Locking Down Corporate AI Usage Webinar
← Back to All Podcasts Locking Down Corporate AI Usage Webinar In this episode, Jason Nadal, Besler Holdings’ and Sypher Security’s Information Security Officer, will provide us with a glimpse into the next Hospital Finance Academy Webinar, “Locking Down Corporate AI Usage,” live on Wednesday, October 7th, at 1 PM ET. Highlights of this episode include: How companies deal with artificial intelligence and how they should make the decision to embrace this technology What the benefits and detriments of AI usage are What tools out there to help protect your company and your data What other challenges you have in keeping aware of AI usage How you manage third parties not directly under your control The key takeaways Subscribe Today! Kelly Wisness: Hi, this is Kelly Wisness . Welcome back to the award-winning Hospital Finance Podcast . We’re pleased to welcome back Jason Nadal , Besler Holdings’ and Sypher Security’s Information Security Officer. In this episode, Jason will provide us with a glimpse into our next Hospital Finance Academy Webinar, “ Locking Down Corporate AI Usage ,” live on Wednesday, October 7th, at 1 PM Eastern Time. Welcome back, and thank you for joining us, Jason. Jason Nadal: Hi. Thanks for having me. Kelly: All right. Well, let’s go ahead and jump in. So, we know artificial intelligence is everywhere now. How should companies deal with this and make the decision to embrace this technology? Jason: Well, if you run a company right now, somebody on your team is likely already using AI. So ideally, that would be via an approved path that you have already set up, but maybe it’s just a browser tab they opened up at lunch, putting something in Google and getting AI results. Either way, the question is not, “Should we use AI?” It’s already embedded in a lot of the approved corporate tools that are already out there. So, the question is, “Do we know what we allow, what we forbid, and how do we keep that promise when the tools keep changing under our feet?” So those are the kinds of conversations that security and IT folks have when leadership asks for a practical plan around AI. So, over the next 10 minutes or so, I’ll walk through some of the benefits and risks. We’ll get into that a bit deeper during the webinar that’s upcoming, but this will give you a methodology of control you can actually run, some of the categories of tooling that support it, and the challenge of feature creep in tools that you’ve already approved. And we’re also going to look at how a vendor and open-source software assessment has to catch up. Kelly: Yeah. I mean, it is really everywhere. It’s embedded in everything now, it seems like. [laughter] Yeah. It’s a lot to keep up with. So, what are the benefits and detriments of AI usage? Jason: Sure. There’s a lot of benefits, and there’s definitely a lot of detriments as well. So, AI earns its value when it shortens the work that you’re already doing, especially that work that used to waste a lot of your time through just tedium, repeated tasks, and things like that. So, I find it really shines at drafting, summarizing, searching or researching, coding assists, and also triaging helpdesk tickets. So those are real-time gains when the data and the use case match the risk. So, in healthcare and adjacent work, that might be a little less clear. So, a nurse or revenue cycle analyst can summarize a long chart note, draft a patient letter, or speed up some prior auth paperwork. A cost report or appeals team can find patterns faster. So done carefully, ideally with this human oversight as to what’s produced, that is time returned to care and to accurate billing. But the downside is just as concrete. So, paste the wrong note into a public chatbot, and you may have moved protected health information, PHI, or something else confidential or sensitive, outside your control. So, a helpful summarizer can invent a fact, called hallucinations, that then gets treated like clinical or financial truth. There’s really a huge downside to that if it’s not checked over by humans with clinical experience. An automation that writes into scheduling, ticketing, or an EHR-adjacent system can turn a bad model answer into a real patient or operations problem. Outside of healthcare, the pattern is much the same. So, marketing could paste customer lists into a public model. Finance could paste financial forecasts. Engineering could paste source code or API keys, maybe in a hurry or just this one time, and leak information that you don’t really intend to leak. Legal can paste contract language. You get the benefit of speed, but the detriment of leaking your data, over trusting the AI, and a trail that, once it’s out there, you can’t really tidy it up after the fact. So, a key point to establishing governance is having frank discussions of what data is acceptable to this risk if it were to leak. I really can’t say that one enough. Kelly: Yeah, I mean, I know that in marketing we use it quite a bit, but I mean, you all help us really understand what we’re really in for there. So, I know there’s a lot to keep in mind. So how do you lock this down without pretending people will stop being curious? Jason: So yeah, you do need this methodology. The first thing I’d say, write an AI usage statement. This is your company’s position on how AI is used. Let it have plain language that’s easily readable. And this company position will include what interactions are allowed and what are not. Who’s able to use what classes of AI? What data classes may never leave the building? It may not just be PHI or employee data. It could be financials, as we said before, or just confidential mergers and acquisition information. So, what AI interactions require a human in the loop? What happens when someone isn’t sure? They should always be trained to ask before they just paste data in somewhere. Publish this conspicuously, train on it, and make sure that people know what’s appropriate to do with their AI. Refresh it when the landscape moves. So, if you don’t have a written position, every employee is going to have their own assumptions on what is good or bad. That’s not really empowerment. That’s just risk that’s out there unmanaged. I’d also recommend don’t write this usage statement from scratch. See what others in the industry, especially your industry, are doing, and tailor what’s out there to yourself. Secondly, you should assess the AI that is in question, the AI that you want to use in any given situation. When a third party uses AI in a product that you buy, treat that as part of vendor due diligence. Ask the vendor, “Where are these models running?” Ask whether the prompts or the outputs of those prompts are retained with them or are they used for training. Ask about sub-processors. Maybe that vendor is using somebody else to do their AI work. Ask also whether AI features can write back into your system. Don’t just accept a blanket, “We’re AI-powered,” as a checkbox. You need enough clarity to decide, yes, this is an acceptable risk. No, this isn’t going to work for us. Or yes, but we need these conditions in place to feel good about the risk of using this tool. And keep logs. Review those regularly. What is not AI today might become AI tomorrow. I’m sure all of us have seen an application that we’ve used online tha...

