{"id":32961,"date":"2025-06-26T22:32:02","date_gmt":"2025-06-26T22:32:02","guid":{"rendered":""},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-30T00:00:00","slug":"enterprise-risk-management-in-healthcare-incorporating-ai-tools-and-addressing-compliance-challenges-3167528","status":"publish","type":"post","link":"https:\/\/www.simbo.ai\/blog\/enterprise-risk-management-in-healthcare-incorporating-ai-tools-and-addressing-compliance-challenges-3167528\/","title":{"rendered":"Enterprise Risk Management in Healthcare: Incorporating AI Tools and Addressing Compliance Challenges"},"content":{"rendered":"<p>Enterprise risk management in healthcare means the steps organizations take to find, evaluate, and reduce risks that can affect many parts of their work. These risks include following rules, money problems, running operations smoothly, protecting against cyberattacks, and keeping patients safe. Risks in healthcare can affect not only the organization but also the care patients get.<\/p>\n<p>Medical offices need to follow many rules like the Health Insurance Portability and Accountability Act (HIPAA), the Health Information Technology for Economic and Clinical Health (HITECH) Act, the 21st Century Cures Act, and state healthcare laws. Groups like the Office for Civil Rights (OCR) under the U.S. Department of Health and Human Services (HHS) watch to see if these rules are followed and check on data breaches.<\/p>\n<p>In April 2025, reports showed that healthcare data breaches rose by 17.9% from the month before, affecting over 10 million people. Big breaches at places like Yale New Haven Health System show the risks from hacking and ransomware. These events show why healthcare providers need strong ERM systems that cover cybersecurity, following rules, and managing risks from third parties.<\/p>\n<h2>Incorporating AI Tools in Healthcare Risk Management<\/h2>\n<p>AI tools like machine learning, natural language processing, and generative AI have changed healthcare by automating simple tasks, improving data analysis, and helping with patient communication. But using AI has new problems with data privacy, fairness, safety, and rule-following.<\/p>\n<p>Lynn Shapiro Snyder, a lawyer with over 40 years of experience in health regulation and AI compliance, says it is important to build integrity and compliance programs designed for AI. Healthcare providers should set up protections to stop AI misuse, whether on purpose or by accident, that might break laws or rules.<\/p>\n<p>In March 2024, the U.S. Department of Justice (DOJ) updated its Evaluation of Corporate Compliance Programs (ECCP) to include AI risks. Organizations must have rules to make sure AI tools are reliable, trustworthy, and only used as they should be. They also need to check AI often, train workers to use AI correctly, and watch for misuse or fraud.<\/p>\n<p>The DOJ\u2019s Deputy Attorney General Lisa Monaco said, &#8220;Fraud using AI is still fraud,&#8221; showing that the government takes AI compliance seriously. Medical offices should handle these issues by adding AI risk management to their overall ERM plans.<\/p>\n<p><!--smbadstart--><\/p>\n<div class=\"ad-widget case-study-ad\" smbdta=\"smbadid:sc_17;nm:UneQU319I;score:0.96;kw:hipaa_0.99_compliance_0.96_encryption_0.93_data-security_0.85_call-privacy_0.77;\">\n<h4>HIPAA-Compliant Voice AI Agents<\/h4>\n<p>SimboConnect AI Phone Agent encrypts every call end-to-end &#8211; zero compliance worries.<\/p>\n<div class=\"client-info\">\n    <!--<span><\/span>--><br \/>\n    <a href=\"https:\/\/simbo.ai\/schedule-connect\">Claim Your Free Demo \u2192<\/a>\n  <\/div>\n<\/div>\n<p><!--smbadend--><\/p>\n<h2>Key Compliance Challenges in Using AI Within Healthcare<\/h2>\n<ul>\n<li><strong>Data Privacy:<\/strong> AI needs lots of patient data from electronic health records (EHRs), manual entries, health information exchanges (HIEs), and cloud storage. Protecting this data to meet HIPAA, HITECH, and other privacy laws is important.<\/li>\n<li><strong>Patient Consent:<\/strong> Patients must be told when AI affects their care. Consent forms should say if AI is used in diagnosis, treatment plans, or admin tasks.