Skip to content
Jump to Section

Artificial intelligence is quickly becoming part of healthcare operations, from clinical decision support and documentation to administrative workflows, patient engagement, and data analysis. But in healthcare, AI adoption cannot be separated from accountability.

The Joint Commission–Coalition for Health AI guidance gives hospitals and health systems a practical foundation for responsible AI use. Its message is clear: AI governance is not only a policy exercise. It must become an operational discipline that helps organizations understand how AI tools are used, what data they touch, how risks are monitored, and how concerns are investigated when something goes wrong.

That distinction matters because AI-related risk can affect more than efficiency. An inaccurate output, inappropriate use or disclosure of patient information, a biased recommendation, a vendor issue, or a failure to detect declining model performance can create privacy, safety, compliance, and trust concerns.

For healthcare leaders, the question is no longer simply whether the organization has approved AI policies. It is whether the organization can demonstrate that those policies work in practice.

What the Joint Commission–CHAI Guidance Means for Healthcare AI Governance

The Guidance on Responsible Use of AI in Healthcare, released jointly by The Joint Commission and the Coalition for Health AI, gives healthcare organizations a shared framework for governing AI across clinical, administrative, and operational settings.

The significance of the guidance is not simply that it describes responsible AI. It makes clear that responsible AI must become repeatable, measurable, and defensible.

Healthcare organizations need more than a process for approving new AI tools. They need a practical operating model for monitoring use, managing risk, coordinating response, documenting decisions, and learning from events over time.

The Seven Elements of Responsible Healthcare AI

The guidance identifies seven elements healthcare organizations should address as they implement and oversee AI:

  • AI policies and governance structures
  • Patient privacy and transparency
  • Data security and data-use protections
  • Ongoing quality monitoring
  • Voluntary, blinded reporting of AI safety-related events
  • Risk and bias assessment
  • Education and training

Together, these elements move responsible AI from principle to practice. They recognize that an AI system cannot be considered responsible solely on the basis of its performance before deployment.

Healthcare organizations also need to understand how the system is used over time, what patient information it processes, whether performance changes, who owns oversight, how vendors are involved, and what happens when a concern is reported.

That last question is where many AI governance programs will face their most important test.

Why AI Governance Will Be Tested During an Incident

Policies establish expectations. Governance committees assign responsibility. Assessments help organizations identify risks before deployment.

But the effectiveness of an AI governance program becomes most visible when the organization encounters an unexpected event.

Consider the questions that may follow an AI-related incident:

  • Did the system expose or improperly use protected health information?
  • Was an incorrect output presented to a clinician or patient?
  • Did model drift affect the reliability of a recommendation?
  • Did the tool perform differently for a particular patient population?
  • Was a third-party vendor involved?
  • Who discovered the event, and when?
  • What corrective measures were taken?
  • Does the event create reporting, notification, contractual, or regulatory obligations?
  • Can the organization demonstrate how it reached its final decision?

These are not merely technical questions. They require coordination among privacy, compliance, clinical safety, legal, cybersecurity, risk, information technology, and vendor-management teams.

A responsible AI program, therefore, needs more than a review process to approve new tools. It needs a repeatable process for receiving, investigating, assessing, escalating, documenting, and resolving AI-related events.

Privacy Must Be Managed Across the AI Lifecycle

The guidance gives patient privacy and transparency their own place alongside data security and data-use protections. That distinction matters.

Security asks whether information is protected against unauthorized access. Privacy also asks whether patient information is being collected, used, inferred, shared, and retained appropriately.

An AI system could remain technically secure while creating privacy concerns. For example, a model might use patient data beyond what patients reasonably expected, expose sensitive information through its generated output, or rely on a vendor whose downstream data practices are insufficiently understood.

Healthcare organizations should therefore evaluate privacy throughout the AI lifecycle, not only during procurement.

That includes determining:

  • What patient information the tool receives
  • Whether the information is used to train or improve external models
  • What sensitive information the system can infer
  • How generated outputs are stored and disclosed
  • Which vendors and subprocessors can access the data
  • What happens to the data when the relationship ends
  • How patients will be informed about material uses of AI
  • How suspected inappropriate uses or disclosures will be investigated

The objective is not to eliminate every possible risk. It is to make risk visible, assign ownership, implement appropriate controls, and create a defensible record of the organization’s decisions.

