Insights
Practical perspectives on AI governance for healthcare leaders.
These briefings are written for healthcare executives navigating AI adoption, governance risk, and accountability. Each document focuses on operational implications and is designed to support board, compliance, and leadership discussions.
When Your Patient's Agent Calls: Part 3
By What Authority Does It Act?
When Your Patient's Agent Calls: Part 3
Why this matters: Patients are sending AI agents into the portal to act for them, and most governance conversations reach for power of attorney to explain it. That frame doesn't hold, and neither does HIPAA's personal representative.
Part 3 places the patient's agent where it actually sits — inside the patient's own right of access under 45 CFR 164.524 — and separates a patient's own agent, a representative's agent, and a vendor's agent into the three different problems a board keeps treating as one.
The Healthcare AI Landscape for Small to Mid-Sized Organizations
Use cases and vendors across hospitals, practices, LTC/AL, FQHCs, and behavioral health.
The Healthcare AI Landscape for Small to Mid-Sized Organizations
Why this matters: AI adoption in healthcare is accelerating but deeply uneven. System-affiliated hospitals run predictive AI at 86%; independent hospitals sit at 37%. The organizations that deliver most community, long-term, and behavioral health care are furthest behind, and most of what they can access is decided by their EHR vendor.
This analysis ranks documented AI use cases from most to least common (ambient documentation and revenue cycle lead), maps the vendor ecosystem behind each, and details the cost, workforce, and governance barriers that keep smaller organizations on the wrong side of the gap. Includes a limitations and AI-research disclosure.
When Your Patient's Agent Calls: Part 2
From the Nursing Inbox to the Board Deck
When Your Patient's Agent Calls: Part 2
Why this matters: A secure message arrives at 6:30 AM. The nurse makes a clinical judgment about how to respond. She has no way to know whether a patient or an AI agent wrote it — and there's no metadata flag, no session-level attribution, and no forensic path to find out.
Part 2 covers the clinical triage failure mode, six things health systems can act on now, and the harder governance question most organizations have already answered by default without a deliberate, documented decision.
When Your Patient's Agent Calls: Part 1
The Governance Gap Nobody Briefed the Board On
When Your Patient's Agent Calls: Part 1
Why this matters: Patients are deploying AI agents that log into your portal, request refills, send messages, and schedule appointments — and from the health system's side, it looks identical to the patient doing it manually.
Most governance frameworks weren't built for tools patients bring. The gap creates three connected exposures: an enforcement position most boards haven't been briefed on, a security gap your SOC can't address without knowing it exists, and an accessibility dimension that complicates any restriction before general counsel reviews it.
What We Told HHS About AI Governance in Healthcare
Our response to the federal RFI on accelerating AI adoption in clinical care.
What We Told HHS About AI Governance in Healthcare
Why this matters: HHS is shaping federal AI policy for healthcare, and the biggest barrier to responsible adoption isn't regulatory ambiguity. It's organizational ambiguity within health systems themselves.
Over 40% of healthcare organizations lack even a basic pre-implementation gate for AI tools, and the governance capacity gap falls hardest on the organizations that can least afford it.
Autonomous AI Agents: What Healthcare Executives Need to Know
When AI systems act independently, governance models built for tools no longer apply.
Autonomous AI Agents: What Healthcare Executives Need to Know
Why this matters: Autonomous AI agents are already operating in ways existing healthcare AI governance frameworks were never designed to oversee.
These systems can act independently, exchange information, and access tools without appearing in traditional IT inventories—creating regulatory, liability, and operational risk that committees alone cannot contain.
Your Patients Will Use ChatGPT Health. Is Your Organization Ready?
Patients are connecting medical records to AI. The conversations are already starting.
Your Patients Will Use ChatGPT Health. Is Your Organization Ready?
Why this matters: Patients are arriving with AI-generated interpretations of their own medical records—and expecting clinicians to respond in real time.
Health systems that have not prepared workflows, training, and documentation practices risk clinical friction, liability exposure, and erosion of patient trust.
The Committee Fallacy in AI Governance
Committees provide input. They don't provide accountability.
The Committee Fallacy in AI Governance
Why this matters: Committee-based AI governance creates the illusion of oversight while diffusing accountability.
When an algorithm harms a patient, “the committee approved it” is not a defensible answer—to regulators, courts, or boards. AI governance requires named ownership, not shared cover.
Stay informed
Get notified when new briefings are published. No spam, no sales pitches.
Part of Mosaic Life Tech's ongoing executive briefing series on AI governance in healthcare.