Showing posts with label CIO. Show all posts
Showing posts with label CIO. Show all posts

Wednesday, October 8, 2025

The Growing Role of Artificial Intelligence in Ambulatory Health Care

 


Introduction

Yesterday, I wrote about the use of Robotic Process Automation (RPA) in health care. Today, I want to discuss the growing role of artificial intelligence in ambulatory health care.

Artificial Intelligence (AI) is reshaping nearly every aspect of modern health care, and ambulatory care settings such as outpatient clinics, physician offices, and same-day surgery centers are no exception. Ambulatory health care has traditionally relied on high patient volume, efficient workflows, and rapid decision-making. With AI emerging as a key enabler of smarter operations, organizations are finding new ways to enhance efficiency, improve diagnostic accuracy, and strengthen patient engagement outside of hospital walls.

What AI Means for Ambulatory Health Care

AI in ambulatory care involves the use of machine learning, natural language processing, and predictive analytics to automate tasks, assist in clinical decision-making, and deliver personalized patient experiences. Unlike inpatient settings, ambulatory care focuses on long-term, short-term and preventive services where time and data coordination are critical. AI systems can quickly analyze patient data, detect patterns, and offer actionable insights that help clinicians make faster and more informed decisions.

Key Use Cases of AI in Ambulatory Care

1. Predictive Scheduling and Resource Management

AI algorithms can analyze historical patient flow, appointment types, and seasonal trends to optimize scheduling and reduce no-show rates. Predictive analytics helps allocate staff and resources more effectively, improving both operational efficiency and patient satisfaction.

2. Clinical Decision Support

AI-powered systems can assist clinicians by analyzing patient data, lab results, and medical history to recommend potential diagnoses or treatment options. In an outpatient setting, this can speed up consultations and ensure early detection of chronic conditions such as diabetes, hypertension, or COPD.

3. Patient Engagement and Virtual Assistance

AI chatbots and voice assistants can manage routine communication such as appointment reminders, pre-visit screenings, and post-visit follow-ups. This frees up administrative staff while improving accessibility for patients who prefer digital interaction.

4. Documentation and Coding Automation

Natural language processing (NLP) tools can transcribe clinical notes, extract relevant information, and automatically assign billing codes. This reduces manual documentation, minimizes errors, and allows clinicians to spend more time with patients.

Ambient listening technology such as that provided by Nuance DAX Copilot and Abridge can listen in on a patient encounter and transcribe the pertinent information into the note section of the patient’s chart in the electronic health record (EHR) system, completing 80-85% of the encounter note for the provider to later review, edit and sign. This frees the provider up to have a more positive interaction with the patient without having to be buried in a laptop taking notes. It also makes the encounter more efficient, allowing the patient to be able to discuss more of their issues with the provider leading to better overall outcomes.

5. Predictive Analytics for Identifying At-Risk Patients

AI algorithms can be applied data stored in an EHR system using a risk-scoring model looking at such data as medical history, social determinants of health, lab results and trended vital stats, treatment plans, medications and urgent care or emergency department and/or inpatient admissions to identify patients who may be at risk of being admitted or readmitted to the hospital. Identifying these patients allows the provider to reach out and potentially intervene to prevent an admission or readmission which could make a huge difference in the health of the patient. Waiting until a condition worsens to the point where the patient has to be admitted to the hospital could have adverse effects on the future health of the patient. Not to mention the huge risk of potential hospital-borne infections, especially for those patients who are immune-compromised. Additionally, these avoiding these preventable admissions or readmissions free up health care dollars and resources that can applied elsewhere to further the health of the community.’

This is rather new use that is still developing and will continue to evolve as more and more data is used to train and refine the models and experts continue to calibrate them. This could also lead to breakthroughs in identifying new protocols and further developing and applying existing ones.

6. Population Health and Risk Stratification

AI can aggregate and analyze data across patient populations to identify those at higher risk of hospitalization or disease progression. Ambulatory clinics can use these insights to implement targeted preventive interventions and reduce avoidable admissions.