<\/li>\n<li><strong>Algorithmic Bias and Fairness:<\/strong> AI systems can carry bias from the data used to train them, causing unfair treatment. Efforts should be made to keep AI fair and clear in how decisions are made.<\/li>\n<li><strong>Vendor Management:<\/strong> Third-party vendors who build and add AI solutions bring extra risks. Healthcare groups must make strong contracts, check vendors carefully, and make sure they follow privacy and security rules.<\/li>\n<li><strong>Regulatory Frameworks:<\/strong> Following AI-specific rules like the AI Bill of Rights, NIST\u2019s AI Risk Management Framework (AI RMF), and federal enforcement policies means updating compliance programs regularly.<\/li>\n<\/ul>\n<p>To handle these challenges, many providers use frameworks made by groups like HITRUST. The HITRUST AI Assurance Program uses guidance from the NIST AI RMF and global standards to support transparency, responsibility, and risk control in AI use. It suggests limiting data exposure, using strong encryption, doing frequent security checks, and keeping strict access controls.<\/p>\n<p><!--smbadstart--><\/p>\n<div class=\"ad-widget checklist-ad\" smbdta=\"smbadid:sc_38;nm:AOPWner28;score:1.77;kw:encryption_0.98_aes_0.95_call-security_0.89_data-protection_0.82_hipaa_0.79;\">\n<div class=\"check-icon\">\u2713<\/div>\n<div>\n<h4>Encrypted Voice AI Agent Calls<\/h4>\n<p>SimboConnect AI Phone Agent uses 256-bit AES encryption \u2014 HIPAA-compliant by design.<\/p>\n<p>    <a href=\"https:\/\/simbo.ai\/schedule-connect\" class=\"download-btn\"> Claim Your Free Demo <\/a>\n  <\/div>\n<\/div>\n<p><!--smbadend--><\/p>\n<h2>NIST AI Risk Management Framework and Its Role in Healthcare<\/h2>\n<p>The National Institute of Standards and Technology (NIST) made the AI Risk Management Framework (AI RMF) to help groups responsibly manage AI risks. It was released in January 2023 and involved many stakeholders. It guides trustworthy AI design, development, and use.<\/p>\n<p>The NIST framework is voluntary but gives practical steps for healthcare groups to align AI risk management with their overall goals. It promotes ongoing monitoring, involving stakeholders, and using public feedback. NIST also released a special guide for generative AI to help organizations spot risks specific to this new type of AI.<\/p>\n<p>Health leaders and IT managers can use AI RMF to build their ERM plans. This helps make sure AI meets standards for accuracy, reliability, fairness, and privacy. Doing this can lower legal risks and build patient trust in AI-based care.<\/p>\n<h2>Managing Third-Party Vendor Risks and Regulatory Compliance<\/h2>\n<p>Third-party vendors provide AI tools, cloud services, and other technology. But working with them adds more compliance tasks.<\/p>\n<p>Under the HITECH Act, vendors are called business associates and must follow HIPAA privacy and security rules. If vendors fail, both they and the healthcare organization can face penalties. Data breaches or negligence by vendors can harm patient privacy and cause fines.<\/p>\n<p>Healthcare providers must do regular audits, risk checks, and thorough vendor reviews. They should enforce Business Associate Agreements (BAAs) with clear cybersecurity and data safety rules. Also, they need backup plans for vendor issues like breaches, including ways to respond and inform patients.<\/p>\n<p>Sumith Sagar, Associate Director at MetricStream, says switching from just checklist compliance to AI-based Governance, Risk, and Compliance (GRC) tools gives better risk awareness and automation. These tools help monitor vendor risks and follow changing rules effectively.<\/p>\n<h2>The Importance of Continuous Compliance Monitoring<\/h2>\n<p>Rules about healthcare data privacy and security keep changing. In recent years, HIPAA privacy rules have been updated and cybersecurity rules increased. The 21st Century Cures Act also affects data sharing and system interoperability.<\/p>\n<p>Healthcare providers should use real-time, automated systems to find compliance problems and security issues quickly. Old manual checks can\u2019t keep up with complex rules and fast new threats.<\/p>\n<p>AI-based tools for continuous monitoring can spot unusual patterns that might show fraud, data leaks, or AI misuse. They also help manage regulatory changes automatically and give compliance staff useful analytics and reports.