Artificial Intelligence (AI) Protections Policy: Difference between revisions

From University of Nebraska Medical Center
Jump to navigation Jump to search
No edit summary
No edit summary
 
(11 intermediate revisions by the same user not shown)
Line 17: Line 17:
|[[Faculty]]
|[[Faculty]]
|}
|}
[[Compliance Program]] | [[Compliance Hotline]] | [[Inspections/Investigations by Third Parties]] | [[Research Integrity]] | [[Export Control]] | [[Code of Conduct]] | [[Use of Human Anatomical Material]] | [[Clinical Research and Clinical Trial Professional and Technical Fee Billing]] | [[Contracts]] | [[Conflict of Interest]] | [[Red Flag Identity Theft Prevention Program]] | [[Principles of Financial Stewardship]] | [[Human Tissue Use and Transfer]] | [[Disclosing Foreign Support and International Activities]] | [[Health Care Vendor Interactions]] | [[Credit Hour Definition]] | [[Whistleblower]] | Electronic Digital Signatures and Records | [[Utilizing Generative AI|UNMC AI Use Guidelines]]
[[Compliance Program]] | [[Compliance Hotline]] | [[Inspections/Investigations by Third Parties]] | [[Research Integrity]] | [[Export Control]] | [[Code of Conduct]] | [[Use of Human Anatomical Material]] | [[Clinical Research and Clinical Trial Professional and Technical Fee Billing]] | [[Contracts]] | [[Conflict of Interest]] | [[Red Flag Identity Theft Prevention Program]] | [[Principles of Financial Stewardship]] | [[Human Tissue Use and Transfer]] | [[Disclosing Foreign Support and International Activities]] | [[Health Care Vendor Interactions]] | [[Credit Hour Definition]] | [[Whistleblower]] | Electronic Digital Signatures and Records | [[Utilizing Generative AI|UNMC AI Use Guidelines]]| [https://wiki.unmc.edu/index.php?title=Artificial_Intelligence_(AI)_Protections_Policy&action=edit Artificial Intelligence (AI) Protections Policy]


Policy No.: '''8020'''


Effective Date: Draft 03/07/2025


Revised Date:
Effective Date: 06/2026


Reviewed Date:  
Revised Date: 06/2026 


'''<big>UNMC AI Use Guidelines</big>'''
'''<big>Artificial Intelligence (AI) Protections Policy - IM #73</big>'''


== Basis for Policy ==
'''1. PURPOSE'''
Ethical and responsible use of artificial intelligence (AI) must be paramount in all university activities that seek to develop or enhance AI systems or implement the use of AI technologies.  UNMC is committed to engaging with AI in support of its academic, research, patient care, and community engagement missions. These guidelines seek to balance the new possibilities offered by generative AI and other AI-enabled tools with awareness of their limitations and the need for rigorous attention to accuracy, intellectual property, security, privacy, and ethical issues. The appropriate use of AI and AI-enabled tools requires a collaborative approach among UNMC administrators, faculty, staff, students, and NU partners.


== Scope ==
The purpose of this policy is to establish a framework for responsible and transformative use of artificial intelligence (AI) technologies to advance extraordinary patient care, operations, research, and education. AI is a strategic capability that can improve quality, safety, efficiency, and experience. At the same time, we have a duty to govern AI with rigor, transparency, fairness, and equity—protecting patients, workforce members, and enterprise. This policy establishes the protections, expectations, and institutional governance required to enable AI safely and confidently within Nebraska Medicine, UNMC, and the members of the Affiliated Covered Entity (ACE).  
This document describes guidelines AI use at UNMC in support of the institution’s academic, research, and patient care missions. All students, faculty, and staff who develop or use AI, including generative AI will follow these guidelines, which are enforced through the [https://wiki.unmc.edu/index.php/Code_of_Conduct UNMC Code of Conduct]t, [https://catalog.unmc.edu/general-information/student-policies-procedures/code-of-conduct/ Student Code of Conduct], and [https://wiki.unmc.edu/index.php/Research_Integrity Research Integrity Policy]. These guidelines are largely focused on the use of generative AI tools. Generative AI is a subset of artificial intelligence that uses generative models to produce text, images, videos, or other forms of data.


