HSCC Issues Guide to Tackle Third Party AI Risk
The Health Sector Coordinating Council (HSCC) has issued new guidance for healthcare organizations to help them effectively manage risks associated with third-party artificial intelligence tools. The healthcare industry has embraced AI-powered tools and services, which are increasingly relied upon for critical functions. Third-party products and services increasingly incorporate AI components, such as clinical decision-making support tools, remote monitoring devices, and revenue cycle automation solutions. These tools provide healthcare organizations with great value, as they improve efficiency by eliminating many manual processes; however, they expose healthcare organizations to new and significant risks.
For instance, healthcare organizations often have limited visibility into the AI components in products and services, which are often sourced through supply chains, making it difficult to verify the security postures of each vendor. Further, the contract language used is often one-sided, shifting risk from vendors to healthcare organizations. Healthcare organizations must also deal with issues such as unreported AI cybersecurity risks, training data leakage, and synthetic data misuse, all of which threaten security and create serious compliance risks.
“The healthcare sector’s accelerating adoption of artificial intelligence has dramatically expanded its dependence on third-party tools and services, introducing complex cybersecurity challenges that traditional risk management models cannot adequately address,” explained HSCC in the guidance. HSCC formed a third-party risk task group consisting of industry leaders to explore the current challenges, identify best practices, and work on new guidance on AI risk and supply chain transparency.
The best practices cover the development of AI governance policies, AI use-case justification requirements, AI training and performance standards, inventory and asset management, quality assurance, model validation, and response and recovery planning. The guidance also includes model contracts addressing data ownership and creating shared responsibility with AI vendors for managing products throughout the entire lifecycle, from procurement to end-of-life.
The guidance has been developed to be used by healthcare organizations of all sizes with all degrees of AI utilization, and can be used in its entirety, or appropriate parts can be used, based on what works for each organization. HSCC encourages healthcare organizations to share the guidance with senior leadership and appropriate teams and evaluate their third-party and supply chain risk management programs against the best practices outlined in the guidance. HSCC has also developed an AI Cyber Glossary – A living reference establishing consistent, governance-ready definitions for artificial intelligence terminology across the health sector, to address the very real risks that come from the use of inconsistent terminology in procurement, contracts, policy development, and patient safety oversight.