<\/p>\n<h2>AI and Workflow Automation in Healthcare Administration<\/h2>\n<p>Automating front-office and admin tasks is important for healthcare providers who want better efficiency and patient communication. For instance, Simbo AI uses AI phone automation and answering services that help with scheduling, appointment reminders, and call routing.<\/p>\n<p>With AI-powered front-office tools, healthcare organizations can lower human errors, manage staff work better, and improve patient satisfaction with fast and personal service. Automated phone systems can handle many calls, letting staff focus on harder tasks.<\/p>\n<p>Still, adding AI workflow automation needs care with risks and following rules:<\/p>\n<ul>\n<li><strong>Data Security:<\/strong> Automated call systems must protect patient data, use encryption, and meet HIPAA rules.<\/li>\n<li><strong>Patient Consent and Transparency:<\/strong> Systems should tell patients when they are dealing with AI and respect their choice to talk with humans or AI.<\/li>\n<li><strong>Regulatory Oversight:<\/strong> Following telehealth laws, the Telephone Consumer Protection Act (TCPA), and other rules avoids penalties.<\/li>\n<li><strong>Accuracy and Reliability:<\/strong> AI should be accurate, especially for scheduling, billing, and handling sensitive patient info.<\/li>\n<li><strong>Integration with EMR\/EHR Systems:<\/strong> Automation should work smoothly with existing electronic records to keep data up to date and prevent data silos.<\/li>\n<\/ul>\n<p>Using AI in workflows fits into the wider risk management plan when combined with policies for AI rules, risk checks, and staff training. Following regulatory guidelines and best practices from frameworks like the NIST AI RMF helps keep automation safe and rule-compliant.<\/p>\n<p><!--smbadstart--><\/p>\n<div class=\"ad-widget regular-ad\" smbdta=\"smbadid:sc_14;nm:AJerNW453;score:0.99;kw:reminder_0.1_appointment-reminder_0.89_patient-notification_0.73;\">\n<h4>AI Call Assistant Reduces No-Shows<\/h4>\n<p>SimboConnect sends smart reminders via call\/SMS &#8211; patients never forget appointments.<\/p>\n<p>  <a href=\"https:\/\/simbo.ai\/schedule-connect\" class=\"cta-button\">Let\u2019s Chat \u2192<\/a>\n<\/div>\n<p><!--smbadend--><\/p>\n<h2>Final Thoughts for Healthcare Practice Administrators and IT Managers<\/h2>\n<p>Medical offices in the U.S. face growing pressure to meet privacy and security rules because cybersecurity threats and regulations have become more complex. Using AI tools in healthcare delivery and admin work can improve efficiency and patient care but must be managed with risk processes.<\/p>\n<p>Practices should:<\/p>\n<ul>\n<li>Make AI compliance programs that follow DOJ rules and legal advice.<\/li>\n<li>Use AI risk management tools like the NIST AI RMF for guidance and controls.<\/li>\n<li>Handle third-party vendor risks with clear contracts, audits, and ongoing checks.<\/li>\n<li>Use AI-powered Governance, Risk, and Compliance (GRC) solutions for better risk monitoring and compliance.<\/li>\n<li>Ensure AI workflow automation meets security rules and patient consent needs.<\/li>\n<li>Train staff regularly on AI risk and compliance issues.<\/li>\n<\/ul>\n<p>By balancing new technologies with rule-following, healthcare providers can better protect patient privacy, lower risks, and improve care quality in a digital world.<\/p>\n<section class=\"faq-section\">\n<h2 class=\"section-title\">Frequently Asked Questions<\/h2>\n<div class=\"faq-container\">\n<details>\n<summary>Who is Lynn Shapiro Snyder?<\/summary>\n<div class=\"faq-content\">\n<p>Lynn Shapiro Snyder is a senior health care regulatory and AI compliance lawyer with over 40 years of experience, advising health care and life sciences companies on regulatory challenges, billing, and compliance, particularly in relation to artificial intelligence and digital health.<\/p>\n<\/p><\/div>\n<\/details>\n<details>\n<summary>What are Lynn&#8217;s main areas of focus in health care law?<\/summary>\n<div class=\"faq-content\">\n<p>Lynn focuses on health care regulatory compliance, artificial intelligence, digital health, telemedicine, Medicare and Medicaid strategy, coding, coverage, reimbursement, and health care fraud enforcement.