AI has the potential to reduce administrative burdens, speed decision-making and improve coordination across many healthcare workflows. But these processes often involve sensitive patient data moving among interconnected systems, and rushed adoption can create new cybersecurity and privacy vulnerabilities. AI can also introduce errors or inappropriate automated actions when organizations don’t build in adequate safeguards and human oversight.
Healthcare organizations must carefully evaluate data access, vendor relationships, security controls and oversight before deploying AI at scale. Below, members of Forbes Technology Council discuss healthcare workflows where AI could improve efficiency and outcomes but also create cybersecurity, privacy or accuracy risks if leaders move too quickly.
Billing And Coding
Billing and revenue cycle management is a healthcare workflow where AI can add real value—faster claims, fewer denials and accelerated time-to-money—but it comes with risks. Unsupported upcoding, leaked protected health information (PHI) and incorrect coding through hallucinations could not only result in higher audit risk but also compromise patient files with misleading diagnoses and treatments. Human-in-the-loop oversight is critical in healthcare. “Primum non nocere”: “First, do no harm.” – Mark Francis, CaregiverZone
RAG-Based Patient Data Search
Using RAG to search medical records creates a hidden privacy loophole. RAG converts files into mathematical data—embeddings—stored in a separate database. If a patient requests data deletion, you might erase the original file but forget this hidden AI copy. This violates right-to-delete laws, and worse, hackers can reverse-engineer those leftover AI files to steal sensitive health data. – Konstantin Klyagin, Redwerk
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
Clinical Trial Recruitment
AI can accelerate clinical trial participant matching by scanning records against eligibility criteria, shortening recruitment dramatically. Yet centralizing sensitive histories from multiple hospitals creates an attractive intelligence target. Before scaling, leaders should isolate datasets, enforce purpose-limited retrieval and continuously verify every cross-organization access request. Every deployment decision should include measurable privacy. – Jagadish Gokavarapu, Wissen Infotech
Automated Patient Notifications
Using AI to auto-text a patient, “We have an opening,” to fill open slots from last-minute cancellations is slick. But without a mask, a “Your HIV test results are ready” message on a shared family phone breaches privacy instantly. The risk isn’t the model; it’s the ungoverned last mile of communication. Leaders need patient-defined safe channels and message obfuscation rules baked in before the first send, not after the first leak. – Eshaan Jain, Mphasis Silverline
Cross-System Patient Record Linking
Patient intake and identity matching can introduce risks. AI that auto-links records across systems speeds care, but rushing it without a strong identity layer invites mismatched or duplicate records and broad data access that exposes PHI. Treat patient identity like verified infrastructure: Authenticate at the source, enforce least-privilege access and audit every link. Efficiency built on unverified identity isn’t efficiency—it’s liability. – Agung Dwi Sandi, rankpillar Group
Remote Patient Monitoring
Remote patient monitoring comes with overlooked risks for sure. Wearables and home devices stream continuous vitals into cloud dashboards, turning care into an always-on data pipeline rather than a single visit. Move fast, and you inherit unaudited device firmware and vendor cloud exposure. Map every device-to-cloud hop, and vet each one before scaling. AI can be best used with human oversight and for review of mundane tasks, not to replace human intervention. – Dan Sorensen, Nexus Security Advisors
Voice AI For Patient Calls
Voice AI in a patient call center poses risk. It cuts hold times, but it also creates voiceprints, which several states treat as biometric data with their own consent rules. HIPAA is not the only statute in play. Decide whether you keep audio or a template, who can search it, and how a patient can opt out before the first call is answered. – Ganesh Ariyur, Transform Smarter
AI-Drafted Patient Portal Replies
AI-drafted replies in patient portals pose risk. The efficiency is real, but to draft one reply, the model reads the whole record. A workflow that once touched a single message now touches everything. The risk isn’t a breach; it’s that the “minimum necessary” standard can quietly break down, and because no data is leaked, the excessive access may go unnoticed. Constrain retrieval per message type, and log what the model reads, not just what it wrote. – Dr. Chiranjiv Roy, C5i.ai
Clinical Decision Support
Assistance with clinical decision-making is a clear opportunity for applying AI in healthcare because it leverages specific contextual information about the patient. By leveraging the patient’s history, including active medications or allergies, it is possible to provide precise insights that are applicable to the specific patient. However, managing patient health information requires enhanced security and risk controls to ensure that information is protected. – Rhett Alden, Elsevier
Patient Intake Automation
Patient intake automation sounds like an efficiency play, but it’s often the quiet risk. Feeding AI years of unstructured records to speed scheduling and triage means every integration point becomes exposure. In regulated systems, I’ve seen that compliance has to be built in from day one. Bolt it on later, and you’re rebuilding, not patching. – Marc Fischer, Dogtown Media LLC
Patient Record Search
Automated search of patient records is one thing that could boost a practitioner’s efficiency immensely, but it is also a realm in which privacy issues arise rapidly. It is crucial to implement strong authentication, access control and encryption as the AI system integrates data from a variety of locations. – Ajay Pandey
Clinical Documentation
Clinical documentation is an area where AI can be helpful. AI scribes and summarizers can save clinicians hours, but they wire straight into EHR systems full of PHI. Move too fast, and you approve the integration on paper without seeing what the app actually accesses or where that data flows at runtime. The risk is the gap between the permissions you granted and the behavior in production. – Aviv Mussinger, Kodem
Predictive Maintenance For Medical Equipment
AI-driven predictive maintenance for connected medical equipment can detect early failure in ventilators, infusion pumps, imaging systems and laboratory devices, reducing downtime and protecting care continuity. However, continuous access to device telemetry and hospital networks can expand the cyberattack surface. Leaders should segment clinical networks, authenticate device data and prevent maintenance AI from changing equipment settings. – Salice Thomas, Wipro Limited
Patient Identity Matching
Patient identity matching is a workflow where AI can reduce duplicate records and care errors, but moving too quickly introduces serious risk. When AI automatically merges records based on probabilistic matching, a wrong match means two patients share a clinical history without anyone knowing. The failure mode is often invisible until a care decision gets made against the wrong record. Human review should be required before AI touches any live record. – Dan Haiem, AppMakers USA


