Enterprise risk management in healthcare means the steps organizations take to find, evaluate, and reduce risks that can affect many parts of their work. These risks include following rules, money problems, running operations smoothly, protecting against cyberattacks, and keeping patients safe. Risks in healthcare can affect not only the organization but also the care patients get.
Medical offices need to follow many rules like the Health Insurance Portability and Accountability Act (HIPAA), the Health Information Technology for Economic and Clinical Health (HITECH) Act, the 21st Century Cures Act, and state healthcare laws. Groups like the Office for Civil Rights (OCR) under the U.S. Department of Health and Human Services (HHS) watch to see if these rules are followed and check on data breaches.
In April 2025, reports showed that healthcare data breaches rose by 17.9% from the month before, affecting over 10 million people. Big breaches at places like Yale New Haven Health System show the risks from hacking and ransomware. These events show why healthcare providers need strong ERM systems that cover cybersecurity, following rules, and managing risks from third parties.
AI tools like machine learning, natural language processing, and generative AI have changed healthcare by automating simple tasks, improving data analysis, and helping with patient communication. But using AI has new problems with data privacy, fairness, safety, and rule-following.
Lynn Shapiro Snyder, a lawyer with over 40 years of experience in health regulation and AI compliance, says it is important to build integrity and compliance programs designed for AI. Healthcare providers should set up protections to stop AI misuse, whether on purpose or by accident, that might break laws or rules.
In March 2024, the U.S. Department of Justice (DOJ) updated its Evaluation of Corporate Compliance Programs (ECCP) to include AI risks. Organizations must have rules to make sure AI tools are reliable, trustworthy, and only used as they should be. They also need to check AI often, train workers to use AI correctly, and watch for misuse or fraud.
The DOJ’s Deputy Attorney General Lisa Monaco said, “Fraud using AI is still fraud,” showing that the government takes AI compliance seriously. Medical offices should handle these issues by adding AI risk management to their overall ERM plans.
To handle these challenges, many providers use frameworks made by groups like HITRUST. The HITRUST AI Assurance Program uses guidance from the NIST AI RMF and global standards to support transparency, responsibility, and risk control in AI use. It suggests limiting data exposure, using strong encryption, doing frequent security checks, and keeping strict access controls.
The National Institute of Standards and Technology (NIST) made the AI Risk Management Framework (AI RMF) to help groups responsibly manage AI risks. It was released in January 2023 and involved many stakeholders. It guides trustworthy AI design, development, and use.
The NIST framework is voluntary but gives practical steps for healthcare groups to align AI risk management with their overall goals. It promotes ongoing monitoring, involving stakeholders, and using public feedback. NIST also released a special guide for generative AI to help organizations spot risks specific to this new type of AI.
Health leaders and IT managers can use AI RMF to build their ERM plans. This helps make sure AI meets standards for accuracy, reliability, fairness, and privacy. Doing this can lower legal risks and build patient trust in AI-based care.
Third-party vendors provide AI tools, cloud services, and other technology. But working with them adds more compliance tasks.
Under the HITECH Act, vendors are called business associates and must follow HIPAA privacy and security rules. If vendors fail, both they and the healthcare organization can face penalties. Data breaches or negligence by vendors can harm patient privacy and cause fines.
Healthcare providers must do regular audits, risk checks, and thorough vendor reviews. They should enforce Business Associate Agreements (BAAs) with clear cybersecurity and data safety rules. Also, they need backup plans for vendor issues like breaches, including ways to respond and inform patients.
Sumith Sagar, Associate Director at MetricStream, says switching from just checklist compliance to AI-based Governance, Risk, and Compliance (GRC) tools gives better risk awareness and automation. These tools help monitor vendor risks and follow changing rules effectively.
Rules about healthcare data privacy and security keep changing. In recent years, HIPAA privacy rules have been updated and cybersecurity rules increased. The 21st Century Cures Act also affects data sharing and system interoperability.
Healthcare providers should use real-time, automated systems to find compliance problems and security issues quickly. Old manual checks can’t keep up with complex rules and fast new threats.
AI-based tools for continuous monitoring can spot unusual patterns that might show fraud, data leaks, or AI misuse. They also help manage regulatory changes automatically and give compliance staff useful analytics and reports.
Automating front-office and admin tasks is important for healthcare providers who want better efficiency and patient communication. For instance, Simbo AI uses AI phone automation and answering services that help with scheduling, appointment reminders, and call routing.
With AI-powered front-office tools, healthcare organizations can lower human errors, manage staff work better, and improve patient satisfaction with fast and personal service. Automated phone systems can handle many calls, letting staff focus on harder tasks.
Still, adding AI workflow automation needs care with risks and following rules:
Using AI in workflows fits into the wider risk management plan when combined with policies for AI rules, risk checks, and staff training. Following regulatory guidelines and best practices from frameworks like the NIST AI RMF helps keep automation safe and rule-compliant.
Medical offices in the U.S. face growing pressure to meet privacy and security rules because cybersecurity threats and regulations have become more complex. Using AI tools in healthcare delivery and admin work can improve efficiency and patient care but must be managed with risk processes.
Practices should:
By balancing new technologies with rule-following, healthcare providers can better protect patient privacy, lower risks, and improve care quality in a digital world.
Lynn Shapiro Snyder is a senior health care regulatory and AI compliance lawyer with over 40 years of experience, advising health care and life sciences companies on regulatory challenges, billing, and compliance, particularly in relation to artificial intelligence and digital health.
Lynn focuses on health care regulatory compliance, artificial intelligence, digital health, telemedicine, Medicare and Medicaid strategy, coding, coverage, reimbursement, and health care fraud enforcement.
Lynn has advised on commercialization strategies and compliance related to artificial intelligence, including developing compliance programs and navigating regulatory requirements for health care innovations.
Lynn serves on multiple boards, including the Women Business Leaders of the U.S. Health Care Industry Foundation and has held various leadership positions at Epstein Becker Green and other healthcare organizations.
Lynn has provided counsel on the Cures Act, the Inflation Reduction Act, and the No Surprises Act, focusing on their implications for health care providers and innovators.
She leads defenses against health care fraud claims, navigates investigations involving the False Claims Act, and represents clients before regulatory entities like the DOJ and DHHS OIG.
Lynn advises on developing compliance strategies for AI tools in health care, ensuring adherence to regulations and addressing enterprise risk management associated with these technologies.
Medical practices often face challenges related to regulatory compliance, risk management, coding and reimbursement for AI tools, and navigating federal and state health policy changes.
Lynn has been recognized in various lists, including Modern Healthcare’s ‘100 Most Powerful People in Healthcare’ and has received accolades for her contributions to health care law.
Recent events include discussions on managing enterprise risk with AI tools, legislative updates on algorithmic discrimination, and strategic considerations for health plans regarding AI implementation.