The short answer
To govern AI use across a healthcare group, put 6 things in place before staff use AI tools at scale: a readiness assessment that finds where sensitive data sits, a data classification and tagging scheme, access controls that separate protected health information from business data, a named governance owner, an approval workflow for AI output, and an audit that runs at every site. Focus builds this framework for multi-location healthcare practices.
Why does a healthcare group need an AI governance policy, not just AI rules?

Because AI is already in use across your sites, whether it was approved or not, and at group scale informal rules cannot keep up. A December 2025 Wolters Kluwer Health survey of 518 providers and administrators found that 40% had encountered unauthorized AI tools at work and nearly 20% admitted using them, with shadow AI now turning up in direct patient care, not only back-office tasks.
The adoption-to-governance gap is the real problem. In 2026, roughly 75% of U.S. health systems have deployed or plan to deploy at least one AI tool, but only about 18% report mature AI governance, according to a February 2026 Eliciting Insights survey of 120 health systems. That gap is where exposure lives. An AI agent is a small team of assistants you have handed the keys to, and unless you tell it what it should and should not touch, it will reach everything it can. Point an ungoverned agent at years of documentation and it can surface protected health information no human would have gone looking for.
The stakes are specific in healthcare. IBM’s 2025 Cost of a Data Breach Report put the average healthcare breach at $7.42 million, the costliest of any industry for the 14th year running, and healthcare breaches took the longest to identify and contain at roughly 279 days. Under HIPAA, civil penalties from the U.S. Department of Health and Human Services reach $2.19 million per violation category in a year at the most serious tier, a figure adjusted for inflation in January 2026. A single ungoverned tool is a fast way to reach those numbers.
An AI agent is an extension of your team, a set of assistants you hand work to. Get your ducks in a row on security and data tagging before you turn the lights on, or it will reach things it never should. — Mark Sternig, Chief Technology Officer, Focus
What does an AI governance framework for a healthcare group include?
An AI governance framework for a healthcare group is 6 decisions, made once at the leadership level and enforced at every location. Together they are your policy. Miss one and staff fill the gap with unsanctioned tools, the pattern IBM found in the 20% of 2025 breaches that involved shadow AI.
- A governance owner or committee that makes the decisions and holds them across sites.
- A data classification and tagging scheme so AI knows what each document is and who it is for.
- Access controls that separate protected health information from business data at the data layer.
- An approved-use policy naming who can use AI and for what.
- An approval workflow for validating and endorsing what AI produces before it spreads.
- An audit process that checks all of the above on a schedule, at every location.
Step 1: Who owns AI governance across the group?

Name the owner first, because every decision below needs a place to live. In most healthcare groups the owner is a small committee, not one person: someone from operations, someone accountable for security and compliance, and a data or IT lead. Their mandate is to set approved uses, own the classification rules, approve which AI platforms are allowed, and review the audit findings.
This step is where most groups stall. In IBM’s 2025 data, 63% of breached organizations had no AI governance policy or were still building one, and the Eliciting Insights survey put mature healthcare governance at roughly 18%. Most healthcare groups are new at this work, because few have ever had to run a formal data governance process. For why this responsibility belongs with the team that already runs your systems, rather than a standalone AI committee, see our piece on where AI governance sits. Naming an accountable owner is what turns governance from a one-time document into an ongoing function.
Step 2: How do you classify and tag data so AI respects it?
Classify data into tiers by sensitivity and audience, then tag every document, email, calendar invite, and message so AI can read the tag. Tagging is the step that makes every later control possible, and it is the one groups skip. Without a valid tag, no matter how capable the model is, AI cannot tell a clinical note from a lunch order, and unlabeled context is where confident wrong answers begin.
At minimum, most groups need 3 tiers: protected health information, business and financial data, and general internal content. Each tier carries a tag, and the tags are what your AI tools read to decide what they may use. The table below is a starting scheme.
| Data tier | Example content | Who should reach it | AI access rule |
|---|---|---|---|
| Protected health information (PHI) | Charts, encounter notes, lab results, anything tied to a patient | Clinical staff with a treatment relationship | Off-limits unless the tool and the user are both cleared, under a BAA |
| Business and financial data | Billing, payroll, contracts, revenue reporting | Finance and operations roles | Reachable only by roles already cleared for it, never mixed with PHI |
| General internal content | Policies, schedules, internal announcements | All staff | Safe for broad AI use once tagged |
Read the table as the rule set behind your tools. The tags are not paperwork. They are the instructions an AI tool follows when it decides whether a given file is fair game for a given user. Get the tiers and tags in place and the access controls in Step 3 have something concrete to enforce. If you have not yet mapped where sensitive data sits across your locations, that groundwork is the readiness assessment we cover in what “AI-ready” means right after go-live.
Step 3: How do you keep AI from touching PHI it should not see?
Set access controls at the data layer so an AI tool can only reach information the user was already cleared to see. This mirrors how your people already work: accounting has access to accounting data, not clinical data, and providers have access to clinical data, not the financials. AI has to sit inside those same lines. Enforced at the data layer, that is row-level security, and it is what keeps one badly scoped prompt from becoming an exposure.
The evidence for doing this first is stark. IBM’s 2025 report found that 97% of organizations that suffered an AI-related security incident lacked proper AI access controls. Access control is not a late-stage hardening step. It is the control that separates a useful AI rollout from a reportable one.
Separating protected health information from business data is a job in its own right, and it is the piece to execute before any AI tool goes live. Governance sets the rule here; the data work is how you enforce it.
Step 4: What is the approval workflow for what AI produces?
Decide who reviews AI-assisted work and how approved output gets marked before it moves across the group. Everything earlier governs what goes into AI. This step governs what comes out, and in a multi-site group it quietly decides whether adoption succeeds. People will build reports, summaries, dashboards, and drafts with these tools. The first time a wrong one circulates, staff decide they cannot trust any of it.
A workflow fixes that. Name the reviewers for the uses that carry real weight, and give staff a clear signal for what has been checked versus what is a rough draft. Trust has to scale with adoption, or adoption stalls and the money spent on tools erodes confidence instead of building it.
Step 5: How do you audit AI use across every site?

