Healthcare AI Governance

Practical AI Governance Insights for Hospital Leaders & Clinicians

Evidence-informed frameworks, governance handbooks, and onsite workshops that help hospitals deploy AI safely—and help patients trust it.

Healthcare AI Governance - The Growing Sense of Urgency

Frustrated patients are growing increasingly concerned about a healthcare system that they understand that lacks true healthcare governance in a way that they understand.

Healthcare AI Governance - The Growing Sense of Urgency
The Urgency of Healthcare Governance

"I just want my information out of a system I don't trust."

That came from a friend after I wrote about killing the clipboard, after I spent months writing a book on healthcare AI governance. His verdict on it all: "Dan, the whole thing is messed up. We're doomed."

They're right. Unless something changes.

Last week, CareCloud confirmed that attackers took the records of 3,756,469 patients, including names, addresses, dates of birth, Social Security numbers, driver's license numbers, financial account numbers, and medical and insurance information. The intrusion lasted about eight hours in March. It took five months to learn how big it was. It is one of the three largest healthcare breaches reported so far in 2026.

So far. It's August.

Two things have to change.

Governance has to become the priority, and it has to be written in language people can actually read. The National Assessment of Adult Literacy found that only 12% of American adults have proficient health literacy. The AMA and NIH recommend patient materials at a sixth-grade reading level. Our consent forms and data policies routinely land at college level. A right you cannot read is not a right. It's paperwork.

And patients and clinicians have to be in the room. I sit with the CMS Health Tech Ecosystem group. What has shocked me most is how few patients and how few clinicians have shown up.

Governance begins when we all sit down together and talk.

The seat is open. Take it.

The CareCloud Breach Was Not an Outlier, It Was the Pattern

I called CareCloud one of the three largest healthcare breaches reported so far in 2026. Let me update that, because the story kept growing after I wrote it. TechCrunch's original March reporting described an eight-hour intrusion into one of CareCloud's six electronic health record environments TechCrunch, CareCloud breach detected. By August, the confirmed number had grown to 3,756,469 individuals, making it the fifth-largest healthcare data theft of the year, not third TechCrunch, CareCloud confirms 3.7M patients. Five months passed between the intrusion and the public knowing its true scale.

It gets worse in context. Becker's Hospital Review tracked the 20 largest healthcare breaches reported to HHS in 2026 so far, led by TriZetto Provider Solutions at 3.43 million people and QualDerm Partners at 3.1 million, both business-associate breaches that most patients never see coming because they don't even know these vendors touch their data Becker's Hospital Review, 20 largest breaches of 2026. The Identity Theft Resource Center's H1 2026 report counted 281 healthcare data breaches affecting more than 11.7 million patients in just the first six months, and current OCR data show that number has already more than doubled to over 28.8 million victims HIPAA Journal, ITRC H1 2026 Data Breach Report.

This is not a technology problem hospitals can outsource to their IT department and consider handled. It is a governance problem, because most of these breaches happen at business associates and vendors, exactly the kind of third-party AI and data-processing tools your governance committee is supposed to be vetting before they ever touch patient data.

A Right You Cannot Read Is Not a Right

I wrote that consent forms and data policies routinely land at college reading level while only 12% of American adults have proficient health literacy, per the National Assessment of Adult Literacy AHRQ, America's Health Literacy issue brief. The peer-reviewed evidence backs this up in specific, damning detail. A 2021 study of over 2,500 patient education materials from high-impact medical journals found only 2.1% met the AMA's recommended sixth-grade reading level, and just 8.2% met the more lenient NIH eighth-grade recommendation Readability of Patient Education Materials, PMC. A study of 37 hospital consent forms for cardiology procedures found only one met the general usability threshold for being "understandable," with the average form requiring a 10th to 12th grade education to comprehend Cardiology consent form readability, PubMed. A 2025 systematic review of informed consent forms across multiple institutions found 76.3% had poor readability Readability of Informed Consent Forms, PMC.

The AI angle makes this worse before it makes it better. Every new AI tool your hospital deploys, patient-facing chatbots, algorithmic risk scores, consent language for data sharing with third-party model vendors, adds another document written by a lawyer or a vendor's compliance team, not by anyone thinking about a sixth-grade reader. Interestingly, one 2025 study found that GPT-4-revised patient education materials more than doubled the share meeting the AMA's sixth-grade standard, from 9.1% to 23.1% GPT-4 revised patient education materials readability, PMC. AI created part of this literacy gap. It can also help close it, but only if governance committees make readability review, not just legal review, a required step before any patient-facing AI document goes live.

  • Run every patient-facing AI consent form and disclosure through a validated readability tool (Flesch-Kincaid, SMOG) before publication, target sixth-grade level per AMA guidance
  • Require your legal and compliance teams to co-sign off with a health literacy or patient experience reviewer, not sign off alone
  • Track the percentage of your AI-related consent documents that meet AMA/NIH readability targets as an actual governance metric, not an assumption

The Empty Chairs Are Measurable Too

I wrote that what shocked me most, sitting with the CMS Health Tech Ecosystem group, was how few patients and clinicians showed up. That is not just my anecdote. HealthIT.gov's own 2026 Health IT Advisory Committee annual report work group lists "increase patient participation in health IT and AI policy development" as an explicit, named priority, which tells you the federal government's own advisors have identified the gap too HITAC Annual Report Workgroup Update, 2026. When federal advisory bodies are writing memos to themselves about needing more patients in the room, that confirms the seat is open for a reason, not because patients don't care, but because no one is actively recruiting them or making participation feasible around work schedules, transportation, or health literacy itself.

The stakes of leaving that chair empty go beyond feelings of exclusion. Research on algorithmic bias in health equity settings has found that only 15% of healthcare AI tools include community engagement in development, and that algorithmic bias can produce roughly 17% lower diagnostic accuracy for minority patients Symbiotic AI and equitable digital health, Frontiers. The CDC has been direct about the mechanism: AI models are typically trained on available data, which may not adequately represent racial and ethnic minority groups or other populations that are medically underserved, and the fix requires diverse expert teams and inclusive data collection, not just better math CDC, Health Equity and Ethical Considerations in AI.

If your hospital's AI governance committee has zero patients and zero frontline nurses on it, you don't have a governance committee. You have a vendor management committee wearing a governance committee's name tag.

Continue the Conversation

If this resonated, here is where to go next: Join the AI-in-Healthcare Workshop · Get the Books · Contact Dan