Healthcare AI

Your AI needs an alibi.

A state privacy officer, a CMIO, a payer executive, and an attorney on AI governance, and why it takes proof, not promises.

18 min read
Joe Braidwood
Joe Braidwood
Co-founder & CEO
18 min read

On a Tuesday night in Seattle, a room full of healthcare builders, operators, and founders gathered at the AI House for a panel convened by SeaHealthTech. The title of the event, “From Promises to Proof in Healthcare,” named the tension in the room. Healthcare AI adoption is moving quickly, while independently checkable operational records remain uneven. No single artifact can prove that a system is safe, accountable, or compliant.

Originally published February 3, 2026. Legal and regulatory status updated August 26, 2026.

Moderator Neha Patadia, co-founder of SeaHealthTech, opened with a striking statistic: according to Menlo Ventures, healthcare is adopting AI applications 2.2 times faster than any other industry. Two-thirds of physicians are already using AI tools. Two-thirds of hospital systems have deployed some form of AI technology. “This is the first time in history there has been no mandate, no regulation, and AI applications are organically jumping up,” she said.

And then the question that hung over the entire evening: “What happens when a vendor puts an application into your hospital system, and then you ask, ‘Can you tell me exactly what the algorithm had when that patient had this decision made at this time?’ Most of the times there will be no answer. It’s a gap.”

That gap, between what AI vendors claim and what organizations can independently check, is what the panel spent the next hour dissecting. The useful target is not a universal safety certificate. It is evidence scoped to a particular action, control, and claim.

The panel was stacked with exactly the right people to pull this apart from every angle. Dr. Michael Han is CMIO of MultiCare Health System, which runs 12 hospitals, more than 300 clinics, and one of the oldest Epic installations in the country. Corinne Stroum heads emerging technologies at SCAN Health Plan, one of the nation’s largest Medicare Advantage organizations. Jefferson Lin is a healthcare technology attorney at Scale LLP who spends his days red-lining AI vendor contracts. Our own Dr. Jennifer Shannon, physician and GLACIS co-founder, brought the patient-level reality of what happens when AI fails in the exam room. And Katy Ruckle is Washington State’s Chief Privacy Officer, a national leader in AI governance who sits on the state’s AI Task Force, leads the implementation of the governor’s AI executive order, and who, as the evening would reveal, is quietly building one of the most sophisticated state-level AI regulatory frameworks in the country.

Full Panel: AI Governance in Healthcare, SeaHealthTech at the AI House, Seattle. February 3, 2026.

SeaHealthTech panel ‘From Promises to Proof in Healthcare’ at the AI House, Seattle. From left: Neha Patadia (moderator), Katy Ruckle, Jefferson Lin, Corinne Stroum, Dr. Jennifer Shannon, Dr. Michael Han.
“From Promises to Proof in Healthcare,” with Katy Ruckle, Jefferson Lin, Corinne Stroum, Dr. Jennifer Shannon, and Dr. Michael Han. AI House, Seattle.

Governance gets you through the door. Then what?

Dr. Han opened with a story that anyone in health system procurement will recognize, and one that shows why post-deployment monitoring matters more than most people think.

MultiCare undertook one of the most ambitious ambient scribe evaluations in the country. They enrolled 550 providers across three competing solutions for a head-to-head comparison. Cleveland Clinic did something similar with five vendors, sequentially rather than simultaneously. Both organizations ultimately selected Ambience. The process was rigorous and data-driven. Han’s team even measured Levenshtein distance on edited notes and found a bimodal distribution, with most providers changing fewer than 20 to 30 characters but outliers changing over a thousand.

But Han’s point wasn’t about the evaluation. It was about what comes after.

“That’s intake. That’s bringing a new vendor, a new capability on board. But it says nothing about what you do once that vendor is in your stack. Does it comply with what your contract says it’s supposed to? Does it comply with rules and regulations? Does it drift? Is it biased? Is it safe? Is it effective? Is it producing an ROI?”

DR. MICHAEL HAN · CMIO, MultiCare

Han calls himself the “CM-I-No,” the person who reflexively says no to every bright shiny object a vendor places in front of him, because he knows his providers will reject anything they don’t trust. His AI Governance Committee at MultiCare is the gatekeeper. “In order to get in the door, there’s a lot of hoops you have to jump through, from a security standpoint, from a compliance standpoint. If you don’t know that HIPAA is two A’s as opposed to two P’s, then you’re not ready.”