Protecting Patient Health Information (PHI) in an AI Environment

As AI systems handle sensitive health data, maintaining privacy and compliance with regulations such as HIPAA is essential. The use of AI in ambulatory care introduces specific security challenges, including the protection of EHRs and the safe handling of data used for model training.


To mitigate these risks, organizations should adopt the following safeguards:

 

  1. Data De-Identification: Remove personally identifiable information before using data to train AI models.

  2. Encryption and Access Controls: Encrypt all PHI at rest and in transit and use role-based access to limit data exposure.

  3. Audit Trails and Monitoring: Maintain detailed logs of who accesses data and when to ensure accountability.

  4. Vendor Due Diligence: Evaluate AI vendors for compliance with HIPAA, HITRUST, and other relevant standards.

  5. Human Oversight: Keep clinicians and compliance officers involved to review AI recommendations and identify potential biases or anomalies.

  6. Local Storage and Execution of Models: Wherever and whenever possible, store and run AI models locally. While this requires more compute resources and deeper knowledge to train the models, it ensures that PHI doesn’t leave the organization through the use of a shared model. As models become more specialized to particular tasks and industries, they are also becoming much smaller. Something the size of ChatGPT is not required to run the use cases that we just discussed as models like ChatGPT, Gemini, Claude, etc. are created to handle a wide-open array of questions and requests which require an enormous breadth of data, while the uses we just discussed only require specialized data, such as patient data, charges, etc. making them substantially smaller in size. In fact, some models have been demonstrated that can be run on just a laptop and accomplish amazing tasks! Some vendors may also train and deliver models for on-premises use that can be delivered and retrained at regular intervals.

  7. Create an Organizational Policy Covering the Use of AI: Just as most organizations have policies covering security, having an AI policy that governs the use of AI in the organization is key. Additionally, these policies should be written in such a way that they can be evolved and updated as the technology and use of it grows.

Security and privacy must be treated as foundational elements of responsible AI use in health care.

The Future of AI in Ambulatory Health Care

The future of AI in ambulatory care is deeply connected to interoperability and precision medicine. As electronic health records, wearable devices, and remote monitoring systems continue to generate vast amounts of data, AI will play a central role in integrating this information and making it clinically useful.

In the coming years, we can expect advances in:

  • Personalized treatment recommendations that adapt to individual patient profiles.

  • AI-Driven Preventive Screening Tools that analyze biometric, genomic, and lifestyle data to identify early indicators of disease before symptoms appear.

  • Automated Clinical Workflow Optimization that continuously monitors clinic operations, identifies process bottlenecks, and recommends real-time adjustments to improve throughput and efficiency.

  • Emotion and Sentiment Analysis for Patient Interaction that enables AI to assess tone and engagement during patient communications, helping clinicians identify patients at risk of anxiety, depression, or disengagement from care.

  • AI-driven triage systems that guide patients to the appropriate care setting before they arrive at a clinic.

  • Synthetic Data for Research and Model Training that allows developers and researchers to create realistic, privacy-safe datasets for testing and innovation without exposing real patient information.

The most effective AI systems will act as augmented intelligence, enhancing rather than replacing human clinicians. When designed responsibly, AI can empower health care teams to deliver more efficient, data-driven, and compassionate care.

Conclusion

AI is transforming ambulatory health care by reducing administrative burdens and allowing clinicians to focus on what matters most: patient well-being. By combining automation with strong data governance and security practices, health care organizations can confidently adopt AI while maintaining patient trust and privacy. As technology continues to advance, AI will help make outpatient care faster, more accurate, and more human-centered.


Wednesday, August 20, 2025

What is IT Governance and Why is it Important?


 

In my almost three decades in IT, what has truly amazed me is how few organizations actually have IT governance programs. What is even more amazing is how few C-suite leaders and other leaders even understand what IT governance is and the value that it can bring to their organizations. This group of leaders includes those within IT as well, many of whom see IT governance as a threat to their leadership. Let’s take a dive into what IT governance really is, why it is valuable and why IT leaders should actually embrace and not fear it.

What is IT Governance?

