By Scott M. McAuliffe, CPA, CISA, CFE, Risk Advisory Services Partner
Establishing AI Guardrails to Protect Patient Data and Critical Systems
Artificial intelligence (AI) is quickly finding its way into healthcare organizations. Your team members may already be using AI to summarize documents, draft communications, analyze data, support administrative workflows, or automate routine tasks. AI capabilities are also increasingly being built into technology your organization already uses.
For healthcare leaders, that creates an important question: How can you take advantage of AI while protecting sensitive information and managing the risks that come with it?
Practical AI guardrails can help your organization establish appropriate boundaries without unnecessarily limiting useful applications of the technology.
Start with visibility
One of the first challenges with AI governance is knowing how AI is already being used across your organization.
Consider a team member who wants to save time summarizing a document containing protected health information (PHI). Pasting that information into an AI application may seem like a simple solution, but it raises important questions. Where does that information go? Is it retained? Can the provider use it to train its models? Does the application meet your organization’s security and privacy requirements?
When team members use AI applications without formal approval or oversight, it is often referred to as shadow AI. The risk is that sensitive information can move outside established security and compliance processes without leadership or IT knowing it happened.
Your team members may not always know what information is appropriate to share with an AI platform, so clear guidance can help them make informed decisions.
Before setting that guidance, take a closer look at how AI is being used today. Identify the applications your team members use and ask:
- What are they using the application for?
- Could the application access PHI or other sensitive information?
- How does the provider store, retain, and use your data?
- Who reviews AI-generated information before it is used?
- What happens when the application gets something wrong?
Understanding what is happening today gives healthcare leaders a more practical starting point for deciding what should happen next.
Apply controls based on risk
Not every use of AI comes with the same level of risk. Using an approved AI application to polish a general internal communication, for example, is very different from using an AI tool to analyze patient information or support a decision that could affect patient care.
Your guardrails should reflect those differences.
Consider setting clear expectations around which applications are approved, what information can be shared, who has access, and when human review is required. Training, monitoring, and incident response should also be part of the conversation.
The goal is to give team members enough direction that they do not have to guess whether an AI use is appropriate.
AI security is also a third-party risk issue
Healthcare organizations already rely on a broad network of technology providers, and AI vendors should not sit outside your existing third-party risk management process.
If an AI application will process PHI, patient data, financial information, or other sensitive information, understand how the provider protects and uses that data before introducing the technology into your environment.
Depending on the application, that may mean reviewing encryption and access controls, data retention, breach notification requirements, regulatory considerations, subcontractors, and whether your information could be used to train AI models.
Your existing vendor management processes may already cover many of these risks. Instead of starting from scratch, look for opportunities to add AI-specific questions to the controls you already have in place.
What should your AI guardrails include?
Effective AI governance does not have to begin with a complicated new framework. It does require clear ownership and expectations.
Healthcare leaders should consider addressing:
- Approved applications. Identify which AI platforms team members may use and establish a process for reviewing new applications.
- Data restrictions. Clearly define whether PHI, patient data, financial information, and other sensitive data can be entered into AI applications.
- Access controls. Limit access to AI capabilities and organizational data based on roles and business needs.
- Human review. Establish when AI-generated information requires review and validation before it is used.
- Vendor management. Include AI providers in your existing third-party risk management process.
- Training. Give team members practical guidance about appropriate AI use, including what information should not be entered into unapproved tools.
- Monitoring. Periodically review which AI applications are being used and whether established controls remain appropriate.
- Incident response. Consider how your organization would respond if sensitive information were entered into an unapproved AI platform or an AI application were involved in a cybersecurity incident.
The right controls will depend on how your organization uses AI, the information involved, your regulatory requirements, and your existing risk environment. The objective is not to remove every risk. It is to understand where meaningful risks exist and establish reasonable controls around them.
How can Keiter help?
Healthcare organizations do not have to approach AI governance as an entirely new cybersecurity initiative. Existing policies, vendor management processes, access controls, data protection practices, and incident response plans can provide a starting point.
Keiter’s Cybersecurity & Risk Advisory specialists work with healthcare and medical practices to evaluate where AI fits within existing cybersecurity, governance, and risk management practices. This may include assessing controls, identifying gaps, considering third-party risks, and developing practical AI governance policies.
Questions about AI governance, SI, or your healthcare organization’s cybersecurity controls? Contact Keiter’s Cybersecurity & Risk Advisory Services team to learn more.
Sources: Cybersecurity and Infrastructure Security Agency; Anders, “How AI Guardrails Can Make or Break Your AI Adoption.”
About the Author
The information contained within this article is provided for informational purposes only and is current as of the date published. Online readers are advised not to act upon this information without seeking the service of a professional accountant, as this article is not a substitute for obtaining accounting, tax, or financial advice from a professional accountant.