HSCC Releases AI Governance Framework for Healthcare, Warning of Clinical Risks Including Fatal Hallucinations
Key Insights
The Health Sector Coordinating Council (search) published an 87-page AI governance playbook addressing cybersecurity, privacy, and patient safety risks unique to healthcare AI deployments.
The guide warns that AI hallucinations could lead to wrong diagnoses or drug recommendations, potentially causing patient harm or death, and calls for enterprise-level risk controls.
Healthcare organizations are advised to exclude clinical applications and protected health information from AI indexing features and implement immutable audit logs for HIPAA compliance.
The Health Sector Coordinating Council (search) (HSCC) released a comprehensive AI governance framework on Monday, warning that artificial intelligence tools in healthcare settings pose unprecedented risks—including the potential for large language models to hallucinate incorrect diagnoses or drug recommendations that could lead to patient harm or even death.
The 87-page Health Industry AI Cyber Governance Framework Implementation Guide aims to help security leaders navigate the complex intersection of AI adoption and regulatory compliance in a sector where, as the guide states, "AI governance in healthcare differs fundamentally from that of other sectors due to the life-and-death nature of medical decisions and the complex regulatory environment governing patient care."
"With AI, data governance in healthcare organizations is becoming much more complicated due to all of these flows of data, both within the organization and to third parties," said regulatory attorney Jordan Cohen, a partner at Akerman LLP (search). "As those workflows, especially agentic workflows, get more complex, you're going to be introducing new risks."
Enterprise Risk Controls for Clinical AI
The playbook addresses cyber governance challenges spanning the full spectrum of AI technologies deployed in healthcare—from traditional machine learning and reactive models to newer generative AI and agentic AI systems capable of autonomous action. Each category, the guide notes, presents distinct cyber risk issues requiring governance oversight and controls.
Among the threats identified are potentially dangerous clinical AI hallucinations, prompt injections that could disrupt clinical workflow, model drift, output variability, data poisoning, protected health information leakage, and adversarial attacks. The framework positions AI as an enterprise technology risk that must be governed with the same diligence as electronic health record systems, medical devices, and cloud platforms—but with additional controls for AI-specific threats.
"Just as cybersecurity is a shared responsibility that healthcare providers and vendors including device manufacturers bear, so too is cybersecurity of AI tools," the playbook states.
Protecting Patient Data on AI-Enabled Devices
As AI PCs increasingly embed features such as Microsoft Recall, Copilot+ semantic indexing, on-device transcription, and personalized assistants, healthcare organizations face growing pressure to prevent inadvertent exposure of protected health information (PHI).
"The foundational control is data classification and scoping," said Nitesh Saxena, professor of computer science and engineering at Texas A&M University. "Organizations must define which directories, applications and workflows are permitted to be indexed or processed by local AI models."
Saxena emphasized that clinical applications, electronic health record sessions, and folders containing PHI should be explicitly excluded—through enterprise policy enforcement—from features such as screen snapshots, semantic search indexes, and ambient transcription. "This ensures that AI personalization does not silently ingest regulated data into local vector stores or caches that fall outside traditional HIPAA audit boundaries," he said.
The framework further recommends that AI PC features generate immutable audit logs capturing what was indexed, transcribed, or retrieved, integrated into the organization's security information and event management tools to support HIPAA's accounting of disclosures and breach investigation requirements. Retention policies must automatically purge AI caches, embedded data, and transcripts in alignment with minimum necessary principles, and devices must support remote wiping of AI data stores upon loss, theft, or employee offboarding.
Keeping AI Inference Local
Dr. Justin Collier, healthcare CTO for Lenovo (search), advocated for leveraging AI PCs, AI edge servers, and other on-premises devices to provide AI inference within the organizational network. "Keeping data within the system provides greater security and privacy protection," he explained, adding that this approach also yields faster insights because data is processed closer to where it is generated.
Collier also recommended that healthcare organizations "strongly consider including patients, such as patient and family advisory council members, in the AI governance committee or process" and to "create guardrails, not roadblocks, for deploying AI within the organization."
A Measured Path Forward
The playbook is part of an ongoing series of AI-specific documents from the HSCC, a 500-member coalition of private-sector critical healthcare infrastructure organizations operating in a national public-private partnership. It follows an AI supply-chain risk guide issued in April, with additional installments planned to address emerging AI considerations in healthcare.
For organizations navigating deployment, experts recommend a deliberate, sequenced approach. "The productivity gains are real. The compliance risks are manageable," said Eaton, emphasizing that "the key is sequencing." The recommended strategy begins with a use-case inventory focused on where local AI processing creates measurable workflow value, followed by a dedicated HIPAA risk analysis tied specifically to AI PC capabilities rather than relying on existing enterprise assessments.
Collier further advised that deployments align with evolving HIPAA security and privacy requirements—including proposed updates to the HIPAA Security Rule—as well as established frameworks such as the NIST Cybersecurity Framework 2.0 and zero-trust principles, encompassing multifactor authentication, encryption, asset inventory and tracking, endpoint protection, network segmentation, and continuous monitoring.
"Ultimately, security depends on how devices, applications and AI services are selected, configured, governed and monitored across the enterprise," Collier said.