But security is just the first step. Beyond that, there’s a new software request process, a data governance committee review, an AI governance review, an architecture review, a CFO review. “And this isn’t even contracting,” Han noted. “This isn’t even BAAs and MSAs and alphabet soup. This is just getting through new software vendor, security questionnaire, data governance committee, and AI governance. It takes a lot of grit.”

The vendors who make it through that gauntlet earn a rare thing: trust. But trust without ongoing verification is fragile, and that was Han’s point. Procurement evaluates a moment in time. What happens on day 31, day 90, day 365? His willingness to say in public that this monitoring gap exists carries weight precisely because he is the skeptic, the person who already runs the hardest front door in the industry. Even he can’t see what’s happening after a vendor is live.

Corinne Stroum from SCAN reinforced the point from the payer side. “The first question eliminates about 90% of potential vendors,” she said. That question: do you have a CISO? “You can give us this top-tier technology, but fail us on the basics. Penetration testing. Simulated phishing against your employees. Multifactor authentication. Making sure your antivirus software is up to date, instead of asking your employees to bring their own machines.” Her advice to startups was blunt: “Get a fractional CISO. Get someone in who has done this before. Not, ‘Well, we’ve got this guy Ted, and he really likes doing the security.’”

When AI hallucinates in the exam room

Dr. Shannon made the problem concrete with a story that made the room go quiet.

The first time she used an ambient scribe in her practice, it transcribed that she was prescribing Lamictal for PTSD, which is not an indication for PTSD, and generated it directly in the clinical note. She caught it. She was able to go back to the raw transcript and verify that nothing in her actual conversation would have prompted that output.

But catching the error wasn’t enough. As a physician with twenty years of practice, her instinct ran past fixing the note. She wanted a forensic reconstruction of how the sentence got there.

“I really wanted to be able to go back and reconstruct: were there safety controls at that time? What was actually happening when the AI made that decision?”

DR. JENNIFER SHANNON · Physician & GLACIS Co-founder

This is the difference between a general safety claim and a record that supports review of a particular event. A hallucination that puts the wrong drug indication in a medical record can become a clinical, legal, or board-level concern. Reconstruction still depends on the system’s routing, model, human-review, and coverage evidence, not on a receipt alone.

Shannon said out loud what physicians feel but rarely say in public. The old documentation paradigm, “if you don’t document it, you can’t prove it happened,” now has a dangerous corollary. If the AI documents something that didn’t happen, how do you prove it didn’t? “The gap is patient and physician safety, the proof gap,” she said. “That’s what I would like to see as evidence from the vendors that we work with.”

The payer sees it too

Corinne Stroum from SCAN described the payer’s need for evidence that survives beyond a vendor questionnaire, the same operational gap Glacis is built to close.

On the lifecycle problem, she was blunt: “AI governance is there for the entire lifecycle. Those same groups that you had to get in the door: you’re actually just running on a treadmill and you didn’t know.” She described the emerging discipline: “One of the hottest new terms right now is evals, this capacity to build monitors on what is actually happening with this technology.”

She picked up on a word from earlier in the discussion, drift, and gave it weight: “I like the symbolism of this word, because it implies that we are dealing with something dynamic, whose answers may change over time.” Dynamic systems require dynamic monitoring. You don’t take a single x-ray of something that’s constantly moving. You put it on continuous telemetry.

On what monitoring looks like in practice, Stroum outlined a multilayered approach that extends far beyond engineering teams. “It’s not just your techies who are running synthetic tests. It’s also your legal team. My favorite is legal red-teaming: go find ways that this might get us in trouble, and have them do that sort of testing on an ongoing basis.” That is a payer telling the market that compliance is not a one-time exercise. It is an ongoing adversarial process.

Stroum also reframed the entire motivation behind AI adoption with a line that brought the room together: “This idea that we can do better is what attracts people, regardless of background, towards AI. They’re not excited necessarily about the AI. They’re excited about breaking the processes that we hate.” The flip side of that excitement, she warned, requires vigilance: “We are trying on something that maybe feels a little unsteady to us. Keep that in the back of your mind.”

On the payer’s specific mandate, Stroum framed it in terms of trust and service: “We want to instill trust, retention, and satisfaction. Our job is to remove friction when one of our seniors is trying to access care or understand their benefits.” AI enables faster responses to physician partners, communications in a member’s native language, at an appropriate literacy level, sensitive to their context. But every one of those capabilities needs to be monitored for the same safety and accuracy problems that haunt the provider side.

When a Medicare payer describes your product category (continuous lifecycle monitoring, evals, legal red-teaming, drift detection) without knowing you exist, you’re building the right thing.

