Skip to content
Tiatra, LLCTiatra, LLC
Tiatra, LLC
Information Technology Solutions for Washington, DC Government Agencies
  • Home
  • About Us
  • Services
    • IT Engineering and Support
    • Software Development
    • Information Assurance and Testing
    • Project and Program Management
  • Clients & Partners
  • Careers
  • News
  • Contact
 
  • Home
  • About Us
  • Services
    • IT Engineering and Support
    • Software Development
    • Information Assurance and Testing
    • Project and Program Management
  • Clients & Partners
  • Careers
  • News
  • Contact

Healthcare CIOs rethink AI rollout

Healthcare organizations are under intense pressure to operationalize gen AI. But unlike many industries, they can’t afford to move fast and fix problems later. The earliest large-scale deployments, especially ambient clinical documentation, are already delivering measurable gains. At the same time, though, they’re exposing new fault lines around protected health information (PHI) and clinical trust.

What’s emerging isn’t a slowdown in AI adoption, but a redesign of how it’s introduced. Healthcare CIOs, CISOs, and clinical informatics leaders are converging on a shared understanding that scaling AI safely requires rethinking governance, security controls, and infrastructure in parallel.

According to Mark Mabus, CMIO and SVP of electronic health records at Parkview Health, ambient documentation, otherwise known as ambient listening or AI charting, has quickly become healthcare’s most visible gen AI use case. By capturing and summarizing physician-patient conversations, the technology promises to reduce clinician burnout while improving documentation quality. “It helps our providers get their notes done faster,” he says. “It reduces the amount of typing and their cognitive burden.”

That momentum, however, is forcing IT leaders to confront new operational questions that traditional healthcare architectures weren’t designed to answer. The closer organizations get to production scale, the more complex the risk profile becomes.

“Where’s the audio processed?” asks Mabus. “Is it on site, in a cloud? Is protected health information retained in there or not, and who validates the output? Those are things we have to assess and validate even before we consider putting a tool into production.”

Central to the emerging healthcare AI playbook is the idea that all decisions are made by humans. Assistive systems can draft notes, summarize charts, or suggest responses, but clinicians remain firmly in the loop. “Physicians still have to edit it and sign off on it,” says Mabus.

srcset=”https://b2b-contenthub.com/wp-content/uploads/2026/03/Mark-Mabus-CMIO-and-SVP-of-electronic-health-records-Parkview-Health.jpg?quality=50&strip=all 1800w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Mark-Mabus-CMIO-and-SVP-of-electronic-health-records-Parkview-Health.jpg?resize=300%2C200&quality=50&strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Mark-Mabus-CMIO-and-SVP-of-electronic-health-records-Parkview-Health.jpg?resize=768%2C512&quality=50&strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Mark-Mabus-CMIO-and-SVP-of-electronic-health-records-Parkview-Health.jpg?resize=1024%2C683&quality=50&strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Mark-Mabus-CMIO-and-SVP-of-electronic-health-records-Parkview-Health.jpg?resize=1536%2C1024&quality=50&strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Mark-Mabus-CMIO-and-SVP-of-electronic-health-records-Parkview-Health.jpg?resize=1240%2C826&quality=50&strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Mark-Mabus-CMIO-and-SVP-of-electronic-health-records-Parkview-Health.jpg?resize=150%2C100&quality=50&strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Mark-Mabus-CMIO-and-SVP-of-electronic-health-records-Parkview-Health.jpg?resize=1046%2C697&quality=50&strip=all 1046w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Mark-Mabus-CMIO-and-SVP-of-electronic-health-records-Parkview-Health.jpg?resize=252%2C168&quality=50&strip=all 252w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Mark-Mabus-CMIO-and-SVP-of-electronic-health-records-Parkview-Health.jpg?resize=126%2C84&quality=50&strip=all 126w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Mark-Mabus-CMIO-and-SVP-of-electronic-health-records-Parkview-Health.jpg?resize=720%2C480&quality=50&strip=all 720w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Mark-Mabus-CMIO-and-SVP-of-electronic-health-records-Parkview-Health.jpg?resize=540%2C360&quality=50&strip=all 540w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Mark-Mabus-CMIO-and-SVP-of-electronic-health-records-Parkview-Health.jpg?resize=375%2C250&quality=50&strip=all 375w” width=”1240″ height=”827″ sizes=”auto, (max-width: 1240px) 100vw, 1240px”>

Mark Mabus, CMIO and SVP of electronic health records, Parkview Health

Parkview Health

This human-in-the-loop requirement does more than just satisfy regulators — it shapes how organizations tier risk and prioritize deployments. At Parkview, AI use cases are formally categorized by clinical impact and automation level, with higher-risk scenarios facing stricter review. The cautious posture reflects hard-earned lessons from early pilots. In some cases, Mabus says, technically impressive tools failed to deliver clinical value. “When I’m expecting three lines and I get nine paragraphs, that creates extra cognitive burden,” he says.