Simply put, IT governance is a framework that helps organizations manage and align their IT operations with their business goals and objectives. At the end of the day, isn’t meeting the organization’s goals and objectives what we should all be about? IT doesn’t exist in a vacuum. In order to make sure that IT is properly aligned with and working towards the organization’s goals and objectives, stakeholders outside of IT need to be involved in determining what that looks like from a strategy and performance management perspective. The goal of IT governance is to bring those outside stakeholders to the table.

Why is IT Governance Important?

So, now that we know what IT governance is, why is it so important? Bringing outside stakeholders to the table to help IT leadership create an aligned strategy ensures that the projects that IT takes on are the right projects to help the business progress. Furthermore, these stakeholders work with IT to help prioritize these projects and provide support and funding to ensure that they get done. One of the most common reasons for projects failing is unclear business objectives or poorly defined project goals and milestones. Including stakeholders in this process can help ensure that the business objectives, project goals, and milestones are clearly defined before the project is even approved and started. This increases the likelihood of project success and that the project will provide the organization value. IT governance is really a “shared responsibility” model where IT works with its key stakeholders to share the responsibility for the success of the IT department and ensure that its efforts are optimized and delivering value to the organization.

Why Should IT Leadership Embrace IT Governance?

In the traditional IT model, IT owns the total responsibility for the success or failure of its initiatives and projects and whether or not it delivers value (real or perceived) to the organization. In this model, IT leadership really becomes the scapegoat for failures related to lack of engagement and support from other business leaders. I don’t know about you, but to me, that just seems like a recipe for failure. And a lot of times, it is.

With a true IT governance model, on the other hand, responsibility for the success or failure of IT to deliver value to the business is a shared responsibility with stakeholders having input into the strategy and execution of the IT department. If done right, there really is very little reason that there should be failure as we will see in the next section when we talk about the mechanics of how IT governance works and how it delivers value.

How Does IT Governance Work?

We stated earlier that, in its most simple terms, IT governance is a framework that brings together IT leadership and leaders or stakeholders from across the organization to share the responsibility for the governance of IT. Let’s talk a little bit, in a very generic way, about ways in which this is typically achieved. Keep in mind that these are broad, high-level applications and the approach and the details required to make this work for a particular organization really depends on that organization’s needs and resources.

1. The Chief Information Officer (CIO) should be a part of the business strategy development process and should be in attendance at board of directors’ meetings. In order to ensure IT alignment with business goals and objectives, the leader of the IT department needs to be in the room when those are developed and discussed.

2.  An IT Steering Committee should be formed made up of stakeholders from across the organization. This committee makes recommendations on the IT strategy and ensures that it aligns with the overall business strategy before being passed up to the board of directors for approval. 

a.      This committee acts as a governance body for IT where key metrics and KPIs for evaluating the operational performance of IT are developed, approved, and presented.

b.     Prioritization of projects and initiatives for that the IT department works on should also generally occur in this committee.

c.      The agreed upon KPIs, metrics, and project portfolio performance should be captured in a balanced scorecard which can then be used to measure the overall effectiveness of the IT department in achieving its strategic objectives. Plans for corrective action, if necessary, can be discussed and developed in this committee and then progress against those corrective action plans can be monitored along with the balanced scorecard. 

      3.  The IT scorecard, as approved and validated by the IT Steering Committee, should then be presented to the board of directors along with summaries of any actions discussed and taken in the IT Steering Committee and project portfolio status.

Conclusion

As you can see, this model sets up an organization for the most effective use and deployment of its IT resources by ensuring that said use and deployment is always in alignment with the needs of the business as directed by the business leaders. This avoids the IT department making key decisions in a vacuum and increases transparency in the effectiveness of the operation of the IT department. This transparency increases credibility and sets the IT department up to be trusted technology advisors and a strategic asset for helping the organization scale and achieve its objectives.



