The Use of AI in Healthcare and Its Impact on Compliance

Artificial Intelligence (AI) is rapidly transforming the healthcare landscape by enhancing diagnostics, automating administrative tasks, and reshaping clinical decision-making. But with these advances…

Read More

Jim Hook, MPH

By Jim Hook, MPH | February 7, 2026

Doctor entering data in EHR tablet with a multitude of obscure colored lights in the background representing artificial Intelligence in healthcare and the impact on regulatory compliance.

Artificial Intelligence (AI) is rapidly transforming the healthcare landscape by enhancing diagnostics, automating administrative tasks, and reshaping clinical decision-making. But with these advances come new ethical, operational, and regulatory challenges. Understanding how AI intersects with healthcare compliance is critical for every organization adopting AI-powered solutions.

Understanding the Early Risks and Guidance on AI in Healthcare

There are a lot of serious and not-so-serious discussions about the use of Artificial Intelligence in healthcare and in many other sectors of the economy and culture, and indeed, in our personal lives. Many of them are harmless, like the generative AI chatbot that recommended adding glue to thicken a sauce. Others are much more serious, like the chatbot that recommended an individual take sodium bromide to reduce his salt intake. Turns out NaBr is good for preventing algae in hot tubs, but is toxic when ingested. And we have probably all heard about the issue of AI “hallucinations”, where AI algorithms make up references to support their recommendations across a wide variety of subjects – including healthcare.

So what about the use of AI in healthcare organizations? In particular, what are the compliance risks and issues with its use? Turns out, someone is at least developing some initial guidance on how healthcare organizations should approach the use of AI in healthcare.

The JC-CHAI Guidance

Into this yawning gap come two organizations that have joined forces to issue initial guidance for healthcare providers considering how and when to deploy AI-enabled tools. The first is the Joint Commission (JC), founded in 1951, which issues standards for measuring and monitoring healthcare quality and safety. It also evaluates how healthcare organizations perform against those standards. And second, the Coalition for Health AI (CHAI), which is a newer consortium that brings together healthcare organizations and technology leaders in the information systems industry. 

One of its recent efforts was to release a Blueprint for Trustworthy AI, containing recommendations on key elements of trustworthy AI in healthcare. The collaboration between these organizations highlights how the healthcare industry is increasingly uniting around shared principles for the responsible and transparent use of artificial intelligence.

As the healthcare industry considers evaluating AI technologies and proceeding with AI implementation, this guidance is a good place to start. The Guidance, issued in September 2025, is entitled “The Responsible Use of AI in Healthcare” or RUAIH. It is broken up into seven elements, which are outlined below.

The Seven Elements of RUAIH

ItemDetails
1. AI Policy and Governance StructuresBesides implementing policies and procedures for AI implementation, healthcare organizations should include a mechanism to keep the governing body updated on uses, outcomes, and potential adverse events. RUAIH also recommends healthcare teams to deal with the myriad of issues that must be considered: selection, implementation, risk management, lifecycle management, healthcare compliance risks, and oversight.
2. Patient Privacy and TransparencyOf course, protecting the privacy of Protected Health Information (PHI) is already required under the HIPAA Privacy Rule. Healthcare organizations should also disclose and educate patients on the use of AI tools in their organization.
3. Data Security and Data Use ProtectionsDatasets are significant to the proper training of AI algorithms. Healthcare organizations must ensure their sensitive patient data is protected from data breaches when it is incorporated into datasets that may be exported outside the organization. Other recommendations echo the requirements of the HIPAA Security Rule. Encryption of sensitive data both in transit and at rest, access controls and access logs, information security risk assessments, and incident response plans are just a few of the steps highly recommended.
4. Ongoing Quality MonitoringAI tools are expected to change over time as underlying AI algorithms are updated. This expectation of changes means healthcare systems must apply the principles of continuous improvement to their adopted AI technologies as well. Quality monitoring policies should include activities such as validating and testing AI tools for relevant performance and reliability, and creating a process for reporting adverse events or ongoing errors.
5. Voluntary, Blinded Reporting of AI Safety-Related EventsAs a new tool with great potential both for improving patient outcomes and introducing new risks in patient safety, an outside independent reporting agency could be of great benefit to the healthcare sector as it seeks to ensure patient safety. Healthcare organizations should consider using their existing systems for tracking and reporting patient safety issues. They should find pathways such as Patient Safety Organizations and/or the FDA for reporting adverse events related to AI systems.
6. Risk and Bias AssessmentBest practices in this area start with asking an AI technologies vendor about the known risks, biases, and limitations of the system you are considering. Ongoing monitoring should also include checking for biases when validating local data and post-deployment. Evaluating and addressing use-case bias is also important.
7. Education and TrainingAs with any new technology, training of users is paramount. Clinicians and other staff who utilize AI technologies must understand the proper use and limitations of the system. Users can also be the key to identifying patterns of bias or errors that should be reported to the vendor or as patient safety issues.

