According to a review on Artificial Intelligence in Healthcare: Current Regulatory Landscape and Future Directions, AI has the potential to “increase clinical efficiency, improve patient outcomes, and reduce the number of healthcare workers required.” However, healthcare systems relying on AI must overcome “regulatory, ethical, implementation, social, and technical challenges.”
AI in healthcare
AI is a broad term covering computerized systems capable of performing tasks or reasoning processes commonly associated with human intelligence. The review explains that AI can involve technologies including machine learning (ML), natural language processing (NLP), computer vision, and deep learning (DL).
In healthcare, machine learning allows computer programs to make decisions based on experience and is commonly used for predictive modeling and disease diagnosis. NLP helps computers interpret and generate human language, while deep learning uses multilayered neural networks to analyze large datasets.
These technologies can be combined in healthcare applications that manage large amounts of clinical information, especially when dealing with the increasing chronic disease prevalence and rising medical costs. AI therefore augments human expertise, helping providers process information, recognize patterns, identify risks, and make more informed decisions.
Examples of how AI is being used in medicine
The review notes that AI applications span radiography, computed tomography (CT), magnetic resonance imaging (MRI), and ultrasound. At present, more than 100 AI/ML-based medical devices have been approved for radiological use in the United States and Europe. More specifically, radiology is described as “one of the most transformative applications of AI in the clinic.”
Another use is in the field of pathology, where machine learning algorithms can identify patterns in histological images, potentially accelerating diagnosis and improving the detection of subtle abnormalities associated with diseases, like cancer. AI could also help providers identify relationships between pathological features and genetic alterations.
In cardiology, AI applications can support echocardiography, cardiac MRI, CT angiography, and other diagnostic modalities as it assists with segmentation and interpretation. Additionally, predictive models that combine clinical and genomic information could eventually help create personalized risk profiles and support earlier intervention for cardiovascular diseases, like heart failure and coronary artery disease. This could lead to more targeted and effective treatments for individuals at higher risk for these conditions.
AI can also support surgery through preoperative planning and help identify patients at increased risk of postoperative complications. AI-powered robotic systems may additionally provide surgeons with better dexterity and precision.
Furthermore, AI can contribute to telemedicine, wearable technologies, biomedical research, clinical trials, public health, and healthcare administration, where it can be used to improve patient-flow management, billing, supply chains, and standardized coding.
Ultimately, AI is a collection of computational approaches that can help assist providers in treating patients at different stages of the clinical course.
AI and personalized healthcare
The abovementioned review study states that “integrating clinical, imaging, and genomic data, predictive models powered by AI may be able to create personalized risk profiles and support proactive interventions…”
AI can process these large datasets to identify relationships and patterns that may be difficult to evaluate manually. The review states that machine learning algorithms can analyze patient data to determine optimal treatment strategies at an individualized level. This could improve treatment outcomes, “for millions of patients worldwide.”
However, personalization is only valuable when the underlying data are reliable, representative, and appropriately protected. An AI system can produce sophisticated predictions without necessarily producing clinically appropriate recommendations.
Addressing algorithmic bias
One of the biggest concerns when it comes to implementing AI systems is producing equitable results. Since AI models learn from data, weaknesses in training datasets can potentially influence their outputs.
The review describes algorithmic bias as a critical ethical concern because AI systems may inadvertently prioritize variables that favor one group over another. In healthcare, this could affect decision-making strategies as healthcare populations are diverse. AI systems developed using narrow or unrepresentative datasets may not perform equally well across different communities.
To minimize these biases, the review suggests training AI systems on diverse datasets and regularly auditing their performance. AI developers and healthcare organizations can use these processes to identify disparities and determine whether models perform consistently across relevant patient groups.
For example, they can analyze the impact of demographic factors such as race, ethnicity, and socioeconomic status on the accuracy of AI predictions. Like, if an African-American patient receives a different diagnosis compared to a Caucasian patient with similar symptoms, it could indicate a potential bias in the AI system that must be addressed.
The problem of the ‘black box’
Healthcare providers must understand why an AI system has produced a particular recommendation, especially when that recommendation could influence clinical decisions.
However, some machine learning and deep learning models are difficult to interpret. The review refers to this concept as the “black box” of certain AI models and states that “explainability is crucial in healthcare, where patients have the right to understand the rationale behind their care.”
The review therefore suggests explainable AI and more transparent “glass box” approaches to improve patient-provider trust. Greater transparency can also help providers understand the strengths and limitations of AI tools, helping them use their outputs more responsibly.
Who is responsible when AI makes a mistake?
“Determining roles and responsibilities for accountability and liability of AI-enabled judgements in healthcare is difficult due to the large number of actors involved from design to implementation,” the study explains. Some of these actors include the developers who design the algorithms, organizations that select and deploy technologies, clinicians who interpret outputs, and the vendors who update systems.
So, who is responsible when an AI-supported clinical decision leads to patient harm?
The review suggests that AI be implemented as part of a governance structure where developers and organizations have defined their obligations concerning system performance, monitoring, safety, and data protection.
