

This week in healthcare AI: a new industry index finds adoption has raced well ahead of the policies meant to control it. Stanford, CHOP, and ChristianaCare describe walking away from AI vendors over data and liability terms. A patient-safety authority's error-reporting push gets turned into a concrete to-do list for health IT leaders. A vendor analysis attaches a dollar figure to ungoverned AI. And CMS and the FDA offer the clearest signal yet of what federal oversight will ask of every AI tool in production.
For CIOs and CISOs, the week reads less like a debate about whether AI belongs in healthcare and more like a shift in who carries the risk once it's there. Here are the five stories worth your team's attention.
An analysis published this week argues that shadow and ungoverned AI carries hidden security, compliance, and care-quality costs that outrun any efficiency it delivers.
The headline figures come from IBM's latest breach research; healthcare data breaches now average $7.42 million, and among organizations that experienced an AI-related security incident, 97% lacked proper AI access controls and 63% had no formal governance policies in place.
A separate survey cited in the piece found that 57% of respondents had used or encountered an unauthorized AI tool inside their organization.
Why it matters: This is the number a security leader can take to a CFO. The 97% figure reframes AI incidents as a governance failure above anything else; the exposure sits with organizations that never put access controls or policies around the tools in the first place.
Source: IBM Cost of a Data Breach 2026, via Wolters Kluwer
The 2026 Healthcare AI Readiness Index, published by MedCity News and Cotiviti, surveyed 70 payer and provider leaders over the summer. More than 70% have started using AI tools — yet fewer than 40% have detailed policies governing how employees use them. Among health plans, 60% reported staff using unauthorized AI tools, and only 42% of payers and 32% of providers said they feel very prepared to handle an AI-assisted cyberattack. Ninety percent expect their AI and cybersecurity spending to climb over the next year.
The picture varies by sector — nearly 40% of insurers now describe AI as core to the business, while most providers remain early in adoption — but the governance shortfall shows up on both sides of the house.
Why it matters: A figure like "60% have staff using unauthorized tools" isn't a worst-case scenario; it's shadow AI stated as a baseline. Policy written faster than tools are catalogued will always trail the actual risk, because you can't govern what you haven't found running across the environment — or hold it to rules it was never mapped to. For security teams, the preparedness gap is the harder read: most respondents are increasing spend without first knowing what they're defending.
Source: MedCity News & Cotiviti
Some of the country's most prominent health systems have made vendor data terms a condition of doing business, Becker's reported. Stanford Health Care's approach is to "contain the model, not just the data request," bringing a vendor's model into its own environment rather than sending patient data out.
Children's Hospital of Philadelphia routes AI tools through role-based access so they can only reach what the user already can; ChristianaCare limits vendors to an approved use case and deidentifies wherever possible.
Stanford's CTO said walking away over unacceptable terms has become routine rather than a last resort, with common sticking points including vendors wanting to train products for other customers on its data, vague usage clauses, and liability caps that leave the system exposed.
The forward-looking worry is agentic AI. Stanford's CTO named agents outpacing the ability to monitor them as his biggest fear, arguing that building oversight in from the start beats retrofitting it once agents are already embedded at scale. CHOP's data leader put the broader point plainly: the industry needs to stop treating HIPAA compliance as the finish line for AI risk.
Why it matters: Governance is quietly becoming a procurement gate — and the questions these systems are asking ("what can the vendor reach, what can it do with what it reaches, and can we prove it?") are ones responsibility for doesn't transfer with the contract. Answering them at the scale of hundreds of models and agents takes continuous visibility into what each tool touches, enforceable limits on what it's allowed to do, and monitoring that flags the behavior no one planned for.
Source: Becker's Hospital Review
When ECRI opened its Problem Reporting Network to clinical AI errors, we covered the launch and the data gap behind it. This week, new analysis turned that development into practical guidance for the people who have to act on it.
The network now captures errors, malfunctions, and near misses across ambient scribes, EHR-embedded decision support, and clinical chatbots — and the paired survey of 124 leaders remains striking: 31% had seen incorrect AI output, 9% said an error reached a patient, and 35% couldn't say whether one had occurred at all.
The operational recommendations are the useful part:
The report also names an error mode specific to virtual care — a scribe misattributing speech between a patient and a family member on the same call — that won't surface if reports only ever go back to the individual vendor.
Why it matters: A fabricated medication in a draft note that a clinician catches before signing never becomes a safety event — and, without monitoring, never leaves a trace anyone can learn from. Near-miss visibility is precisely where continuous monitoring earns its place, and "how do you receive and act on error reports" is fast becoming a procurement question.
Source: Telehealth.org (reporting on ECRI)
At a Consumer Technology Association event in Washington, federal officials laid out where healthcare AI regulation is heading, Fierce Healthcare reported. CMS — now with a newly created chief clinical AI officer — described building clearer pathways for AI market access and reimbursement.
The FDA's August discussion paper proposes evaluating generative-AI medical devices by two factors: how independently the tool acts and how much harm an incorrect output could cause, paired with a "competency-based" model of upfront benchmarking plus real-world clinical validation and post-deployment monitoring. Public comment is open through October 19. One FDA official conceded the agency's current device-review framework is a "square peg" for generative AI.
The panel that followed made clear the field hasn't settled the hard questions. Officials and clinicians debated where fully autonomous AI is acceptable versus where a human must stay in the loop, with the AMA's CEO arguing AI should meet the same evidence bar as any other clinical intervention.
Why it matters: Strip away the policy language and federal direction is converging on a single operating model: benchmark it, validate it in your own setting, and keep watching it after go-live. That's the discipline of continuous validation and monitoring, and the October 19 comment window is a real opportunity for health system leaders to shape it while the framework is still being written.
Source: Fierce Healthcare
Adoption has moved faster than the rules, and the Readiness Index makes that measurable. Health systems have started to respond where they have the most leverage, at the point of purchase, by refusing terms they can't govern and demanding proof rather than assurances. Safety authorities are building the rails to count what goes wrong, and federal regulators are formalizing the expectation that AI be validated and watched, not just approved once and forgotten.
What connects the buyer's new leverage, the safety reporting, and the regulatory direction is a single capability most organizations still lack: the ability to see and account for their own AI in production. Vendor terms you can't verify are just promises. Errors you can't detect can't be reported. And a benchmark that isn't rechecked after go-live tells you how a tool behaved on its best day, not today.
That capability is what Vitea was built to make routine: the visibility to find every AI tool in your environment, sanctioned or not; the enforcement to keep each one inside the rules that apply to its use and jurisdiction; and the continuous validation to prove it's still safe long after launch day. If you're weighing how much of your AI you could actually account for right now, we'd welcome the conversation.
Follow Vitea on LinkedIn for more of the latest news and views on AI governance in healthcare, including our weekly roundup of the stories healthcare leaders need to know.