Jordan T. Cohen, who leads Akerman's Digital Health Team, joined the Healthcare Info Security podcast to discuss the data governance measures healthcare organizations should adopt as they implement agentic artificial intelligence, stressing the importance of a thorough data inventory and a clear understanding of what data can and cannot be used under HIPAA and other laws.
"A data flow inventory is going to be really important. So diagramming and accounting for how you're ingesting data, processing it, storing it and how it's leaving your systems, how vendors are touching it and what they're doing to that data is going to be critical," he said.
Jordan warns that mishandled data carries stakes beyond internal risk management, extending to direct regulatory exposure. "If you fall outside of a permissible use, then technically, if protected health information is involved, that can be considered a reportable breach," he said. He advises healthcare organizations to map how agentic AI tools are being used across clinical and administrative functions and what patient data they touch. From there, he says, organizations need to build in safeguards, from incident response to patient consent, from the outset.
Jordan also discussed how the same tools driving these risks can create opportunities to improve data privacy and security across healthcare and other sectors.