For hospital boards, health system executives, and digital health companies deploying generative AI, governance choices made before a tool goes live determine whether the organization can defend its practices later.

In a recent article by Healthcare IT News, the publication examined how health systems should build AI governance that begins before deployment and extends through incident response. James (Jim) P. Flynn, Managing Director of Epstein Becker Green and counsel to health systems on health care litigation and regulatory compliance, and Alaap B. Shah, Member of the Firm at Epstein Becker Green and counsel to health care and digital health companies on AI governance and data privacy, outlined what that framework should include.

Flynn recommends an AI governance committee at the board or C-suite level, bringing together legal, compliance, clinical, IT, and patient-safety leaders to oversee vendor selection, validation, monitoring, and incident response. He frames the decision in governance terms rather than operational ones.

“AI adoption is not treated as a procurement decision,” Flynn said. “As I see it, it's a governance decision with clinical, legal and operational implications.”

Shah advises health systems to independently validate AI performance across diverse patient populations before deployment, rather than relying solely on vendor claims, and to negotiate contract terms covering audit rights, access to performance data, and notice of model updates. He also recommends periodic audits comparing AI-suggested documentation against the clinician-approved note.

“Do not wait for regulatory clarity because the regulatory landscape for AI in healthcare is a work in progress,” Shah said. “Build your governance framework now as if the most stringent requirements will apply.”

Get in Touch

To discuss how to structure AI governance committees, vendor contract terms, and retention architecture for AI tools used in patient care, contact Jim Flynn at jflynn@ebglaw.com or Alaap Shah at abshah@ebglaw.com.

Jump to Page
Advanced Search ›

Privacy Preference Center

When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.

Strictly Necessary Cookies

These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.

Performance Cookies

These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site, and will not be able to monitor its performance.