Monitoring Must Trigger a Defined Response

The guidance also recognizes that AI oversight does not stop at implementation. Models, underlying data, workflows, vendors, and patterns of use can all change over time.

Ongoing monitoring is therefore essential. But monitoring alone is insufficient.

Healthcare organizations need defined thresholds for intervention. They should know what constitutes an AI safety event, a privacy incident, a quality concern, or evidence of harmful bias. They also need clear escalation paths and the ability to connect related events across departments and facilities.

Without that operating structure, warning signs can remain scattered across support tickets, clinical reports, compliance inboxes, vendor correspondence, and spreadsheets. Each team may see part of the problem while no one sees the complete pattern.

A mature program turns monitoring signals into structured action:

  • Capture the concern through an accessible reporting channel.
  • Triage it based on potential patient impact, privacy, compliance, and operational impact.
  • Assign accountable owners.
  • Preserve relevant evidence.
  • Assess legal, regulatory, contractual, and notification obligations.
  • Document the rationale for the determination.
  • Track mitigation and corrective action.
  • Feed lessons learned back into governance, training, and vendor oversight.

This is how responsible AI becomes repeatable rather than aspirational.

AI Safety Event Reporting Depends on Consistent Internal Records

One of the guidance’s most consequential elements is its support for voluntary, blinded reporting of AI safety-related events.

Healthcare has long understood the value of learning from adverse events and near misses. Applying a similar approach to AI can help organizations identify patterns that no single health system, developer, or regulator could see independently.

For that reporting to work, however, organizations first need consistent internal records. An AI-related event must be documented with enough structure to explain what occurred, the system and parties involved, the populations potentially affected, the harm or risk identified, and the steps taken in response.

Consistent event management creates value beyond the individual case. It produces evidence that can improve:

  • AI policies and approval criteria
  • Staff education
  • Risk and bias assessments
  • Vendor requirements
  • Model monitoring
  • Executive and board reporting
  • Future procurement decisions

Incident response should not sit at the end of the AI governance lifecycle. It should inform the entire lifecycle.

From Guidance to Defensible Practice

The Joint Commission–CHAI guidance is intentionally adaptable. Healthcare organizations vary widely in their resources, AI maturity, technical environments, patient populations, and risk profiles.

But flexibility should not lead to fragmentation.

If each facility, department, or investigator handles AI-related concerns differently, similar events may produce inconsistent outcomes. Key facts may be missed, escalation may be delayed, and the organization may struggle to explain how it reached its final decision.

Healthcare leaders should use the guidance as an opportunity to create a common operating model for AI risk and privacy response. That means connecting policies to workflows, workflows to accountable owners, assessments to evidence, and incident outcomes to organizational learning.

CHAI’s subsequent governance resources and playbooks point in the same direction: healthcare AI governance is moving toward measurable, sustained, and demonstrable practice. Organizations that prepare now will be better positioned to show not only that they support responsible AI, but that they can operationalize it when risk appears.

RadarFirst’s Point of View: Responsible AI Requires Operational Readiness

Responsible AI will not be achieved through policy statements alone.

Healthcare organizations need the operational ability to recognize AI-related events, bring the right stakeholders together, assess consequences consistently, and preserve the reasoning behind each decision.

Privacy and AI risk are already converging. The organizations best positioned to maintain patient trust will be those that integrate AI governance with mature incident management practices before a high-impact event tests the process.

The question for healthcare leaders is no longer, “Do we have an AI policy?”

It is, “Can we show that our governance works when it matters?”

That is the difference between committing to responsible AI and being ready to demonstrate it.

Learn More

RadarFirst helps privacy, compliance, legal, security, and risk teams standardize incident intake, assessment, investigation, documentation, and response.

Learn how RadarFirst can help your organization operationalize AI-related incident response with consistent workflows, defensible documentation, and coordinated decision-making as privacy and AI risks converge.

Let’s Get Started

Trusted by leading organizations, RadarFirst enables teams to manage incidents with speed, consistency, and defensibility by standardizing how incidents are captured, assessed, and actioned.