Tuesday, July 22, 2025

What CEOs Often Get Wrong About Innovation

Innovation at its core is really just defined as a new idea that solves a problem. Let’s focus in on the last three words of that sentence “solves a problem.” To be innovative, one needs a problem to solve. We need to help our CEOs understand that as CIOs, we are here to solve problems. We aren’t typically creating a product, we are supporting the business and helping it grow by providing technological solutions that help the organization achieve its goals. That often comes in the form of solving problems that are holding it back or that are pain points for the business’s operations.

Unfortunately, these days, many CEOs feel that their CIOs aren’t innovative enough unless they come up with flashy solutions and throw around buzzwords like AI or digital transformation not really knowing what they mean or how they even apply to their business. I have been shocked lately as I have talked with several CEOs and discussed projects with them about how many of them seem disinterested in solutions that merely solve the problem. When discussing projects with them, they all perked up when I talked about using AI agents, generative AI solutions or AI scribes for healthcare when they were disinterested in discussing projects around payroll solutions or other system implementations or improvements. This mindset is very dangerous in that a good CIO is there to help the business solve problems by proposing the best solution, not the flashiest or the sexiest solution. When we think about project management, three main tenets come to mind: the project is to be delivered on time, on budget, and be technically adequate (within scope). When we are delivering a project, we don’t add features to give the final product more wow factor as that would typically either mean increasing the budget throw additional manhours or duration or both. The goal is to deliver something that is technically adequate to meet the needs of the business. The same should go for the technological problems that we solve as CIOs. Being innovative means solving the problem in the manner that best suits the organization, nothing more, nothing less.

Unfortunately, our CEOs are inundated with marketing hype trying to sell them flashy solutions to problems that don’t exist or at least are not the most feasible solution to an existing problem. Additionally, they are also exposed to things that other organizations are doing that may or may not be applicable to their organization. As CIOs, this is where we need to put on our educator hat and educate our CEOs on how and why we choose the solutions we do. Sometimes the best solution to a problem is really the simplest solution.

Given this introduction, let’s talk about several questions about innovation in IT.

What is the CIOs role in innovation?

As a CIO, our role is the use of technology with business goals. The investments that we recommend in technology should directly support the goals and objectives of the business and be aligned to strategic objectives stated in the strategic plan or be solutions to problems that are preventing the business from achieving one or more of its goals or objectives. Innovation comes into play in providing those solutions. As stated earlier, innovation is just a new idea that solves a problem. As CIOs, it is our job to facilitate those new ideas.

Does innovation always require a novel idea?

Unfortunately, I think there is a misperception that innovation always requires a novel idea. While a lot of innovation really does start with a novel idea, especially those that we hear and read about, innovation can happen on a daily basis without creating something “novel”. Just coming up with a new idea or solution to a problem that your organization hasn’t tried before is being innovative. That doesn’t require that the idea or solution be so entirely new or original that no one has ever done it, just that the application of it is new to your organization or new to that problem.

With all of the focus and emphasis on innovation these days, isn’t there a cost to trying to drive innovation?

Absolutely. Organizations that want to strive to be innovation-first organizations where their goal is continuously come up with innovations invest in research and development or experimentation time. That may look like entire departments devoted solely to innovation or organizations over staffing their IT departments to give their staff time to experiment and play with new technologies in the hopes of them coming up with innovative solutions. There are very real costs to doing this. Taking your average overworked, understaffed IT department and coming in with a mandate that it needs to become more innovative just doesn’t work. Now, that doesn’t mean that they can’t come up with innovative solutions (many that I have observed do, by the way). It just means that they aren’t going to be actively looking for new ways to be innovative because the organization hasn’t staffed them for that ability.

What are the pitfalls that a CEO can get into when trying to hire an “innovative” CIO?

This really comes down to knowing your business, budget and what you need and can sustain. If you work for a nonprofit healthcare organization, as I do, you probably aren’t going to want or need to hire an executive from one of the big tech firms, even if you could afford them, thinking that they are going to bring innovation to your organization. If you do, the following will probably happen. They will recommend solutions that you can’t afford and the process of constantly being told no and not getting to work on cutting-edge technology will drive them away and you will be stuck recruiting for a CIO yet again, which can be a very costly endeavor. You are much better off hiring someone who understands and gets your industry and can bring their experience and expertise to your problems. Just because they have developed AI solutions or worked on the latest self-driving vehicle technology doesn’t mean they aren’t innovative or can’t provide an innovative approach to problem solving at your organization.

