Tom Walsh of tw-Security Advocates for Enhanced Oversight and Governance in Healthcare AI Vendors
As the adoption of artificial intelligence (AI) in healthcare accelerates, the industry faces pressing challenges regarding the governance and oversight of third-party vendors. Tom Walsh, the founder and principal consultant at tw-Security, emphasizes that healthcare organizations cannot simply rely on the assurances provided by these vendors regarding the security and trustworthiness of their AI tools. In a landscape where data privacy and security are paramount, Walsh argues that a more robust framework for governance is essential.
The Need for Scrutiny in AI Adoption
In his recent statements, Walsh highlighted a critical concern: many healthcare organizations often lack sufficient resources to conduct thorough assessments of the numerous third-party vendors they engage with. This includes various AI firms that have access to sensitive patient data. Recognizing this gap, he suggests that organizations should prioritize their focus on high-risk vendors—those that have significant access to protected health information (PHI) and personally identifiable information (PII). This prioritization is crucial, given the potential risks to patient safety and data integrity.
The rapid integration of AI technologies into healthcare necessitates that organizations not only implement risk assessments but also develop comprehensive AI governance frameworks. Walsh emphasizes the importance of updated vendor assessments and enhanced transparency regarding how vendors are developing, validating, and monitoring their AI capabilities. He underlines the need for better documentation from vendors that clearly details the human oversight integrated into their AI products and services. "We do not want something bad happening to a patient because we relied on an AI that wasn’t accurate," he stated, underlining the gravity of the situation.
The Risks of AI-Powered Systems
Walsh has raised additional concerns regarding AI-powered clinical documentation tools, such as those that record conversations between doctors and patients. These ambient tools, while innovative, can inadvertently introduce errors into electronic health records (EHR) if clinicians do not meticulously review AI-generated notes before finalizing them. Recognizing this issue, Walsh advises healthcare organizations to enhance human oversight processes, revise business associate agreements, and update privacy notices to ensure that patients are aware of how AI collects, processes, and utilizes their personal information.
This lack of awareness among patients is alarming. Walsh points out that many individuals may not realize that conversations with their healthcare providers are being documented by AI systems and subsequently entered into their medical records. He stresses that patients must be informed about AI’s role in their healthcare, which could lead to greater trust and understanding of the technologies being employed in hospitals and health systems.
Addressing Additional AI Challenges
In a recent video interview with Information Security Media Group (ISMG), Walsh discussed several topics of significance in the realm of AI in healthcare, including:
- Strategies for prioritizing high-risk AI vendors for security and privacy reviews.
- The risks connected to the unauthorized or “shadow” use of AI in healthcare settings.
- The implications of AI-generated clinical documentation on data integrity and patient safety.
These discussions are indicative of the growing awareness and need for meticulous scrutiny over AI technologies employed in healthcare. As the sector moves toward a more digitized future, the implications of AI usage will require careful consideration and oversight.
About Tom Walsh and tw-Security
Tom Walsh is not only the founder and principal consultant at tw-Security, a consulting firm focused on healthcare privacy and security, but he also brings a wealth of knowledge to the field. A certified information systems security professional, he is recognized nationally as a speaker and has co-authored four books on healthcare information security. With over 34 years of experience in the domain, Walsh has held positions as a virtual privacy officer for multiple healthcare organizations and business associate firms, bringing invaluable insights into the pressing challenges and solutions facing the industry today.
As the healthcare landscape continues to evolve, Walsh’s emphasis on strengthening vendor oversight and governance underscores the importance of safeguarding patient data and ensuring the integrity of clinical decisions influenced by AI.
