Healthcare AI Governance & Algorithmic Compliance Consulting
Last updated: October 2026
Healthcare AI governance is the set of documented decisions, owners and records that controls which AI tools enter clinical, coverage and administrative workflows and how they are monitored. A formal pre-implementation approval process should exist before any AI tool enters clinical or coverage workflows.
Integral Healthcare Solutions (IHS), founded in 2002 by Thomas G. Goddard, JD, PhD, former Chief Operating Officer and General Counsel of URAC, builds operational AI governance programs for health plans, health systems, health IT developers and pharmacies. IHS drafts the charter, inventory, risk records and policies for your compliance, clinical and IT leaders to review and approve. IHS is not a law firm.
Which federal requirements bear on healthcare AI?
Three federal sources bear on healthcare AI governance. Each row summarizes the source in IHS's words (page opened October 4, 2026), and this page does not report changes made to either rule after publication, so check the current text before you rely on it.
| Source | What it covers |
|---|---|
| ONC HTI-1 final rule, 89 FR 1192, January 9, 2024 (effective February 8, 2024) | Adds a decision support intervention (DSI) criterion at 45 CFR 170.315(b)(11) to the ONC certification program. Certified health IT must support source attributes, which are categories of technical performance and quality information for evidence-based and predictive DSIs. The rule also describes intervention risk management practices for predictive DSIs, with summary information made public, and uses the term FAVES for fair, appropriate, valid, effective and safe. |
| HHS Section 1557 final rule, 89 FR 37522, May 6, 2024 (effective July 5, 2024) | Includes 45 CFR 92.210 on nondiscrimination in the use of patient care decision support tools. The rule's table of dates lists a deadline within 300 days of the effective date for the requirements in 92.210(b) and (c). |
| NIST AI Risk Management Framework 1.0, released January 26, 2023 | A framework intended for voluntary use to manage AI risks to individuals, organizations and society. NIST's page says AI RMF 1.0 is being revised as part of the White House AI Action Plan. |
State AI laws vary by jurisdiction. IHS builds a table of the ones to review for your footprint, and your counsel decides which apply.
What does IHS deliver in an AI governance engagement?
IHS delivers documents, not strategy memos. Each deliverable below is drafted for your leaders to review and approve, and the technical and legal content comes from your clinicians, data scientists and counsel.
- AI governance charter and committee structure: committee composition, decision rights, approval workflows and escalation paths, with a role-level RACI and meeting cadence.
- AI inventory and shadow AI discovery: an inventory of AI tools across clinical, administrative and vendor workflows, with a protocol to find unapproved tools that arrive through vendor channels or departmental purchasing.
- ONC HTI-1 source attribute documentation: for certified health IT developers, transparency documentation for predictive DSIs covering training data, exclusion criteria, known limitations and intended use, organized against 170.315(b)(11).
- Intervention risk management records: risk analysis documentation for each predictive algorithm covering the FAVES criteria, usable as evidence for internal approvals and external review.
- Algorithmic bias and health equity audit records: an audit plan and documentation of how each algorithm performs across demographic subgroups. Your data scientists run the statistical analysis.
- AI vendor agreement review: a review of business associate agreements with AI vendors on PHI handling, training data use, breach notification and subprocessors, for your counsel to approve.
- State AI law mapping: a jurisdiction-by-jurisdiction table of the AI laws to review for your footprint, with monitoring as laws change, for your counsel to confirm.
- FDA documentation support: for makers of AI-enabled devices, organizing pre-submission and change control documentation, with your regulatory counsel and engineers supplying the technical content.
How does an AI governance engagement work?
IHS plans a full AI governance program build over 6 to 12 months in five phases. The durations below are IHS planning ranges, not figures from any agency.
Phase 1: Planning, scoping and gap assessment (2-6 weeks)
IHS scans vendor contracts and departmental purchasing for AI tools, lists the regulatory sources for your counsel to confirm as applicable and compares your current state with the NIST AI RMF. Where you also pursue HITRUST, the HITRUST gap analysis is performed by a HITRUST-licensed firm you engage. The output is a prioritized remediation roadmap.
