Blog Post

Compliance Officer Responsibilities for Using Artificial Intelligence

Richard P. Kusserow | July 2026

As in many business sectors, healthcare compliance officers are increasingly considering how artificial intelligence (AI) can support their duties and responsibilities. AI can help automate routine compliance activities, including policy mapping, regulatory change monitoring, and audit scheduling. It can also assist with risk and fraud detection in billing, claims, coding, prescribing, and arrangements with referral sources.

Many compliance officers also have responsibilities under the Health Insurance Portability and Accountability Act (HIPAA), where AI may be used to support protected health information (PHI) discovery, de-identification, Business Associate Agreement (BAA) identification, and data-loss prevention. Other uses may include contract and vendor management, third-party risk scoring, personalized compliance training, and simulated scenarios.

These opportunities can improve efficiency, but they also require strong governance, documented controls, and ongoing oversight. Compliance officers using AI should address the following responsibilities:

  1. Ensure lawful, ethical, and secure AI use across data, model, and operational lifecycle.
  2. Assess and mitigate key risks, including privacy, bias, safety, reliability, security, and inappropriate reliance on automated outputs.
  3. Maintain documentation, validation records, and audit trails that show how AI tools are selected, tested, used, and reviewed.
  4. Oversee vendor due diligence and contractual safeguards, including data-use restrictions, confidentiality obligations, security controls, breach notification duties, and rights to audit.
  5. Coordinate AI governance with legal, information technology (IT), information security, clinical, privacy, procurement, and operational leaders.
  6. Apply HIPAA safeguards to PHI and electronic protected health information (ePHI), including minimum-necessary access, appropriate de-identification, access controls, and Business Associate Agreements (BAAs) when vendors create, receive, maintain, or transmit PHI.
  7. Monitor applicable state privacy laws, emerging AI requirements, sector-specific rules, and organizational policies to ensure AI use remains current with changing obligations.
  8. Address record retention and access rights, including patient access requests, government audits, investigation needs, and the preservation of records showing how AI-supported decisions were made.

Interested in discussing the needs of your compliance program? Contact Richard Kusserow at [email protected].

About the Author

Richard P. Kusserow established Strategic Management Services, LLC, after retiring from being the DHHS Inspector General, and has assisted over 3,000 health care organizations and entities in developing, implementing and assessing compliance programs.

Subscribe to blog