Primary topic: AI in Healthcare: Industry Transformation, Security, Privacy, and Governance
Research focus: AI in diagnosis, scribing, and clinical workflow; hospital ransomware and third-party breaches; the stalled HIPAA Security Rule update; FDA device oversight; and practical governance for hospitals, digital health startups, and clinicians
What “AI in Healthcare” Covers
AI now touches nearly every clinical and administrative task. Risk rises with how directly a system can affect a diagnosis or a patient record.
| Area | What AI does | Example |
|---|---|---|
| Clinical documentation | Listens to visits and drafts notes | AI scribes and ambient dictation tools |
| Diagnosis and imaging | Reads scans and flags abnormal findings | FDA-authorized radiology and cardiology tools |
| Patient communication | Answers messages and schedules visits | Portal chatbots and triage assistants |
| Billing and claims | Codes visits and checks insurance rules | Automated coding and prior-authorization tools |
| Operations and security | Predicts demand and watches for intrusions | Staffing models and network monitoring |
Visual: AI Across One Patient Visit
AI schedules the appointment
AI scribe listens and drafts the note
AI flags scans or lab results
AI codes the visit for insurance
AI chatbot answers portal messages
Five steps. Five places where a wrong AI output enters a real medical record.
Why Governance Became Urgent in 2026
Four pressures hit healthcare at once. Each is documented. Together they explain why hospital boards now put AI on the same agenda as patient safety.
AI notes have invented content that no one ever said
Healthcare is now the most targeted sector for ransomware
The main federal cybersecurity update has sat unfinished for over a year
AI devices keep multiplying faster than oversight can track them
Visual: Key dates in the 2026 healthcare AI story
HHS proposes a major HIPAA Security Rule update with mandatory MFA and encryption
NYC Health + Hospitals detects a months-long breach via a third-party vendor
118 healthcare breaches hit 9.6 million patients in just two months
DentaQuest discloses a breach of about 15 million people, the largest of the year
FDA’s authorized AI-enabled device count passes 1,600
HHS has not yet finalized the HIPAA Security Rule update as of this writing
Pressure 1: AI scribes have been caught inventing medical content
AI scribes solve a real problem. Doctors spend over half their day typing into records. They spend only a quarter of it with patients. AI tools that listen and draft notes promise real time back.
But the tools can hallucinate. A Cornell-led study of a Whisper-based transcription system found errors in roughly 40 percent of clear audio snippets tested. Close to 40 percent of those errors were judged harmful. A misheard word can misrepresent what a patient actually said.
One widely used scribe, built by Nabla, has transcribed an estimated 7 million patient visits across 30,000 clinicians and 40 health systems. Its maker confirmed it erases the original audio after transcription, for data-safety reasons. That means no one, not the doctor, not the patient, can go back and check what was really said.
Once a hallucinated line enters a permanent medical record, it can spread. Later clinicians read it. Later decisions can rest on it. There is often no built-in way to catch it, since the source recording is already gone.
Usually looks wrong. Gets caught on a quick read. Rarely invents a new symptom or medication.
Sounds clinically fluent. Reads as normal documentation. Can invent a treatment, a symptom, or a comment no one said.
Sources: OpenAI’s Transcription Tool Hallucinates More Than Any Other, Fortune, 2024, Auditing Medical AI Scribes, Koenecke et al., Cornell, 2025, and The Hallucination Problem: When AI Scribes Make Things Up, Twofold, July 2026
Pressure 2: Healthcare is the most targeted industry for ransomware
The numbers are stark. Healthcare accounted for 22 percent of all ransomware attacks worldwide in early 2026. In just January and February, 118 healthcare breaches exposed 9.6 million patient records. A healthcare breach now costs 7.42 million dollars on average. That is the highest of any industry, for the 15th year running.
Real cases show the human cost. In February 2026, NYC Health and Hospitals detected an intrusion that had been running since late November 2025. Attackers stole medical records, government IDs, and even fingerprint and palm-print biometrics from at least 1.8 million people. The entry point was a third-party vendor, not the hospital’s own systems.
In August 2026, dental payer DentaQuest disclosed a breach affecting about 15 million people, the largest healthcare breach reported that year. Research published in February 2026 found that in-hospital mortality rose 34 to 38 percent among Medicare patients already admitted when a ransomware attack hit their hospital.
