For hospitals, health systems, and health care AI vendors, the question has shifted.
It used to be whether an AI tool worked. Now it is who answers for it when it doesn't. As oversight fragments across federal agencies, state legislatures, and medical boards, that question is becoming a matter of legal exposure rather than technical performance.
In a recent article, PYMNTS examined how AI now touches clinical decisions, patient communications, claims administration, and health data exchange. The piece explored why regulatory fragmentation raises the stakes for the organizations deploying it. Alaap B. Shah, a Member of the Firm at Epstein Becker Green, who advises hospitals and health systems on AI governance, vendor risk, and regulatory compliance, discussed why organizations cannot rely on vendors or regulators alone to establish accountability.
Shah explained that laws governing privacy, discrimination, and professional duties already apply to AI-enabled activity, even when the statutes never mention artificial intelligence. The FDA's device-oversight boundary remains unsettled, he said, and state medical boards add another layer of fragmentation. He also pointed to vendor contracts as the mechanism hospitals need to control. Developers often hold the system logs and performance data a hospital would need to explain what happened when a model fails. Shah said hospitals that treat AI oversight as optional are already exposed.
"Self-governance matters because defensibility matters. We have already seen that risk is manifesting with respect to the use of AI technology in the healthcare sector," Shah said.
Get in Touch
To discuss how your organization's AI vendor contracts, logging practices, and governance documentation would hold up under regulatory or litigation scrutiny, contact Alaap B. Shah at abshah@ebglaw.com.