This experience reinforces the broader point now resonating across healthcare IT that clinical usability and compliance readiness must advance together.

The governance problem of shadow AI

Even as formal deployments expand, healthcare leaders are grappling with a familiar enterprise problem where users experiment outside approved channels. “I think it reminds me of texting in the healthcare environment,” Mabus says. “People will still text even though they’re provided secure tools. It’s just human nature.”

The analogy is instructive. Just as secure messaging platforms never fully eliminated SMS workarounds, gen AI policies alone are unlikely to stop clinicians from testing public tools when they perceive a productivity benefit.

Some organizations have attempted technical blocks, but experience suggests those measures have limits. Users can quickly route around network controls using personal devices and cellular connections. Instead, many health systems are pairing policy with education and enterprise-grade alternatives. The goal isn’t to eliminate experimentation but channel it safely.

The risk of unmanaged experimentation isn’t theoretical. “I’ve seen large language models give completely different responses,” Mabus says. “And one of those responses would probably cause patient harm if used.” That variability is pushing healthcare organizations to emphasize validation, transparency, and clinician training alongside traditional compliance controls.

More broadly, healthcare is relearning a lesson familiar to enterprise IT leaders: governance is as much behavioral as it is technical.

The threat curve bending upward

While clinical teams focus on workflow integration, security leaders are watching a different trend line: the accelerating speed of AI-enabled attacks. “It’s not necessarily the complexity of the attacks, it’s the velocity,” says Kevin Torres, CISO and VP of IT at MemorialCare. “It’s coming at us in a relentless fashion.” He points to a recent password spray campaign against his health system that showed a tenfold spike in failed login attempts, an indication that adversaries are increasingly automating credential attacks.

At the same time, the spread of AI-powered clinical tools is expanding the third-party risk surface. Ambient listening platforms, analytics engines, and generative assistants often process highly sensitive patient interactions outside the traditional boundaries of electronic health records. In response, MemorialCare has intensified vendor scrutiny. “We go through an exhaustive third-party risk management process and score whether it’s safe to share data with them,” says Torres. Reviews include NIST alignment, penetration testing history, access controls, and breach track records.

srcset=”https://b2b-contenthub.com/wp-content/uploads/2026/03/Kevin-Torres-CISO-and-VP-of-IT-MemorialCare.jpg?quality=50&strip=all 1800w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Kevin-Torres-CISO-and-VP-of-IT-MemorialCare.jpg?resize=300%2C200&quality=50&strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Kevin-Torres-CISO-and-VP-of-IT-MemorialCare.jpg?resize=768%2C512&quality=50&strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Kevin-Torres-CISO-and-VP-of-IT-MemorialCare.jpg?resize=1024%2C683&quality=50&strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Kevin-Torres-CISO-and-VP-of-IT-MemorialCare.jpg?resize=1536%2C1024&quality=50&strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Kevin-Torres-CISO-and-VP-of-IT-MemorialCare.jpg?resize=1240%2C826&quality=50&strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Kevin-Torres-CISO-and-VP-of-IT-MemorialCare.jpg?resize=150%2C100&quality=50&strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Kevin-Torres-CISO-and-VP-of-IT-MemorialCare.jpg?resize=1046%2C697&quality=50&strip=all 1046w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Kevin-Torres-CISO-and-VP-of-IT-MemorialCare.jpg?resize=252%2C168&quality=50&strip=all 252w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Kevin-Torres-CISO-and-VP-of-IT-MemorialCare.jpg?resize=126%2C84&quality=50&strip=all 126w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Kevin-Torres-CISO-and-VP-of-IT-MemorialCare.jpg?resize=720%2C480&quality=50&strip=all 720w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Kevin-Torres-CISO-and-VP-of-IT-MemorialCare.jpg?resize=540%2C360&quality=50&strip=all 540w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Kevin-Torres-CISO-and-VP-of-IT-MemorialCare.jpg?resize=375%2C250&quality=50&strip=all 375w” width=”1240″ height=”827″ sizes=”auto, (max-width: 1240px) 100vw, 1240px”>

Kevin Torres, CISO and VP of IT, MemorialCare

MemorialCare

The growing executive visibility around AI risk is also reshaping governance. Torres says his organization now provides its board with an enterprise risk management dashboard that explicitly tracks AI-related exposure alongside cybersecurity and business continuity risks. Even with those controls, uncertainty remains high. “We don’t know what we don’t know right now,” he says. “I think we’re due for a big disruption in one of the core AI vendors.”