Does innovation by the CIO always involve technology?

To this question, I would answer with a resounding “NO”. At the end of the day, what you should be looking at is the best solution, not the most cutting-edge solution, not the most technical solution, not the most complicated solution, but the best solution. Sometimes, the best solution may involve a process change and may not require any technology at all or the best solution may require a process change followed by a technological solution. This is where you should listen to your candidate’s problem-solving skills and judge those rather than judging whether they fit your vision of being innovative or not.

This blog post has been written from my experience in technology both as a technologist and a leader and in dealing with numerous CEOs. Given that my experience may not be the same as yours and as always, I welcome your comments and perspectives and always look forward to hearing the perspectives of others as an opportunity to potentially learn and grow.


Friday, January 31, 2025

The Ever-Evolving Role of the CIO in Healthcare

 


It seems that few roles have evolved over the years as much as the role of the Chief Information Officer (CIO) in healthcare. Gone are the days when the CIO was just the person who was responsible for the computer systems and nothing else. . I remember back in the early 2000s when I worked at University Medical Center in Tucson, AZ that the IT team, including the CIO, were stashed in a 40+ year old portable building behind the hospital next to what we called the clinical equipment graveyard where old hospital beds and miscellaneous furniture went to die. In those days, IT was out of sight and out of mind. Flash forward to today and the healthcare CIO is now a trusted advisor, business consultant and valued member of the organization’s executive team. A lot has changed in the last 20+ years!

So, what is the role of the modern healthcare CIO? Let’s break this down a little bit:

Business Process Expert

A healthcare CIO should have a good understanding of how to develop, document and analyze business processes. You can’t add technology to a business process that doesn’t exist, isn’t standardized or even well understood. Well, actually you can, I guess, but what you get is a bigger, more complicated mess.

The CIO needs to be able to facilitate sessions to understand and map current business processes and help the functional area determine what is working and what isn’t and then formulate problem statements for the areas that aren’t working so that requirements for a solution can then start to be collected. The thing to keep in mind here is that the solution may not always be one that involves technology even though the CIO or their delegate is leading the process to identify and help implement a solution. Many times, without going through this process, you don’t know what the right solution is. Organizations that don’t take this approach can throw money and technology at a problem hoping to solve it, but if you haven’t accurately defined the problem and what it would take to functionally solve it, you are really just shooting in the dark.

This function of the CIO relies on the CIO’s business skills and acumen which in today’s healthcare environment are just as important for the CIO to have as knowledge of technology and technical trends.

Security Expert

Healthcare is one of the most highly regulated industries and also one of the most targeted industries by threat actors. Because of this, today’s healthcare CIO needs to be well-versed in threat landscape and how to mitigate potential threats to protect the privacy and safety of patient data and the organization’s systems. The threat landscape is ever evolving and shifting, requiring the CIO to always be researching and understanding these changes in a way that can be easily communicated back to the rest of the executive team and the board. The CIO needs to be able to accurately assess and communicate the risks to the organization and provide a strategy that is tailored to the organization and makes sense. This is a very time-consuming aspect of the CIO’s job and one that shouldn’t be taken lightly by the organization’s leadership.

Change Agent

There are probably few areas that introduce as much change through the organization as the IT department. While these changes are rarely true IT initiatives, most are led by IT on behalf of a functional area, IT is the one who generally leads and manages these changes. As a result, it typically falls on the CIO to come up with a change management strategy to help the organization’s workforce adapt to these changes with as little disruption and displeasure as possible. This role calls on the CIO to be an excellent planner, leader and psychologist. That last attribute is not one that you will find in any CIO job description, but an understanding of the psychology of change and how change is viewed and ultimately accepted is critical to ensure the success of any large project. This requires the CIO to have a strong understanding of the organization’s culture and be highly visible during the change process, actively listening and evolving the change strategy to help the workforce successfully adapt to the change.

