Artificial Intelligence in Healthcare
Artificial Intelligence

Importance of Addressing Shadow AI for HIPAA Compliance

Criminal Use of Artificial Intelligence (AI) Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS 

The process of identifying and containing a breach can be lengthy and expensive, particularly in healthcare, in addition to eroding patient trust.  Breaches can disrupt critical healthcare operations, leading to delays in patient care and financial losses due to closing emergency departments and cancellation of appointments. Healthcare providers are legally obligated to notify affected individuals and provide credit monitoring services, which incurs substantial costs. This article addresses AI use by cyber criminals and summarizes 2024-2025 breach findings as reported by IBM’s 2025 Report.

Introduction

In 2025, the average cost of a healthcare data breach is $7.42 million, according to a recent report by IBM. Even with a reduction of $2.35 million in breach cost to the healthcare sector, healthcare breaches remain the most expensive of all studied industries for 14 consecutive years! This figure represents a decrease compared to the previous year but still signifies the highest average cost across all industries. The 2025 IBM report, conducted by Ponemon Institute, sponsored and analyzed by IBM, is based on data breaches experienced by 600 organizations globally from March 2024 through February 2025.

Shadow AI security incidents cost more - Security incidents involving Shadow AI carried an added cost. They contributed USD 200,000 to the global average breach cost. This higher cost was likely driven by longer detection and containment times for these security incidents, approximately a week longer than the global average.

According to Suja Viswesan, Vice President, Security and Runtime Products, IBM "The data shows that a gap between AI adoption and oversight already exists, and threat actors are starting to exploit it."

She also states that "The report revealed a lack of basic access controls for AI systems, leaving highly sensitive data exposed, and models vulnerable to manipulation. As AI becomes more deeply embedded across business operations, AI security must be treated as foundational. The cost of inaction isn't just financial, it's the loss of trust, transparency and control."

Employees may turn to Artificial Intelligence (AI) tools to speed up tasks, solve problems, or improve productivity. However, there are risks associated with employees using AI tools, like ChatGPT, Midjourney, or AI-powered assistants, without IT's knowledge or permission, such as Shadow AI being used by criminals. Using AI tools that don't comply with regulations (like GDPR or HIPAA) can result in fines and legal issues. 

Shadow AI

Shadow AI refers to the unauthorized use of artificial intelligence (AI) tools and models within an organization, often bypassing IT oversight and security protocols.

AI tools are being used by cyber criminals to launch smarter attacks.  Shadow AI tools can introduce unsecured APIs, unmanaged integrations, or other vulnerabilities that attackers can exploit.  To reduce the risk of an AI generated attack, it is important to address Shadow AI. 

As AI becomes integral to operations, AI security incidents have the potential to disrupt a range of business activities, including compromising sensitive data and disrupting patient care (i.e. ransomware attacks locking access to important patient treatment records).  IBM’s report identifies the following:

  • Security for AI is lacking  
    • The Cost of a Data Breach Report 2025 – the AI Oversight Gap quantifies the extent to which attackers are taking advantage of this deficiency and successfully targeting AI models and applications. While the share of breaches involving AI security incidents are small, IBM researchers expect them to grow as AI vendors gain greater market share and penetration into enterprise systems. Shadow AI is of particular concern.
  • Impacts of security incidents involving Shadow AI  
    • Among organizations that experienced a security incident involving Shadow AI, 44% suffered data compromise. Another 41% reported increased security costs as a result of those incidents. Operational disruption was more widespread than incidents involving authorized AI. These results suggest Shadow AI incidents have an outsized impact on downstream breach issues that extend beyond data security.
  • Researchers found 16% of breaches involved attackers using AI
    • Most of these breaches focused on human manipulation through phishing (37%) or deepfake attacks (35%).
  • Supply chain compromise was the most common cause of AI security incidents
    • Security incidents involving AI models and applications were varied, but one type clearly claimed the top ranking: supply chain compromise (30%), which includes compromised apps, APIs and plug-ins. Following supply chain compromise were model inversions (24%) and model evasions (21%). Incidents involving prompt injections and data poisoning made up 17% and 15% of cases respectively.
  • Unsanctioned AI security incidents were more common than sanctioned AI
    • Shadow AI may go undetected by an organization, and attackers can exploit its vulnerabilities when employees use it. Security incidents involving Shadow AI accounted for 20% of breaches, which is 7 percentage points higher than those security incidents involving sanctioned AI. A further 11% of breached organizations were unsure if they experienced a Shadow AI incident.

Foster a Culture of Responsible AI to Reduce Risk

Healthcare organizations can cultivate a culture of responsible AI by prioritizing ethical considerations and extensive workforce training regarding Shadow AI tools and how to avoid an attack.  A few tips to reduce risk are listed below.

Build communication with your workforce - Instead of penalizing your workers for using AI tools without permission, find out what they’re using and why. Their feedback could be useful in highlighting the gaps in your technology stack and governance policies. This allows you to either optimize your workflows or find a way of integrating the tool into them, thereby moving them from unsanctioned “Shadow AI” to legitimate AI tools.

  • A modern data stack is a collection of tools and technologies that are used to manage and analyze data in a particular organization or business. It includes various software, programming languages, frameworks, and platforms that can be used to extract, store, process, and visualize data.

Develop Clear Policies - Establish guidelines for AI tool usage, including approved tools and security protocols. This requires inter-departmental teamwork.  When integrating AI tools into your business, make sure that IT, operations, and governance departments are aligned.

  • For example, operations might want to use the tool in a way that compromises HIPAA security. Another example is when IT evaluates the tool for security but doesn’t understand the need for privacy in this assessment, which is the main concern for governance.
  • By bringing all these departments together, you will create better policies for responsible AI use and oversight that work for everyone.

Effectively Communicate Policies - Provide workforce training and support. Educate employees about the risks of Shadow AI and offer resources for using AI responsibly. By investing in training and education, you inform your workforce of potential pitfalls and consequences. At the same time, you train those unfamiliar with such tools so they can utilize them effectively as well. Whether it’s GenAI or AI-powered automation, using it responsibly helps reduce your security vulnerabilities and helps your employees perform better.

Implement Authentical methods - Today, many attackers are logging in rather than hacking in, according to IBM’s report. To combat this issue, it’s critical to prevent attackers from obtaining those credentials in the first place. One of the most effective ways to do so is by ensuring all human users adopt modern, phishing-resistant authentication methods, such as passkeys. These technologies are designed to eliminate the vulnerabilities of traditional passwords and one-time codes, making it significantly harder for attackers to intercept or misuse login credentials.

Monitor and Manage AI Usage - AI models and applications can pose significant risks if left unchecked. Consider including tools powered by AI and automation which can augment already overburdened security teams. They can significantly reduce the volume of alerts; identify at-risk data; spot security gaps and threats earlier; detect in-progress breaches; and enable faster, more precise attack responses.

Conclusion

The rapid evolution of AI technology presents a challenge to existing regulatory frameworks. Relying solely on HIPAA, not originally designed specifically for AI, leaves gaps in addressing AI-specific risks.

When employees use Shadow AI, healthcare organizations lose visibility and control over how PHI is being accessed, processed, and stored. This makes it difficult to ensure that HIPAA's Privacy and Security Rules are being followed. Shadow AI tools may not have the same robust security measures in place as approved, HIPAA-compliant systems, making them vulnerable to cyberattacks and data breaches. If sensitive patient information (Protected Health Information or PHI) is exposed through these unauthorized channels, it constitutes a HIPAA violation, triggering potential fines legal repercussions and reputational damage. Another consideration is the lack of required Business Associate Agreements. Many AI tools are developed by third-party vendors. If these vendors handle PHI without a Business Associate Agreement (BAA) in place, another HIPAA enforcement action could be looming as Shadow AI usage bypasses the essential BAA requirement, exposing healthcare organizations to significant risk.

About the author

Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS. Joanne is the Chief Executive Officer of the American Institute of Healthcare Compliance, a Licensing/Certification non-profit partner with CMS. She shares her experience of over 40 years as a nurse, consultant, auditor and investigator in the healthcare field.

References

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Artificial Intelligence in Healthcare
Artificial Intelligence

Coding Under Pressure

Documentation Challenges and the Impact of Ambient AI on Medical Coding Integrity   

Written by Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE   

Clinical documentation expertise and coding skills are both required as ambient Artificial Intelligence (AI) technology is being implemented by healthcare providers.  This article explores the dual-edged impact of ambient AI on coding integrity, highlighting the challenges, risks, and opportunities coders face in this evolving documentation landscape.

