AI technologies are bringing remarkable new capabilities to health systems, especially when it comes to leveraging health data to improve patient care. But before healthcare providers can integrate AI tools into their workflows, they must ensure their strategies align with relevant privacy laws.
“Data privacy compliance is not an option for an AI strategy; it is a requirement,” says Chris Hutchins, Founder and CEO of Hutchins Data Strategy Consulting. “We in healthcare are custodians of deeply personal data. Trust lost is everything lost.”
Hutchins is a nationally recognized leader in AI strategy and healthcare analytics who has held leadership roles at the nation’s most prestigious healthcare systems, guiding the development of AI adoption strategies. He has spent more than three decades helping hospitals and healthcare organizations leverage data and technology to improve patient care. As the Founder and CEO of Hutchins Data Strategy Consultants, he partners with organizations to unlock the full value of their data through ethical, scalable healthcare delivery strategies.
“Effective AI strategies must balance quality, equity, accessibility, and operational integrity,” Hutchins explains. “Privacy is a critical part of the equation, one of the primary principles that contribute to making AI useful and worthwhile in the first place.”
The key compliance risks of AI in healthcare
Data is the lifeblood of AI systems. AI developers use data to train models and generate algorithms. Once AI applications are created, they are often used to analyze data and identify patterns that can be used to drive personalization or guide decision-making.
In the healthcare field, the privacy of electronic health records and other forms of patient data is protected by law. Consequently, the integration of AI with digital health systems poses risks in the form of data compliance.
“One of the most concerning risks the healthcare leaders must address as they use AI is data exposure and breach,” Hutchins says. “This is especially true when the application of AI involves third-party tools, cloud services, or large language models that transfer sensitive data beyond the organization’s protected environment.”
Statistics show that data breaches are a huge concern among patients, with 95 percent reporting they fear the use of AI could lead to sensitive health information being abused by criminals. Providing clear communication about how patient data is secured and how it could be used by AI software is critical for addressing patient fears.
“Informed consent needs to be a core element of AI adoption strategies,” Hutchins warns. “Patients have a right to be told when AI solutions are part of their healthcare and how that affects the decision-making process and likely health outcomes. Data security and informed consent are not solely compliance risks, but also present ethical and clinical responsibility challenges for healthcare professionals.”
Examples of AI strategies that benefit healthcare systems
Providers must take steps to develop compliance-driven strategies for their healthcare systems if they expect to fully realize the benefits of AI. To ensure AI healthcare strategies are sound, compliance and privacy teams should be integrated into the process early on. Legal, risk, cybersecurity, clinical, and data governance functions should be engaged early and as part of a coordinated process.
Providers should prioritize data governance frameworks to ensure AI models are reliable and compliant. A strong investment in governance lays the foundation for accountability, fairness, and performance.
“Providers need to make sure the data fueling their AI is high-quality, consistent, and well-maintained,” Hutchins says. “Effective governance accomplishes that. Without it, AI initiatives will be jeopardized before they even start.”
Effective strategies must also consider the steps vendors are taking to ensure compliance. Third-party providers of AI tools for the healthcare industry should be able to explain how they address issues such as proof of equity and data provenance.
“Healthcare companies should be asking vendors what safeguards are in place to keep systems on course, along with how they know the system is not being misused or diverging from the goal over time,” Hutchins explains. “If a vendor cannot clearly answer those questions, healthcare providers should see it as a red flag that the product is not ready for direct clinical application.”
Healthcare providers can’t ignore the benefits of AI
AI provides the power to transform the delivery of healthcare in a wide variety of ways. But tapping into that power while also maintaining patient trust requires striking a balance between innovation and compliance.
“AI helps make the healthcare system more efficient by relieving the manual burden and improving throughput and insights that allow earlier and more effective interventions,” Hutchins says. “Most importantly, AI can give time back to those providing the care — time to focus, time to connect, and time to make decisions that are both data-driven and humane. The key is responsible adoption of AI with the appropriate guardrails.”