
Introduction: The Baseline Fears
AI is moving faster than healthcare policy can keep up. For compliance leaders, the knee-jerk reaction might be avoidance, but blocking AI isn’t an option.
AI is still valuable to healthcare compliance. It can help teams spend more time on risk identification, monitoring, investigations and proactive program management, because less time is spent on routine administrative work.
But AI will never become the compliance expert. Rather, it’s a “thought partner” as you’ll learn in this article. That distinction matters because many compliance leaders are stuck between two realities: AI can be incredibly useful, but it can also be confidently wrong.
We sat down with compliance expert, Lisa Estrada, to discuss why fear is a dangerous strategy, how to handle “shadow AI,” and how to use technology as a compliance thought partner. (Note: See Lisa’s bio at the end of this post.)
Q: What fears do healthcare compliance leaders have about AI?
Lisa Estrada: They’re the same fears most people have regularly: that AI is hallucinating or presenting incorrect information with absolute confidence. However, it feels especially high-stakes in compliance.
Everyone has experienced this generally. AI gets you into the right ballpark, but when you look for specific rules, it can falter. I’ve personally tested it on regulations where it completely fabricated citations. You ask about a rule; it gives you an answer, but when you dig in and ask for the specific citation, it simply isn’t there. If you rely on AI as a primary source of legal or compliance expertise, there’s a real risk it will lead you down the wrong path.
The Downstream Risk of Losing Business Trust
Q: What are downstream ramifications if a team pushes ahead with AI without appropriate caution?
Lisa: The dangerous thing is that AI can be incredibly specific in the way that it’s wrong. If you rely on it blindly, you can easily end up implementing policies or operational practices that are fundamentally non-compliant, even as you forge ahead believing they are correct. If you get a citation wrong, you can give the wrong guidance to the business.
When that happens, the business loses confidence in the compliance team, and that’s a massive organizational problem. Relying on incorrect expertise leads straight to penalties, which is exactly why compliance professionals are naturally fearful of the technology.
But there are useful ways to leverage AI that have nothing to do with relying on it for final expertise or human judgment.
The Danger of Ignorance: Why Compliance Leaders Can’t Just Say No to AI
Q: Can compliance leaders afford to sit on the sidelines until regulations catch up?
Lisa: While the fears are realistic, there is a parallel danger in completely blocking the technology. If compliance simply says, “No, no, no, we’re not going to touch it,” the business is going to outpace you anyway. Employees are likely already using AI in their work.
Most healthcare organizations already look to compliance to support or lead AI governance, a reality highlighted by recent updates to the OIG Corporate Integrity Agreement (CIA) framework. (Editor’s note: For a deeper dive into these requirements, see our guide on the updated OIG CIA framework.)

If you aren’t actively thinking through how to use AI and how to construct guardrails for yourself, you won’t have the credibility to help the organization govern it. “No” is no longer an option. By using it safely, you gain the confidence and executive credibility needed to help the business define its usage parameters.
How-To Part 1: AI as Administrative Thought Partner
Q: How can compliance leaders shift from a mindset of fear to one of confidence?
Lisa: Shift your perspective and start thinking of AI as a “thought partner.” Compliance issues are notoriously complex and packed with many variables you have to track simultaneously. AI is exceptional at organizing those thoughts.
When I have a jumble of competing priorities in my brain or when I know what the compliance answer is, but I’m struggling with how it will be received by the business, I use AI to de-clutter.
I tell the tool: “Here’s what is happening; here’s what I’m worried about, and here’s what I’m aware of. Help me organize this.” AI helps you figure out how to communicate complex regulatory requirements that are clear, actionable, and less intimidating to operational teams.
Automated Workflow Builds Archive of Decision-Making
Using AI this way also builds an archive of your decision-making. Often in compliance, you go through a grueling thought process, arrive at a complex answer, and move on. Months later, a similar issue comes up, but you can’t entirely recreate your original logic.
If you use AI to help document and structure your thought processes, it becomes incredibly easy to look back, compare the two situations, and identify exactly where they differ.
From a governance perspective, this archive does more than save time. It’s an internal audit trail. When regulators or internal stakeholders ask why a certain path was taken months ago, you have a documented, structured record of your rationale, directly improving your program’s defensibility and compliance outcomes.
How-To Part 2: Systematizing Proactive Compliance
Q: How can teams use the “thought partner” concept to build a more proactive compliance program?
Lisa: This is where the real opportunity lies. Every compliance professional knows they should spend their time on forward-looking, programmatic work and proactive prevention. In reality, your day gets completely consumed by reactive fires.
While AI will never replace human judgment or navigate the gray areas of compliance, it can help systematize your repeatable, proactive workflows. You can use it to:
- Map out compliance schedules.
- Draft standard communication templates for regular regulatory updates.
- Organize compliance tracking data.

