Most health systems have AI in more places than they can name. And that creates risk for patient care, HIPAA, vendor oversight, and security.

If I boil this article down, the message is simple: I can’t govern AI I haven’t listed. The fix is not a long policy project. It’s a 90-day plan to log every AI tool, assign an owner, run one intake process, sort tools by risk, and keep the list current.

Here’s the article in plain English:

  • The main problem: AI is showing up inside EHRs, imaging tools, revenue cycle systems, vendor updates, and staff-driven chatbot use.
  • Why that matters: Missing AI tools can lead to patient safety issues, HIPAA gaps, weak ownership, and new security paths.
  • Where systems lose track: In declared AI, embedded AI, and shadow AI.
  • What the first 90 days should look like:
    • Days 1–30: Pick an executive owner and build one AI register
    • Days 31–60: Find tools through contracts, vendor reviews, staff interviews, and data monitoring
    • Days 61–90: Sort each tool by risk and set review, logging, access, and shutoff rules
  • What the program needs to produce: A live asset register, one intake workflow, named owners, review triggers, and shared reporting for security, privacy, and compliance teams

A few numbers stand out:

  • 51% of healthcare groups still find AI through reactive discovery
  • 38% split AI risk across teams or have no clear owner
  • More than 50% have no written way to detect vendor-added AI
  • 70% have AI governance committees, but only 30% keep an enterprise-wide AI inventory
  • 64% are already testing or using agentic AI

Quick comparison

Area What the article says What I should do
Visibility gap AI is often missing from central records Build one register for all AI use cases
Main risk sources Embedded vendor AI, local staff use, hidden third-party models Review contracts, survey teams, monitor data access
Biggest risks Patient safety, HIPAA exposure, weak ownership, security gaps Assign owners and tie each tool to review rules
90-day plan Ownership, discovery, risk sorting Follow a 30-30-30 rollout
Key deliverables Register, intake, reporting, review triggers Treat inventory as a live control, not a one-time sheet

My takeaway: this article is not just about making a list. It’s about building a working control system for AI in healthcare, starting with visibility and ending with action.

Where Health Systems Lose Track of AI

Health systems tend to lose sight of AI in three places: inside approved tools, inside vendor updates, and inside department-level shadow use.

Declared AI, Embedded AI, and Shadow AI

AI doesn't enter a health system in just one way. And that matters, because each path creates a different visibility problem.

AI Category Typical Source Data Touched Visibility Main Risk
Declared AI IT/governance approved PHI, Operational, Financial High Compliance and cost
Embedded AI Vendor updates (EHRs, devices) PHI, Clinical Decision Support Low (often hidden in UI) Drift and low transparency
Shadow AI Individual departments or clinicians PHI, Sensitive patient data None (until discovered) Security, privacy, and bias

Declared AI is logged and approved. Embedded AI shows up through product updates and can slip past review. Shadow AI gets adopted locally and never makes it into governance.

That simple breakdown makes one thing clear: AI often hides in plain sight. The next step is figuring out where it gets in.

Common Blind Spots Across Clinical, Operational, and Vendor Environments

The blind spots usually show up in the same places.

On the clinical side, predictive models can go live inside existing EHR workflows through routine product updates without setting off a separate governance review. The same pattern shows up in imaging systems and medical devices.

On the operational side, AI used for scheduling, revenue cycle management, prior authorization, and diagnosis coding often skips clinical governance committees because it's labeled administrative instead of clinical. But that label can be misleading. These tools still touch PHI, and they still shape patient care. They just don't face the same level of review.

EHR transparency rules help, but they only cover part of the AI stack.

The shadow AI problem is not small. 51% of healthcare entities rely on reactive discovery to find AI tools within their environment [2]. So more than half of health systems are still finding AI by accident instead of through an active search.

Once AI is buried inside workflows, the next problem is what vendors tuck behind those workflows.

Why Third-Party and Fourth-Party AI Complicate Oversight

A SaaS contract can hide downstream AI dependencies. A vendor may depend on a third-party model hosted somewhere else, with little to no visibility into training data, hosting, or update behavior. That's where oversight gets messy, and it often won't show up in a standard contract review.

Tracking third-party AI means asking vendors direct questions, such as:

  • What AI or ML models are embedded in the product?
  • Where is the model hosted?
  • What data trained it?
  • Does the model update automatically?
  • Who owns the problem if it drifts?

Model dependence, host location, PHI exposure paths, and update behavior should be standard fields in every AI asset record.

These blind spots shape the intake questions and asset fields the 90-day inventory program needs to capture.