That expectation is reinforcing a broader shift toward continuous monitoring rather than one-time compliance checks.

Healthcare architecture must be rebuilt for AI

Beneath the policy and security layers lies a deeper structural issue that many healthcare environments weren’t designed for the speed and fluidity of gen AI workflows. According to Cletis Earle, healthcare field CTO at cloud computing company Citrix, the first cracks often appear when clinicians begin experimenting with external tools. “If you don’t have a secure environment with de-identified information, clinicians think they’re doing a great thing,” he says. “But it creates a chaotic event.”

The problem isn’t malicious behavior but workflow friction. When approved tools lag behind user needs, clinicians may copy and paste data into consumer-grade AI services to save time, inadvertently exposing PHI.

Traditional perimeter controls are poorly suited to this pattern. So Earle argues organizations need to build what many now call a safe runway for AI innovation — an architectural approach that enables experimentation while containing risk. “You need to create sandboxes to allow clinicians to experiment,” he says. “But make sure the data is de-identified and contained.” In practice, that means tighter data segmentation, automated de-identification pipelines, and isolated environments where models can be tested without touching production PHI.

Another emerging risk lies in how quickly POCs can outgrow their original guardrails. “Proofs of concept are essential, but if they’re not done thoroughly, they can break the framework of the architecture later,” Earle says. The warning highlights a growing concern among healthcare IT leaders that early AI pilots must be designed so governance, identity controls, and monitoring can scale with successful deployments.

srcset=”https://b2b-contenthub.com/wp-content/uploads/2026/03/Cletis-Earle-healthcare-field-CTO-Citrix.jpg?quality=50&strip=all 1800w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Cletis-Earle-healthcare-field-CTO-Citrix.jpg?resize=300%2C200&quality=50&strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Cletis-Earle-healthcare-field-CTO-Citrix.jpg?resize=768%2C512&quality=50&strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Cletis-Earle-healthcare-field-CTO-Citrix.jpg?resize=1024%2C683&quality=50&strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Cletis-Earle-healthcare-field-CTO-Citrix.jpg?resize=1536%2C1024&quality=50&strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Cletis-Earle-healthcare-field-CTO-Citrix.jpg?resize=1240%2C826&quality=50&strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Cletis-Earle-healthcare-field-CTO-Citrix.jpg?resize=150%2C100&quality=50&strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Cletis-Earle-healthcare-field-CTO-Citrix.jpg?resize=1046%2C697&quality=50&strip=all 1046w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Cletis-Earle-healthcare-field-CTO-Citrix.jpg?resize=252%2C168&quality=50&strip=all 252w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Cletis-Earle-healthcare-field-CTO-Citrix.jpg?resize=126%2C84&quality=50&strip=all 126w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Cletis-Earle-healthcare-field-CTO-Citrix.jpg?resize=720%2C480&quality=50&strip=all 720w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Cletis-Earle-healthcare-field-CTO-Citrix.jpg?resize=540%2C360&quality=50&strip=all 540w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Cletis-Earle-healthcare-field-CTO-Citrix.jpg?resize=375%2C250&quality=50&strip=all 375w” width=”1240″ height=”827″ sizes=”auto, (max-width: 1240px) 100vw, 1240px”>

Cletis Earle, healthcare field CTO, Citrix

Citrix

Taken together, these experiences are beginning to crystallize into a recognizable operating pattern across health systems. Rather than pursuing fully autonomous AI, many organizations are advancing through a deliberately staged approach. Assistive-first deployments keep clinicians in control while teams build confidence in model performance and data handling. Risk tiering frameworks help separate low-impact automation from clinically sensitive use cases. And sandboxed environments allow experimentation without exposing production PHI.

At the same time, security teams are tightening third-party reviews and expanding behavioral monitoring while boards demand clearer visibility into AI-related enterprise risk. Education has also become a central pillar. Instead of relying solely on technical blocks, leading organizations are investing in clinician training and transparent communication about where AI can and can’t be used safely.

The result isn’t a slowdown in innovation but a more engineered approach to scale, one that treats compliance and security as design constraints rather than after-the-fact controls.

Compliance by design: the new CIO mandate

For now, assistive AI remains the dominant pattern in healthcare. But most leaders expect the pressure toward greater automation to increase as models improve, and vendors push more advanced capabilities into clinical workflows. That shift will likely reopen many of today’s governance questions at a higher level of urgency. Autonomous ordering, agentic workflows, and cross-system orchestration will introduce new safety and accountability challenges that current frameworks only partially address.