Introduction

Medical coders are vital to the healthcare system’s operational and financial backbone, yet their work is often misunderstood and underappreciated. Coders face immense pressure to extract meaningful, compliant data from clinical records that are frequently incomplete, ambiguous, or rushed. As the healthcare industry seeks to alleviate physician burnout and improve clinical efficiency, ambient artificial intelligence (AI), technology that silently captures patient-clinician dialogue and generates real-time documentation, has emerged as a transformative solution. While ambient AI promises to ease burdens for providers, it introduces new complexity for coders.

The Realities Coders Face: Burden, Ambiguity, and Incomplete Records

The responsibility of a medical coder goes far beyond transcribing diagnoses into codes. Coders interpret complex medical narratives and translate them into standardized codes that support clinical quality metrics, billing accuracy, and regulatory compliance. Yet the documentation coders rely on is often insufficient, filled with vague language, or completely missing critical elements. This not only slows productivity but results in increased claims denials, higher query volumes, and elevated coder burnout.

Studies indicate that a significant portion of documentation-related denials are due to issues like insufficient specificity or lack of medical necessity, both of which can be tied directly to documentation quality. Coders are often forced to query providers repeatedly, which can strain professional relationships and delay claim submission.

What Is Ambient AI and How Is It Changing Documentation?

Ambient AI refers to passive, voice-enabled technologies designed to record and transcribe patient-clinician interactions in real time. Solutions like Nuance’s DAX (Dragon Ambient eXperience), Suki, and Notable are increasingly being deployed across primary care, urgent care, and specialty settings. These tools are marketed as clinician support technologies, offering automatic generation of structured progress notes, improved documentation timeliness, and enhanced patient-provider interaction by removing the burden of manual EHR entry.

While these systems offer clear benefits for provider wellness and workflow, they also reshape the nature of clinical documentation. The AI-generated notes may reflect patient discussions accurately, but they do not always align with coding or billing requirements. For coders, this means navigating a new documentation style with inconsistent structures and a growing need for auditing both clinical and AI accuracy.

The Impact on Coders: Efficiency vs. Integrity

From a compliance and reimbursement standpoint, ambient AI documentation presents a double-edged sword. On one hand, AI-generated notes reduce physician documentation errors and may eliminate transcription backlogs. On the other, they often produce templated language, redundancies, or incomplete clinical pictures.

Coders have reported challenges in interpreting these notes due to the lack of specificity, missing time elements, or insufficient medical decision-making details. The AI may also inaccurately capture conversation snippets that create contradictions in the note or inflate complexity. This requires coders to serve not only as clinical interpreters but as AI editors—flagging inconsistencies, auditing for risk adjustment data, and ensuring the documentation meets payer and regulatory standards. Furthermore, the rise of ambient AI has introduced new legal and ethical concerns about authorship, documentation attribution, and coder responsibility.

Systemic Challenges and Industry Trends

The healthcare industry’s shift to ambient documentation is not occurring in a vacuum. It intersects with larger issues such as coder shortages, increased demand for productivity, and evolving compliance requirements. Coders are expected to maintain accuracy and turnaround time despite growing documentation complexity. The American Health Information Management Association (AHIMA) and AAPC have both issued guidelines acknowledging the growing tension between coder expectations and the limitations of emerging technologies. Without adequate training, ongoing evaluation of AI systems, and coder feedback integration, the promise of ambient AI may become a source of further burden.

Healthcare organizations must treat coders as key stakeholders in the implementation process—not afterthoughts. Only then can ambient AI reach its intended goal of enhancing documentation.

Opportunities and Recommendations

Despite the challenges, there is room for optimism. Coders are uniquely positioned to inform how ambient AI evolves. Organizations can involve coding professionals in pilot programs, conduct dual audits of human- and AI-generated notes, and build feedback loops to improve note quality. Additionally, coders can play a central role in training clinicians to understand what is—and is not—captured accurately by AI tools.

Best practices include standardizing templates for AI-generated notes, enhancing collaboration between coding and clinical teams, and investing in AI literacy for coding staff. With proactive investment and interdisciplinary collaboration, ambient AI can supplement human expertise rather than obscure or replace it.

Coder Burnout and the Hidden Cost of Automation

As documentation technology evolves, the human cost of automation must be addressed. Coders increasingly experience mental fatigue from toggling between multiple systems, interpreting AI-generated notes, and maintaining productivity quotas. Research highlights that coder burnout mirrors patterns seen in clinicians: decreased job satisfaction, higher turnover intentions, and increased error rates.

Organizations must treat coder well-being as a strategic asset.

A sustainable documentation ecosystem must include workload monitoring, ergonomic tools, mental health resources, and professional development opportunities. Coder fatigue not only impacts morale but may result in missed diagnoses, under coding, or compliance breaches that trigger payer audits or liability exposure.

Ethical Implications and Documentation Integrity

As ambient AI increasingly authors parts of the medical record, the question of authorship and accountability becomes more urgent.

If a physician passively approves an AI-generated note with embedded inaccuracies, who is responsible when an audit reveals discrepancies? Coders, tasked with ensuring that documentation meets payer guidelines and legal standards, face ethical dilemmas when AI documentation is flawed yet signed. Institutions must establish clear attribution protocols, provide coders with protected mechanisms to flag concerns, and create policies that reflect the shared accountability between technology and human oversight. Ensuring documentation integrity in this new era requires ethical clarity as much as technical precision.

Conclusion: Human Expertise Still Matters

Medical coders remain indispensable to the integrity of the healthcare system. While ambient AI presents a compelling solution to clinician burden, it must be implemented with an understanding of how documentation changes impact downstream functions like coding and billing. High-quality clinical documentation requires both technological innovation and human oversight. As healthcare continues to embrace digital transformation, coders must be empowered—not overlooked—to ensure accuracy, compliance, and financial sustainability.

Start with clinical documentation expertise – enroll in the Clinical Documentation Improvement online training program. This online education is designed for office nurses with coding experience and those responsible for providing support services to healthcare providers to improve both outpatient documentation and services related to inpatient pro-fee 1500 claims. Earn your Certified Medical Documentation Professional (CMDPSM) credential offered by the American Institute of Healthcare Compliance, a Licensing/Certification Partner w/CMS.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  1. AHIMA. (2022). The Evolving Role of the Medical Coder in the Age of Artificial Intelligence.
  2. Dyrda, L. (2023). How ambient listening tech like DAX is changing physician documentation. Becker’s Healthcare.
  3. Gordon, P., & DeCicco, M. (2022). Ambient AI and Documentation Integrity: Risks and Rewards. Journal of AHIMA.
  4. Wong, A., Otles, E., Donnelly, J. P., et al. (2022). External validation of a widely implemented proprietary sepsis prediction model in hospitalized patients. JAMA Internal Medicine, 182(5), 540–548.
  5. AAPC. (2023). Ambient Documentation Technology: Best Practices for Coders.
  6. Miliard, M. (2022). How Suki and similar tools aim to streamline clinical documentation. Healthcare IT News.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Artificial Intelligence in Healthcare
Artificial Intelligence

The Expanding Role of Artificial Intelligence in Healthcare

Compliance Considerations for Patient Care, Administration, and Financial Accountability   

Written By Dr. Stacey Atkins, PhD, MSW, LMSW, CPC, CIGE   

As Artificial Intelligence (AI) changes the healthcare landscape, compliance professionals must anticipate how AI alters how organizations manage corporate compliance.  If your organization has implemented AI, your compliance program should now include cross-functional oversight committees to review and monitor AI deployments. Insights to considerations are provided below.

Introduction

Artificial Intelligence (AI) is revolutionizing the healthcare industry by enhancing diagnostic precision, increasing administrative efficiency, and fostering innovative patient care models. However, this advancement also demands rigorous scrutiny through a compliance lens.

Regulatory frameworks must evolve to match the complexity of AI-powered systems and ensure that patient rights, data integrity, and financial accountability remain protected. Compliance professionals must anticipate how AI intersects with laws such as HIPAA, the False Claims Act, and the 21st Century Cures Act to maintain ethical standards and institutional trust.

AI in Patient Care

AI’s impact in clinical environments includes risk prediction models, virtual health assistants, and real-time monitoring tools. Clinical decision support tools that analyze large datasets can help clinicians identify trends and recommend personalized interventions. However, risks such as bias in algorithmic training data or lack of explainability in AI decisions pose threats to equitable care. These concerns underscore the importance of incorporating transparency, fairness, and accountability into the AI development lifecycle.