Washington is already writing the playbook

This is where the evening got genuinely surprising.

Katy Ruckle is Washington State’s Chief Privacy Officer, a role that carries national weight in a state with one of the most active AI policy environments in the country. She sits on the state’s AI Task Force and leads the implementation of the governor’s AI executive order, and she was named to the AI 50 by the Center for Public Sector AI. She is also a licensed attorney with deep experience directing privacy programs for the Department of Social and Health Services.

At the February 3 panel, Ruckle described Washington state-agency operating practices, including procurement expectations and interdisciplinary review, alongside bills then under consideration. Those agency and procurement practices should not be read as a generally applicable Washington law for private healthcare organizations, and the panel remarks do not predict what other jurisdictions will enact.

NIST AI RMF in Washington state-agency practice

Ruckle described the NIST AI Risk Management Framework as an operating standard for Washington state agencies. That statement concerned executive-branch administration and agency operations, not a general statutory mandate for every private organization in Washington.

“In the state of Washington, we’re focusing on the responsible AI practices that come from the NIST AI Risk Management Framework. That’s been baked into how all our state agencies are required to operationalize the NIST AI principles, and that’s also a recommendation from the AI Task Force to the state legislature to have that be adopted for use in law in Washington.”

KATY RUCKLE · Chief Privacy Officer, Washington State

The first part of that quotation concerns requirements for state-agency implementation. The Task Force recommendation to the legislature was a separate policy proposal; as of August 26, 2026, it should not be characterized here as a generally applicable NIST mandate enacted into Washington law.

When organizations asked “which framework should we follow,” Ruckle answered: “NIST is actually very well respected in industry. Part of the reason is it is also free, versus ISO and some of the other ones you have to pay for.” That was practical framework guidance offered at the February panel, not a statement that NIST use alone satisfies a legal or procurement requirement.

Vendor representations in state procurement

For vendors participating in relevant Washington state contracting, Ruckle described an agency procurement practice at the time of the panel:

“We are in a place right now where, when we’re contracting, we have to get certification from vendors that they’re using an AI governance program like NIST AI Risk Management Framework, or something consistent, like the ISO standards. We’re trying to bake in that AI governance, no matter how you’re thinking about the use of AI, but especially around high-risk use cases.”

KATY RUCKLE · Chief Privacy Officer, Washington State

And on the question of whether healthcare qualifies as high-risk, Ruckle was unambiguous: “In healthcare, you’re almost always going to be walking into the high-risk space.”

The quotation supports a narrower point: relevant Washington state procurements may request vendor representations about an AI governance program. Contract language, agency, system, and use case determine the actual requirement; the remark does not establish a live requirement for every healthcare vendor or private deployment.

Panel discussion in progress at SeaHealthTech's From Promises to Proof event, AI House, Seattle.
The February 2026 panel discussed vendor representations in state procurement, risk assessments, and bills then under consideration.

What lawmakers were considering in February 2026

Ruckle also outlined proposals under consideration during the 2026 session. The quotation is historical and does not show that each proposal enacted:

“Our lawmakers are looking at AI bills this session that include requiring pretty extensive risk assessments on uses for high-risk AI cases, concerns around algorithmic discrimination and bias, and especially around any uses of biometrics, where you can get into some really high-risk areas, including facial recognition.”

KATY RUCKLE · Chief Privacy Officer, Washington State

As of August 26, 2026, the proposed broad high-risk AI legislation discussed at the panel did not enact. Organizations should assess duties under laws and contracts that actually apply to their activity; the February discussion does not establish a general Washington risk-assessment mandate for clinical, employment, insurance, or other high-risk AI uses.

The February discussion of private enforcement

Ruckle discussed private rights of action, the mechanism that can allow individuals to sue directly under a law rather than leaving enforcement solely to government. Her comments described Washington policy debates as they stood at the February panel.

Washington introduced the Washington Privacy Act in 2020, which became a model for approximately 25 other states across the US. But it failed to pass in Washington itself, in part because it didn’t include a private right of action. The My Health, My Data Act, which did pass, took a different approach. “We tied it to the Consumer Protection Act,” Ruckle explained, “and so you have to actually still prove unfair and deceptive practice, and that the harm was caused. And so we haven’t seen the flood of lawsuits that is the fear of having a private right of action.”

On the then-pending companion-chatbot proposal, Ruckle said: “We’re hoping to accomplish the same thing with the AI chatbot bill that’s been introduced this year.” The proposal was later enacted, with an effective date of January 1, 2027; see the Washington state AI laws guide for the August 26 status and primary sources.