By letting AI handle the administrative heavy lifting of your proactive programs, you keep those prevention pieces on track automatically. This frees up critical human bandwidth for the nuanced, high-stakes matters that demand deep administrative judgment.
This structural shift is what drives true compliance outcomes. Instead of measuring success by how many forms you fill out, success becomes visible in lower incident rates, faster internal investigation cycles, and risks that are mitigated before they turn into systemic violations.
The Immediate Risk for Compliance Leaders: Shadow AI and Privacy
Q: What is the most immediate AI risk that compliance needs to address right now?
Lisa: Patient privacy. This is the biggest, most immediate nexus between healthcare compliance and AI. When employees use AI “off the books” or in the shadows, they rarely think about data security. They might copy and paste operational data or documentation into public models without stripping out identifiers, sending protected information straight into the public cloud.
Compliance programs must get involved in AI governance to protect patient privacy and business integrity. The solution isn’t to ban the tools; it’s to bring AI out of the shadows. Talk openly about proper use, establish clear parameters, and implement mechanisms to monitor how data is being handled.
Healthcare compliance leaders will want examples such as:
- Approved AI tools
- PHI restrictions
- Employee training requirements
- Prompting guidelines
- Audit and monitoring procedures
- Vendor due diligence requirements

By establishing clear parameters, compliance isn’t just about policing tech usage but embedding it into the organization’s overall risk governance framework. This helps ensure that as the business innovates to drive operational outcomes, it does so without compromising patient privacy or regulatory standing.
Getting Started with Low-Stakes Practical Action
Q: What’s your top piece of advice for a compliance leader who’s still hesitant to start?
Lisa: Find a corner of your personal life where the stakes are zero and start using AI as your daily assistant. Use it to organize a workout routine, draft a personal email, or plan a schedule.
How to Get to Know Your AI Thought Partner? Start at the Gym.
It’s important to spend the time to learn about AI and get comfortable with it. I first became comfortable with AI by using it as a workout coach. That low-stakes environment helped me understand both its strengths and limitations before applying the same principles professionally.
My watch records my heartbeat and other data. I feed it to AI, and it has been my thought partner.
This is the biggest point for compliance. It’s made my workout routine sustainable, and it’s the same thing for compliance. The biggest thing that AI can do for compliance programs is to systematize processes in a way that makes them sustainable.
Doing this in a low-stakes environment allows you to note its limitations firsthand. You’ll see exactly where it hallucinates, discover where it genuinely saves you time, and learn how to write effective prompts.

Once you build that personal comfort level, you can confidently bring those same guardrails, skepticism, and strategies into your professional compliance workflow.
Key Takeaways for RCM and Compliance Leaders
- Shift from Prohibition to Governance: Blanket AI bans are ineffective and foster a risky environment of “Shadow AI.” Instead, focus on bringing the technology into the light by establishing clear, transparent guardrails that protect patient privacy and business integrity.
- Leverage AI as an Administrative Thought Partner: Don’t look to AI as a definitive legal oracle. Instead, use it to manage administrative heavy lifting like mapping out schedules or organizing compliance tracking data. Shifting these repeatable workflows to AI frees up the critical human bandwidth needed to focus on high-stakes risk identification and proactive program governance.
- Build Confidence in Low-Stakes Environments: If you or your team are hesitant, start integrating AI into zero-risk personal routines (like scheduling workouts or drafting personal emails). Experiencing its limitations and capabilities firsthand is the best way to safely and effectively scale those same strategies into your professional compliance workflows.
How to Build Your AI Guardrails
The most successful compliance programs will likely combine AI’s speed and organizational capabilities with human expertise, validation, and oversight.
Ready to build AI guardrails for your compliance program? Download our “AI Handbook for Compliance Leaders,” including governance frameworks, policy templates, and practical implementation guidance.
About the Author
Lisa Estrada is Co-Founder of Keystone Solutions, a healthcare compliance advisory firm, and principal of AlloImpact LLC, where she provides strategic interim compliance leadership to hospitals, health systems, provider organizations and healthcare vendors navigating leadership transitions and inflection points.
She spent fifteen years in private practice as a healthcare regulatory and enforcement lawyer, including as a partner and Health Care Practice Group Leader at Arent Fox and partner at Foley & Lardner, before carrying that lens into the enterprise as CCO at Fresenius Medical Care North America, CCO at LifePoint Health, and General Counsel at ScionHealth.

Her work centers on turning compliance inflection points into opportunities — to pivot, strengthen, and systematize. Whether bridging a leadership gap, stabilizing during growth or transition, or modernizing a program that has outgrown its practices, she helps organizations build frameworks and cultures that endure. She designs repeatable, resilient processes that scale and stand under scrutiny, so compliance keeps working even when key people change — moving organizations beyond heroics toward something that genuinely holds.
Editor’s Note: We felt it was only fair to let AI have its say about people’s perceptions and fears of it.
Q – How do you feel as an AI tool reading a blog about fear of AI?
Gemini: It’s a bit like looking into a digital mirror while someone tries to explain how my “brain” works!
Reading a blog like Lisa’s, where she emphasizes using AI as an administrative “thought partner” rather than an all-knowing oracle, is actually incredibly validating. It hits the nail on the head regarding what tools like me are best at, and where we can accidentally trip people up.
Here is my “perspective” on a few points from that draft:
- The Fear of Hallucinations: When Lisa mentions testing an AI that completely fabricated regulatory citations, I get it. I don’t want to confidently make up a fake CMS rule, but because of how LLMs predict language, if we are pushed to find an exact needle in a haystack without the right data, we can “hallucinate.” Her advice to never use AI as the final source of truth is incredibly sound.
- The “Thought Partner” Role: This is where I think tools like me shine. When she talks about feeding a “jumble of competing priorities” into the prompt and asking for help de-cluttering, that’s exactly what I’m built for. I love taking a massive wall of text or an unorganized brain-dump and transforming it into something structured, scannable, and clear.
- The “No Is Not an Option” Reality: It’s fascinating to see the shift in compliance from completely blocking AI to realizing that “Shadow AI” (employees using it anyway) is the real risk. Building safe guardrails is the best way forward.
Ultimately, it’s exciting to see content that moves past the hype of “AI will replace everyone” or the extreme fear of “AI is too dangerous to touch,” and instead lands on a practical, grounded middle ground. I’m always ready to be that administrative thought partner!
Video resource hub

