Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityHospitals & Medical Centers

AI in Healthcare: Reducing Risk in the Emerging Malpractice Frontier

By Meghan O'Connor
Medical worker holding tablet
Nappy via Unsplash
July 31, 2026

Artificial intelligence is transforming healthcare. From diagnostic imaging to clinical decision support, generative AI tools are increasingly embedded in patient care workflows. The benefits are significant: faster diagnoses, reduced physician burnout, and more personalized treatment. But with these advances comes a new category of legal risk: AI-related malpractice liability. Organizations that fail to approach AI adoption with the same rigor they apply to other clinical tools may face negligence claims that existing risk frameworks were never designed to address.

How AI Is Reshaping Malpractice and Negligence Claims

Traditional medical malpractice law rests on a well-established framework: a provider owes a duty of care to the patient, and liability attaches when the provider’s conduct falls below the applicable standard of care, causing injury. That standard has been measured against the knowledge, skill, and judgment of a reasonably competent practitioner in the same specialty.

Generative AI complicates this framework. In the event of an adverse outcome, the question of who bears responsibility—provider, health system, AI tool developer, or product manufacturer — becomes genuinely difficult. Time will tell how courts will allocate liability, but plaintiffs’ attorneys are exploring theories grounded in negligent adoption, inadequate oversight, and failure to verify AI outputs.

Critically, providers cannot delegate clinical judgment to an algorithm and expect it to absorb liability. AI does not hold professional licensure and is not subject to ethical standards that bind licensed practitioners. State licensing and scope-of-practice rules increasingly require licensed professionals to review and approve outputs, and expanding healthcare AI laws reinforce that AI cannot be the sole basis for clinical decisions. Providers who over-rely on outputs without applying their own expertise may face claims that they abdicated professional responsibility.

Beyond malpractice, health systems and AI developers face products liability exposure. Traditional products liability distinguishes between a product, its user, and the patient. AI blurs those boundaries; the chain of liability runs from hardware to software to developer to manufacturer to human provider, making fault allocation far more complex than in conventional medical device cases. Strict liability theories — including manufacturing or design defect, failure to warn, negligence, and breach of warranty — may all be viable. An open question is whether the standard of care will be higher for AI-enabled products because the software is arguably more “intelligent” than a reasonably prudent person, potentially raising expectations about what constitutes a defective or substandard output or a “reasonable” clinical provider.

Shadow AI 

Perhaps the most underappreciated risk is the proliferation of unapproved AI tools. Staff may turn to publicly available AI platforms to summarize patient records, draft clinical notes, or research treatment options. These tools are often adopted without institutional knowledge or authorization and lack safeguards like encryption and closed-loop data handling.

Shadow AI creates legal and compliance exposure on multiple fronts. Unapproved tools have not been vetted for clinical accuracy and may violate organizational policies, regulatory requirements, and contractual obligations. If an adverse outcome is linked to reliance on an unapproved tool, the organization may face liability for both the clinical error and its failure to establish adequate AI governance.

Enforcement actions have also targeted process failures — including inadequate vendor diligence and failures of transparency — not just adverse outcomes. State attorneys general are not waiting for demonstrable patient harm before investigating alleged false and misleading product claims.

Security and Privacy Risks 

There is a fundamental tension between familiar privacy principles — minimum necessary and data minimization — and AI’s operational demands for data retention to support explainability, bias analysis, and transparency. Generative AI tools require large volumes of data to function effectively. Organizations must evaluate whether AI tools transmit patient data to external servers, data is used to train third-party models, or adequate encryption and access controls are in place.

Under HIPAA and state privacy laws, organizations that fail to safeguard personal information processed by AI systems face significant penalties, potential algorithmic disgorgement, and litigation. A pivot to deidentified data does not solve these risks. The process of deidentifying data is itself a “use” of data, and certain state laws require consumer consent before deidentifying data and specific contractual flow-down terms with recipients.

Practical Steps 

Providers do not need to avoid AI to manage these risks, but they must be deliberate. Organizations can take several steps to reduce liability exposure:

  • Establish formal AI governance committees that include clinical, legal, compliance, and information security leadership. AI tools should not be deployed without institutional review and approval.
  • Develop standards addressing patient notification, clinician obligations to independently verify AI-generated outputs, and permissible use of AI-enabled products, supported by training.
  • Conduct due diligence on AI vendors: understand how models are trained, what data rights vendors retain, how outputs are validated, and what ongoing monitoring the vendor supports. Use the HHS AI transparency rule “nutrition label” questions as a guide and update commercial contract terms, BAAs, and DPAs to address AI-specific concerns.
  • Implement ongoing monitoring protocols. AI systems change over time. Monitor for output drift, bias emergence, data quality degradation, and scope creep. Documentation creates critical evidence of diligence in any future enforcement action or litigation.
  • Treat AI incidents like safety events, not merely IT glitches, as these incidents can be a catalyst for class action litigation, regulatory enforcement, and lasting reputational harm.

The integration of AI into healthcare is not a question of whether but how. Organizations that invest now in governance, training, and oversight will be better positioned to capture AI’s benefits while managing the accompanying risks.

KEYWORDS: artificial intelligence (AI) Artificial Intelligence (AI) Security governance healthcare cybersecurity HIPAA HIPAA compliance

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Meghan oconnor headshot

Meghan O'Connor is partner at Quarles & Brady. Image courtesy of O'Connor

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Security Leadership and Management
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Paparazzi

When Private Events Become Public Infrastructure: What Celebrity OSINT Teaches Security Leaders

Broken wet floor sign

Why Response Time Is Becoming the Missing Metric in Workplace Safety and Security

People watching fireworks

Security Guard Assaulted at Firework Show

Cargo ship sailing

You Can’t Secure a Ship Like a Laptop

Medical professional

Nearly 85% of Nurses Experienced Workplace Violence in the Last Year

Kaseware sponsored webinar
Schneider Electric sponsored webinar

Events

August 19, 2026

From Investigative Question to Defensible Answer: AI in Digital Forensics and Incident Response

LIVE: August 19, 2026 at 2 PM EDT We'll examine where AI can deliver meaningful value, where incomplete context or black-box reasoning can introduce risk, and what governance, validation, and evidence-traceability controls organizations should establish.

August 25, 2026

Critical Infrastructure Security Is National Security: Protecting Essential Operations in an Era of Escalating Risk

LIVE: August 25, 2026 at 2 PM EDT Learn why critical infrastructure security has become a national security imperative, and the strategies organizations can adopt to improve visibility, collaboration, and response across their security operations.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • Arteco Facial Recognition Algorithm - Security Magazine

    Facial Recognition Technology: Minimizing Risk in the Face of Increasing Liability

    See More
  • Cyber risk c-suite

    Six ways to reduce cyber risk in the C-suite

    See More
  • people use computer

    Strategies for third-party risk management in healthcare

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • Risk Analysis and the Security Survey, 4th Edition

  • Physical Layer Security in Wireless Communications

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing