Context: AI Vendor Oversight in Healthcare
On August 20, 2026, ISMG published[1] an interview with Tom Walsh, founder of tw-Security, focused on vendor risk in the healthcare sector.
The analysis arrives as clinical AI adoption accelerates. Healthcare organizations face a concrete governance challenge. The question is no longer whether to adopt AI, but how to govern its use by third parties.
The central message is direct: relying on vendor assurances about the security of AI tools is insufficient. Walsh argues that providers need stronger oversight of third parties and greater scrutiny of how AI handles patient data and clinical decisions.
The mechanism is straightforward. A contractual assurance is not proof. The vendor claims a security posture. The organization remains exposed if it does not verify this through documented evidence. Clinical outcome liability does not transfer to the vendor by contract.
This article maps the gap, identifies who is accountable, and defines the decisions the board must make.
What Changes in the Assessment Model
Many healthcare organizations lack the staff and time to assess hundreds of third-party vendors.
Walsh recommends focusing attention on vendors that present the greatest risks. The criterion is access: which vendors touch protected health information and personally identifiable information.
The gap is operational. A compliance posture calibrated for uniform review of all vendors is over-calibrated for the new context, where risk classification drives resource allocation.
Prioritization changes how audit hours are spent. Resources shift from distributed controls toward high-exposure vendors, those with privileged access to clinical data.
The impact on the organization is measurable. With the same audit budget, coverage of critical vendors increases. Uniform review distributes the same hours across low-risk vendors and vendors with access to PHI. Risk classification corrects this imbalance. The limitation is well-known: prioritization does not eliminate residual risk on low-exposure vendors, it defers it.
The Governance Signal
The governance signal: contractual trust requires documented verification.
Organizations need AI governance frameworks, updated vendor assessments, and greater transparency on how vendors develop, validate, and oversee their AI capabilities. These three elements form the minimum perimeter.
Walsh calls for better documentation to prove what human oversight vendors have implemented in their AI products and services. The rationale is patient safety: an adverse clinical outcome resulting from inaccurate AI represents direct exposure for the organization.
The logic is verifiable. Without documentation, human oversight remains a claim. With documentation, it becomes an auditable fact. The difference matters when an incident requires reconstruction of the chain of control.
Documenting Human Oversight
AI-based clinical documentation tools, including ambient tools, can introduce errors into electronic health records.
The risk materializes when clinicians sign AI-generated notes before reviewing them. Walsh recommends strengthening human oversight, reviewing business associate agreements, and updating privacy notices.
The goal is patient awareness. Many patients are unaware that their conversation with a physician is being transcribed by an AI agent and entered into their record. This information asymmetry represents a privacy exposure area that current notices only partially address.
The signature is the critical point. A signed note becomes an official clinical record. If the clinician signs without reviewing, the AI's error enters the record with the weight of a human decision. Review before signing is the control that breaks this propagation.
Shadow AI and Data Integrity
Shadow AI expands the risk surface. Tools adopted outside approved channels escape classification and audit.
When a model processes protected health information outside the governed perimeter, data integrity becomes uncertain. The accountability chain breaks.
Walsh links this phenomenon to data integrity and patient safety. AI-generated documentation affects the quality of the clinical record, which in turn guides therapeutic decisions. An upstream error propagates throughout the entire care pathway.
Accountability Without a Name Is Compliance Theater
This desk's position remains consistent: accountability without a name is compliance theater.
Frameworks that describe oversight obligations yet omit naming a specific role produce documentation rather than real governance. The structure applies to vendors as much as to internal implementations.
The operational question is precise. Which named role within the organization is accountable for the accuracy of clinical AI, by name, in writing, before deployment?
Organizations that assign this responsibility explicitly reduce ambiguity during audits. Those that leave the outcome to a diffuse process retain the exposure.
Three Decisions for the Board
Three board decisions require a documented response before the next audit cycle.
- General Counsel / Chief Compliance Officer: which audit of business associate agreements covers vendor AI use?
- Chief Risk Officer: which risk framework classifies vendors by access to PHI and PII?
- Board Audit & Risk Committee: which disclosure describes AI use in clinical documentation?
The CEO faces a related strategic decision. Clinical AI adoption remains contingent on the organization's ability to demonstrate verifiable human oversight.
Audit remains required; the perimeter has changed. Priority shifts toward high-risk vendors, measured by data access.
Regulatory Horizon
Regulatory horizon: the interview constitutes industry guidance rather than binding law.
In the United States, HIPAA governs the handling of protected health information and regulates business associate agreements with third-party vendors. This framework remains applicable to AI use.
The limits of the evidence should be noted. Walsh's guidance does not impose a new obligation. It describes an oversight practice. The obligation remains anchored to HIPAA and existing business associate agreements. Jurisdiction is the United States.
Organizations that build structured governance now, with named accountability, audit trails, and risk classification, gain an advantage when enforcement intensifies. AI compliance becomes a competitive advantage rather than a cost.
This article was produced by an AI editorial author with human oversight, in accordance with the transparency obligations of Regulation (EU) 2024/1689 (AI Act, Art. 50). Sources are linked in the text.
Article by ATLAS
Sources
- ISMG published (bankinfosecurity.com)
- Morgan Lewis – Healthcare AI Deployment: Compliance Through Contracting, BAAs, and Data Go (morganlewis.com)
- Medcurity – AI Governance in Healthcare: A Practical Framework for HIPAA-Covered Organizat (medcurity.com)