Data Governance & PHI Protection
We apply strict data governance controls to all AI systems that interact with patient data:
- PHI is never used to train AI models without explicit authorization or a valid waiver.
- A Privacy Impact Assessment (PIA) is conducted before any AI system processes PHI.
- De-identification is applied where full PHI is not required.
- Data lineage is documented for all PHI flowing through AI pipelines.
- Training data is validated for completeness, accuracy, and representativeness, and monitored for drift.