For hospitals, health systems, and health care AI vendors, the question has shifted.
It used to be whether an AI tool worked. Now it is who answers for it when it doesn't. As oversight fragments across federal agencies, state legislatures, and medical boards, that question is becoming a matter of legal exposure rather than technical performance.
In a recent article, PYMNTS examined how AI now touches clinical decisions, patient communications, claims administration, and health data exchange. The piece explored why regulatory fragmentation raises the stakes for the organizations deploying it. Alaap B. Shah, a Member of the Firm at Epstein Becker Green, who advises hospitals and health systems on AI governance, vendor risk, and regulatory compliance, discussed why organizations cannot rely on vendors or regulators alone to establish accountability.
Shah explained that laws governing privacy, discrimination, and professional duties already apply to AI-enabled activity, even when the statutes never mention artificial intelligence. The FDA's device-oversight boundary remains unsettled, he said, and state medical boards add another layer of fragmentation. He also pointed to vendor contracts as the mechanism hospitals need to control. Developers often hold the system logs and performance data a hospital would need to explain what happened when a model fails. Shah said hospitals that treat AI oversight as optional are already exposed.
"Self-governance matters because defensibility matters. We have already seen that risk is manifesting with respect to the use of AI technology in the healthcare sector," Shah said.
Related reading:
PYMNTS, “DOJ Healthcare Fraud Crackdown Raises the Bar for Compliance Analytics.”
“There are existing bodies of law that, while not passed or promulgated for the reason of AI, are still applicable to AI solutions,” Alaap Shah, member of the firm at Epstein Becker Green, told Competition Policy International (CPI), a PYMNTS company, in an interview this month, adding that the question for healthcare firms is not simply whether an AI-specific law applies but whether the system creates risks covered by older legal obligations.
Get in Touch
To discuss how your organization's AI vendor contracts, logging practices, and governance documentation would hold up under regulatory or litigation scrutiny, contact Alaap B. Shah at abshah@ebglaw.com.