spot_img
HomeMedical Billing and CodingWhat Healthcare Organizations Need to Consider as AI Moves Into Practice

What Healthcare Organizations Need to Consider as AI Moves Into Practice

Healthcare organizations are finding many different ways to use artificial intelligence (AI). Some are building AI into their own technology, while others are purchasing products with AI capabilities already embedded. In other cases, AI may be used by a vendor or business partner somewhere downstream.

That range of use cases is important because the risks will look different for every organization. A health information exchange (HIE), a healthcare analytics company, and an organization supporting medical billing or clinical coding may all use AI differently, with different data, workflows, and responsibilities involved.

As organizations begin looking more closely at how AI fits into their operations, several actionable best practices are becoming clearer.

Start by Understanding Where AI Is Already Being Used

Organizations may discover that AI use began before anyone established a formal AI strategy. Employees can access public generative AI platforms, use meeting assistants and writing tools, or work with AI features built into software they already use every day.

Before an organization can put effective controls in place, it needs a clear picture of that activity. Leaders should understand which tools are being used, what employees are using them for, and what types of information are being entered into them.

That exercise is particularly important in healthcare settings where workflows may involve patient, customer, or other sensitive information. It also gives organizations a more realistic starting point for developing policies and training employees on acceptable use.

Bring the Right People Into the Conversation Early

AI decisions can quickly touch privacy, compliance, security, legal, human resources, and operations. The people responsible for those areas need an opportunity to evaluate how AI affects their work and where new responsibilities may arise.

For organizations involved in medical billing and coding, for example, AI could support data analysis, documentation review, workflow automation or other activities that influence information moving through the organization. That makes questions about accuracy, oversight, access, and accountability relevant to more than the technical team selecting or managing the tool.

Early involvement from across the organization also helps uncover issues that may be difficult to address after an AI-enabled process is already part of daily operations.

Use Governance to Examine the Specific Use Case

Organizations do not need to wait until they have a mature AI program before evaluating risk. In many cases, working through a governance framework can help identify questions that need to be answered before implementation moves further.

That review should reflect the organization’s actual business model and use of AI. An organization developing its own AI technology will have different considerations from one purchasing an off-the-shelf product. Another organization may not operate an AI system directly but could depend on vendors that do.

The same principle applies to the data involved. Organizations should understand what information enters an AI-enabled process, what the system produces, who reviews the results, and what happens when the output is inaccurate or unexpected.

Plan for Ongoing Review and Human Intervention

AI outputs need continued evaluation after a system is deployed. Organizations should decide how they will validate results, monitor performance, and identify problems that could affect downstream processes.

Quality assurance may involve comparing outputs with other sources, reviewing exceptions or setting defined points where a person must evaluate a result before it moves forward.

Organizations should also know how they will respond when something goes wrong. If an AI-supported workflow produces an unreliable result, there needs to be a clear way for someone to intervene, stop the process or return to another method of completing the work.

Revisit How Data Is Classified

One takeaway from our use cases that deserves more attention is what happens when AI creates information that did not previously exist as a separate data set.

An AI system may take existing information and generate a new analysis, summary or output. That new information still needs to be classified and protected appropriately. Organizations should determine whether it is considered public, internal, confidential, sensitive or subject to another category within their existing data classification structure.

Healthcare organizations also need to consider situations where AI-generated information becomes combined with patient or customer data. Policies and workforce training may need to be updated so employees understand how those new forms of information should be handled.

Review Retention and Destruction Requirements

AI-generated information also raises practical questions about how long data should be retained and how it should eventually be destroyed.

Existing policies may already establish retention requirements for medical information, customer records or other regulated data. AI-created information may introduce a separate set of requirements, particularly when it is combined with protected health information.

Organizations need to understand whether those records can remain together, whether they may need to be separated and which retention or destruction rules apply to each type of information.

These questions will continue to develop as AI becomes more common across healthcare. Organizations do not need identical approaches, because their technologies, data and business models are not identical. What they do need is a clear understanding of how AI is being used and a governance process that helps them identify the risks that come with that use.

For medical billing, coding, and other healthcare data organizations, those conversations are becoming part of responsible implementation and day-to-day operations.