The practical scope depends on the enacted law, covered product, actor, conduct, enforcement provision, and facts. Governance documentation may support oversight and investigation, but it is not a legal defense or proof of compliance by itself.

Transparency without exposing the secret sauce

Ruckle also addressed a common vendor objection: that transparency requirements may expose proprietary information. Her February response described one way policy teams were thinking about that tension:

“That’s where we’re talking about more like nutrition labels, where you’re not necessarily sharing the secret sauce recipe, but really sharing the basics of what the model contains: categories of data, training elements, those types of things. So you have the model cards.”

KATY RUCKLE · Chief Privacy Officer, Washington State

The “nutrition label” analogy is a policy concept, not a uniform disclosure rule. Actual disclosure duties depend on the applicable law, contract, system role, and protected information.

Interdisciplinary review: privacy, security, architecture, accessibility

Ruckle described interdisciplinary design review inside Washington state operations: “We are creating the design review team to incorporate the AI piece, to bring all those disciplines (privacy, security, architecture, technology) and then also the users and even accessibility. We’re doing it very intentionally.”

That state-agency example echoed the cross-functional review practices Han and Stroum described in their own organizations. It illustrates an operating model, not a generally binding rule for private deployments. Ruckle connected it to agency vetting: “That’s why you hear about all the vetting that has to happen before you bring an application into your system. That’s because the liability that we have to hold when we bring the products into our environments.”

A reassurance for founders

Ruckle also had a direct message for the founders and startups in the room, many of whom expressed anxiety about the pace and complexity of the regulatory landscape:

“The regulations that I’ve been seeing are not that prescriptive. They’re really more about documenting your risk assessments and demonstrating due diligence. It’s not about being a burden. It’s about trying to help protect consumers from bad practices that might be happening with their data.”

KATY RUCKLE · Chief Privacy Officer, Washington State

The February remark favored documented, risk-based governance over a prescriptive checklist. It should not be read to mean that documentation, risk assessment, or monitoring is sufficient for compliance, or that later legislation followed the path discussed that evening.

The February timeline, checked in August

Jefferson Lin described a regulatory timeline at the February panel. The cards below separate those historical remarks from status checked as of August 26, 2026:

January 2027

Colorado ADMT duties begin

SB 26-189 repealed and replaced the 2024 Colorado AI Act before that earlier framework took effect. The enacted ADMT regime begins January 1, 2027 and centers on notices, disclosures, correction, human review, and records; the old reasonable-care and framework safe-harbor provisions are gone.

2027 to 2028

EU high-risk rules phase in

Following the enacted AI Omnibus timeline, relevant Annex III high-risk rules apply from December 2, 2027 and relevant Annex I product-embedded rules from August 2, 2028. Duties and dates remain role- and classification-specific.

Ongoing

California CIPA Litigation

As of August 26, 2026, the case remained a putative class complaint; its allegations were not adjudicated precedent.

Status at Aug 26, 2026

Washington 2026 outcomes

The companion-chatbot law enacted and takes effect January 1, 2027. The proposed broad high-risk AI bill discussed at the panel did not enact. Washington state-agency NIST policy and procurement practices remain distinct from generally applicable law.

Deadline passed

HHS Clinical AI RFI

Comments were due February 23, 2026. As of August 26, that request for information is no longer an open comment opportunity; the panel remark is historical.

Lin connected attestation to precedents in other industries: “Finance with SWIFT and streaming attestation and fraud detection. Aviation: we use that analogy, the flight recorder, the black box to be able to go back and see what happened.” The pattern is clear across regulated industries: when the stakes are high enough, retrospective documentation gives way to real-time evidence capture. Healthcare is arriving at the same conclusion, just slower.

The Sharp HealthCare case loomed large. Lin detailed how plaintiffs used California’s Invasion of Privacy Act, a 1960s wiretapping statute, to file a class action related to ambient scribe deployment. “It’s not necessarily about AI being wrong or the output,” he noted. “It’s about how AI systems are deployed, how they’re configured.”

Han walked through the consent problem in operational detail. MultiCare’s workflow includes signage in clinics, language in annual privacy notices, and a provider obligation to obtain verbal consent before recording. But the fundamental paradox remains: you can’t start recording until after you receive consent, which means the consent itself never appears on the recording. Han proposed asking for consent twice, once before the recording starts and again on the recording itself, so the ambient vendor can include the verification in the transcript. “It adds fifteen seconds. It’s cumbersome. But you can’t start recording until after you receive the consent.”