Phase 2: Remediation and policy development (4-12 weeks)
This is the most labor-intensive phase. IHS drafts the charter, the risk records, transparency documentation, bias audit plans and vendor agreement revisions, and your technical staff implement security controls.
Phase 3: Mock Desktop Review (3-6 weeks)
IHS reviews your documents against the governing text and lists remaining gaps in a corrective action plan with owners and dates.
Phase 4: External assessment support (1-4 weeks)
If an outside body assesses or certifies you, IHS supports document preparation and your team's answers to the assessor. Your organization's named contact submits.
Phase 5: Maintenance
IHS offers standing maintenance support for the AI governance program, policies and evidence as tools and rules change.
Who needs an AI governance program?
Any organization that deploys AI in clinical, coverage or administrative decisions needs one in IHS's view, because governance records are what you show when someone asks how a tool was approved and monitored. Two groups face a specific federal source above.
- Developers of certified health IT, including EHR vendors: the HTI-1 decision support criterion applies to certified health IT modules.
- Organizations the Section 1557 rule covers, which the rule defines: 45 CFR 92.210 applies to their use of patient care decision support tools. Confirm coverage with counsel.
Health plans using AI in prior authorization, hospitals and health systems with clinical decision support, pharmacies using AI-assisted decision support and behavioral health providers using patient-facing AI also build governance programs. IHS drafts AI governance policies to fit the accreditation and compliance programs your organization already runs.
When is IHS alone not enough?
An organization that wants an FDA submission written for it, a legal opinion on a state AI law or a certified algorithm audit is not a fit for IHS alone. Those need your regulatory counsel, your engineers or a qualified auditor.
What does AI governance consulting cost?
The cost has three parts: IHS's consulting fee, your internal time from compliance, clinical, legal and IT staff, and any fees charged by outside assessors or testers, which those bodies set. IHS sets a fixed fee for each engagement after a free discovery session, because scope, number of sites and gap severity change the work.
What this is not
- IHS is not a law firm. This page is not legal advice, and IHS gives no opinion on whether a law applies to you.
- IHS is not a regulator, certifier or accrediting body. IHS drafts, and your organization's named contact submits to any agency. IHS does not communicate with them for you.
- IHS is not a HITRUST licensee and does not perform HITRUST assessments. No engagement guarantees an audit or certification result.
Frequently asked questions
What is healthcare AI governance?
It is the documented system that decides which AI tools your organization uses, who approves them, how bias and safety are reviewed and how tools are monitored after launch. The core records are a charter, an AI inventory, risk records and policies.
Which organizations need a formal AI governance program?
Any organization using AI in clinical, coverage or administrative decisions benefits from one. Certified health IT developers face the HTI-1 decision support criterion, and organizations covered by Section 1557 face 45 CFR 92.210 for patient care decision support tools.
What does ONC HTI-1 require for decision support interventions?
The final rule adds a decision support intervention criterion at 45 CFR 170.315(b)(11) to the certification program. Certified health IT must support source attributes for evidence-based and predictive DSIs, and the rule describes intervention risk management for predictive DSIs. Check the current regulation, because this page does not report later changes.
What does Section 1557 say about decision support tools?
The 2024 final rule includes 45 CFR 92.210 on nondiscrimination in the use of patient care decision support tools. Check the current regulation and confirm with counsel whether your organization is covered.
Is the NIST AI RMF required?
NIST describes the AI RMF as intended for voluntary use. IHS uses it as a reference when it compares your current state with a governance framework.
How long does an AI governance program take?
IHS plans 6 to 12 months for a full build in five phases, and 2-6 weeks for the gap assessment alone. These are IHS planning ranges.
What does IHS deliver, and what does it cost?
IHS delivers a governance charter, AI inventory, intervention risk management records, transparency and bias audit documentation, vendor agreement review for your counsel and state law mapping. IHS sets a fixed fee for each engagement after a free discovery session.
Who is this not for?
An organization that wants IHS to write an FDA submission, give legal advice on a state AI law or run a certified audit is not a fit. IHS drafts governance documents for your leaders and counsel to approve.
Start with a gap assessment
A free discovery session covers where your organization stands against the sources above and what it would take to close the gaps before your next audit or accreditation cycle.
Schedule a Free Discovery Session