Before using clinical AI, bring the right people together to talk through privacy, security, data, and clinical oversight. The details will vary, but this checklist gives your team a practical place to begin.
Ownership and intended use
- Named executive, clinical, operational, and technical owners
- A documented intended use and clearly stated boundaries
- Defined responsibilities for configuration, training, and review
Privacy, security, and data
- Data flows, storage, retention, access, and deletion requirements
- Identity, authentication, authorization, and audit expectations
- Vendor review, contractual requirements, and incident processes
Clinical oversight and acceptable use
- Clinician review and responsibility for completed documentation
- Training on appropriate use, limitations, and escalation pathways
- A process for quality concerns and unintended outcomes
Monitoring and change
Decide what will be reviewed after launch, how feedback will be collected, and who can approve configuration or scope changes. Governance should continue as the workflow, product, and organizational needs evolve.
Use this checklist to start the conversation
This resource is general planning guidance, not legal, privacy, security, or clinical advice. Your organization’s qualified stakeholders should determine the requirements that apply to your environment.