Responsible AI adoption for healthcare and healthtech
Move AI forward without losing sight of the people affected by it.
Healthcare organizations and the companies building for them are under pressure to use AI to improve care, reduce administrative burden, support clinical decisions, and make limited resources go further. Founders in this space feel a second pressure too: move fast enough to stay competitive, without becoming the next headline about AI gone wrong.
Promising technology is not enough on its own. AI has to fit real clinical and operational workflows, protect sensitive information, support appropriate human judgment, and earn the confidence of patients, professionals, customers, and oversight bodies.
I help healthcare and healthtech organizations understand how AI fits their particular environment, and put practical structures around its responsible use, all without slowing your progress.
When AI adoption outpaces organizational readiness
AI adoption challenges rarely begin with a complete absence of policies or good intentions. They emerge in the gaps between a proposed AI use and the realities surrounding it.
You may be seeing signs such as:
- Teams experimenting with AI before expectations for protected or sensitive information are clear
- AI-enabled features shipping faster than anyone can clearly explain how they were vetted or who is accountable for them
- AI-enabled features advancing without enough input from clinicians, staff members, patients, or other affected groups
- Vendor claims that are difficult for product, clinical, compliance, and technology leaders to evaluate together
- Unclear boundaries between recommendations AI may produce and decisions people must continue to own
- Policies that prohibit too much, explain too little, or don't help employees navigate real situations
- Leaders struggling to explain what safeguards apply, who approves an AI use, or how concerns will be identified after launch
These are more than documentation and policy problems. They're a sign that AI adoption has outpaced the workflows, responsibilities, risk tolerances, and obligations that need to move with it.
Healthcare AI requires more than HIPAA compliance
HIPAA privacy and security obligations remain essential when protected health information is involved. Depending on your organization and technology, other requirements may also affect product transparency, safety, accessibility, clinical oversight, vendor management, and patient rights.
But compliance with any individual requirement doesn't answer every practical question AI creates:
- Is this an appropriate use of AI in this particular context?
- What evidence is sufficient before it moves forward?
- Where is human review necessary?
- What should employees or users be told?
- What happens when the system is wrong, uncertain, or used differently than intended?
- Who has the authority to pause, revise, or retire it?
I use the NIST AI Risk Management Framework as an organizing resource to help examine questions like these. It's one small example of the kind of judgment call every healthcare AI program eventually has to make explicit:
"I've worked with teams who set a confidence threshold — below a certain percentage, a human reviews the output before it goes anywhere near a patient or a clinician. The exact number is almost always a little arbitrary. What matters is that someone owns the decision, writes it down, and builds it into the workflow so no one has to remember it under pressure."
The work I do is adapted to your circumstances, and it complements (not replaces) legal, privacy, security, clinical, and technical expertise.
How I can help
I use a method called REAL (Rooted, Embedded, Actionable, and Legible) to systematically guide recommendations that encompass a robust view of critical decision points.
Establish the ground truth
Through the REAL Diagnostic, I examine how AI is being used or proposed, what your stakeholders need, where friction and risk are already emerging, and what to prioritize next.
Depending on scope, this may include:
- Stakeholder interviews and workflow analysis
- An inventory of AI use cases
- Preliminary risk tiers and ownership recommendations
- Risks mapped to relevant NIST AI RMF considerations
- Responsible AI priorities based on your goals and risk tolerance
- A practical action plan and executive working session
Turn priorities into operating practices
Through the REAL Blueprint, I help organizations with sufficiently clear priorities translate their intentions into a workable responsible AI approach that is built into how work already happens, rather than bolted on.
This can include:
- Practical boundaries and safeguards for AI use
- A process for proposing, reviewing, approving, and reconsidering AI uses
- Defined responsibilities and escalation paths
- A working-group structure and decision-tracking tools
- Leadership guidance and NIST-aligned documentation
- A pilot and feedback plan
Build shared understanding
A customized Get REAL Workshop helps leadership teams, product groups, committees, or staff develop shared language, examine realistic scenarios, and practice making responsible AI decisions together.
Human-centered work for a human-stakes environment
I bring together two decades of research experience, more than a decade working with digital product teams, and direct experience examining responsible AI adoption in healthtech. I work with the people who build, approve, use, support, and may be affected by AI to ensure real-world alignment.
I recently worked with a founder-led healthtech company serving federal clinical clients, whose ~40 employees had all embraced AI enthusiastically — so enthusiastically that no one could quite say who owned which decisions anymore. A 3-week REAL Diagnostic gave their founders a clear use-case inventory and risk picture, and, in their own words, "forced a massive acceleration on visioneering our AI strategy."
Read the Bitscopic case study →Not sure where your gaps are?
The REAL Readiness Snapshot is a free way to start: a short self-assessment on whether your current AI approach is rooted in evidence, embedded in real work, actionable when questions arise, and legible to the people expected to trust it.
You’ll see an instant picture of where you stand, and can request a full report and field guide.
GroundSpring provides responsible AI research, strategy, and governance design. It does not provide legal advice, compliance certification, clinical validation, or technical implementation.