Sources: Biometrics, Diagnoses, and Bank Details Exposed in Major Healthcare Breach, Malwarebytes, May 2026, 15M Patients Impacted by Largest Healthcare Data Breach of 2026, HealthExec, August 2026, Healthcare Ransomware in 2026: Why 118 Breaches in Two Months Is a Warning, Valtik Studios, April 2026, and Ransomware Attacks on Hospitals: 38 Statistics for 2026, FaxSipIt, August 2026
Pressure 3: The federal cybersecurity rulebook is stuck
In January 2025, HHS proposed the biggest HIPAA Security Rule update since 2003. It would make encryption mandatory, not optional. It would require multi-factor authentication for every system holding patient data. It would mandate network segmentation and regular penetration testing.
The agency targeted May 2026 for a final rule. That date has passed. As of this writing, no final rule has been published. Industry pushback during the comment period was heavy. The current administration has generally favored less new regulation, not more. The rule could still finalize in a modified form, or it could stall further.
Compliance lawyers give the same advice regardless of the outcome. The proposed rule shows exactly where regulators believe the bar sits. Waiting for a final version before acting is a bad bet, especially while breaches keep climbing.
Sources: HIPAA Security Rule 2026: OCR Enforcement, MFA, and Encryption Action Plan, ComplianceHub, 2026 and HIPAA Security Rule Final Rule: May 2026 and the MFA and Encryption Uncertainty, ComplianceHub, 2026
Pressure 4: AI medical devices are multiplying faster than generative AI oversight
The FDA has authorized over 1,600 AI-enabled medical devices as of September 2026. Radiology accounts for most of them. Growth keeps accelerating. The agency cleared 86 AI-enabled devices in the second quarter of 2026 alone.
One detail matters more than the count. As of early 2026, no FDA-authorized device used generative AI or a large language model. The devices going through formal review are mostly narrower machine learning tools.
Meanwhile, generative AI scribes, chatbots, and documentation assistants are spreading through hospitals largely outside that same clearance pathway, since many are marketed as workflow software rather than regulated medical devices.
Sources: Artificial Intelligence-Enabled Medical Devices, FDA, September 2026 and The Current State of FDA-Approved AI-Enabled Medical Devices, Medical Futurist, March 2026
Research Study: Auditing Medical AI Scribes
Cornell researcher Allison Koenecke and colleagues examined hallucinations in Whisper-based medical transcription at scale. Their earlier work found 187 hallucinations across roughly 13,000 clear audio snippets. Nearly 40 percent of those were judged harmful or concerning, since a patient’s words could be misread or misrepresented. Their later paper focuses on a specific risk.
Fabricated content, once written into a chart, can shape every later care decision. There is no way to trace it back to the original audio if that audio has already been erased.
What healthcare organizations can learn:
- Never let an AI scribe tool erase or auto-delete the original audio
- Require a clinician to review and sign off on every AI-drafted note before it becomes final
- Flag notes with unusually specific details that the clinician does not remember discussing
- Ask every scribe vendor for their measured hallucination rate, not just a marketing claim of accuracy
Source: Auditing Medical AI Scribes, Koenecke et al., Cornell, 2025
Research Study: Ransomware and Patient Mortality
Research published in the American Economic Journal in February 2026 studied Medicare claims data around ransomware attacks. It found a real, measurable increase in mortality. Patients already admitted when an attack hit saw in-hospital mortality rise 34 to 38 percent. Separate earlier research estimated 42 to 67 Medicare patient deaths tied to ransomware attacks between 2016 and 2021.
What healthcare organizations can learn:
- Treat a ransomware readiness plan as a patient-safety document, not only an IT document
- Test downtime procedures for EHR access, pharmacy scanning, and imaging queues specifically
- Build ambulance diversion protocols before an attack forces you to improvise one
- Report near-misses internally, since they reveal gaps before a real attack does
Research Study: Hallucination in Speech Foundation Models
A 2025 paper on speech-model hallucination looks past the headlines to the mechanism. It argues hallucination stems from a distribution shift. Models trained mostly on clear, common speech struggle with accents, pauses, background noise, or unusual medical terms. Instead of transcribing uncertainty honestly, the model fills the gap with a fluent, plausible-sounding guess.