<\/p>\n<\/p><\/div>\n<\/details>\n<details>\n<summary>What experience does Lynn have with AI in health care?<\/summary>\n<div class=\"faq-content\">\n<p>Lynn has advised on commercialization strategies and compliance related to artificial intelligence, including developing compliance programs and navigating regulatory requirements for health care innovations.<\/p>\n<\/p><\/div>\n<\/details>\n<details>\n<summary>What organizations and boards does Lynn serve on?<\/summary>\n<div class=\"faq-content\">\n<p>Lynn serves on multiple boards, including the Women Business Leaders of the U.S. Health Care Industry Foundation and has held various leadership positions at Epstein Becker Green and other healthcare organizations.<\/p>\n<\/p><\/div>\n<\/details>\n<details>\n<summary>What legislative acts has Lynn counseled clients on?<\/summary>\n<div class=\"faq-content\">\n<p>Lynn has provided counsel on the Cures Act, the Inflation Reduction Act, and the No Surprises Act, focusing on their implications for health care providers and innovators.<\/p>\n<\/p><\/div>\n<\/details>\n<details>\n<summary>What legal issues does Lynn handle related to health care fraud?<\/summary>\n<div class=\"faq-content\">\n<p>She leads defenses against health care fraud claims, navigates investigations involving the False Claims Act, and represents clients before regulatory entities like the DOJ and DHHS OIG.<\/p>\n<\/p><\/div>\n<\/details>\n<details>\n<summary>How does Lynn assist clients with artificial intelligence compliance?<\/summary>\n<div class=\"faq-content\">\n<p>Lynn advises on developing compliance strategies for AI tools in health care, ensuring adherence to regulations and addressing enterprise risk management associated with these technologies.<\/p>\n<\/p><\/div>\n<\/details>\n<details>\n<summary>What are some challenges faced by medical practices regarding AI technology?<\/summary>\n<div class=\"faq-content\">\n<p>Medical practices often face challenges related to regulatory compliance, risk management, coding and reimbursement for AI tools, and navigating federal and state health policy changes.<\/p>\n<\/p><\/div>\n<\/details>\n<details>\n<summary>What recognition has Lynn received in her career?<\/summary>\n<div class=\"faq-content\">\n<p>Lynn has been recognized in various lists, including Modern Healthcare&#8217;s &#8216;100 Most Powerful People in Healthcare&#8217; and has received accolades for her contributions to health care law.<\/p>\n<\/p><\/div>\n<\/details>\n<details>\n<summary>What recent events have focused on AI in healthcare?<\/summary>\n<div class=\"faq-content\">\n<p>Recent events include discussions on managing enterprise risk with AI tools, legislative updates on algorithmic discrimination, and strategic considerations for health plans regarding AI implementation.<\/p>\n<\/p><\/div>\n<\/details><\/div>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Enterprise risk management in healthcare means the steps organizations take to find, evaluate, and reduce risks that can affect many parts of their work. These risks include following rules, money problems, running operations smoothly, protecting against cyberattacks, and keeping patients safe. Risks in healthcare can affect not only the organization but also the care patients [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[],"tags":[],"class_list":["post-32961","post","type-post","status-publish","format-standard","hentry"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.simbo.ai\/blog\/wp-json\/wp\/v2\/posts\/32961","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.simbo.ai\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.simbo.ai\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.simbo.ai\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.simbo.ai\/blog\/wp-json\/wp\/v2\/comments?post=32961"}],"version-history":[{"count":0,"href":"https:\/\/www.simbo.ai\/blog\/wp-json\/wp\/v2\/posts\/32961\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.simbo.ai\/blog\/wp-json\/wp\/v2\/media?parent=32961"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.simbo.ai\/blog\/wp-json\/wp\/v2\/categories?post=32961"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.simbo.ai\/blog\/wp-json\/wp\/v2\/tags?post=32961"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}