A 90-day plan to build an AI inventory program

90-Day Healthcare AI Inventory Program: Build, Discover, Govern

90-Day Healthcare AI Inventory Program: Build, Discover, Govern

Start small: one owner, one register, and one process your team can repeat. Then build from there over 90 days.

Days 1–30: Assign ownership and build the AI asset register

Begin with accountability. 38% of healthcare organizations either split AI risk across groups without clear escalation paths or have no defined owner at all [1]. That kind of split is where programs get stuck before they even get moving.

Pick an executive sponsor. Then set up a cross-functional working group with clear decision rights, so people know who decides what and where issues go when something needs attention. Your register should be a living record of AI assets, named owners, and escalation paths.

Once ownership is clear and the register exists, the next job is finding the use cases that aren't obvious by managing third-party AI risk.

Days 31–60: Discover AI use cases with a standard intake checklist

Run discovery in two directions at once: top-down through procurement and contracts, and bottom-up through interviews and surveys. That matters because over 50% of healthcare organizations have no documented method for detecting when vendors embed AI into existing products [1].

Use three main discovery paths to find what procurement alone won't catch:

Discovery Method Coverage Effort Likely Findings
Vendor Reviews High (third-party AI) Moderate Embedded AI in existing SaaS/EHR modules
Procurement/Contract Scans High (new assets) High Documented AI tools and BAA gaps
Continuous Data Monitoring High (shadow AI) Low (automated) Unauthorized API calls and agentic AI activity
Staff Surveys/Interviews Low (fragmented) High Department-specific shadow AI (e.g., ChatGPT)

Continuous monitoring of data access patterns helps you spot shadow AI that may show up through vendor updates and slip past normal procurement [1]. Every tool you find should go through the same intake checklist before it enters the register. If a tool is missing a BAA, flag it right away.

Days 61–90: Classify assets by risk and launch governance actions

After tools are logged and intake is done, move to classification. Give each asset a risk tier based on clinical impact, PHI access, autonomy, operational criticality, and patient-safety risk [1].

Risk Tier Clinical/Safety Impact Data Sensitivity Required Governance Action
Critical Direct patient care or autonomous action High-volume PHI / training data Continuous verification, kill switch, weekly audit review
High Clinical decision support (supervised) Limited PHI access Monthly audit review, attribute-based access control
Moderate Operational or administrative efficiency De-identified or internal data Quarterly review, least-privilege access
Low General productivity or non-clinical use Publicly available data Annual review, standard identity management

Treat agentic AI as Critical by default until your team validates it another way. 64% of healthcare organizations are already experimenting with or deploying agentic AI [1]. And these systems don't behave like standard chatbots. They can create non-human identities that authenticate thousands of times per hour, which means logging needs to track actions at the data level, not just logins [1].

Across every tier, enforce least-privilege access and purpose-limited access so AI systems can reach only the data classes and functions they were approved to use. Set kill switches for autonomous agents that start behaving outside the norm. And centralize logging and audit trails so the CISO, compliance officer, and privacy officer are all looking at the same evidence.

Core deliverables every healthcare AI inventory program needs

A 90-day plan only matters if it leads to live records, clear owners, and review triggers. Not another policy document that sits in a folder and gathers dust.

That’s the key issue here. AI doesn’t show up in just one place. It can sit inside clinical systems, back-office tools, and quiet vendor updates. So the inventory has to work like a living system, not a one-time spreadsheet. Once assets are risk-tiered, the program needs a set of working artifacts that keep those assets visible, reviewable, and up to date.

AI asset register and departmental use-case examples

A usable register needs more than a tool name and a launch date. It should show which PHI the system uses, who owns access, which vendor or business associate runs it, how its outputs are classified, and whether it needs human review or can act on its own [1].

That level of detail matters. 70% of healthcare organizations have established AI governance committees, but only 30% maintain an enterprise-wide AI inventory [1]. That gap is where risk slips through. It’s one thing to have a committee. It’s another to know what is actually running across the organization.

The register also needs to track use cases, not just product names. The same tool can carry very different risk depending on where it’s used, what data it touches, and who controls it.

Department Use Case What the Register Should Capture
Radiology Imaging triage and prioritization PHI access scope, autonomy level, output classification
Nursing Documentation support and ambient AI charting PHI access scope, vendor or business associate, human review status
Revenue Cycle Coding assistance and claims review PHI access scope, contractual obligations, revocation conditions
Contact Center Call summarization and patient intake PHI access scope, output classification, human review status
Supply Chain Demand forecasting Output classification, autonomy level, vendor or business associate

Ownership model, intake workflow, and risk criteria

Executive ownership has to be assigned clearly, and escalation paths need to be written down. If that doesn’t happen, the CISO, compliance team, and clinical leaders can each assume someone else is handling the risk [1].

