What the CISO Now Owns
AI arrived in healthcare before security did. Technical debt in legacy systems, quickly built and poorly documented APIs, governance treated as a post-deployment task, governance transferred to cloud and partner platforms, and consent forms that never mentioned AI. What the CISO now owns, and where transparency has to start.
A recent study of AI adoption in Fortune 500 companies and its impact on cybersecurity has identified a disturbing trend. It found that, in most cases, companies have taken an “AI first, security later” approach, which forces the cybersecurity professionals responsible for safeguarding those companies to play a dangerous game of catch-up. Cybersecurity teams in the healthcare space — even outside of Fortune 500 companies — are among those most challenged by this new trend. The pace of AI adoption in healthcare is accelerating rapidly, and with good reason. AI has the potential to reduce care gaps while also preventing doctor burnout. It gives providers the tools they need to better manage, understand, and leverage data. But AI also introduces risks that, while not new, have become more difficult to manage due to the rapid pace of adoption. Chief among those risks are issues emerging within the systems used by healthcare providers to collect and safeguard data.
New risks for healthcare data Technical debt is one of the risks that has become more difficult to manage as the pace of tech development and deployment increases. Increased demands created by increased data flows push legacy systems to their limits. In some cases, the APIs needed to connect new tools to older existing systems are developed quickly and with little documentation, creating the potential for security holes that can’t easily be patched. Governance is a critical cybersecurity concern that suffers when the pace of technological adoption speeds up. Recent guidance provided by the American Medical Association encourages healthcare organizations to ensure adoption of new AI tools includes setting up governance systems to “manage and guide how that technology will be used to help physicians, patients and others in the organization.” For many organizations, however, governance is viewed as a post-deployment task. Roles and responsibilities for model monitoring, risk review, and drift management are often unclear or entirely absent. And those that scale systems through external partnerships and cloud platforms often engage in governance transfer, a practice that can leave them unaware of vulnerabilities and incapable of effectively responding to breaches. Gaps in patient understanding about how their information is used is another security concern that can quickly appear as new AI tools are integrated into electronic health record management systems. As new AI systems come online, consent processes must be updated to reflect their new use. Traditional consent forms tend to focus on treatment or billing and rarely explain the use of AI training, third-party access, or the long-term use of health data in predictive systems. De-identification is often used to mitigate the risk of data breaches when protected health information or other patient data is used by AI applications. But that measure has become far less effective as AI has given cybercriminals the power to combine stolen data with other sources to reverse the de-identification process.
Guman Chauhan, on The Signal Room Alerts are often treated as a proxy of truth in our industry. If dashboards are quiet, leadership assumes everything is fine. But attackers understand this better than anyone. And actually, design attacks specifically to stay invisible. So instead of deploying malware, they use valid credentials. Steps to staying secure in the age of AI The key to preventing security gaps in health systems is to embed transparency and governance from the beginning. As AI applications are being built, security teams should work with the other departments involved to ensure that workflows are traceable, explainable, and auditable. The more transparent AI systems become, the easier it will be to identify and address emerging risks. Concerning governance, organizations should clarify ownership of every model and clearly define who is responsible for monitoring performance. When relying on third-party systems, organizations should strengthen internal fluency in managing vendor access and platform risk.
To avoid regulatory, ethical, and reputational risks, organizations should redesign patient consent systems to reflect AI use, not just legacy data policies. Where de-identification is used to secure patient data, organizations should conduct re-identification risk analysis before releasing it.
AI has the potential to improve care and efficiency, but it won’t achieve those goals without first earning patient trust. When governance is visible, risk is managed, and patient data is used responsibly, the needed level of trust can be achieved. Responsible adoption begins with clarity, accountability, and the willingness to lead with transparency.
One signal a week. No noise.
Join healthcare leaders reading The AI Health Pulse every Monday.
Facing a challenge like this in your own system?
See how we approach healthcare AI consulting and data and analytics strategy, or book a call.