Compliance teams must work with clinical leaders to ensure AI tools meet FDA regulatory classifications, including premarket submissions and post-market surveillance, to ensure patient safety. As AI begins to play a larger role in recommending or even initiating treatment pathways, the responsibility to ensure appropriate validation, risk mitigation, and documentation grows significantly. Ethical considerations such as patient consent and clinical override procedures must also be addressed in policy.  Recommendations for Physicians and Nurses to consider include:

  • Active participation in training to understand AI tool functionalities and limitations;
  • Remaining vigilant when evaluating AI-driven recommendations, using clinical judgment to identify potential biases or anomalies; and
  • Report concerns or discrepancies promptly to compliance teams.

Administrative Use of AI

Administrative AI tools can significantly improve workflow efficiencies by reducing paperwork, automating prior authorizations, and managing patient scheduling. For example, AI-driven chatbots help route patient inquiries, while robotic process automation (RPA) can streamline claims processing. Despite these benefits, improper configuration or inadequate oversight of administrative AI systems may introduce compliance risks such as data breaches or noncompliant billing practices which result in unintended consequences.

Compliance programs should include cross-functional oversight committees to review and monitor AI deployments. These teams should ensure the use of AI aligns with payer contract requirements and is auditable during external reviews or governmental investigations. Furthermore, organizations should ensure their administrative AI tools do not inadvertently violate payer rules or documentation standards. System logs, user feedback, and integration testing are essential to ensure that automation supports, rather than compromises, compliance. Recommendations for Medical Billing Coders to consider include:

  • Regularly review AI-generated billing and coding to verify accuracy against clinical documentation;
  • Report discrepancies or patterns of errors immediately to compliance teams; and
  • Participate in ongoing training to stay updated on coding standards and AI tool developments.

Information Blocking and AI

ASTP (the Assistant Secretary for Technology Policy/Office of the National Coordinator for Health IT), previously known as “ONC” is organizationally located within the Office of the Secretary for the U.S. Department of Health and Human Services (HHS).  ASTP is the principal federal entity charged with coordination of nationwide efforts to implement and use the most advanced health information technology and the electronic exchange of health information.

AI applications that create or manage electronic health information (EHI) must comply with the ASTP’s information blocking rule. This includes tools that produce clinical summaries, generate patient documentation, or assist in diagnosis. Providers may invoke one of the eight permissible exceptions, but they must be able to justify their decisions with evidence. For example, the “Preventing Harm” exception may be valid if an AI-generated output could mislead or distress a patient.

Compliance officers must ensure that EHI-sharing policies are clearly documented; that patients have timely access to their data; and that systems are equipped to deliver requested data in accordance with federal requirements. Training and real-time decision support can help providers appropriately apply exceptions without violating the rule. Health systems must also monitor whether AI-generated data is accessible in usable formats and whether any AI-integrated tools restrict or delay data sharing in ways that could constitute noncompliance.

Recommendations for Allied Health Professionals to consider include:

  • Ensuring familiarity with AI-driven documentation and patient interaction tools;
  • Actively facilitate patient access to EHI generated by AI systems; and
  • Reporting any barriers to data sharing or potential compliance concerns promptly.

Financial Accountability and Algorithmic Errors

AI tools involved in billing or coding introduce serious financial accountability considerations. A coding algorithm that misclassifies a procedure or service can lead to overpayments and potential allegations of fraud. In such cases, the provider may be held liable under the False Claims Act if they knew or should have known about the inaccuracy. The Office of Inspector General’s (OIG) compliance guidance urges healthcare organizations to implement auditing mechanisms tailored to detect errors, regardless of whether those errors were made by means of electronic, human or AI.

Establishing protocols for reviewing AI-generated claims, comparing them to manual audits, and investigating anomalies is essential to achieve and maintain compliance. Compliance programs should include procedures for escalation, correction, and refund when errors are found. AI tools used for utilization review or determining medical necessity must be subject to similar scrutiny. Additionally, organizations must foster a culture where staff feel empowered to report discrepancies without fear of reprisal, and where corrective action plans include AI system revalidation. Recommendations for All Healthcare Professionals to consider is to:

  • Conduct regular audits comparing AI outputs with manual reviews, the monitor periodically to ensure compliance standards continue to be met;
  • Participate in cross-functional teams to review AI-driven financial processes; and
  • Engage in training on financial accountability, focusing on identifying AI-related discrepancies.

Conclusion

As AI continues to evolve, so must our compliance infrastructure to ensure that AI innovations align with ethical standards and legal obligations. With thoughtful integration, AI can support high-quality care, enhance administrative efficiency, and reduce costs. However, these benefits cannot come at the expense of accountability, transparency, or patient trust.

Organizations that invest in cross-disciplinary governance, risk management, and regulatory alignment will be best positioned to harness the promise of AI while safeguarding their mission and integrity. Compliance professionals must remain vigilant, agile, and collaborative to meet the demands of this fast-evolving frontier.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  1. U.S. Food and Drug Administration (FDA). (2021). Artificial Intelligence and Machine Learning (AI/ML)-Based Software as a Medical Device (SaMD) Action Plan. https://www.fda.gov/media/145022/download
  2. Office of the National Coordinator for Health Information Technology (ONC). (2020). 21st Century Cures Act: Interoperability, Information Blocking, and the ONC Health IT Certification Program. https://www.healthit.gov/curesrule/
  3. U.S. Department of Health and Human Services, Office of Inspector General (OIG). (2021). Compliance Program Guidance. https://oig.hhs.gov/compliance/compliance-guidance/index.asp
  4. Office for Civil Rights (OCR), HHS. (2022). HIPAA and Health IT. https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/index.html
  5. U.S. Department of Justice. (2023). False Claims Act Overview. https://www.justice.gov/civil/false-claims-act
  6. Centers for Medicare & Medicaid Services (CMS). (2023). Program Integrity Manual – Chapter 3: Verifying Potential Errors and Taking Corrective Actions. https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/pim83c03.pdf

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Artificial Intelligence in Healthcare
Artificial Intelligence

AI Transcription Software

A Chief Compliance Officer’s Perspective   

Written By Robert Colon-Torres, CHCO, CHA 

The documentation burden in healthcare has reached crisis levels. The question is no longer whether we should adopt AI transcription technology, but how quickly we can implement it to realize these substantial benefits for our patients, providers, and organization. Using advanced technology can lead to actionable insights, enabling quality control, performance assessments, and more informed business strategy decisions.

Introduction

AI transcription software leverages advanced algorithms to provide accurate, real-time transcriptions, making them a critical asset in environments ranging from healthcare and legal practices to business meetings and educational settings.12   This initiative supports the strategic integration of AI transcription technology to streamline operations and foster a more inclusive workplace.

Enhanced Efficiency and Productivity

AI transcription software automatically captures spoken content, reducing the need for manual notetaking. This shift not only saves time but also allows professionals to engage more closely with their core tasks. With real-time, accurate documentation, healthcare systems can significantly decrease administrative overhead, streamline workflow, and enable staff to dedicate more time to high-priority tasks.

The documentation burden in healthcare has reached crisis levels. Providers now spend approximately 8.7 hours per week on administrative tasks, with documentation being the primary contributor to this workload.3

AI transcription software fundamentally transforms this equation by:

  • Reducing clinical documentation time by an estimated 50-70%, based on early adopter studies.4
  • Automatically capturing and structuring the provider-patient conversation into appropriate medical note sections
  • Eliminating the cognitive burden of simultaneous patient interaction and documentation
  • Converting passive documentation time into active patient care time
  • Decreasing after-hours “pajama time” documentation, directly addressing clinician burnout.

Improved Communication and Accessibility

By providing precise text-based records, AI transcription software enhances communication within care teams and with patients. They support individuals with hearing impairments and offer the benefit of searchable documentation, which improves information retrieval during critical decision-making processes.5 This level of accessibility is especially vital in environments where clear, unambiguous communication is paramount.

Increased Accuracy and Error Reduction

Compared to traditional transcription methods, AI-powered tools can greatly minimize human error—providing higher accuracy in recording information.6 This is crucial for industries such as healthcare and legal services, where accurate documentation is not only important for operational excellence but also for regulatory compliance and risk management.