Run the same checks at every location on a fixed schedule, watching two things: exposure and drift. Exposure means protected health information sitting where it should not be, or sensitive data getting emailed and posted into channels an agent could reach. Drift means new tools appearing outside the approved list and classification tags going unapplied. A policy you do not check is a policy you do not have.
Shadow AI is the reason this matters: you cannot govern what you cannot see. Data-loss-prevention settings, network monitoring, and a recurring readiness scan are how you find unsanctioned use before an AI tool creates an incident. Ground the program in a recognized standard rather than inventing one. The NIST AI Risk Management Framework gives healthcare groups a structured way to identify and manage AI risk across the lifecycle. And the HHS Security Rule update proposed in January 2025 would require a written inventory of every technology asset that touches electronic PHI, with AI systems squarely in that scope.
The AI governance checklist for a multi-location healthcare group
- Name the governance owner or committee and give them authority over approved uses and platforms.
- Run a readiness assessment to find where protected health information and sensitive data sit today.
- Classify data into tiers by sensitivity and audience, and tag every document, email, and message.
- Set access controls at the data layer so AI can only reach what a given user is already cleared to see.
- Confirm a Business Associate Agreement with any AI platform that will touch patient data. A BAA is a legally binding contract, and for groups running in Microsoft Azure it is typically part of the subscription, one reason Copilot and Azure tagging are a common starting point.
- Write the approved-use policy: who can use AI, for what, and what is off the table until reviewed.
- Stand up an approval workflow that validates and endorses AI output before it spreads across sites.
- Schedule the audit, including DLP checks and a recurring readiness scan, and run it at every location.
Where most healthcare groups get AI governance wrong

They treat it as a training problem when it is a data problem. Teaching staff to prompt well is worth doing, but the decisive work is data governance: classifying, securing, and validating information before anyone points an AI tool at it. That is the part healthcare groups have rarely had to build, and it is the part that determines whether AI is safe to use across sites.
Order decides the outcome. Put security and data tagging in place before you switch AI on, not after. Done in that order, the technology that was a liability becomes what it is supposed to be. Groups that give staff an approved, governed tool consistently see unsanctioned use fall, because people take the safe path when it is also the easy one. Governance is what makes that path exist.
Focus has spent 16+ years working only in healthcare, and only in IT, security, and data. We have run more than 2,000 EHR conversions for healthcare practices, and standing up AI governance across a multi-location group is the work we do: the readiness assessment, the classification and tagging, the access controls, and the audit that keeps it honest. If AI is already showing up across your locations without a policy governing it, that is where to start, and it is worth doing before the next tool goes live.
Frequently asked questions
What are the risks of using AI with PHI?
The main risks are exposure and compliance. An AI tool without access controls can surface protected health information to the wrong user or send it to a vendor with no Business Associate Agreement, which HHS can treat as a HIPAA violation. IBM found 97% of organizations with an AI-related incident lacked proper AI access controls. Our guide to the major AI risks in healthcare covers the full picture, and our guide on AI and HIPAA compliance goes deep on the compliance side.
How can a practice use AI without exposing patient data?
Separate PHI from business data before AI goes on, then enforce access at the data layer so a tool can only reach what the user is already cleared to see. Tag content by audience, and confirm a BAA with any platform that touches patient data.
What foundation does a practice need before using AI?
A clean, classified, tagged data environment and a clear picture of where sensitive data sits. Most failed AI efforts trace to a weak data foundation, not the model. Start with a readiness assessment. Our guide on what AI readiness takes for a healthcare practice covers the technical checkpoints before any governance policy is written.
How do you safely adopt AI across a medical group?
Adopt it under governance, not around it. Name an owner, classify and tag data, set access controls, require BAAs, approve specific uses, and audit at every site. Groups that give staff an approved, governed tool see unsanctioned use fall, because the safe path becomes the convenient one. This guide is the full framework.
Do you need a BAA for AI tools that touch patient data?
Yes. Any AI platform that creates, receives, maintains, or transmits protected health information on your behalf is a business associate under HIPAA and needs a signed Business Associate Agreement with HHS-defined obligations. For groups in Microsoft Azure, a BAA with Microsoft is typically included in the subscription, which is part of why Azure-based tooling is a common healthcare starting point.