AI in Healthcare Organizations and the Compliance Function

As artificial intelligence becomes more embedded in daily healthcare operations, maintaining strong regulatory compliance practices ensures that innovation does not outpace legal and ethical responsibilities.

The scope of the Compliance processes and function in healthcare organizations is pretty broad. Yet there are areas where there is minimal impact on compliance officers. Clinical patient care and physical plant operations are two examples. In the case of evaluating and monitoring AI implementation, there is considerable benefit in involving the Compliance program on the team assigned to evaluate, implement, and monitor an AI system.

  • One of the initial significant risks is selecting and contracting with an AI systems vendor. Compliance/Privacy Officers should help evaluate prospective AI technologies for the concerns related to Patient Privacy and Data Security risks noted above.
  • Compliance Departments often operate hotline reporting systems to receive reports of compliance violations related to other compliance risks, such as billing or privacy. Healthcare organizations can utilize the compliance hotline to receive reports of adverse events or ongoing errors related to AI technologies in use in the organization.
  • One of the other serious risk areas for healthcare professionals and provider organizations is the medical record keeping, coding, and billing of claims to government healthcare programs such as Medicare and Medicaid. Compliance professionals already serve as advisors for regulatory adherence for such programs. Expanding the scope of risk assessment to include medical records originated by AI algorithms, as well as coding of patient care services, is a natural fit for the Compliance program.
  • In many institutions, the Privacy Officer is a member of the Compliance Department. Issues with health data security, breaches resulting in unauthorized exposure of ePHI, can also fall within the scope of the healthcare Compliance function.

What to look forward to in Compliance by AI in Healthcare

Extensive use of artificial intelligence in healthcare delivery is just beginning to take off in a serious way. AI offers significant benefits, aiding healthcare providers and optimizing healthcare operations. But many healthcare professionals are skeptical about the accuracy and reliability of current AI systems, while almost desperate for help with administrative tasks. Beyond easing administrative workloads, AI-driven solutions also offer opportunities to enhance operational efficiency, streamlining workflows and allowing healthcare professionals to focus more on patient care and quality outcomes.

And the evolving regulatory landscape is only beginning to consider or implement relevant regulations for the advanced use of AI tools. As innovation accelerates, healthcare organizations must balance the promise of AI with the obligation to navigate complex regulatory requirements that govern data privacy, patient safety, and technology oversight. For instance, the Office of the National Coordinator for Health Information Technology (ONC) operates the Certification Program for Health IT modules in electronic health records. The ONC recently issued a final rule on its clinical decision support criteria (renamed Decision Support Interventions). The criteria are mainly an attempt to make transparent how DSIs were trained and the data used to train them. (No hallucinations and no bias!).

The other main source of regulatory requirements is maintained by the FDA when AI algorithms are utilized in a device. The Federal Trade Commission could also weigh in when there are actions that can be construed as false or misleading with respect to software performance. 

AI technologies are seemingly on the way to transforming healthcare. At The Fox Group, we have participated in this trend with our services to clients seeking certification of their Health IT applications. As you consider your team for analyzing new AI technologies, consider the potential contributions from experienced consultants as well!

(PS, no AI chatbots were injured – or used – in the preparation of this article!)