Data-Driven Insights and Continuous Improvement

The digital nature of AI transcription allows healthcare systems to easily archive and analyze verbal interactions.7 This can lead to actionable insights, enabling quality control, performance assessments, and more informed business strategy decisions. Over time, the system’s machine learning capabilities further refine accuracy, adapting to unique industry terminology and conversational nuances.

Integration with Existing Systems

Successful implementation of AI transcription software should involve seamless integration with current communication platforms, electronic health records (EHR), customer relationship management (CRM) systems, and other digital workflows.8 Planning and collaboration between IT, operational, and compliance teams are essential to ensure compatibility and optimize the benefits of AI integration.

Security and Privacy

Given that transcription software process potentially sensitive information, it is vital to enforce robust data security protocols, healthcare systems must ensure that all data is encrypted, access is strictly controlled, and the technology adheres to all relevant regulatory requirements (such as HIPAA in healthcare or GDPR in European contexts).9 Regular security audits and updates will help maintain a secure environment.

Training and Change Management

Adopting AI transcription technology requires thorough training for staff on how to utilize these tools effectively and understand their capabilities.10 Change management initiatives should include detailed guidelines, instructional sessions, and ongoing support to maximize user adoption and confidence, ensuring that the technology is leveraged to its full potential.11

Advancing Organizational Innovation

Implementing AI transcription software is more than a technological upgrade—it is a commitment to continuous innovation. By leveraging AI advancements, healthcare systems can remain competitive in today’s fast-paced digital landscape, fostering an environment where technology actively supports strategic business goals and operational excellence.12

Enhancing Customer and Client Experience

The accuracy and speed provided by AI transcription improve internal workflows and external communications. This benefits customer service, legal proceedings, patient care, and any interaction where clear, documented communication improves overall service quality.13 The insights gained from transcription analytics can also lead to enhanced client relations and operational improvements.

Conclusion

Integrating AI transcription software represents a transformative step forward in how healthcare systems document and manage their communication.14  With clear benefits including increased accuracy, enhanced accessibility, and substantial productivity gains, these technologies are poised to redefine operational efficiency, healthcare systems adopting AI-powered transcription will not only achieve significant administrative improvements but also foster a culture of innovation and continuous improvement that directly impacts long-term success.

The question is no longer whether we should adopt AI transcription technology, but how quickly we can implement it to realize these substantial benefits for our patients, providers, and organization.

About the Author

Roberto Paolo Colon-Torres, CHCO, CHA

Robert P. Colon-Torres holds a degree from Loyola University Chicago School of Law with an emphasis on Health law. He is certified as both a HIPAA Compliance Officer (CHCO) and Healthcare Auditor (CHA) through the American Institute of Healthcare Compliance. With over 25 years in healthcare, he currently serves as Chief Compliance Officer at San Ysidro Health in San Diego. His career began as a First Responder in Oakland before advancing through various Federally Qualified Health Centers throughout California.

References

1 Elhadad, Ahmed. (2024). Advancing Healthcare: Intelligent Speech Technology for Transcription, Disease  Diagnosis, and Interactive Control of Medical Equipment in Smart Hospitals.  https://www.mdpi.com/2673-2688/5/4/121

2 Nithya, Maheshwaran, et. al. (2024). AI-Driven Legal Automation to Enhance Legal Processes with Natural Language Processing. https://ieeexplore.ieee.org/abstract/document/10823316  

3 Himmelstein, David, et. al. (2014), Administrative work consumes one-sixth of U.S. physicians’ working hours and lowers their career satisfaction. https://journals.sagepub.com/doi/10.2190/HS.44.4.a

4 M.D. Bongurala, Archana, et. al. (2024). Transforming Health Care with Artificial Intelligence: Redefining Medical Documentation. https://www.mcpdigitalhealth.org/article/S2949-7612(24)00041-5/fulltext

5  Khamaj, Abdulrahman (2025). AI-enhanced chatbot for improving healthcare usability and accessibility for older adults. https://www.sciencedirect.com/science/article/pii/S1110016824016880

6  Baurasien, Bander, et. al. (2023). Medical errors and patient safety: Strategies for reducing errors using artificial intelligence. International Journal of Health Sciences (IJHS).https://www.neliti.com/publications/583940/medical-errors-and-patient-safety-strategies-for-reducing-errors-using-artificia 

7  Coiera, Enrico. (2022). Evidence synthesis, digital scribes, and translational challenges for artificial intelligence in healthcare. https://www.cell.com/action/showPdf?pii=S2666-3791%2822%2900424-4

8 Olusegun, John, et. al. (2024). INTEGRATION OF AI WITH ELECTRONIC HEALTH RECORDS: ENHANCING CLINICAL WORKFLOWS. https://www.researchgate.net/profile/Seraphina-Brightwood/publication/384773568_  

9  Edward, Aaron. (2020). AI-Enhanced IAM Strategies for Ensuring HIPAA and GDPR Compliance in Healthcare. https://www.researchgate.net/profile/Aaron-Edward-2/publication/384600591_

10 PHD, Regina, Russell, et. al. (2021). Competencies for the Use of Artificial Intelligence–Based Tools by Health Care Professionals. https://www.researchgate.net/profile/Aaron-Edward-2/publication/384600591 

11 O.E., Ademola. (2024). Change Management Trends in the AI Modern World: Adapting to the Future of Work. https://www.researchgate.net/publication/379449370_Change_Management_Trends_in_the_AI_Modern_World_Adapting_to_the_Future_of_Work  

12 Aman, Zain, et. al. (2025). Role of Artificial Intelligence in Strengthening Healthcare Systems. https://www.igi-global.com/chapter/role-of-artificial-intelligence-in-strengthening-healthcare-systems/365869   

13 Saadat, Saeed. (2025).  Enhancing Clinical Documentation with AI: Reducing Errors, Improving Interoperability, and Supporting Real-Time Note-Taking. https://www.isjtrend.com/article_213273.html

14 Sarella, Prakash. (2023). AI-Driven Natural Language Processing in Healthcare: Transforming Patient-Provider Communication.  https://www.researchgate.net/profile/Prakash-Sarella/publication/377264896

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved 

Read More
Artificial Intelligence in Healthcare
Artificial Intelligence

AI and Algorithms: An Effective Approach to Medical Claims Processing

Authored by Corliss Collins, BSHIM, RHIT, CRCR, CSM, CCA, CBCS, CPDC   

Founder. Principal and Managing Consultant     



This is Part 7 in a series of articles providing a general overview of Artificial Intelligence (AI) impacting the healthcare industry.  This information is an overview of very basic suggestions on Standard Operating Procedures (SOP), Policies and Best Practices for smaller hospitals and provider organizations. This information is not designed to be all-inclusive. and is not intended as consulting or legal advice.

Introduction

The Health Leaders Media Report, Final Denial Rate Increase, states that denials increased by 51% in 2021 and 2023 despite significant investments in Artificial Intelligence (AI) Automation and Revenue Cycle Management (RCM) Operations utilizing AI-Powered Medical Coding and Medical Claims Processing Software. This pressing issue demands our attention!

About the technology - Optical Character Recognition (OCR) and Natural Language Processing (NLP) are powered by AI Machine Learning (ML) and deep learning large language models (LLM). These technologies have become a core function in RCM Operations and have also been adopted by the Health Insurance, Health System, and Provider communities across the United States. Nonetheless, claim denials continue to show an alarming increase year over year. 

So, why aren't the numbers of healthcare claim denials and rejections declining with all the automation and technology advancements?

Are Automated Coding Models Powered by AI Not Accurate Enough for Medical Coding?

This article delves into this complex and sometimes very confusing topic, briefly recapping Part 6, AI and Algorithms: The Other Side of Medical Claims Processing, and then providing a general synopsis in Part 7AI and Algorithms: An Effective Approach to Medical Claims Processing. 

Advancing RCM Operations

Every year, more than five billion medical claims are processed by Payers in the United States for reimbursement, according to the Centers for Medicare & Medicaid Service, CMS.gov.  Many of these claims are processed using the Healthcare Common Procedure Coding System (HCPCS) and the Current Procedural Terminology (CPT®) coding systems. These two coding systems are the backbone of our billing process. It is essential to comprehend the underlying causes of AI, algorithms, and Rule-Based Automation in order to reduce risks:

There are Three Primary Claim Edit Types to Pay Attention to:

  1. Technical Edits are triggered by missing or incomplete claim information
  2. Clinical Edits are directly associated with care or services rendered
  3. Underpayments Claim amounts aren't being paid as the Contract Agrees to pay

Artificial Intelligence (AI) in the Medical Claims Process

AI leverages cutting-edge technology, including robotic process automation and AI machine learning, to improve the different medical claims adjudication activities that enable accurate billing for provided healthcare services.

