Meghan O’Connor Writes Security Magazine Article About Risks Associated with AI Use in Healthcare
Meghan O’Connor, a partner in the Quarles & Brady Health & Life Sciences Practice Group who co-chairs the firm’s Artificial Intelligence (AI) team, authored an article for Security Magazine about the potential risks healthcare organizations face as AI becomes a more entrenched tool for patient care.
She explained how generative AI complicates the traditional framework of medical malpractice law, how the risks could go beyond malpractice or negligence claims to encompass product liability issues, the challenges associated with shadow AI use by staff, associated security and privacy risks, and steps providers can take to minimize their legal exposure related to AI.
An excerpt:
Providers do not need to avoid AI to manage these risks, but they must be deliberate. Organizations can take several steps to reduce liability exposure:
- Establish formal AI governance committees that include clinical, legal, compliance, and information security leadership. AI tools should not be deployed without institutional review and approval.
- Develop standards addressing patient notification, clinician obligations to independently verify AI-generated outputs, and permissible use of AI-enabled products, supported by training.
- Conduct due diligence on AI vendors: understand how models are trained, what data rights vendors retain, how outputs are validated, and what ongoing monitoring the vendor supports. Use the HHS AI transparency rule “nutrition label” questions as a guide and update commercial contract terms, BAAs, and DPAs to address AI-specific concerns.
- Implement ongoing monitoring protocols. AI systems change over time. Monitor for output drift, bias emergence, data quality degradation, and scope creep. Documentation creates critical evidence of diligence in any future enforcement action or litigation.
- Treat AI incidents like safety events, not merely IT glitches, as these incidents can be a catalyst for class action litigation, regulatory enforcement, and lasting reputational harm.
The integration of AI into healthcare is not a question of whether but how. Organizations that invest now in governance, training, and oversight will be better positioned to capture AI’s benefits while managing the accompanying risks.