What healthcare organizations can learn:
- Expect higher hallucination rates for patients with accents, speech differences, or complex medical vocabulary
- Do not assume a tool tested on clear studio audio will perform the same in a noisy exam room
- Push vendors to report accuracy broken out by accent and audio quality, not just an overall average
- Treat silence and uncertainty in a transcript as a signal to review, not a gap to fill in later
Research Study: The Growth and Limits of FDA-Authorized AI Devices
Independent trackers following the FDA’s AI-enabled device list describe explosive growth alongside a narrow scope. The list grew from roughly 1,451 devices at the end of 2025 to over 1,600 by September 2026. Radiology holds the largest share, with cardiology, neurology, and hematology next. Almost none of these devices use generative AI, since the clearance pathways were built for narrower, more predictable machine learning models.
What healthcare organizations can learn:
- Do not assume every AI tool in your hospital has passed FDA review, since many have not
- Ask vendors directly whether their tool is FDA-cleared, and for which specific use
- Apply your own internal review to generative AI tools that fall outside formal device clearance
- Track a tool’s real-world performance after adoption, not just its clearance summary
Source: FDA-Approved AI Medical Devices List: Complete 2026 Guide, IntuitionLabs, July 2026
What the Experts Are Saying
Alondra Nelson, former acting director of the White House Office of Science and Technology Policy, on AI transcription errors in hospitals
Notice what these voices share. None argue hospitals should abandon AI scribes or diagnostic tools. They argue for a basic safeguard that is often missing today. Keep the original recording. Let a human check the output. Do not treat fluent-sounding text as automatically true.
Sources: Fortune, 2024 and AI Transcription Tool Whisper Hallucinates, Raises Concerns, Tucson.com
Privacy: Health Data Is the Most Sensitive Data There Is
A leaked bank statement is bad. A leaked mental health diagnosis, an HIV status, or a fingerprint cannot be changed once exposed. AI adds new ways for that data to move and new places it can leak from.
Third-party tools store or process visit audio and notes
Staff paste patient details into public AI tools
Medical devices with known, unpatched flaws sit on hospital networks
Billing, scheduling, and lab partners hold copies of records
Practical privacy rules for every healthcare organization:
- Never let staff paste patient names or details into public, unapproved AI tools
- Require every AI vendor to sign a business associate agreement before touching any patient data
- Keep original audio and source data available for a defined retention period, so AI output can be checked
- Apply multi-factor authentication and encryption now, ahead of any final HIPAA rule
- Segment AI and research systems away from live clinical networks where possible
- Tell patients clearly when an AI tool, not a person, is drafting their note or answering their message
Governance Stack: Who Owns What
Set AI risk appetite. Own the AI inventory. Fund cybersecurity ahead of the final HIPAA rule.
Own review standards for AI-drafted notes and diagnostic suggestions.
Own device patching, network segmentation, and vendor access controls.
Own vendor agreements, breach response, and FDA clearance tracking.
Actionables: What Each Team Should Do, Why, and What It Changes
Use these tables as working checklists. Each row names the action, why it matters, and the result you should expect.
For Boards and Hospital Executives
| Action | Why it matters | Expected impact |
|---|---|---|
| Adopt MFA and encryption now, ahead of any final HIPAA rule | Waiting for the rule wastes the year it has already been delayed | Lower breach risk and less scramble when the rule lands |
| Require a full inventory of every AI tool touching patient data | Most AI tools in hospitals sit outside FDA device review | You govern what actually runs, not just what is cleared |
| Treat ransomware readiness as a patient-safety plan, not only an IT plan | In-hospital mortality rises during an active attack | Faster, safer downtime response when an attack hits |
| Vet every AI vendor’s data-retention and audit practices before signing | A vendor that erases source data removes your ability to verify it | Contracts that protect the hospital, not just the vendor |
For Clinicians and Clinical Leaders
| Action | Why it matters | Expected impact |
|---|---|---|
| Read every AI-drafted note before signing it | Hallucinations read as fluent, normal documentation | Fewer invented details entering the permanent record |
| Flag any note detail you do not remember discussing | Hallucinated content is designed to sound plausible | Errors caught before they shape future care |
| Ask your scribe vendor if it keeps the original audio | Some tools erase it, removing any way to verify the note | A real audit trail when something looks wrong |
| Treat an AI diagnostic flag as a second opinion, not a final answer | No FDA-cleared generative AI device exists yet for diagnosis | Clinical judgment stays the deciding factor |
For Developers and Health IT Teams
| Action | Why it matters | Expected impact |
|---|---|---|
| Patch and segment connected medical devices | 99 percent of hospitals run devices with known, exploited flaws | A breached device reaches far less of your network |