These AI systems also use LLMs, which are machine learning models with the capacity to communicate in normal language with claim managers to evaluate substantial amounts of data. Complex patient data management, medical record administration, processing medical claims, collecting payments, and financial reporting are among the duties covered by CMS AI Resources.

There are hundreds of HIPAA-Compliant Medical Coding Software Applications on the market (see CMS for more on HIPAA-Compliant Code Sets.) Using automation more and manual intervention less is supposed to lead to the reduction of errors and inefficiencies. If this is the case, why do claim rejection and denial rates seem to not be declining annually?

On another note, unautomated accounts are processed differently. Claims are routed to manual review work queues (WQs) to be analyzed, corrected and billed. 

AI-Powered Challenges

Historically, rule-based algorithms for coding and claim adjustments (also known as coding-related edits) were created to streamline the claims adjudication and payment procedure for providers sending medical bills to payers. However, according to a 2022 Experian Report, rejections are still increasing year over year.  Statistics on Healthcare Claim Denials Healthcare Claim Denial Statistics are provided below:

Claim Denials Statistic Examples:

  • In 2009, there was an estimated $210 billion rise in claim denials
  • In 2019, a decade later, that number increased to $265 billion

These technologies seek to transform coding quality, accuracy, and financial performance, even as artificial intelligence in medical claims processing is a game-changer. In order to determine why claim denial rates are still rising, it is imperative that automation accountability, compliance, and transparency (ACT) standards be established; criteria suggestions are provided below:


Key AI-Powered Automation Evaluations could start with the Challenge Areas below:

  1. Patient Registration and Scheduling:
    • Chatbots and Virtual Assistants: AI-driven chatbots assist patients with scheduling appointments
    • Automated Data Entry: AI tools can automatically populate patient information from various sources, ensuring data consistency.
  2. Claims Processing and Billing:
    • Claims Scrubbing: AI systems can review claims for errors or omissions before submission.
    • Predictive Analytics: AI can predict the likelihood of claim approval based on historical data.
  3. Denial Management:
    • Root Cause Analysis: AI can analyze denial patterns to identify common causes and suggest process improvements.
    • Automated Appeals: AI-driven tools can generate and submit appeals for denied claims.
  4. Payment Posting and Reconciliation:
    • Automated Payment Posting: AI can automate the posting of payments received from payers.
    • Discrepancy Detection: AI systems can identify and flag discrepancies between expected and received payments.  
  5. Patient Engagement and Collections:
    • Predictive Payment Models: AI can analyze patient payment behaviors to predict the likelihood of payments.
    • Automated Reminders: AI can send personalized payment reminders to patients.
  6. Financial Reporting and Analysis:
    • Revenue Forecasting: AI models can predict future revenue based on current and historical data. 
    • Insights and Analytics: AI provides real-time analytics and dashboards, offering insights into key performance indicators (KPIs).
  7. Compliance and Risk Management: 
    • Fraud Detection: AI systems can identify unusual patterns that may indicate fraudulent activities.
    • Regulatory Compliance: AI helps ensure billing and coding practices comply with current healthcare regulations.

AI-Powered Algorithmic Opportunities Can be Leveraged

Best Practices for resolving discrepancies, recoding, and resubmitting rejected claims, and appealing denials are outlined in the Six Key Mitigation and Remediation guidelines below: 


Rejected or Denied Claims Review Strategy

  1. Claim Rejections
    1.1 Opportunity:      One or more edits caused the entire claim to be rejected
    1.2 Solution:             Identify the edit error, correct it, and resubmit the claim for payment
  2. Line-Item Rejections
    2.1 Opportunity:     One or more edits caused individual line items to be rejected
    2.2 Solution:            Identify claim edit line-item error, correct it, and resubmit it for payment
  3. Claim Denials    
  4.      3.1 Opportunity:    One or more edits have caused the entire claim to be denied

         3.2 Solution:          The provider must submit a letter with documented medical necessity                                                                                                                    

  5. Line-Item Denials
    4.1 Opportunity:     One or more edits caused individual line items on a claim to be denied
    4.2 Solution:             The claim line item that was denied must be appealed.
  6. Return-to-Provider
    5.1 Opportunity:     One or more edits caused the entire claim to be returned to the provider
    5.2 Solution:             The Provider should correct the claim edit error and resubmit it for payment
  7. Suspension 
    6.1 Opportunity:     One or more edits caused the entire claim to be suspended
    6.2 Solution:             The MAC must review the claim and determine if it will be paid


The Time to ACT is Now

It is estimated that the Medical Coding AI business will invest around $8.5 billion between 2024 and 2033, a period of nine years. The first step in reimagining a successful medical claims processing strategy is to set up and implement Accountability, Compliance, and Transparency (ACT) Best Practices.

The Department of Health and Human Services (HHS) has produced and distributed a trustworthy AI  (TAI) playbook, which assists Healthcare Leaders and Staff in developing TAI-specific Standard Operating Procedures (SOP), Policies, AI Playbooks, and Process Optimization Solutions.


HHS TAI Playbook Objectives

  1. Promote understanding of TAI Principles in the Playbook
  2. Provide guidance and frameworks for applying TAI Principles
  3. Centralize relevant federal and non-federal resources on TAI
  4. Serve as a framework for future HHS Policies on TAI acquisition, development, and use

The HHS TAI Playbook provides a great Blueprint for improving AI, Algorithms, Medical Claims Processing, and Revenue Cycle Management (RCM) Operational outcomes. 

REFERENCES:

About the Author

Corliss Collins, BSHIM, RHIT, CRCR, CSM, CCA, CBCS, CPDC

Corliss is the Founder. Principal and Managing Consultant of P3 Quality LLC. She serves as a subject matter expert and volunteer on the Education Committee for the American Institute of Healthcare Compliance.



Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved

Read More
Artificial Intelligence in Healthcare
Artificial Intelligence

AI and Algorithms: The Other Side of Medical Claims Processing

Written by Corliss Collins, BSHIM, RHIT, CRCR, CSM, CCA, CBCS, CPDC   


Artificial Intelligence (AI) and Revenue Cycle Management (RCM) are hot topics in the healthcare industry.  Optimizing RCM across all payment and reimbursement models can reduce overhead and improve accuracy which results in allowing your RCM workforce to focus on financial counseling and other important area requiring personal interactions with your patients and conducting pre and post documentation and coding audits.  This article addresses what Chief Financial Officers (CFOs) and other C-Suite executives needs to know about AI efficiencies and revolutionizing your RCM process.

Revenue Cycle Management Compliance

Revenue cycle management involves complex processes to manage financial transactions related to healthcare services.  Artificial Intelligence (AI) Automation and Claims Processing Algorithms for coding, billing, and payments are designed to reduce billing errors and maximize revenue recovery.  Payers are already implementing AI as a solution to deny inappropriately coded claims and detect potential fraud and abuse. 

In today’s environment, it is important for providers to increase efficiency and reduce the cost of operations, and it is the responsibility of Revenue Cycle Managers to understand and get ahead of root causes which can contribute to potential compliance issues. As we navigate some of the more common underlying causes of billing and reimbursement compliance discussed below, it becomes evident that AI and advanced technology may be a solution to consider, but what if AI algorithms don't perform as expected?

Revenue Cycle Management Coding Edit Errors 

Implemented by payers is Medicare’s NCCI Edits (National Correct Coding Initiative) which are coding edits designed to minimize improper payer payments.  They include Procedure-to-Procedure (PTP) edits and Medically Unlikely Edits (MUEs).  Auto-Coding Edit Errors (automated prepayment edits) significantly impact RCM billing, claims processing, and revenue operations.  Because payers are advancing their technology in these areas, it is important for providers to increase billing accuracy and implement cost-effective technology to stay compliant.

Coding related edit errors stem from improperly programmed edits and rules-based algorithms designed or written by human intelligence.  These issues can exist within your practice management system or occur during an update.  These unintentional flaws can cause claims to be held up in the Medical Claims Scrubber, and not submitted to payers timely.  This causes delayed payments, cash flow problems, manual work to detect and correct as well as compliance issues.