The Sharp complaint alleges what can happen when chart language is treated as evidence of consent. “That’s a no-no,” Han said. “There’s no way of knowing.” A signed operational record can make a configured control’s reported outcome tamper-evident. It still does not establish that consent actually occurred, that the control was effective, or that every encounter used the covered path.

From checklists to continuous proof

Shannon crystallized the gap between where the industry is and where it needs to be:

“We have these static checklist frameworks: we’re compliant, we follow NIST AI RMF. But when it really comes down to it, how are we implementing this, both from an operational standpoint and a technical standpoint? That’s where there isn’t a lot of detail in these frameworks.”

DR. JENNIFER SHANNON · Physician & GLACIS Co-founder

Ruckle confirmed it from the regulatory side and put a name on the gap:

“How you operationalize those pieces: that’s really where the rubber meets the road, where you’re really bringing in your controls or remediation to control against risk.”

KATY RUCKLE · Chief Privacy Officer, Washington State

They came at it from different directions and landed in the same place. Ruckle named the operationalization gap from the regulatory side. Stroum described governance as a treadmill from the payer side. Han put it in health system terms: procurement tells you nothing about what happens once a vendor is live. Claiming compliance is not the same as proving it.

Shannon made the business case directly: “It’s much easier and cheaper and better to integrate that earlier into either the vendor’s infrastructure or hospital systems, versus after the fact, when you’re having that oh crap moment: what happened, and can we actually reconstruct it?”

Capture purpose-appropriate operational evidence before an incident, not as a promised legal defense but to support later investigation and review. Reconstructing a patient-safety event or regulatory inquiry after the fact can be materially harder when relevant records were never preserved.

Your AI needs an alibi

Shannon described the shift from x-ray to telemetry, from static, point-in-time snapshots of compliance to continuous monitoring of what AI systems are actually doing. It is the difference between checking a patient’s vital signs once a year and putting them on a monitor that never stops reading. In critical care the choice is obvious. In high-stakes AI deployment we are somehow still working from the annual checkup.

And then the line that names the category:

“Your AI needs an alibi… every AI decision having an alibi, and being able to know exactly where it’s been, what it’s doing.”

DR. JENNIFER SHANNON

What that means in practice is that covered decisions are preserved, reported control outcomes are independently checkable, and the scope and the gaps are both stated plainly, without turning any single artifact into a safety or compliance certificate.

“Build that. I’m in.”

The panel closed with a lightning round: what proof capability sounds like science fiction today?

Ruckle went the furthest: “Being able to see what is actually happening in the neural networks, to know how it’s making its decisions.” It is an aspiration for mechanistic interpretability that leading AI labs have not fully achieved. The remark does not establish a future regulatory requirement; current explanation and documentation duties remain use-, role-, and jurisdiction-specific.

Lin cited streaming attestation, meaning real-time and continuous proof of what AI systems are doing, analogous to the financial industry’s fraud detection infrastructure.

Stroum described consensus-based outcomes: “Not just one AI, but a series of systems that are fact-checking against each other and their perception of reality from different perspectives.”

Shannon brought it back to the alibi.

And then Han closed the evening:

“I’m going to think about Minority Report… where I can monitor every app that says they have AI in my stack, and be able to monitor them for ROI, for drift, for safety, for efficacy, and be able to drill down… Joe, if you can build that, I’m in.”

DR. MICHAEL HAN · CMIO, MultiCare
SeaHealthTech panelists together after the panel discussion at the AI House, Seattle.
The panelists after the discussion. AI House, Seattle. February 3, 2026.

Those questions point to the operational evidence gap Glacis is working on.

Glacis connects intended policy to configured controls and signed records for covered healthcare-AI actions. Those records can make specific control claims and reported outcomes checkable. They do not establish complete coverage, control effectiveness, safety, or legal compliance.

The panel brought together clinical, payer, privacy, and legal perspectives on the same practical questions: how consent is recorded, which controls operate in a live workflow, and what a reviewer can inspect afterward. The conclusion worth carrying out of the room is narrower than a slogan. Policy and contracts remain necessary, and consequential healthcare workflows also need operational records with explicit scope and limitations.

Proof, not promises, is the standard the room described. If you are working through the gap between policy, control execution, and reviewable evidence, we should talk.

Talk to us about one healthcare AI workflow

Map the intended rule, the control that should run, and the scoped evidence a clinical, security, or legal reviewer would need afterward.

Talk to us