healthcare organizations face challenges in adopting AI while ensuring data protection and regulatory compliance. The report introduces the concept of "defensible AI," defined as AI systems that reliably achieve organizational objectives while meeting rigorous safety, data protection, and regulatory standards. It emphasizes three core concepts for building defensible AI platforms:
-
Control Management: This involves systematically aligning AI functionalities with regulatory requirements and best practices through controls and requirements mapping. The process includes defining necessary controls, translating them into technical specifications, and creating operating guidelines for continuous monitoring and adaptation. An example is using LLMs and NLP to automate control mapping from regulatory documents to frameworks like ISO and NIST, achieving efficient risk assessment and implementation planning.
-
Secure Insights with Synthetic Trends: To balance AI utility and data security, the report proposes using "synthetic trends" derived from abstracted data within embedding spaces. This method preserves statistical properties and behavioral patterns for AI modeling without exposing sensitive data. By training models on synthetic trends, organizations can enhance data utility while ensuring privacy and compliance. The report highlights a case study where synthetic health trends increased machine learning precision by over 16x, unlocking revenue growth potential 10x greater than previous methods, without altering baseline approaches or feature engineering.
-
Secure Health Fabric: The report advocates for a data fabric architecture aligned with a data mesh strategy, creating segregated workspaces controlled by independent teams. This setup allows for decentralized innovation while maintaining centralized oversight through protocols, AI agents, and human-in-the-loop checkpoints. The secure health fabric ensures data integrity and security, supports plug-and-play functionality for diverse AI use cases, and incorporates federated learning (both horizontal and vertical) to combine insights across datasets without compromising confidentiality.
The report concludes by emphasizing the importance of scalable AI management, robust data security, and thoughtful data architecture grounded in rigorous controls and standards. It recommends adopting these principles to lead in the evolving healthcare AI landscape, ensuring innovation aligns with patient care, operational efficiency, and trust. The IQVIA Synthetic Trends Engine and AI Governance and Privacy Operations (AI PrivOps) monitoring are presented as tools to support privacy and security in AI applications.