Here are a few examples of why coding edit errors may occur and why detecting system failures is critical to the RCM process:

  1. Incorrect Coding: One of the primary causes of errors is incorrect coding. This could involve using the wrong CPT (Current Procedural Terminology) or HCPCS (Healthcare Common Procedure Coding System) codes.
  2. Bundling Issues: PTP edits often occur when procedures or services should not be billed separately because they are considered bundled together.
    • For example, if a comprehensive service includes specific components that should not be billed separately, attempting to do so will trigger a PTP edit.
  3. Mutually Exclusive Procedures: PTP edits also arise when two procedures are mutually exclusive, meaning they should not ever be performed during the same encounter.
    • Billing for both procedures would trigger an edit and if billed, could trigger an audit.
  4. Frequency Limits: MUEs limit the number of times a specific service can be billed within a given timeframe.  Payer edits look for inappropriate number of units per line-item on a claim as well.
    • Errors occur when providers attempt to bill for services that exceed these limits.
  5. Documentation Deficiencies: Errors can also stem from documentation deficiencies.
    • If the medical record does not support the services billed or lacks sufficient detail, it can trigger automated edits.
  6. Upcoding or Unbundling: Sometimes errors occur due to intentional or unintentional upcoding.
    • An example is billing for a more complex or expensive service than what was provided; or unbundling (billing separately for components that should be billed together).
  7. System Glitches or Errors: Occasionally, edit errors can occur due to glitches or errors in the billing system.
    • Software updates, database errors, or incorrect application of rules could cause this.
  8. Changes in Coding Guidelines or Regulations: Updates to coding guidelines or regulations can sometimes lead to errors.
    • When providers are not aware of the changes and the systems and software applications aren't updated appropriately for guidelines/regulations to be applied correctly.
  9. Inaccurate Charge Capture: Failing to capture all automated billable services rendered to a patient. This includes failing to charge for documented services which are medically necessary and allowed under the patient’s insurance plan.
    • Inaccurate charge capture results in lost revenue and potential compliance issues.
    • Manual Review determines an automation edit error occurred (Claim should not have ever been placed on a bill hold).

While it would be very challenging to provide an exact dollar amount for the cost of auto-coding edit errors across all healthcare organizations, studies and industry reports suggest that they contribute to significant financial losses. Inaccurate auto-coding can lead to poor data quality, which can undermine the reliability of healthcare data used for billing, claim reimbursements, quality improvement, and policy development.

Conclusion

Each year the complexity of medical coding increases due to provider’s need to capture detailed accuracy in how they charge for treatment to maximize revenue.  AI can sort through codes, annual updates and guidelines with lightning speed.  The root causes of these automated coding edit errors are broad in scope and require a multifaceted approach to identifying the issues involved, reconciling and improving AI programming, and Algorithmic System updates. 

To mitigate the auto-coding edit errors' financial impact, healthcare organizations should implement effective coding validation processes, regularly audit coding edit rules, and leverage technology solutions that help to improve coding accuracy and efficiency.

Healthcare Organizations should address coding edit errors proactively, evaluate how the current state and rework cost impact revenue, and enhance overall revenue cycle management performance:

  • Implement robust testing policies and procedures;
  • Measure, and monitor progress (what is measured is what improves);
  • Provide ongoing oversight to critical education system users;
  • Address the factors that can help reduce auto-coding edit error occurrences;
  • Created sustainable accuracy and efficiency best practices for the entire revenue cycle management process; and
  • Realize that AI and algorithms can cause claims processing errors in key ways, including overreliance on incomplete or inaccurate data, lack of human oversight, and the inability to keep up with evolving regulations and guidelines.

Addressing these issues through automating error-proofing measures, data quality control, and maintaining the right balance between automation and human expertise is crucial to mitigate the risk of AI-driven claims processing errors.

Auditing & Implementing a Proactive Approach 

As providers implement advanced technology, critical oversight is needed to ensure the new systems are performing within compliance guidelines.  Your coding professionals can be assigned to perform oversight by conducting Root Cause Analysis (RCA) after a problem is identified and implementing prospective assessments, as seen with Healthcare Failure Mode and Effect Analysis (HFMEA).   

HFMEA is a prospective assessment that identifies and improves steps in a health care process thereby reasonably ensuring a safe and clinically desirable outcome. It is also considered a systematic approach to identify and prevent product and process problems before they occur.

References

About the Author

Corliss Collins, BSHIM, RHIT, CRCR, CSM, CCA, CBCS, CPDC

Corliss is the founder and Chief Revenue Integrity Officer, Chief Compliance Officer of P3 Quality LLC.  She is serves as a subject matter expert and volunteer on the Education Committee for the American Institute of Healthcare Compliance.



Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved 

Read More
Artificial Intelligence in Healthcare
Artificial Intelligence

Artificial Intelligence, Extinction-Level Threat or Solution?

Written by the AIHC Education Department    


This article provides an overview of how the media and government are reacting to the potential of artificial intelligence (AI) and potential threats associated with this advanced technology.  Please read other AI articles published by the American Institute of Healthcare Compliance regarding how AI can advance quality of care, how AI is regulated, use of AI and HIPAA privacy/security, to name a few topics.

A Government-Commissioned Report Released February 2024

The U.S. State Department commissioned the first-ever assessment of proliferation and security risk from weaponized and misaligned AI. In February 2024, Gladstone AI, a four-person company which runs technical briefings on AI for government employees, completed that assessment. It includes an analysis of catastrophic AI risks, and a first-of-its-kind, government-wide Action Plan for what we can do about them entitled “An Action Plan to Increase the Safety and Security of Advanced AI.”

According to Time in a March 11, 2024 exclusive, U.S. Must Move ‘Decisively’ to Avert ‘Extinction-Level’ Threat From AI, the Gladstone AI report recommends a threshold should be set by a new federal AI agency which would require AI companies to obtain government permission to train and deploy new models above a certain lower threshold.

We can argue that there needs to be some type of controls to guide artificial intelligence, but hopefully the government will dive deeper, and quickly seek additional recommendations.  The government commission for this report from Gladstone AI was made in 2022.  According to the Time article, “The rise of advanced AI and AGI [artificial general intelligence] has the potential to destabilize global security in ways reminiscent of the introduction of nuclear weapons. AGI is a hypothetical technology that could perform most tasks at or above the level of a human. Such systems do not currently exist, but the leading AI labs are working toward them and many expect AGI to arrive within the next five years or less.”

As technology advances, so do cyber criminals 

When it comes to cyberattacks and cyber extortion (ransomware attacks), health care organization continue to suffer as prime targets and continue to struggle to recover after an attack.  

Threat actors (cyber criminals or extortionists) are leveraging AI to their advantage, which can be used as a potent weapon.  According to the National Cyber Security Centre (United Kingdom), artificial intelligence (AI) is expected to increase the global ransomware threat over the next two years. “AI enables relatively unskilled threat actors to carry out more effective access and information-gathering operations. This enhanced access, combined with the improved targeting of victims afforded by AI, will contribute to the global ransomware threat in the next two years.”

Using AI to Secure Healthcare Data

Government agencies are harnessing the power of AI for threat intelligence and defense. This involves using AI algorithms to analyze vast datasets, identify potential threats, and predict cyberattacks before they occur.  For now, health care organizations and business associates can access cybersecurity guidance through various agencies.

America’s cyber defense agency CISA (Cybersecurity & Infrastructure Security Agency).  CISA provides information on AI under Cybersecurity Best Practices on their website: https://www.cisa.gov/ai.

Artificial Intelligence, Cybersecurity and the Health Sector July 13, 2023 from the Office of Information Security and Health Sector Cybersecurity Coordination Center.  This PPT addresses:

  • What is artificial intelligence?
  • How does it work?
  • What does it mean for cybersecurity, especially for healthcare?
  • What can be done to remain secure, given AI-enhanced cyberthreats?

AIHC recommends training healthcare executives, managers and key workforce members in HIPAA privacy and security – training online available at: https://dev-main.aihc-assn.org/courses/hipaa-privacy-security-course/

AIHC is a Licensing/Certification Partner with the Centers for Medicare & Medicaid Services (CMS)

https://www.cms.gov/training-education/medicare-learning-network/partnerships#Licensing


Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved 

Read More
Artificial Intelligence in Healthcare
Artificial Intelligence

Artificial Intelligence – Resources to Technology Governance

This article provides an introduction to Artificial Intelligence, large multi-modal models and the impact on health care.  This information is not intended as legal or consulting advice.  Please utilize resources provided within this article for more information.     

During the design and development of machine-learning models (aka general-purpose foundation models), the responsibility rests with the developers.

