惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

C
Cybersecurity and Infrastructure Security Agency CISA
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Latest news
Latest news
L
LINUX DO - 热门话题
Cisco Talos Blog
Cisco Talos Blog
S
Securelist
T
Threatpost
AWS News Blog
AWS News Blog
P
Privacy & Cybersecurity Law Blog
C
CERT Recently Published Vulnerability Notes
B
Blog RSS Feed
T
Threat Research - Cisco Blogs
P
Proofpoint News Feed
T
Tor Project blog
P
Palo Alto Networks Blog
博客园 - 三生石上(FineUI控件)
人人都是产品经理
人人都是产品经理
M
MIT News - Artificial intelligence
云风的 BLOG
云风的 BLOG
H
Help Net Security
小众软件
小众软件
C
Cisco Blogs
有赞技术团队
有赞技术团队
Cyberwarzone
Cyberwarzone
雷峰网
雷峰网
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Apple Machine Learning Research
Apple Machine Learning Research
S
Schneier on Security
The GitHub Blog
The GitHub Blog
Y
Y Combinator Blog
The Register - Security
The Register - Security
Project Zero
Project Zero
Hugging Face - Blog
Hugging Face - Blog
The Cloudflare Blog
V
Vulnerabilities – Threatpost
Security Latest
Security Latest
爱范儿
爱范儿
A
About on SuperTechFans
T
The Exploit Database - CXSecurity.com
P
Privacy International News Feed
A
Arctic Wolf
大猫的无限游戏
大猫的无限游戏
V
V2EX
Stack Overflow Blog
Stack Overflow Blog
K
Kaspersky official blog
Scott Helme
Scott Helme
Spread Privacy
Spread Privacy
The Hacker News
The Hacker News
H
Hackread – Cybersecurity News, Data Breaches, AI and More

WhatIs

Hims & Hers launches AI agent for lab results Twilio revamps, updates customer engagement platform CISA launches critical infrastructure cyber resilience initiative Most patients find appointment scheduling, billing overly complex Teradata's latest targets putting agentic AI into production AHA, Joint Commission launch cyber resilience program Tableau in transition as AI forces BI vendors to evolve California hospitals sue Elevance over out-of-network penalty CMS Health Tech Ecosystem adds electronic prior auth pledge Atlassian MCP updates take aim at AI token usage Leapfrog: Hospitals improved in 17 patient safety measures United promises another 30% cut to prior auths in 2026 AI outperforms docs on clinical reasoning, but not ready for solo work ServiceNow's Autonomous CRM takes aim at Salesforce ServiceNow reintroduces itself as an AI 'security company' New Tableau leader talks vendor's evolution in era of AI Deloitte warns of a "bubble effect" caused by the GLP-1 boom Tableau repositions for AI, unveils new knowledge layer IBM Bob AI coding agent ships, HashiCorp AIOps previewed DOJ forms West Coast Strike Force to stop healthcare fraud Most people benefit from the ACA's free preventive services SAP acquisitions of Dremio, Prior Labs target AI development Bridging the gap: Legacy tools gain enterprise AI support Amazon Connect Talent: AWS enters AI interviewing market AHA, West Health launch health tech adoption initiative How are states preparing for Medicaid work requirements? Medical device security improves, but cyberattacks remain pervasive Weekly news roundup: Musk vs. Altman, Google’s Pentagon AI deal, China and EU hit Meta Skin substitute spending driven by patients, products, prices Clinical AI company Aidoc snags $150M in new funding Qlik's Capone departs after eight years as CEO OIG: CMS paid millions in improper virtual care payments FDA moves toward real-time review of clinical trial data FQHCs in low-income neighborhoods have lower cancer screening rates Solving quantum computing's longstanding no-cloning problem Qdrant boosts performance, reliability to meet AI needs Racial health disparities still impact U.S. as policy changes loom Agentforce Operations tackles workflow orchestration Boehringer's dual agonist obesity drug spurs up to 16.6% weight loss Legacy architecture, awareness gaps stifle microsegmentation adoption in healthcare AMA alerts officials of health plans' No Surprises Act abuse Latest SAS capabilities focus on fostering reliable AI AHA calls for TEFCA individual access SOP delay, citing patient privacy concerns Actian targets secure, compliant AI with new vector database Payers promise standardized electronic prior auths MIT EmTech: 2026 is the year AI goes to work As Claude Design debuts, Adobe users -- and buyers -- shrug GoodData joins agentic AI development mix with Agent Builder Comfort, affordability top drivers of digital mental health tool use CMS accelerates Medicare coverage for breakthrough medical devices Weekly news roundup: Tim Cook exits Apple, Meta layoffs intensify and Anthropic investigates Claude Merck inks $1 billion AI drug development deal with Google Cloud OCR settles four HIPAA investigations, prioritizes risk analysis OpenAI launches ChatGPT for Clinicians 90% of patients re-check AI chatbot health info with other sources Gemini Enterprise Agent Platform adds 'connective tissue' to Vertex AI AMA urges greater oversight of AI mental health chatbots CMS benches BALANCE Model for Medicare Former ransomware negotiator pleads guilty to BlackCat conspiracy New Google TPUs multiply AI infrastructure efficiency When brand-name drugs need a prior auth, brace for delays Google unveils data cloud purpose built for agentic AI Snowflake updates further goal of being control pane for AI UnitedHealthcare eliminates prior authorization for rural providers Yelp launches appointment scheduling button from Zocdoc Oracle takes steps toward CMS Health Tech Ecosystem goals OpenAI debuts AI model GPT-Rosalind to speed up drug discovery Which patient care access barriers deter cancer screening? Redis unveils Feature Form to improve AI, ML workloads Adobe defines its AI-powered customer experience platform How to escape agentification pilot purgatory for scalable AI Data quality, fast failures and quick wins key to AI success Stop Overpaying for Storage: A FinOps Guide for CIOs AWS launches AI-driven tool to speed up early-stage antibody discovery AMA: Clinician burnout in specialties persists as overall rates drop Mental health parity remains elusive in 43 states Before revenue cycle AI, payers and providers need to get along Edge and physical AI poised to upend enterprise networks Salesforce releases Agentforce dev tools, updates Agent Fabric Cyberattack continues to disrupt operations at Signature Healthcare FDA reminds sponsors, researchers to report clinical trial results AI arms race leading to prior auth problems, reimbursement cuts Abridge dives deeper into clinical decision support with NEJM, AMA AI provider search is here. How can health orgs stay visible? Judge dismisses No Surprises Act lawsuit against HaloMD What IT leaders should know from Nutanix .NEXT HubSpot builds answer engine optimization into its platform Sutter Health, MemorialCare face class action lawsuit over AI scribe use Latest Qlik tools target helping users achieve AI goals CMS taps Verily, Noom, 150+ others to participate in ACCESS model Starburst intros AI assistant to boost analysis, exploration Payers face faster prior authorization approvals under CMS proposal Lenovo deploys AI data agent for marketing, UX, e-commerce Cisco Galileo buy reflects blurring lines in AI observability CMS proposes 2.4% IPPS bump, joint replacement model expansion Patients unsure what to trust amid health information overload Nutanix expands flexibility by building out external storage Amazon Pharmacy adds Lilly's obesity pill with same-day delivery ServiceNow AI pricing change takes on enterprise ROI struggles Oracle's Sudha Raghavan on AI's infrastructure renaissance
New HSCC guidance tackles third-party AI risk
2026-04-17 · via WhatIs

