AI in healthcare driving risks for patients and intellectual property
Recent Cybernews S&P 500 research reveals significant vulnerabilities in the healthcare and pharmaceutical sectors as they increasingly adopt AI for advancements in diagnostics and medical discovery
According to Statista, the artificial intelligence (AI) healthcare market, which was valued at US$11 billion in 2021, is projected to be worth $187 billion in 2030. This significant growth shows that we will likely see substantial changes in how medical providers, hospitals, pharmaceutical and biotechnology companies, and other organisations in the healthcare industry operate.
However, this rapid and often uncontrolled adoption is creating a perfect storm of risks. While 83% of doctors, according to a recent study, believe AI will be a net positive, a striking 70% have serious concerns about using it in the diagnostic process. A single inaccurate medical algorithm could impact thousands of patients simultaneously, turning what would be an isolated clinical error into a systemic healthcare crisis.
Žilvinas Girėnas, Head of Product at nexos.ai, an AI platform for enterprises, explained that the risk of systemic failure was heightened by two key issues: data bias and the “black box” nature of many AI models: “If an algorithm is trained on data that does not represent certain populations well, it won’t just be wrong – it will also reinforce health disparities. Many AI models act as ‘black boxes’. This means they cannot show clinicians which specific data points, such as a certain lab result or a slight shadow on an X-ray, influenced their conclusion. This puts doctors in a difficult situation. They must either trust an output they cannot verify or miss a potentially lifesaving insight.”
Why healthcare is uniquely vulnerable to AI risks
AI’s rapid growth has attracted the attention of security experts, who warn that the healthcare AI revolution may be on unstable ground. Cybernews analysis of S&P 500 companies revealed a concerning truth: among 44 major healthcare and pharmaceutical organisations actively using AI, researchers found 149 potential security flaws, with healthcare being one of the top-three most vulnerable sectors.
Unlike other industries where AI failures mean lost revenue or damaged reputation, healthcare's unique challenge is that every vulnerability carries the potential for real human harm.
The research also reveals that healthcare organisations face a particularly dangerous combination of risks – it mentions 28 cases of insecure AI outputs, 24 data leak vulnerabilities, and, most critically, 19 direct threats to patient safety where algorithmic errors could scale across entire hospital systems.
The stakes are just as high for intellectual property. With AI-driven drug discovery deals valued at up to $2.9 billion and development timelines often exceeding 10 years, a single leak of proprietary research via an unsecured AI tool could erase a decade of work and billions in future revenue.
“The biggest AI threat in healthcare isn’t a dramatic cyberattack, but rather the quiet, hidden failures that can grow rapidly,” said Girėnas. “These risks include data poisoning, where a tampered data set subtly disrupts thousands of future diagnoses, and untested algorithms delivering bad recommendations across a whole hospital network.
“Leaders must ask themselves who is responsible when AI is wrong, rather than what happens if AI is wrong. Currently, there’s a serious gap in accountability for algorithms, and, without a system to monitor and manage how these tools are used, organisations are putting their patients and valuable information at serious risk.”
Practical steps forward: a dedicated AI governance layer
To resolve the tension between rapid innovation and critical risk, healthcare and pharmaceutical organisations must implement a dedicated AI governance layer. This approach goes beyond simply blocking tools, providing organisations with the visibility and control necessary to unlock AI’s potential safely.
According to Girėnas, the future of safe AI in healthcare comes down to three non-negotiables:
- Establish an approved list of AI tools. Create a centrally managed ‘whitelist’ of AI models that have been vetted for clinical accuracy and safety. This ensures that clinicians use specialised tools for high-stakes tasks like diagnostics, preventing reliance on unvetted, general-purpose chatbots for patient care
- Make data protection automatic. Use technology that automatically finds and removes sensitive information, like patient names, health records, or proprietary research, from any query before it is processed by an AI. Data protection should be treated as a default, not as an afterthought, to ensure compliance and safeguard patient privacy
- Make sure every AI action can be traced. Set up a system that logs each AI query and its response, linking each interaction to a specific user and timestamp. This detailed audit trail is essential for reviewing clinical incidents, protecting patient safety, and complying with the strict accountability standards of emerging legal frameworks.
Mandy Langfield
Mandy Langfield is Publishing Director for Voyageur Group. She has written extensively on the topic of international travel and health insurance, as well as medical assistance provision and air medical transportation. Mandy is also on the committee for the International Travel & Health Insurance Conferences (ITIC).
February 2025
Issue
Offering readers a deep dive into the issues facing providers and payers of healthcare services around the world. Cost containment, international patient department development, the role of AI in healthcare delivery and more.