A general-purpose foundation model can be used by a third party (a “provider”) through an active programming interface for a specific purpose or use. Governments bear the responsibility to set laws and standards to require or forbid certain practices.  Another aspect to consider is compliance to national and state security standards.  In the United States, America’s cyber defense agency is CISA (Cybersecurity & Infrastructure Security Agency). Secure by Design means building cybersecurity into the manufacturing of the technology.


International Governance

International governance is necessary to ensure that all governments are accountable for their investments and participation in the development and deployment of AI-based systems and that governments introduce appropriate regulations that uphold ethical principles, human rights and international law. International governance can also ensure that companies develop and deploy LMMs that meet adequate international standards of safety and efficacy and are upholding ethical principles and human rights obligations. Governments should also avoid introducing regulations that provide a competitive advantage or disadvantage for either companies or themselves.

Published in September 2023 by Oxford Academic, journal article The Global Governance of Artificial Intelligence: Next Steps for Empirical and Normative Research discusses the international impact of AI technology posing a global governance challenge.  The first section of the article explains why AI is now global governance concern:

“Why does AI pose a global governance challenge? In this section, we answer this question in three steps. We begin by briefly describing the spread of AI technology in society, then illustrate the attempts to regulate AI at various levels of governance, and finally explain why global regulatory initiatives are becoming increasingly common. We argue that the growth of global governance initiatives in this area stems from AI applications creating cross-border externalities that demand international cooperation and from AI development taking place through transnational processes requiring transboundary regulation.”


NIST – the National Institute of Standards and Technology

Published in January 2023, NIST’s Artificial Intelligence Risk Management Framework (AI RMF) guidance targets mitigating risk while cultivating trust in AI technologies. 

“This voluntary framework will help develop and deploy AI technologies in ways that enable the United States, other nations and organizations to enhance AI trustworthiness while managing risks based on our democratic values,” said Deputy Commerce Secretary Don Graves. “It should accelerate AI innovation and growth while advancing — rather than restricting or damaging — civil rights, civil liberties and equity for all.”

On March 30, 2023, NIST launched the Trustworthy and Responsible AI Resource Center, which will facilitate implementation of, and international alignment with, the AI RMF.

As the United States and other governments regulate foundation models, new legal definitions have emerged.  The World Health Organization (WHO) is weighing-in with free resources related to health care.


World Health Organization and the Governance of Generative Artificial Intelligence (AI) Technology

The six core AI principles identified by WHO are:

  1. Protect autonomy;
  2. Promote human well-being, human safety, and the public interest;
  3. Ensure transparency, explainability, and intelligibility;
  4. Foster responsibility and accountability;
  5. Ensure inclusiveness and equity;
  6. Promote AI that is responsive and sustainable.

In January 2024, the World Health Organization (WHO) posted a new guidance regarding AI ethics and governance guidance of large multi-modal models.

This is an update to the previous June 2021 publication Ethics and governance of artificial intelligence for health.

Multimodal language models are considered to be next steps toward artificial general intelligence.  A large multimodal model (LMM) is an advanced type of artificial intelligence model that can process and understand multiple types of data modalities. These multimodal data can include text, images, audio, video, and potentially others.

As reported by WHO, LMMs have been adopted faster than any consumer application in history, with several platforms – such as ChatGPT, Bard and Bert – entering the public consciousness in 2023.  GPT-4, the latest iteration in the GPT series of models maintained by OpenAI, is capable of responding to multimodal queries. Multimodal queries use text and images.

The new WHO guidance outlines five broad applications of LMMs for health:

  • Diagnosis and clinical care, such as responding to patients’ written queries;
  • Patient-guided use, such as for investigating symptoms and treatment;
  • Clerical and administrative tasks, such as documenting and summarizing patient visits within electronic health records;
  • Medical and nursing education, including providing trainees with simulated patient encounters, and;
  • Scientific research and drug development, including to identify new compounds.

Read Additional Free Articles on Artificial Intelligence and Health Care posted to the American Institute of Healthcare Compliance Blog.

This article is written by members of the AIHC Volunteer Education Committee.  AIHC is a non-profit organization.  We value our members, credentialed professionals and greatly appreciate the talents offered by our member volunteers!


Copyright © February 2024 American Institute of Healthcare Compliance All Rights Reserved

Read More
Artificial Intelligence in Healthcare
Artificial Intelligence

Asynchronous Telehealth & Patient Privacy

This article provides a basic overview of Artificial Intelligence, Telehealth, Asynchronous Services and HIPAA privacy concerns.  This information is not intended as legal or consulting advice.  Please utilize resources provided within this article for more information.   

Telehealth refers to a collection of methods to enhance health care delivery and education — it’s not a specific service. 

Synchronous telehealth is a virtual interaction between a patient and a provider that takes place in real time, like a video call, audio call, or secure text messaging. It usually results in a provider giving a patient a diagnosis, treatment plan, or prescription, according to Health & Human Services. Synchronous telehealth has been shown to reduce the number of no-show patients, shorten the wait time for patients to see their provider, and increase efficiency in a physician’s practice.  Asynchronous telehealth, on the other hand, is a virtual interaction between a patient and a provider that doesn’t take place in real time.

Telehealth spans four distinct applications:

  • Live Video;
  • Store-and-Forward;
    • Mobile Health (mHealth); and
    • Remote Patient Monitoring (RPM).

Store-and-Forward

Asynchronous telehealth is generally used for patient intake purposes or follow-up care. Store-and-Forward is considered “asynchronous telehealth, a communication between parties that is not live.”  It is a service rendered outside of a real-time or live interaction with a patient.

Within asynchronous telehealth is also called “Store-and-Forward”.  There are two subcategories:

  1. Mobile health (also called mHealth); and
  2. Remote patient monitoring, or RPM.

Mobile health involves using a device such as a smartphone or a wearable device (like an Apple Watch) to support a patient’s health and transmit health data between a patient and their provider.

Remote patient monitoring involves transferring patient data from a medical device, like a blood pressure monitor or a pacemaker, to a provider.

According to https://telehealth.hhs.gov  asynchronous direct-to-patient telehealth can streamline patient workflows by standardizing patient data for later use, flexibility because no scheduling is involved and efficiency through automated patient intake.  Examples include:

  • Messaging or texting between patient and provider with follow-up instructions or confirmations;
  • Patient report sharing;
  • Symptom survey questionnaires;
  • Wound imaging;
  • Images sent for evaluation, X-ray or MRI sharing;
  • Lab results or vital statistics;

Store-and-forward technologies are most commonly used in radiology, pathology, dermatology, ophthalmology and for electronic consultations (eConsults).  eConsult is a web-based system that allows a primary care physician (PCP) and a specialist to securely share health information and discuss patient care.

Although store-and-forward services can increase efficiency, these services are not always reimbursable by private insurers.  Medicaid policies on this issue vary from state to state.


Address HIPAA and Privacy Concerns

Technology considerations

The telehealth platform you use should meet HIPAA requirements.  All telehealth services provided by covered health care providers and health plans must comply with the HIPAA Rules. This means only using technology vendors that comply with the HIPAA Rules and will enter into HIPAA business associate agreements in connection with the provision of their video communication products or other remote communication technologies for telehealth.


HIPAA Telehealth Compliance Resources


Other Telehealth Resources

American Telemedicine Association

Artificial Intelligence -Article posted in the National Library of Medicine

Center for Connected Health Policy (CCHP) and the National Consortium of Telehealth Resource Centers has finalized a Telehealth Definition Framework to help clarify how to accurately use “telehealth” and its key components. 

Centers for Medicare & Medicaid Services (CMS) offers a 17-page PDF:

Center for Connected Health Policy (CCHP) - Medicare and each Medicaid program are different in how they approach and reimburse telehealth delivered services.

E-consults - Telehealth for Emergency Departments -E-consults are communications between providers only. Providers can interact with each other by using phone, video, or a HIPAA-compliant platform that allows two-way communication and can securely share patient records.

E-Consults and Their Outcomes: a Systematic Review

This article is written by members of the AIHC Volunteer Education Committee.  AIHC is a non-profit organization.  We value our members, credentialed professionals and greatly appreciate the talents offered by our member volunteers!

Copyright © February 2024 American Institute of Healthcare Compliance All Rights Reserved

Read More
Artificial Intelligence in Healthcare
Artificial Intelligence

Is Your Organization HITECH Compliant?

