1. Treat PHI routing as the first design decision
Why: Unauthorized PHI disclosure is a reportable breach with per-record penalties — and shadow usage by staff is the most common way it happens.
In medicine, an AI mistake can harm a patient and a privacy slip is a legal event. The playbook: keep clinicians in the loop, keep PHI out of unauthorized systems, and validate on your own population before trusting any benchmark.
Why: Unauthorized PHI disclosure is a reportable breach with per-record penalties — and shadow usage by staff is the most common way it happens.
Why: Models hallucinate plausibly, and in medicine plausible-but-wrong is the dangerous kind. Review keeps accountability with a licensed human, which is also what regulators expect.
Why: Models degrade across sites — different populations, equipment, and documentation styles. Subgroup checks catch bias that aggregate accuracy hides.
Why: Reclassification after launch means pulling the product; the boundary between wellness/admin tools and regulated devices is where legal review earns its keep.
Why: Early recoverable wins build the audit, review, and monitoring muscles you'll need before any patient-facing decision support goes live.
The proven wins in 2026 are unglamorous: ambient scribing that drafts the visit note, coding and prior-authorization assistance, inbox triage, and discharge-summary drafting. They share a shape — the AI does the typing, a clinician does the deciding — and they free hours per clinician per week without creating a new category of clinical risk.
The failure pattern is equally consistent: pilots that skipped the BAA conversation, staff quietly using consumer chatbots with patient data, and decision-support tools deployed on benchmark trust that didn’t survive contact with the local patient population. Every item in the checklist above traces back to one of those three stories.