The following is a guest article by Sam Peters, Chief Product Officer at IO
Healthcare organizations are moving quickly to adopt artificial intelligence. From clinical documentation assistants and patient communication tools to operational automation and decision support systems, AI is becoming embedded throughout healthcare workflows. The promise is significant: greater efficiency, reduced administrative burden, and improved experiences for both patients and providers.
What many organizations are discovering, however, is that the challenge is not simply adopting AI. It is governing risk in an environment where technologies, vendors, and regulatory expectations are evolving faster than many oversight processes were designed to accommodate. Healthcare organizations were already managing increasingly complex technology environments, growing third-party dependencies, persistent cybersecurity threats, workforce shortages, and expanding compliance obligations. AI is arriving on top of those existing realities, adding another layer of complexity and forcing leaders to examine whether their governance practices are capable of keeping pace with a rapidly changing risk landscape.
Governance Was Already Under Pressure
Much of the conversation around AI assumes healthcare is confronting an entirely new category of risk. In practice, many organizations are encountering familiar governance challenges that have simply become more visible as AI adoption accelerates. Fragmented oversight, limited resources, growing supplier dependencies, and difficulty maintaining visibility across complex technology environments have all been longstanding concerns for healthcare leaders.
Recent research from IO’s State of Information Security report reflects this reality. While 47% of healthcare organizations identified AI-driven phishing as a significant threat and 51% cited AI-generated misinformation and disinformation as a growing concern, the underlying pressures were already present. More than half (51%) reported budget constraints affecting security initiatives, 47% identified information security skills shortages, and 55% experienced a third-party or supply chain incident during the past year.
AI is changing the speed and scale at which these risks can materialize. Threat actors can automate activities that previously required significant time and expertise, while healthcare organizations are simultaneously under pressure to evaluate and deploy AI-enabled technologies faster than many governance processes were designed to support. The result is an environment where risks evolve more quickly than traditional oversight models can track.
The challenge extends to the defensive side as well. While AI has the potential to help healthcare organizations improve threat detection, prioritize alerts, and streamline security operations, it cannot compensate for fragmented governance or inconsistent risk management practices.
Annual Assessments Cannot Keep Pace
For years, healthcare organizations have relied on annual risk assessments, periodic compliance reviews, and point-in-time audits to evaluate security, privacy, and operational risks. Those practices remain important, but they were developed for environments where major technology changes occurred over months or years. Today’s healthcare technology ecosystem operates very differently.
AI-enabled platforms receive frequent updates, vendors continuously introduce new capabilities, and data flows evolve as systems become more interconnected. A healthcare organization’s risk profile can look very different at the end of the year than it did when the annual assessment was conducted. Yet many governance programs still rely heavily on periodic reviews that provide only a snapshot of risk at a particular moment in time.
This becomes even more challenging because AI-related risks rarely fit neatly within a single department. A clinical documentation assistant, patient engagement platform, or operational AI tool may simultaneously create cybersecurity, privacy, compliance, third-party risk, and patient safety considerations. Governance structures built around isolated functions often struggle to maintain visibility into risks that span multiple teams and evolve continuously.
Many healthcare leaders are finding that annual assessments remain valuable, but snapshots alone are no longer sufficient. Organizations increasingly need mechanisms for ongoing assessment, communication, and accountability that provide visibility into how risks change over time.
Governance Must Become an Operational Function
The challenge becomes even more complex in healthcare’s highly interconnected vendor ecosystem. Most organizations are not building AI systems themselves. They are acquiring capabilities from software providers, cloud platforms, medical device manufacturers, and specialized healthcare technology vendors. As those suppliers introduce new functionality and update existing products, healthcare organizations must understand how those changes affect their own risk posture.
This is why governance is increasingly becoming an operational function rather than a compliance exercise. Across cybersecurity, privacy, operational resilience, and emerging AI governance requirements, regulators and executive leadership teams are looking for evidence that organizations understand and manage risk continuously, not just during audit cycles. The expectation is shifting from demonstrating compliance at a specific point in time to demonstrating ongoing awareness, accountability, and resilience.
For healthcare leaders, the priority should be strengthening the fundamentals: governance, resilience, supplier assurance, workforce capability, and risk management. Frameworks such as ISO 27001, ISO 27701, and ISO 42001 can provide useful structure, but what matters most is establishing repeatable processes that help organizations assess, communicate, and adapt to risk as conditions change.
The organizations that realize the greatest value from AI are unlikely to be the ones deploying the most tools. They will be the organizations that can confidently understand and manage risk as their environments evolve. As AI adoption continues to accelerate, governance must evolve from a periodic compliance activity into an ongoing operational discipline—one that enables organizations to innovate while maintaining trust, accountability, and resilience.
About Sam Peters
Sam Peters is Chief Product Officer at IO and has more than 20 years of experience in cybersecurity, privacy, risk management, and governance. He previously served as Chief Information Security Officer and Data Protection Officer, leading programs focused on ISO 27001, privacy governance, and emerging AI governance frameworks.
No comments:
Post a Comment