Every new AI request should move through one documented intake workflow. New tools and vendor AI updates should face the same checklist before they reach production. That checklist should confirm the register fields above, verify that the BAA and other contract terms are current, and flag whether the tool changes PHI access, output classification, or autonomy level [1].

In plain terms, there should be no side door. If a vendor adds an AI feature, it goes through intake. If a department wants a new AI tool, it goes through intake. Same path, same review.

Governance actions and reporting that keep the inventory current

The register has to change when the environment changes. Review triggers should include new deployments, vendor feature changes, major model updates, security incidents, and scheduled reassessments. Continuous monitoring should also be used to spot shadow AI and vendor changes [1]. For higher-risk or agentic AI, the inventory should record alerting and escalation rules, along with kill switch conditions as required fields.

Reporting has to work for more than one audience at the same time. The CISO, compliance officer, and privacy officer should all look at the same central dashboard. That dashboard should show asset status, open exceptions, corrective actions in progress, and audit trail completeness [1]. Exportable reports for the board and for audits matter too, especially during regulatory review. HIPAA’s Security Rule also requires documented information system activity reviews for systems that process ePHI [1].

These deliverables work best when a single system ties the register, intake workflow, and reporting together.

How Censinet helps healthcare teams build and manage AI inventory

Censinet RiskOps brings AI inventory, risk, and governance into one workflow. Put simply, the inventory can't sit in spreadsheets or scattered review threads. It needs one operating system for the work.

Using Censinet RiskOps as the system of record for AI assets and risks

Censinet RiskOps works as the central workflow for AI inventory. It connects cybersecurity, compliance, vendor management, and clinical governance teams around the same set of data. That gives governance teams one live register, linked assessments, and a shared view of AI risk.

It also covers AI use across clinical, operational, vendor, and fourth-party sources. Those inputs come together in a single record, so issues don't get lost in the handoff between teams.

Once that register is in place, the next choke point shows up fast: intake and evidence review.

How Censinet AI and AITM speed up intake, evidence review, and task routing

Two stubborn bottlenecks slow AI inventory work: third-party risk questionnaires and fuzzy task ownership. Censinet AI and AITM (AI Trust Management) are built to handle both.

AITM automates vendor questionnaires, summarizes evidence, and routes remediation tasks, including fourth-party AI exposures. Censinet AI then generates risk summaries and sends remediation tasks to the right stakeholders.

Human review still matters for high-impact decisions. Risk teams set which decisions need human review, so automation handles the volume while clinical and compliance leaders keep control over high-impact calls.

The gap, for many health systems, is day-to-day execution. Inventory, detection, ownership, and routing are still handled by hand in many cases.

With inventory, intake, and routing in place, the next job is keeping the program current.

Conclusion: What healthcare leaders should do in the next 90 days

The core problem is simple: most health systems still don't have a full picture of where AI is running. That gap creates real exposure across cybersecurity, compliance, patient safety, and vendor oversight.

In the next 90 days, health systems should put the basics in place:

  • Build the register
  • Set up the intake workflow
  • Define risk tiers
  • Create a reporting loop that keeps AI visible and governed

The fix is a 90-day inventory program with named owners, standardized intake, risk tiers, and reporting. It should be treated as a core risk control and kept current through continuous monitoring, not one-time procurement reviews, as AI use keeps growing.

FAQs

What counts as AI in a healthcare inventory?

AI includes all machine learning, generative, and agentic models used across the organization.

That means everything counts: vendor products, in-house tools, pilot programs, and shadow AI.

Catalog any tool that touches patient records, generates clinical notes, supports treatment recommendations, handles communications, billing, scheduling, clinical workflows, EHR integrations, or PHI - no matter who brought it in or started using it.

Who should own the AI inventory program?

The AI inventory program should sit with a cross-functional AI governance committee. That group should include clinical leadership, cybersecurity/IT, privacy, legal, and compliance. There should also be a named executive AI program lead, so one person is clearly accountable.

Each AI asset should have clear business and technical owners. When the asset affects care or clinical workflows, it should also have a clinical owner. That way, risk decisions and escalations don’t get lost in the shuffle - there’s one responsible party for each issue.

How do we find shadow AI already in use?

Don’t rely on policy documents alone. Use active detection. That means combining network-level visibility, endpoint monitoring, and scans of SaaS and EHR app usage to spot unauthorized tools as they appear.

You also need one centralized AI inventory that stays up to date. It should track every known tool and each use case tied to it. If any unapproved AI touches PHI, affects clinical decisions, or connects with the EHR, log it right away and send it through intake for risk-tiering and governance.

Related Blog Posts