| Preserve source audio and data behind every AI scribe output | Deleted audio makes hallucinated notes impossible to verify | Any flagged note can be checked against the original |
| Restrict AI vendor access with least privilege | Recent major breaches started at a third-party vendor | A compromised vendor reaches far less patient data |
| Test downtime procedures for EHR, imaging, and pharmacy systems | These systems go dark first in a real ransomware event | Care continues on paper while systems recover |
For Digital Health Startups and Founders
| Action | Why it matters | Expected impact |
|---|---|---|
| Publish your tool’s measured hallucination or error rate | Hospitals are starting to ask this before buying | Stronger trust and faster procurement conversations |
| Keep source audio and data available for clinician review | Erasing it removes the only way to catch a hallucination | A real differentiator over tools that delete the evidence |
| Be clear about your FDA status, or lack of one | Most generative AI tools are not FDA-cleared devices yet | Fewer compliance surprises for your hospital clients |
| Sign business associate agreements and build for HIPAA from day one | Hospitals cannot legally buy from a vendor that won’t sign one | Faster sales cycles with regulated healthcare buyers |
For Compliance and Privacy Officers
| Action | Why it matters | Expected impact |
|---|---|---|
| Implement the proposed HIPAA rule’s controls voluntarily | It shows exactly where OCR’s enforcement attention is heading | Compliance readiness whenever the rule finalizes |
| Audit every AI vendor’s business associate agreement annually | Vendor breaches now drive most major healthcare incidents | Gaps found by you, not by a regulator after a breach |
| Maintain a breach-notification playbook specific to AI tools | An AI vendor breach still triggers your notification duties | Faster, compliant notification when an incident occurs |
| Track which AI tools are FDA-cleared and which are not | Oversight expectations differ sharply between the two | A clear, defensible answer during any regulatory review |
For Patients and Caregivers
| Action | Why it matters | Expected impact |
|---|---|---|
| Read your visit notes in the patient portal | You are often the first person to spot an AI hallucination | A wrong detail gets corrected before it affects your care |
| Ask if an AI tool is drafting your notes or messages | You have a right to know who, or what, is documenting your care | More informed trust in your care team |
| Watch for breach notifications, even from vendors you never met | Most healthcare breaches now start at a third-party vendor | Faster response if your data is exposed through a partner |
Risk Tiers: Matching Oversight to Impact
| Tier | Example | Required control |
|---|---|---|
| Assist | Chatbot answers a scheduling question | Clear AI labeling and an easy path to a human |
| Recommend | AI drafts a visit note from audio | Clinician review and sign-off, with source audio kept |
| Execute bounded tasks | AI flags a scan for radiologist review | FDA-cleared tool with documented accuracy data |
| High-impact decision | A diagnosis, treatment plan, or care denial | Mandatory clinician decision, AI as input only |
Implementation Roadmap
List every AI tool touching patient data, cleared or not
Add MFA, encryption, and device patching ahead of any final rule
Keep source audio and require clinician sign-off on AI notes
Test downtime and breach-response plans before you need them
KPIs to Track
| KPI | What it tells you |
|---|---|
| AI note correction rate | How often clinicians fix an AI-drafted note before signing |
| Device patch coverage | Share of connected medical devices with known flaws fixed |
| Vendor agreement coverage | Share of AI vendors with a signed business associate agreement |
| Downtime recovery time | How fast core systems return after a simulated outage |
| FDA clearance tracking | Share of clinical AI tools with a confirmed, documented clearance status |
Future Predictions: 2027 to 2030
2027: The HIPAA Security Rule Finally Lands, in Some Form
Given how long the proposal has sat, expect a final rule, likely softened from the original draft, rather than an indefinite stall.
2028: Audio Retention Becomes a Standard Contract Term
As hallucination lawsuits and complaints grow, expect hospitals to require scribe vendors to retain source audio for a fixed period as a condition of purchase.
2029: FDA Extends Its Framework to Generative AI Tools
As generative scribes and chatbots keep spreading outside formal device review, expect a dedicated FDA pathway built specifically for these tools.
2030: Real-Time Hallucination Detection Becomes Built-In
Expect AI scribes to ship with automatic confidence scoring, flagging low-confidence passages for review at the moment of drafting, rather than after the fact.
Startup and Product Opportunities
- Audio-preserving AI scribe: Keeps source recordings available for a defined retention window
- Clinical note hallucination detector: Flags AI-drafted content a clinician may not have actually said
- Medical device patch management platform: Tracks and prioritizes fixes across connected hospital devices
- AI vendor compliance mapper: Tracks business associate agreements and FDA clearance status in one place
- Ransomware downtime simulator: Rehearses paper-based care continuity before a real attack hits
- Patient-facing AI transparency tool: Clearly labels which parts of a visit note or message came from AI
Frequently Asked Questions
Can AI scribes really invent things a patient never said?