Jill Hughes

By

Published: 17 Apr 2026

As healthcare organizations continue to embrace AI-powered tools, effective third-party risk management strategies and supply chain transparency remain essential to safeguarding operations. As such, the Health Sector Coordinating Council (HSCC) developed guidance to identify critical third-party AI risks and provide recommendations for managing them. 

The HSCC established a third-party task group on AI risk and supply chain transparency, composed of industry leaders, to explore these issues. It encouraged healthcare organizations to distribute the document to senior leadership and evaluate their own third-party and supply chain risk management programs against the best practices outlined in the guidance. 

"The healthcare sector's accelerating adoption of artificial intelligence has dramatically expanded its dependence on third-party tools and services, introducing complex cybersecurity challenges that traditional risk management models cannot adequately address," the document stated.  

Third-party AI tools come with hidden risks 

From AI-driven clinical decision support tools to revenue cycle automation and remote monitoring devices, AI is quickly becoming embedded in healthcare systems. While these tools promise great value, they also open healthcare organizations up to unprecedented risk, the task group suggested.  

Those risks include limited visibility into AI components sourced through supply chains, challenges with verifying vendor security postures and vendors shifting risk to healthcare organizations using one-sided contract language.  

What's more, issues like unreported AI cybersecurity risks, such as training data leakage and synthetic data misuse, can put healthcare organizations in a difficult position when it comes to managing security and compliance. 

"Acceleration of change of AI infrastructure, algorithms, and models at unprecedented rates introduce complexity, steep learning curves, an ever-evolving set of new and updated risks, and an exponentially complex and broad attack surface," the document added. 

The task group stressed that organizations of all sizes and sophistication levels can and should adopt its best practices as they work to balance AI innovation with cybersecurity risk. 

Best practices, implementation guidance 

The HSCC identified several best practices centered on governance, legal protections and tried-and-true cybersecurity protocols. The document also provides detailed guidance on every phase of AI adoption, from vendor evaluation to ongoing performance management. 

Under HIPAA, healthcare organizations are required to maintain technical and administrative safeguards to protect against cyber risks. However, HIPAA was enacted in 1996, long before the widespread adoption of AI changed the nature of healthcare ecosystems. 

The HSCC's guidance outlines AI-specific considerations for established best practices, highlighting the ways in which healthcare organizations should evaluate, adopt and maintain AI-powered technologies. 

The recommended best practices include developing comprehensive AI governance policies, AI use-case justification requirements and model contract language that addresses data ownership, AI training and performance standards. The guidance also suggests that organizations include AI-specific clauses in their business associate agreements. 

Inventory and asset management, quality assurance, model validation and response and recovery planning -- in coordination with AI vendors -- are all crucial to mitigating risk, the guidance document notes.  

Putting these best practices to use requires a measured approach and will look different depending on organization size and sophistication. Regardless of size, healthcare organizations using AI should establish AI governance bodies, enact shared responsibility models with AI vendors and manage the AI lifecycle from initial procurement to end-of-life, the HSCC said. 

As healthcare organizations continue to integrate AI into their workflows, they must carefully consider third-party risk management and vendor transparency. 

Jill Hughes has covered health tech news since 2021.

Dig Deeper on Cybersecurity strategies