Executive Summary

Loma Linda University Health (LLUH), a California academic health system with 6 hospitals and 1,000+ beds, has reported a patient data exposure through an AI platform that the organization was using without a formal security assessment. The incident is one of the first documented cases of shadow AI in healthcare (use of AI tools by medical staff without IT department approval).

The exposure was discovered during a routine audit and affected an unspecified number of patients. The case illustrates a growing risk: healthcare professionals adopt AI tools (medical transcription, assisted diagnosis, clinical chatbots) at a pace that exceeds security teams’ capacity to evaluate them.

Key Points

  • Exposure type: shadow AI, not ransomware or traditional breach
  • Vector: third-party AI platform without prior security assessment
  • Compromised data: patient information processed by the platform
  • Detection: routine audit, not by the security team
  • Exposure time: unknown, could be weeks or months
  • Emerging TTPs: third-party AI tools without clear BAAs are a new breach vector

Regulatory Implications

HIPAA AI platforms that process PHI are subject to HIPAA. If LLUH didn’t have a BAA with the provider, regulatory responsibility falls on the hospital. OCR expects CEs to do due diligence on any third party with access to PHI, including AI tools.

NIS2 Art. 21 on supply chain risk management also applies to AI providers. Hospitals must catalog all AI tools used (even unapproved ones) and assess their risk.

GDPR If the AI platform processed EU patient data, the provider must be under a DPA. Without a DPA, it’s a GDPR breach. International data transfers to AI providers outside the EEA require SCCs or BCRs.

MDR If the AI platform is classified as SaMD (Software as a Medical Device), it requires MDR conformity assessment before clinical use.

Recommendation

  1. AI inventory: what AI tools is your staff using right now? ChatGPT, Whisper, Notion AI, Claude, medical transcription, clinical chatbots. Run an anonymous survey and you’ll find 70% of staff uses AI without approval.
  2. AI policy before technology: you don’t solve shadow AI by banning AI use. You provide approved alternatives that are safe and useful.
  3. Mandatory BAAs with EVERY AI provider that processes PHI: OpenAI Enterprise, Microsoft Azure OpenAI, Google Vertex AI, Anthropic Claude for Healthcare, Abridge, Suki, etc. All require formal BAAs.
  4. DLP for prompts: monitor what information staff enters into AI tools. If a doctor pastes a clinical history into ChatGPT, it’s a breach.
  5. Specific training: staff isn’t malicious, they simply don’t know that copying a clinical history to ChatGPT is a HIPAA breach. Training must be practical, not legalistic.
  6. AI Governance Committee: create a multidisciplinary committee (IT, legal, medical, compliance) that evaluates and approves AI tools. No gatekeeping, no bottlenecks.

Source: Becker’s Hospital Review - Loma Linda AI platform data exposure

This analysis is part of HealthSec, the weekly briefing on healthcare cybersecurity.