Blog Post

Meeting Compliance Challenges of Artificial Intelligence

Richard P. Kusserow | April 2026

As healthcare organizations adopt artificial intelligence (AI) in service delivery, compliance officers face a complex and evolving set of risks related to privacy, patient safety, legal exposure, and operational integrity. Without proper controls, organizations may experience increased liability exposure, ranging from malpractice and contractual breaches to regulatory fines, while remediation efforts can be costly and disruptive.

Key areas of concern for compliance officers regarding the use of AI include:

  1. Information that is inaccurate, misleading, incomplete, or poorly documented
  2. Unclear ownership or sourcing of information generated or used by AI
  3. Vulnerability to cyberattacks, data poisoning, and insecure access to information
  4. Threat to patient privacy due to unauthorized access
  5. Use of biased, incomplete, or poorly documented datasets
  6. Insufficient controls for logging, vulnerability testing, and breach detection and remediation
  7. Inadequate training of clinicians and staff on AI limitations, safe usage, and reporting mechanisms
  8. Noncompliance with privacy laws, payer rules, record retention policies, and disclosure obligations
  9. Threats to patient safety from incorrect or misleading AI-generated outputs that harm care
  10. Inability to explain AI outputs to clinicians, patients, or regulators
  11. Insufficient pre‑deployment validation
  12. Lack of ongoing performance monitoring
  13. Failure to provide patient notice of AI use, honor opt-outs, or prevent improper secondary data use
  14. Exposure to malpractice, regulatory fines, contractual breaches, and unclear indemnity from vendors
  15. Lack of rollback plans, insufficient incident response, and insufficient backup and availability strategies
  16. Hidden costs

Interested in learning more and finding out how Strategic Management can help support your compliance program?  You can reach Richard Kusserow at [email protected] or connect with a compliance advisor to schedule a meeting.

About the Author

Richard P. Kusserow established Strategic Management Services, LLC, after retiring from being the DHHS Inspector General, and has assisted over 3,000 health care organizations and entities in developing, implementing and assessing compliance programs.

Subscribe to blog