Security teams, in particular, are entering a more turbulent phase. As Torres argues, the real impact of AI-enabled disruption is still ahead, with rising attack velocity and an expanding threat surface likely to test current defenses. Moreover, the current human-in-the-loop equilibrium is unlikely to hold indefinitely.

If there’s a unifying theme across healthcare AI adoption today, it’s that momentum and caution are advancing together. Health systems aren’t pulling back from gen AI. Ambient documentation, clinical summarization, and intelligent workflow support are already delivering tangible benefits. But the organizations moving most confidently are those investing early in governance redesign, architectural containment, and continuous risk monitoring.

The lesson for healthcare CIOs is becoming clear. The challenge is no longer whether to deploy AI, but how to build the guardrails that allow it to scale safely. The future of AI in healthcare will belong to the best runway engineers, not the fastest adopters.


Read More from This Article: Healthcare CIOs rethink AI rollout
Source: News

Category: NewsApril 8, 2026
Tags: art

Post navigation

PreviousPrevious post:La innovación inteligente en pagos transforma cada transacción en crecimiento y confianzaNextNext post:Beyond the gold rush: Hunting for ‘digital eggs’ to secure AI value

Related posts

SAS makes AI governance the centerpiece of its agent strategy
April 29, 2026
The boardroom divide: Why cyber resilience is a cultural asset
April 28, 2026
Samsung Galaxy AI for business: Productivity meets security
April 28, 2026
Startup tackles knowledge graphs to improve AI accuracy
April 28, 2026
AI won’t fix your data problems. Data engineering will
April 28, 2026
The inference bill nobody budgeted for
April 28, 2026
Recent Posts
  • SAS makes AI governance the centerpiece of its agent strategy
  • The boardroom divide: Why cyber resilience is a cultural asset
  • Samsung Galaxy AI for business: Productivity meets security
  • Startup tackles knowledge graphs to improve AI accuracy
  • AI won’t fix your data problems. Data engineering will
Recent Comments
    Archives
    • April 2026
    • March 2026
    • February 2026
    • January 2026
    • December 2025
    • November 2025
    • October 2025
    • September 2025
    • August 2025
    • July 2025
    • June 2025
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024
    • November 2024
    • October 2024
    • September 2024
    • August 2024
    • July 2024
    • June 2024
    • May 2024
    • April 2024
    • March 2024
    • February 2024
    • January 2024
    • December 2023
    • November 2023
    • October 2023
    • September 2023
    • August 2023
    • July 2023
    • June 2023
    • May 2023
    • April 2023
    • March 2023
    • February 2023
    • January 2023
    • December 2022
    • November 2022
    • October 2022
    • September 2022
    • August 2022
    • July 2022
    • June 2022
    • May 2022
    • April 2022
    • March 2022
    • February 2022
    • January 2022
    • December 2021
    • November 2021
    • October 2021
    • September 2021
    • August 2021
    • July 2021
    • June 2021
    • May 2021
    • April 2021
    • March 2021
    • February 2021
    • January 2021
    • December 2020
    • November 2020
    • October 2020
    • September 2020
    • August 2020
    • July 2020
    • June 2020
    • May 2020
    • April 2020
    • January 2020
    • December 2019
    • November 2019
    • October 2019
    • September 2019
    • August 2019
    • July 2019
    • June 2019
    • May 2019
    • April 2019
    • March 2019
    • February 2019
    • January 2019
    • December 2018
    • November 2018
    • October 2018
    • September 2018
    • August 2018
    • July 2018
    • June 2018
    • May 2018
    • April 2018
    • March 2018
    • February 2018
    • January 2018
    • December 2017
    • November 2017
    • October 2017
    • September 2017
    • August 2017
    • July 2017
    • June 2017
    • May 2017
    • April 2017
    • March 2017
    • February 2017
    • January 2017
    Categories
    • News
    Meta
    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org
    Tiatra LLC.

    Tiatra, LLC, based in the Washington, DC metropolitan area, proudly serves federal government agencies, organizations that work with the government and other commercial businesses and organizations. Tiatra specializes in a broad range of information technology (IT) development and management services incorporating solid engineering, attention to client needs, and meeting or exceeding any security parameters required. Our small yet innovative company is structured with a full complement of the necessary technical experts, working with hands-on management, to provide a high level of service and competitive pricing for your systems and engineering requirements.

    Find us on:

    FacebookTwitterLinkedin

    Submitclear

    Tiatra, LLC
    Copyright 2016. All rights reserved.