Why Healthcare AI Vendor Risk Demands Stronger Oversight #AI


Artificial Intelligence & Machine Learning
,
Data Privacy
,
Data Security

Tom Walsh of tw-Security on Prioritizing High-Risk Vendors and AI Governance


Tom Walsh, founder and principal consultant, tw-Security

Healthcare organizations can’t rely solely on vendors’ assurances that artificial intelligence tools are secure and trustworthy. As AI adoption accelerates, providers need stronger governance, better oversight of third-party vendors and greater scrutiny of how AI affects patient data and clinical decisions, said Tom Walsh, founder and principal consultant at consultancy tw-Security.

See Also: A Darkening Landscape: AI, Friend and Foe of Cyber Resilience

Many healthcare organizations lack the staff and time to thoroughly assess hundreds of third-party vendors. Walsh recommends prioritizing attention on vendors – including AI technology firms – that pose the greatest risks based on their access to protected health information and personally identifiable information.

Along with those efforts, organizations also need AI governance frameworks, updated vendor assessments and greater transparency into how vendors develop, validate and oversee AI capabilities.

“I would ask for better documentation from the vendors to prove what human oversight they’ve implemented into their AI products and services,” Walsh said. “We do not want something bad happening to a patient because we relied on an AI that wasn’t accurate.”

Walsh also warned that AI-powered clinical documentation tools – including ambient tools – can introduce errors into electronic health records if clinicians fail to review AI-generated notes before signing them. He advises healthcare organizations to strengthen human oversight, revise business associate agreements and update privacy notices so patients understand how AI collects, processes and uses their information.

“I don’t think a lot of patients know or recognize that their conversation with a doctor or clinician is being scribed by an AI agent and then placed into their record,” he said. “I think that’s one area that patients are not aware of how AI is being used in hospitals or healthcare systems today.”

In this video interview with ISMG, Walsh also discussed:

  • How to prioritize high-risk AI vendors for security and privacy reviews;
  • Risks related to shadow AI use in healthcare;
  • How AI-generated clinical documentation can affect data integrity and patient safety.

Walsh is founder, partner and principal consultant of tw-Security, a healthcare privacy and security consulting firm. He is a certified information systems security professional, a nationally recognized speaker and co-author of four books on healthcare information security. Walsh has over 34 years of information security experience. In addition to being an independent consultant, Walsh has been the virtual privacy and information security officer for several healthcare organizations and business associate firms.





Click Here For The Original Source.

——————————————————–

..........

.

.