Comparing AI regulation around the world
“In April 2021, the European Commission proposed an AI Act that addresses security and human rights concerns across EU member states.” This is a risk-based approach that incorporates the AI Act alongside frameworks like the General Data Protection Regulation (GDPR) and Medical Devices Regulation. Healthcare AI applications that fall into high-risk categories face requirements relating to areas such as data governance, risk management, integrity, honesty, transparency and accountability.
The United Kingdom is developing its own regulatory approach through organizations including the Medicines and Healthcare products Regulatory Agency (MHRA) and initiatives such as the “NHS AI Lab, established by the National Health Service (NHS).” The review describes the UK approach as one that “focuses on developing rigorous standards for evidence and validation, as well as emphasizing transparency in use of AI tools within the NHS.”
The United States takes a more decentralized approach, with the Food and Drug Administration (FDA) regulating AI-enabled medical devices and software. “The FDA’s approach to AI regulation is based on a framework that categorizes AI applications based on the level of risk they pose to patients,” the review adds. The FDA also affirms a “total product lifecycle” approach, recognizing that AI/ML systems can change over time as they learn from new data.
Protecting patient privacy
The review identifies patient privacy as a central ethical issue associated with AI in healthcare, stating that “at the heart of these ethical issues is patient privacy.” This concern stems from AI systems’ reliance on healthcare datasets that contain protected health information (PHI), including medical histories, diagnostic results, genetic information, and other medical details.
It warns that misuse or unauthorized disclosure of sensitive information can result in consequences including discrimination, social stigma, and financial harm. AI systems can also be vulnerable to cybersecurity threats such as data breaches.
In the United States, the Health Insurance Portability and Accountability Act (HIPAA) establishes the requirements for safeguarding patients’ PHI. Therefore, healthcare organizations using AI must protect patient health information throughout the data lifecycle. Organizations must also understand what information an AI system collects, where that information is stored, who can access it, how it is transmitted, and how it is ultimately used.
AI governance cannot be separated from healthcare data governance. If an AI tool is integrated with electronic health records (EHR) or other clinical systems, appropriate safeguards should extend across these different platforms.
Using HIPAA compliant email to support AI-enabled care
AI recommendations and outputs should be communicated between healthcare providers, patients, and other members of the care team. For example, an AI system may identify a potential risk or generate information that is useful to a clinician, but that information still must move through the healthcare organization while still safeguarding PHI.
The U.S. Department of Health and Human Services (HHS) confirms that HIPAA does not prohibit healthcare providers from using email. HHS states that the Privacy Rule allows providers to communicate electronically with patients “provided they apply reasonable safeguards when doing so.” HHS also explains that providers should use appropriate safeguards for electronic PHI and consider limiting the information disclosed via email.
For organizations using AI, protecting the AI model itself is not enough if sensitive information is subsequently copied into standard email, like Google or Outlook. HHS guidance recommends communication mechanisms that allow organizations to implement Security Rule safeguards, including systems that encrypt messages or require patient login. HHS specifically states that healthcare providers may use email to communicate with other healthcare professionals and patients “as long as you use safeguards.”
HIPAA compliant email solutions, like Paubox, meet these requirements, offering advanced encryption and audit controls to help providers uphold HIPAA regulations. Paubox email also complements AI-enabled workflows.
For example, an AI-supported clinical system could help identify information requiring clinician attention, while secure email facilitates the subsequent communication of PHI. Providers can also use HIPAA compliant emails to send personalized follow-up care instructions, referrals, patient education, and coordinate treatment plans.
The way forward for AI and secure communication
The review states that “stakeholder collaboration is also critical to ensuring robust AI systems, ethics, and patient and provider trust.” Healthcare providers need sufficient education to understand AI outputs, recognize potential bias, and appreciate the privacy implications of AI-enabled systems.
Developers must design technologies that are transparent, secure, clinically appropriate, and responsive to regulatory requirements. Policymakers, meanwhile, must create frameworks that protect patients while supporting innovation.
The review proposes greater international coordination, including common standards, governance structures, and ongoing monitoring mechanisms. It argues that regulatory systems must be capable of adapting as new AI technologies are introduced.
The bottom line
As the review concludes, using AI in healthcare can improve “diagnosis, personalized treatment, and operational efficiency,” but realizing that potential requires safeguards that protect patients and maintain trust. The authors also add that “ethical AI development requires a commitment from both developers and institutions to prioritize patient safety, privacy, and fairness.”
Ultimately, patient privacy, cybersecurity, bias, explainability, accessibility, accountability, and regulatory compliance must be considered alongside clinical performance.
Related: How AI promises a healthier future
FAQs
Can AI improve personalized patient education?
Yes, providers can use AI to analyze patient data to generate customized educational materials, like articles, videos, or interactive modules, addressing specific health concerns and challenges.
Can AI be integrated into HIPAA compliant emails?
Yes, AI-powered features can be integrated with HIPAA compliant emailing platforms, like Paubox, to automate processes like patient consent management and sending personalized emails while maintaining HIPAA compliance.
Are there any limitations when using AI in HIPAA compliant emails?
Yes, healthcare providers must ensure that AI-powered features comply with HIPAA regulations and industry best practices for data security and privacy. Additionally, providers should evaluate the reliability of AI algorithms to avoid potential risks or compliance issues.
Read also: HIPAA compliant email API