Governance

A successful CIO needs to be able to organize and lead the governance process as it relates to technology. This process can take several forms and while not all organizations have all forms of governance, it should be the direction that the CIO is pushing for. The types of governance, as I would recommend them, are outlined below:

IT Governance

It is important that there is some sort of governance structure that loops together leaders of the organization and the board to vet long-term IT strategy and prioritize IT initiatives. Part of the chart of this governance structure should be to always make sure that the work and projects that IT takes on always align with the broader goals and objectives of the organization. This is usually chaired (or facilitated) by the CIO and includes leaders from the key areas of the organization to help provide visibility and context into the needs of the organization.

Project Governance

This could be done through a Project Management Office (PMO) and/or a Project Steering Committee. The purpose of this governance structure is to oversee the intake process for prospective projects, lead the analysis and vetting of those projects and formulate recommendations on projects that should be undertaken. Once projects are approved, the reporting and management of those projects and the organization’s overall project portfolio should go through this governance structure. This usually falls under the supervision of the CIO.

Data Governance

While most electronic data is managed by the IT department, it is important to remember that the IT department doesn’t really own this data or even completely understands how data is used in its entirety across the organization. This is where data governance comes into play. Data governance entails identifying all the various types of data as it is used throughout the organization as well as identifying data stewards for each type of data. Data stewards are individuals who are subject matter experts with regard to the data under their stewardship and can be looked to for decisions regarding who needs access to the data, retention requirements for the data and would be part of any integration discussions where the data may be transferred or exchanged. This function is important as it takes decisions around data out of the hands of the IT department and assigns ownership of it to those who actually use and understand it, with the advice and consultation of the CIO and the IT department.

EHR or Health IT Systems Governance

This governance model usually involves the leadership of the Chief Medical Information Officer (CMIO) along with the CIO to take changes and optimizations requested by the users of the various health IT systems and evaluates them for need, scope, difficulty or feasibility, and impact. This usually involves a committee structure made up of representatives of the systems’ stakeholders who, under the leadership of the CMIO with the support of the CIO, meet and discuss system change requests and then either approve or deny them and subsequently prioritize them for scheduling. This committee also receives reports back on the status and progress of requested changes.

Finance Manager

The assets, capital and operating budgets under the management of the CIO are typically some of the largest in the organization. This requires the CIO to be a keen financial manager who can project and budget for the organization’s needs and then effectively manage within that budget. To do this, the CIO must be a strong negotiator, both with internal stakeholders and vendors, and must be adept at vendor management to ensure that the organization always receives the highest value for the dollars spent. In some organizations, this also means vetting vendors to make sure that their values align with the organization's.

This role may require the creation or input into the creation of RFPs and evaluating responses as well as the subsequent negotiation of a contract for services.

Communicator

Last, but not least, is the role of communicator. The CIO needs to be constantly communicating to a large number of constituents. They are expected to communicate recommendations, risk assessments and progress reports to the executive team and the board; they communicate upcoming changes, either in person, by email or virtually, to the workforce and are available to take questions and concerns; they should be constantly communicating with the entire organization about potential security risks, educating them on how to avoid them and protect themselves and the organization; they communicate with external partners, establishing and maintaining relationships that benefit their organization; they may be responsible for communication with auditor or regulatory bodies regarding compliance with regulations and internal controls. Additionally, a good CIO is always in touch with the staff, understanding what they see and hear, their concerns and needs and is available to advocate for them to enable them to do their jobs to the best of their ability.

Conclusion

As you can see, today’s healthcare CIO has evolved way beyond the traditional technology role and is a key player in the operations and decisions across the entire organization. The role of the CIO today is a respected member and advisor to the executive team and C-suite and is required to wear many hats and have expertise far beyond that of the technology stack.


The Growing Role of Artificial Intelligence in Ambulatory Health Care

  Introduction Yesterday, I wrote about the use of Robotic Process Automation (RPA) in health care . Today, I want to discuss the growing ...