Written by the AIHC Education Volunteer Committee 

Contributors: Nancie Cummins, Sheryn Honest, Joanne Byron   

This article is written to help educate individuals new to HIPAA & HITECH compliance by addressing the basic elements needed for a health care organization and/or business associate to be in compliance with Health Information Technology for Economic and Clinical Health (HITECH). 

The focus of this article is to “connect the dots” between Health Insurance Portability & Accountability Act (HIPAA) and HITECH regarding privacy and security of electronically protected health information (ePHI).

HIPAA covers all protected health information (PHI), while HITECH extends the HIPAA privacy and security provisions to electronic health records (EHRs).

What is “HITECH”?

“HITECH” is the acronym for the Health Information Technology for Economic and Clinical Health (HITECH Act), which is title XIII of division A and title IV of division B of the American Recovery and Reinvestment Act of 2009 (ARRA), Pub. L. 111-5.

HITECH is a federal regulatory requirement used to implement privacy and security provisions for healthcare providers and entities, by the Office of Civil Rights (OCR).  HITECH enhanced the HIPAA Privacy & Security Rules, while addressing the standards and implementation of electronic health record technology.  There are four sections to the HITECH Act (Subtitles A, B, C, D):

Subtitle A—Promotion of Health Information Technology

Subtitle B—Testing of Health Information Technology

Subtitle C—Grants and Loans Funding

Subtitle D—Privacy

Due to the implementation of advanced technology, the HIPAA security requirements have become insufficient.  HITECH puts a “bite” into specific elements of the HIPAA rule, such as higher penalty amounts for non-compliance.  However, your organization should not address only “HIPAA” or only “HITECH”.  Combining the requirements of both Acts and implementing best practices will help mitigate risk suffering non-compliance consequences for violating the rules. 

Why HITECH?

It has to do with the every-evolving advancement in healthcare information technology.

If you have been working in healthcare over the past 10 years, you’ll remember the implementation of attesting to “Meaningful Use”, the government’s ploy to strongly encourage implementation of electronic health records.  Meaningful use means healthcare providers need to show that they are using certified EHR technology in a way that can be measured in both quantity and quality.

The transition from paper to electronic records has been both expensive and exhausting resources for providers.  Documentation, for most providers, takes longer in an electronic system.  Combining this with historical documentation requirements, progress notes became “bloated” with information required for reimbursement purposes with little impact on quality of care.  This increase in expense and provider time was added to the exposure of potential hacking, ransomware and other cybersecurity risks associated with storing and transmitting electronic patient records.

In addition to complying with the HIPAA security standards, the HITECH Act also set the stage for stricter enforcement of the Privacy and Security Rules of HIPAA by mandating security audits of all healthcare providers. These audits are used to investigate and determine whether providers meet minimum specified standards and are therefore in compliance with the HIPAA’s Privacy Rule and Security Rule.

Summary of the Goals or Objectives of the HITECH Act

There are five HITECH Act goals in the United States healthcare system:

  1. Improve quality, safety, and efficiency
  2. Engage patients in their care
  3. Increase coordination of care
  4. Improve the health status of the population, and
  5. Ensure privacy and security

To achieve these goals, HITECH incentivized the adoption and use of health information technology, enabled patients to take a proactive interest in their health, paved the way for the expansion of Health Information Exchanges, and strengthened the privacy and security provisions of the Health Information Portability and Accountability Act of 1996 (HIPAA).

What about Artificial Intelligence?

The HITECH Act will continue to evolve and adapt due to the rapid development in health care information technology (HIT). In 2020, the U.S. government introduced the 21st Century Cures Act, which builds upon the HITECH Act and aims to promote innovation in HIT and improve patient access to healthcare services. The 21st Century Cures Act provides additional funding for HIT research and development and includes provisions for interoperability and patient access to health information.

The HITECH Act supports advancements in HIT, such as the use of artificial intelligence (AI), telemedicine, and other innovative technologies. These new technologies have the potential to further improve patient care, provide innovations to increase the quality of care and patient outcomes while increasing efficiency, and reduce costs.

Penalties?

The consequences for noncompliance with the HITECH Act can be severe. The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) is the government enforcement agency over both HIPAA and HITECH.  OCR can impose civil money penalties up to $1.5 million per violation, as well as criminal penalties for violations that involve the wrongful disclosure of individually identifiable health information (IIHI).

Consequences can include public disclosure of the provider’s violation, administrative reprimands, and termination of Medicare and Medicaid billing privileges by being listed on the Office of Inspector General (OIG) Exclusions List.

On February 27, 2023, due to OCR’s increase in case load, OCR has renamed the Health Information Privacy Division (HIP) to the Health Information Privacy, Data, and Cybersecurity Division (HIPDC) to be more reflective of their work and role in cybersecurity.

  • For example, breaches of unsecured PHI, including ePHI, reported to OCR affecting 500 or more individuals (large breaches) increased from 663 large breaches in 2020 to 714 large breaches in 2021.
  • This trend is continuing with OCR reporting hacking incidents accounting for 80% of the large breaches they have received.

HIPDC will continue to meet the growing demands to address health information privacy and cyber security concerns.

HITECH’s Recognized Security Practices” (“RSPs”)

Back in January of 2021, Congress enacted an amendment to the HITECH Act aka as the “HITECH Amendment”.  This requires the Department of Health and Human Services (“HHS”) to consider whether a covered entity or business associate has “adequately demonstrated” that the organization has, for not less than the previous 12 months, “recognized security practices” in place when making certain determinations under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) Security Rule (e.g. mitigation of fines, early termination of an audit, or other remedies).

The HITECH Amendment provides that “recognized security practices” (“RSPs”) include:

  • standards, guidelines, best practices, methodologies, procedures, and processes developed under section 2(c)(15) of the National Institute of Standards and Technology (“NIST”) Act;
  • the approaches promulgated under section 405(d) of the Cybersecurity Act of 2015; and
  • other programs and processes that address cybersecurity and that are developed, recognized, or promulgated through regulations under other statutory authorities.

Documentation of historical, present and future security practices is critical for your organization. OCR suggests the following can be provided as evidence, although the list is not exhaustive:

  • Policies and procedures regarding the implementation and use of RSPs
  • RSP implementation project plans and meeting minutes
  • Diagrams and narrative detail of RSP implementation and use
  • Training materials regarding RSP implementation and use
  • Application screenshots and reports showing RSP implementation and use
  • Vendor contracts and statements of work regarding RSP implementation
  • OCR also requires dates that support the implementation and use of RSPs for the previous 12 months

Are there Resources to Help Organization Subject to HIPAA/HITECH Compliance?

When an enforcement agency offers free templates, education and resources, it is wise to participate. 

  • OCR Recognized Security Practices VIDEO

This video released in October, 2022 features Nick Heesters, senior advisor for cybersecurity at OCR.  He explains how the HITECH Act was amended, what constitutes Recognized Security Practices, and how they can be implemented to reduce liability. Recognized Security Practices are standards, guidelines, best practices, methodologies, procedures, and processes developed under:

  • The National Institute of Standards and Technology (NIST) Cybersecurity Framework
  • Section 405(d) of the Cybersecurity Act of 2015, or
  • Other programs that address cybersecurity that are explicitly recognized by statute or regulation

HIPAA-regulated entities are free to choose the Recognized Security Practices that are best suited to their organization. Click Here or copy this link to view the video: 

  • HHS 405(d) Program

The HHS 405(d) Program is a collaborative effort between The Health Sector Coordinating Council and the federal government to align healthcare industry security practices.

As the leading collaboration center of the Office of the Chief Information Officer, the 405(d) Program is focused on providing organizations across the nation with useful and impactful Healthcare and Public Health (HPH) focused resources, products, and tools that help educate, raise awareness, and provide vetted cybersecurity best practices which drive behavioral change and strengthen the sector’s cybersecurity posture against cyber threats.

Take advantage of “Knowledge on Demand” located on the Education page of the 405(d) website.  Click Here or copy this link to view resources on this page:

  • HIPAA/HITECH for Managed Service Providers

If your organization is a Managed Service Provider, it is highly recommended that at least one person has HIPAA/HITECH training specifically designed for IT professionals. Click Here for more information about this online training w/option to certify online or use this link:

  • HIPAA Compliance Officer Training

This online program in HIPAA Privacy & Security is designed for those working for a Covered Entity or Business Associate. Click Here for more information or use this link:

Copyright © 2023 American Institute of Healthcare Compliance All Rights Reserved 

Read More