Overview
Artificial intelligence is transforming how healthcare organizations deliver care, manage operations, and ensure compliance. But with opportunity comes risk—and oversight is no longer optional.
In this episode of Speaking of Health Law, Andrew Mahler, Vice President of Privacy and Compliance Services at Clearwater, is joined by Kathleen Healy, Partner at Robinson Cole, and Robert Martin, Senior Legal Counsel at Mass General Brigham. Together, they break down the legal and operational steps compliance teams can take to assess and monitor AI systems effectively.
Their discussion draws from their presentation at AHLA’s 2025 Complexities of AI in Health Care Conference and offers strategic, real-world insights for building responsible AI oversight programs.
What You’ll Learn
How to design a scalable, risk-based AI governance framework
Key roles in multidisciplinary governance committees
Strategies to assess bias, fairness, and transparency in AI models
How HIPAA and the 21st Century Cures Act intersect with AI deployments
What HHS, FTC, and other regulators are signaling about AI enforcement
Best practices for auditing AI tools post-implementation
Featured Experts
Andrew Mahler, VP, Privacy and Compliance Services, Clearwater
Kathleen Healy, Partner, Robinson Cole
Robert Martin, Senior Legal Counsel, Mass General Brigham
Why It Matters
As AI becomes embedded across healthcare workflows—from clinical decision support to ambient documentation—compliance teams need to stay ahead of rapidly evolving legal and regulatory landscapes. This episode provides practical guidance to help organizations move from reactive oversight to proactive governance.
Take the Next Step
Want to assess your organization’s readiness to manage AI-related risks?
Connect with Clearwater to learn how our privacy, compliance, and cybersecurity experts can support your AI governance strategy.
Schedule a consultation
Clearwater helps healthcare organizations implement:
Comprehensive, OCR-aligned risk analysis and risk response
Purpose-built incident response plans and tabletop exercises
24/7 managed detection and response with IRM|Pro® analytics