Yes. Studies of Whisper-based medical transcription found hallucinations in roughly 40 percent of clear audio snippets tested, with close to 40 percent of those judged harmful or concerning.
Why does it matter that some AI scribes erase the original audio?
Without the original recording, no one, not the clinician and not the patient, can check whether the AI-drafted note is accurate.
Has the HIPAA Security Rule been updated yet?
Not as of this writing. HHS proposed a major update in January 2025 and targeted May 2026 for finalization. That date has passed without a final rule.
How many AI medical devices has the FDA actually approved?
The FDA had authorized over 1,600 AI-enabled medical devices as of September 2026, mostly in radiology, cardiology, neurology, and hematology.
Is generative AI regulated the same way as other medical AI?
Not yet. As of early 2026, no FDA-authorized device used generative AI or a large language model, even as generative AI scribes and chatbots spread widely through hospitals.
How bad are healthcare data breaches right now?
Very. In just the first two months of 2026, 118 healthcare breaches exposed 9.6 million patient records, and the average breach now costs 7.42 million dollars.
What should a hospital do first if it has no formal AI governance program yet?
Inventory every AI tool touching patient data, then confirm whether each scribe or documentation tool preserves the original source recording.
Final Perspective
Healthcare runs on trust that a diagnosis is accurate and a record is true. AI can make both faster to produce. It can also quietly corrupt both, at a scale no single chart review could catch.
The 2026 record is now clear. AI scribes have documented things patients never said, sometimes with no way to check. Healthcare became the most ransomware-targeted industry on earth, with a measurable death toll during attacks. The main federal cybersecurity update has sat unfinished for over a year. And AI devices keep multiplying faster than generative AI oversight can keep up.
None of this argues for pulling AI out of the exam room. It argues for basic discipline. Keep the original recording. Require a human sign-off on anything that enters a chart. Patch the devices. Vet the vendors. Hospitals that build this now will keep the trust of patients, clinicians, and regulators through whatever AI brings next.
For sector-specific playbooks that apply the same discipline elsewhere, see our related guides on AI Security and Governance in Insurance, AI Security and Governance in Banking, AI Security and Governance in FinTech, AI Security and Governance in Investment and Asset Management, and our earlier guides on AI in Capital Markets and AI in Trading.
For deeper coverage of the healthcare topics above, see our reporting on AI in general hospitals, AI in telemedicine and telehealth providers, AI in remote patient monitoring tools, AI in digital health SaaS platforms, AI in medical billing companies, AI in primary care research, AI in academic research hospitals, and the OpenAI health portal breach rebuke.
Sources
- Artificial Intelligence-Enabled Medical Devices, FDA, September 2026
- The Current State of FDA-Approved AI-Enabled Medical Devices, Medical Futurist, March 2026
- FDA-Approved AI Medical Devices List: Complete 2026 Guide, IntuitionLabs, July 2026
- OpenAI’s Transcription Tool Hallucinates More Than Any Other, Fortune, 2024
- Auditing Medical AI Scribes, Koenecke et al., Cornell, 2025
- The Hallucination Problem: When AI Scribes Make Things Up, Twofold, July 2026
- Lost in Transcription, Found in Distribution Shift: Demystifying Hallucination in Speech Foundation Models, arXiv, 2025
- AI Transcription Tool Whisper Hallucinates, Raises Concerns, Tucson.com
- Biometrics, Diagnoses, and Bank Details Exposed in Major Healthcare Breach, Malwarebytes, May 2026
- 15M Patients Impacted by Largest Healthcare Data Breach of 2026, HealthExec, August 2026
- Healthcare Ransomware in 2026: Why 118 Breaches in Two Months Is a Warning, Valtik Studios, April 2026
- Ransomware Attacks on Hospitals: 38 Statistics for 2026, FaxSipIt, August 2026
- Healthcare Cybersecurity Statistics 2026, ORDR, April 2026
- HIPAA Security Rule 2026: OCR Enforcement, MFA, and Encryption Action Plan, ComplianceHub, 2026
- HIPAA Security Rule Final Rule: May 2026 and the MFA and Encryption Uncertainty, ComplianceHub, 2026


Leave a Reply