惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
雷峰网
雷峰网
S
SegmentFault 最新的问题
博客园 - 【当耐特】
博客园_首页
量子位
爱范儿
爱范儿
博客园 - 叶小钗
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Jina AI
Jina AI
V
V2EX
美团技术团队
V
Visual Studio Blog
博客园 - 三生石上(FineUI控件)
IT之家
IT之家
Hugging Face - Blog
Hugging Face - Blog
Apple Machine Learning Research
Apple Machine Learning Research
小众软件
小众软件
博客园 - 聂微东
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
The Cloudflare Blog
宝玉的分享
宝玉的分享
WordPress大学
WordPress大学
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻

WhatIs

Hims & Hers launches AI agent for lab results Twilio revamps, updates customer engagement platform CISA launches critical infrastructure cyber resilience initiative Most patients find appointment scheduling, billing overly complex Teradata's latest targets putting agentic AI into production AHA, Joint Commission launch cyber resilience program Tableau in transition as AI forces BI vendors to evolve California hospitals sue Elevance over out-of-network penalty CMS Health Tech Ecosystem adds electronic prior auth pledge Atlassian MCP updates take aim at AI token usage Leapfrog: Hospitals improved in 17 patient safety measures United promises another 30% cut to prior auths in 2026 AI outperforms docs on clinical reasoning, but not ready for solo work ServiceNow's Autonomous CRM takes aim at Salesforce ServiceNow reintroduces itself as an AI 'security company' New Tableau leader talks vendor's evolution in era of AI Deloitte warns of a "bubble effect" caused by the GLP-1 boom Tableau repositions for AI, unveils new knowledge layer IBM Bob AI coding agent ships, HashiCorp AIOps previewed DOJ forms West Coast Strike Force to stop healthcare fraud Most people benefit from the ACA's free preventive services SAP acquisitions of Dremio, Prior Labs target AI development Bridging the gap: Legacy tools gain enterprise AI support Amazon Connect Talent: AWS enters AI interviewing market AHA, West Health launch health tech adoption initiative How are states preparing for Medicaid work requirements? Medical device security improves, but cyberattacks remain pervasive Weekly news roundup: Musk vs. Altman, Google’s Pentagon AI deal, China and EU hit Meta Skin substitute spending driven by patients, products, prices Clinical AI company Aidoc snags $150M in new funding
New HSCC guidance tackles third-party AI risk
2026-04-17 · via WhatIs

Jill Hughes

By

Published: 17 Apr 2026

As healthcare organizations continue to embrace AI-powered tools, effective third-party risk management strategies and supply chain transparency remain essential to safeguarding operations. As such, the Health Sector Coordinating Council (HSCC) developed guidance to identify critical third-party AI risks and provide recommendations for managing them. 

The HSCC established a third-party task group on AI risk and supply chain transparency, composed of industry leaders, to explore these issues. It encouraged healthcare organizations to distribute the document to senior leadership and evaluate their own third-party and supply chain risk management programs against the best practices outlined in the guidance. 

"The healthcare sector's accelerating adoption of artificial intelligence has dramatically expanded its dependence on third-party tools and services, introducing complex cybersecurity challenges that traditional risk management models cannot adequately address," the document stated.  

Third-party AI tools come with hidden risks 

From AI-driven clinical decision support tools to revenue cycle automation and remote monitoring devices, AI is quickly becoming embedded in healthcare systems. While these tools promise great value, they also open healthcare organizations up to unprecedented risk, the task group suggested.  

Those risks include limited visibility into AI components sourced through supply chains, challenges with verifying vendor security postures and vendors shifting risk to healthcare organizations using one-sided contract language.  

What's more, issues like unreported AI cybersecurity risks, such as training data leakage and synthetic data misuse, can put healthcare organizations in a difficult position when it comes to managing security and compliance. 

"Acceleration of change of AI infrastructure, algorithms, and models at unprecedented rates introduce complexity, steep learning curves, an ever-evolving set of new and updated risks, and an exponentially complex and broad attack surface," the document added. 

The task group stressed that organizations of all sizes and sophistication levels can and should adopt its best practices as they work to balance AI innovation with cybersecurity risk. 

Best practices, implementation guidance 

The HSCC identified several best practices centered on governance, legal protections and tried-and-true cybersecurity protocols. The document also provides detailed guidance on every phase of AI adoption, from vendor evaluation to ongoing performance management. 

Under HIPAA, healthcare organizations are required to maintain technical and administrative safeguards to protect against cyber risks. However, HIPAA was enacted in 1996, long before the widespread adoption of AI changed the nature of healthcare ecosystems. 

The HSCC's guidance outlines AI-specific considerations for established best practices, highlighting the ways in which healthcare organizations should evaluate, adopt and maintain AI-powered technologies. 

The recommended best practices include developing comprehensive AI governance policies, AI use-case justification requirements and model contract language that addresses data ownership, AI training and performance standards. The guidance also suggests that organizations include AI-specific clauses in their business associate agreements. 

Inventory and asset management, quality assurance, model validation and response and recovery planning -- in coordination with AI vendors -- are all crucial to mitigating risk, the guidance document notes.  

Putting these best practices to use requires a measured approach and will look different depending on organization size and sophistication. Regardless of size, healthcare organizations using AI should establish AI governance bodies, enact shared responsibility models with AI vendors and manage the AI lifecycle from initial procurement to end-of-life, the HSCC said. 

As healthcare organizations continue to integrate AI into their workflows, they must carefully consider third-party risk management and vendor transparency. 

Jill Hughes has covered health tech news since 2021.

Dig Deeper on Cybersecurity strategies