AI is playing an increasingly central role in patient care at hospitals across the country, but the same models driving that innovation are also being turned against providers by hackers.
Cyberattackers and nation-states are now using AI to automate and scale their attacks with a speed and precision that didn’t exist just a few years ago, said Karen Habercoss, chief information security and privacy officer at the University of Chicago Medicine.
She noted that cybercriminals are using AI for the same reasons hospitals are — to automate tasks and operate with more speed and scale.
“The risk has to be balanced,” Habercoss remarked during an interview this month.
Healthcare remains the most attacked industry in the country, which she said is a problem compounded by the amount of legacy technology still in use across many health systems.
That older infrastructure can’t be replaced overnight, so organizations instead have to focus on segmenting and isolating it to reduce risk, Habercoss explained.
Layered on top of that is the growing complexity of third-party vendors, many of which are now embedding their own AI tools into their products. Habercoss said her organization treats vendor oversight as a continuous process rather than a one-time checklist. This involves auditing partners over time to make sure their security and privacy practices still align with the health system’s own standards.
That type of ongoing scrutiny has become essential as AI adoption accelerates on both sides of the security equation, Habercoss added.
To manage that increasingly complex web of risks, Habercoss said UChicago Medicine has developed a multilayered AI governance system over the past several years.
It includes a steering committee that oversees subcommittees focused on AI intake, inventory, education and training, and auditing and monitoring. A separate cross-functional committee, which Habercoss co-chairs with the health system’s chief analytics officer, brings together physicians, legal, compliance and other senior leaders. A third committee focuses specifically on clinical use cases, pairing nurse and physician leaders with her team to vet new tools before they reach patients.
Any new AI tool — whether it’s introduced through a vendor contract, a physician request or a faculty research project — gets routed through all three committees before it’s approved, Habercoss said. She noted that redundancy is intentional.
“If you think you’re talking to enough people, you’re likely not,” Habercoss declared, adding that AI decisions often touch on federal and state regulations that no single department can track alone.
The goal is to make sure no one part of the organization is making decisions about AI in isolation, she stated.
Photo: Tunvarat Pruksachat, Getty Images