
AI is playing an increasingly central role in patient care in hospitals across the country, but the same models that are driving this innovation are also being turned against providers by hackers.
Cyberattackers and nation states are now using AI to automate and scale their attacks with a speed and precision that didn’t exist just a few years ago, said Karen Habercoss, the agency’s chief information security and privacy officer. University of Chicago Medicine.
She noted that cybercriminals use AI for the same reasons hospitals do: to automate tasks and operate faster and at larger scale.
“Risk has to be balanced,” Habercoss remarked in an interview this month.
Healthcare remains the country’s most attacked sector, which she said is a problem compounded by the amount of existing technology still used in many healthcare systems.
This old infrastructure cannot be replaced overnight, so organizations must focus on segmenting and isolating it to reduce risk, Habercoss explained.
Added to this is the growing complexity of third-party providers, many of whom are now integrating their own AI tools into their products. Habercoss said his organization treats supplier monitoring as an ongoing process rather than a one-time checklist. This involves auditing partners over time to ensure their security and privacy practices continue to meet the health system’s own standards.
This type of continuous monitoring has become essential as AI adoption accelerates on both sides of the security equation, Habercoss added.
To manage this increasingly complex set of risks, Habercoss said UChicago Medicine has developed a tiered AI governance system over the past several years.
It includes a steering committee that oversees subcommittees focused on AI admission, inventory, education and training, and auditing and oversight. A separate cross-functional committee, which Habercoss co-chairs with the head of health system analysis, brings together physicians, legal leaders, compliance officers and other senior leaders. A third committee focuses specifically on clinical use cases, bringing nurse and physician leaders on its team to review new tools before they reach patients.
Any new AI tool, whether introduced through a vendor contract, a doctor’s request or an academic research project, goes through all three committees before being approved, Habercoss said. She stressed that the dismissal is intentional.
“If you think you’re talking to enough people, that’s probably not the case,” Habercoss said, adding that AI decisions often touch on federal and state regulations that no single department can follow on its own.
The goal is to ensure that no part of the organization makes decisions about AI in isolation, she said.
Photo: Tunvarat Pruksachat, Getty Images