Table of Contents
Summarize and analyze this article with
You cannot govern the AI you never listed
Score inherent risk from the clinical decision
| Attribute | What to capture | Example |
|---|---|---|
| Decision type | What the tool decides or influences | Screening, triage, diagnosis support, coverage, documentation |
| Population affected | Who is subject to the decision | All ED patients; a specific condition cohort |
| Consequence if wrong | Harm if the output is wrong and acted on | Missed acuity; inappropriate denial; erroneous note |
| Human position | Whether a clinician acts before the consequence | Clinician reviews before order vs after the effect |
Map each system to the obligations that apply
- HTI-1 transparency : Where a certified EHR surfaces predictive decision-support interventions, record the source attributes and transparency information the rule expects.
- HIPAA : Record whether the tool creates, receives, or transmits PHI, and whether a business associate agreement is in place.
- Coverage and utilization-management rules : For tools that inform coverage or medical-necessity decisions, record where human authority sits, consistent with the state and CMS rules governing those decisions.
- Materiality threshold : Write down what qualifies for inclusion so shadow AI, adopted team by team, is captured rather than missed.
Where PiTech fits
The bottom line
Frequently Asked Questions (FAQs)
What is a healthcare AI inventory?
Why score healthcare AI risk from the decision rather than the vendor?
How does HTI-1 affect a healthcare AI inventory?
HTI-1, the ONC rule addressing decision-support interventions in certified health IT, expects transparency about predictive decision-support interventions surfaced through the EHR, including source attributes that let users understand and evaluate them. In an inventory, that means recording, for each decision-support intervention, the transparency information the rule anticipates, so the health system can demonstrate it. HTI-1 does not cover every AI tool a health system uses, so the inventory must map each system to the obligations that actually apply to it rather than assuming one rule governs all. Confirm the current HTI-1 requirements and timelines at implementation, as health-IT rules continue to evolve.
Should shadow AI be in the inventory?
What is the difference between inherent and residual risk for clinical AI?
How do we inventory AI embedded in our EHR or other software?
Who should own the healthcare AI inventory?
Ownership should be central enough to enforce a consistent threshold and scoring approach, but informed by the clinical, IT, compliance, and operational teams who know where AI actually runs, including the embedded and shadow tools. A common failure is leaving the inventory to a single function that only sees centrally procured systems, which produces an incomplete list. Effective ownership pairs a central governance function with active discovery across departments, so the inventory reflects real use rather than procurement records. The inventory should feed the broader AI governance program, informing monitoring, human-review design, and reporting, rather than existing as a static compliance document.
How does an AI inventory support HIPAA compliance?
By recording, for each AI system, whether it creates, receives, maintains, or transmits protected health information and whether a business associate agreement is in place with the vendor. Many AI tools, including ambient scribes and cloud-based analytics, handle PHI and make their vendors business associates, so the inventory is where a health system tracks that these agreements exist and that data handling is understood. It also supports the HIPAA Security Rule by making the AI attack surface and data flows visible, which is a prerequisite for risk analysis. An inventory that omits AI tools handling PHI leaves a gap in exactly the systems HIPAA governs most directly.
How long does it take to build a healthcare AI inventory?
A usable inventory can be built in weeks when scoped deliberately: define the materiality threshold, adopt decision-based inherent scoring, discover embedded and shadow AI actively rather than by self-report, and map each system to HTI-1, HIPAA, and coverage obligations. It becomes far longer and less reliable when attempted reactively under an audit or board request, because discovery and scoring are rushed and third-party and embedded tools get missed. Building it ahead of demand, in the order of scoring from the decision first, keeps the effort contained and produces an inventory that answers a reviewer in one export rather than weeks of reconstruction. The exact timeline scales with the size and fragmentation of the estate.


