" appear a couple days later, were not happy that they now had to sit at a workstation and clearly dictate into a microphone, then proofread their report on-screen and correct the voice recognition results, which were very crappy in the early days. So they cheated. They used "boilerplate" procedure notes with fill-in-the-blanks that would be modified with the patient's information. More than one doctor had their secretary read the boilerplate text into the voice rec. workstation, then electronically sign his name. And unsurprisingly, almost every surgical procedure had the same op notes, right down to "this patient had numerous complications which made the procedure more difficult than usual, taking much more time than normal." (To inflate their billing, of course.)

We sold our business to a national transcription company before cloud drives and cloud computing was introduced, but I'm sure that the "cheating" is more sophisticated and more widespread today. As for me, my VPN places me in a different state, and my phone goes into a Faraday bag before I leave home.

Tracy Sanders's avatar

I have thought for a very long time that if professional services providers were to articulate in their sales/marketing messaging things which convey how seriously they take customer data/information without revealing too much that could be used by malicious actors, I think they would have a distinct competitive advantage. True that the customers have to care. But if the pricing is fairly consistent with competitors or a bit more while articulating protections and just an attitude/culture of the organization of taking things seriously, it would go a long way.

The current situation is such that because so few customers articulate their preferences or walk away from insecure providers, the only anti-sales complaints heard by the providers is about cost. I talk to them. They don't hear from prospects who chose to take business elsewhere because of a lack of demonstrable care of data security. They seem to only hear from those who whine about cost.

I do a lot of professionally paid counterparty risk assessments and teach classes on third party information security risk management. Doing things right usually takes the same amount of effort and cost as doing them wrong, even in the short run. The right way is always the least expensive in the long run.

Business decisions makers in the vast majority of cases will do what their prospects and customers express demand for.

I also feel like these factors for potential competitive advantage are in the hands of the small operator. The small to medium business can compete with the large providers in quality and risk avoidance, but only if they can prove it and articulate it well.

Since there are so few professional services providers that really have their ducks in a row, a lot of orgs and individuals are left going it alone. A solid risk management approach I have used for decades is to not outsource. This decision was a product of seeing over 400 businesses and how they mishandled data because they did not create a culture of training and seriousness. All it takes are policies, documented procedures, weekly training of about 15 minutes, and enforcement. Those are all necessary for solid, consistent service delivery anyhow.

The annual training practice is hilariously ineffective.

Anytime a business leader fills out an insurance application, they are legally attesting that things are going on that they say yes to. When they fail to harmonize their policies/procedures and actual culture of the organization with what they said yes to, they are effectively invalidating insurance coverage. When their customer contracts are contingent on having certain coverage in place, the business is now in breach of contract.

I've also seen a bunch of instances where something should have been caught on a vendor risk assessment or was legally reportable to State Atty General office. Until the customers care enough to seek enforcement by having their vendors prove to them the truth of what they say they are doing, I think the problems will keep occurring.

People like myself are under contractual NDAs on the details. The customers need to make these decisions themselves by asking questions of the providers and saying no when they don't get good answers.

It's a lot cheaper on the front end to do a risk assessment (typically less than 15 minutes of effort) than to deal with the impact of a service provider who failed to protect the data.

Capital9's avatar

In one of my recent comments left for a previous post of yours, Dr. Yoho, I expressed strong disapproval of your promotion of AI, being fully aware of the looming evils of the venue. There are certainly many great alternatives to facilitate cures for carpal tunnel syndrome, my own case being a perfect example, and I do lots of typing. It's difficult, even sad, to me that you are now using the Substack platform to actually advertise your use of AI, using carpal tunnel syndrome as an excuse.

Unfortunately this has crossed my final line, and at this time I will no longer like, subscribe to, or follow any of your posts. I am in total agreement with Nosey Parker's response to this latest money-making strategy of yours. This is yet another reason not to trust doctors. Btw, for many years now, I have felt increasingly strongly that I would no longer resort to the medical industry's treatments, methods, or drugs to save my life, now being more certain than ever that such submission would in all likelihood do much more harm than good. At almost 75yoa, I am on zero drugs, and do not "have" any doctor or dentist. I treat my ailments holistically, even when it means cutting back on food to be able to foot the bill that no "health insurance" will cover.

Robert Yoho, MD's avatar

If you are afraid of doing something because you're going to make someone unhappy, you'll never go anywhere. The other thing I would say is that talking about AI without ever having used it is like a virgin opining about the problems with sex.

Capital9's avatar

Who said anything about FEAR??? Take whatever insulting statements you want to make about my person ELSEWHERE! DO the frikken research! AI data centers are already causing death and misery for many people! Let me remind you that GREED is one of the seven deadly sins! I do not care what you have to say from this point forward, and if you attack me again for my personal views, as stated, I will block you!

Randy's avatar

Thank you for going away, Cap.

Capital9's avatar

Still here, dude!

Everything Voluntary Jack's avatar

Thanks for the tips, Robert.

One back for you, if you are not yet using NotebookLM AI, try it.

The Pro version is $20/month and allows 300 uploads.

This is an amazing resource as you can load the files on a project and select which ones for the AI to work on and not only produce papers with academic references but then create videos and two voice deep dive audios for over 50 minutes.

Thanks for your great work for Health Freedom.

Keep free then safe.

nosey parker's avatar

What goes around comes around. This is why I'm suddenly unemployed. If you can't get people to make paid subscriptions, this is why. Also why I boycott the medical industry.

Scrub-Texas's avatar

As a former medical transcriptionist and laid off during the 2008 economic downturn aka replaced by VR - voice recognition- my typing skills were 100+ wpm, I can hang with your great equipment - not feeling sooo obsolete yet! Give me a shout out if shite goes down - lol - I can pound it out for ya! By the way your desk looks like my hubs music room I crash and play music with him. We both enjoy your stacks soo much!

Robert Yoho, MD's avatar

I would never impose. I have other options, but thank you.

Jack Regula's avatar

Hi Robert,

Keep up the good work and keep fighting the good fight.

Don't go quietly into the night.

Robert Yoho, MD's avatar

It's a compulsion.

FREED0ML0VER's avatar

I wonder if A Midwestern Doctor knows how useful this is. AMD just posted an article on carpal tunnel explaining how it was affecting him/her because of all the typing involved for substack articles.

Robert Yoho, MD's avatar

I sent the info to them.

nosey parker's avatar

Raw goat milk cured my very extreme carpal tunnel permanently in three weeks. I ate it in Indian curd added to curry. Plus newborn goat kids are the more charming babies in the world.

Amberlina's avatar

Anyone else have fun perusing Dr. Robert Yoho's desk to see what all he takes? Haha

And yes, Unbekoming is something else! My favorite Substackers are Dr. Robert Yoho, Curious Outlier, and Unbekoming. I sometimes read others but those are my faves

Robert Yoho, MD's avatar

You are my fave.

Judy Heintschel's avatar

So happy for you!!! And thank you so much for ALL you do. 🤍🙏🏻

Ge's avatar

Good info. Thanks.

Musician's & Filmies Jam's avatar

I have been using otter.ai, I wonder how they compare?

Robert Yoho, MD's avatar

That is designed for meetings, but I've heard it does pretty good dictation too. The one I have is a specific dictation app.

Musician's & Filmies Jam's avatar

Yes you just talk into your phone then upload it into http://otter.ai and it types it all out or creates a mp3, txt or pdf but you have to edit the mistakes.