Otter AI bot leaks hospital patient health information
Otter AI bot leaks hospital patient health information
Occurred: September 2024
Page published: September 2026
An unauthorised, automated transcription bot automatically joined a virtual hospital meeting, transcribing and sharing sensitive personal health information about seven patients, exposing serious administrative, offboarding, and AI governance vulnerabilities in healthcare data security.
A group of physicians at an Ontario hospital held a virtual hepatology "rounds" meeting to discuss the medical records and care plans for seven admitted patients.
Unbeknownst to the attendees, an Otter.ai transcription bot automatically joined the call, listening to the discussion, transcribing it, and emailing a full summary, including patient names, genders, primary physicians, diagnoses, and detailed treatment notes, to 65 people on the calendar invitation list, 12 of whom were no longer employed at the hospital.
The breach was driven by a combination of inadequate employee offboarding procedures and agentic AI functionality:
Corporate offboarding gaps. A physician who left the hospital was never removed from recurring hepatology meeting calendar invites, nor was his access to the hospital's internal calendar infrastructure fully revoked.
Corporate email use policy violations: Contrary to hospital rules requiring official work email addresses, the former physician maintained access using a personal email address.
Autonomous bot syncing. The former physician connected Otter.ai to his personal calendar. The tool's auto-join feature ("OtterPilot") detected the upcoming virtual meeting, autonomously joined the call on the former physician's behalf without explicit live host authorisation, transcribed the PHI and automatically shared the output with all calendar invitees.
The incident underlines how "shadow AI" and autonomous meeting agents can bypass security perimeters through legacy user access points.
For health organisations, it highlights the need for strict offboarding, technical meeting controls (e.g., waiting rooms/lobbies), and endpoint restrictions against unapproved AI tools.
For policymakers, it emphasises the privacy risks of third-party consumer AI tools processing regulated data without institutional oversight or consent.
System: Otter.AI; OtterPilot
Developer: Otter.ai Inc.
Deployer: Hospital
Purpose: Transcribe hospital meeting
Technology: Audio-to-text; Machine learning; NLP/text analysis; Speech recognition
Ethical issue: Confidentiality; Consent; Privacy/surveillance
News trigger: Regulatory investigation
External harm: Privacy loss
Impacted stakeholder: Patient
Impacted sector: Health
Jurisdiction: Ontario, Canada
Consequence: Regulatory investigation/action
Response:
June 2023. The physician leaves employment at the Ontario hospital but remains on recurring internal meeting invites and calendar links.
September 2024. The former physician sets up an Otter.ai account linked to his personal calendar.
September 23, 2024. The Otter.ai bot joins the hospital rounds meeting undetected, transcribes the PHI of seven patients, and emails the notes to 65 meeting invitees
December 17, 2024. The hospital self-reports the privacy breach to the Information and Privacy Commissioner of Ontario (IPC).
October 27, 2025. The IPC publishes its official response letter to the incident.
Personal Health Information Protection Act (PHIPA)
Information and Privacy Commissioner of Ontario. IPC response to hospital privacy breach involving an AI scribes tool
AIAAIC Repository ID: AIAAIC2172