== Guidelines ==
1.    Be mindful of including sensitive information in AI tools. External generative AI tools incorporate everything you send to them into their model, including the prompts, data, and reactions you supply. Most AI tools do not offer terms that are consistent with UNMC’s obligations to protect university data. Any information entered in external generative AI tools is considered public and may be stored and used by anyone else. UNMC employees and students are expected to:


* Not enter confidential, proprietary, or patient-related information that is subject to federal or state regulations or otherwise considered sensitive or restricted. Follow the UNMC  [[Privacy/Confidentiality|Privacy, Confidentiality and Security of Patient and Proprietary Information Policy]] and applicable privacy laws.
* Follow the University of Nebraska’s [https://nebraska.edu/offices-policies/its/policies-processes/responsible-use-of-university-computers-and-information-systems Policy for Responsible Use of University Computers and Information Systems], [https://nebraska.edu/offices-policies/policies/no-41-policy-on-research-data-and-security Policy on Research Data and Security], and [https://nebraska.edu/offices-policies/policies/no-42-policy-on-risk-classification-and-minimum-security-standards Policy on Risk Classification and Minimum Security Standards].


2.     All UNMC users are accountable for their academic or professional work, regardless of the tools used to produce it. When using generative AI tools, users should always verify the information produced for errors and biases and exercise caution to avoid copyright infringement.
'''2. BASIS FOR POLICY'''


* Generative AI tools may fabricate facts, create fake citations, or disregard or discredit true statements. Users must verify the accuracy of information used from generative AI tools. Since AI-generated material may be included in other materials, users should be prepared to invest extra effort in validating information.
Nebraska Medicine/UNMC implements reasonable and appropriate controls for AI systems in alignment with National Institute of Standards and Technology (NIST) standards and guidance. NIST Special Publication 800-53, NIST CSF 2.0, and the HIPAA Privacy and Security Rules outline considerations for these controls.
* Review all generative AI output carefully to guard against introducing unintended bias into work.  Generative AI tools can amplify biases present in data used to train the large language model. Results can include bias, and users’ interaction with results can reinforce these biases. Be mindful that bias can shape output.


* Research personnel are accountable for any plagiarized, falsified, or fabricated material that was generated by AI, regardless of funding. The [[Research Integrity|UNMC Research Integrity Policy]] and federal funding agencies specify the definitions and processes involved if material has been plagiarized, falsified, or fabricated. Federal funding agencies specify the definitions and processes involved if material has been plagiarized, falsified, or fabricated.


3.     Employees and students must maintain current awareness on ethical and responsible use of AI in research and creative activities by regularly reviewing university policies and relevant guidelines from funding agencies.


4.     Before initiating agreements with vendors, subcontractors, or collaborators inquiries should be made regarding any potential use of AI. Additional terms and conditions may be needed in current and future agreements to ensure the responsible and ethical use of AI that aligns with these guidelines.
'''FRAMEWORK REFERENCES''' 


5.     Federal funding agencies prohibit the use of AI tools during the peer-review process. The National Institutes of Health (NIH), in its discussion of AI peer review, explains that using AI in the peer review process is a breach of confidentiality because peer review is a confidential process and these tools “have no guarantee of where data are being sent, saved, viewed or used in the future.” The National Science Foundation (NSF) shares guidelines for declaring the use of AI in proposals and explicitly prohibits the use of AI in the NSF merit review process.
NIST SP 800-53 Rev 5: AC-2, AC-3, AU-2, AU-6, CM-2, CM-6, IR-4, IR-5, RA-3, RA-5, SI-3, SI-4, CP-2, CP-4


== Use for Education ==
NIST CSF 2.0: PR.AC-1, PR.AC-4, PR.PT-1, DE.CM-7, PR.IP-1, PR.IP-3, RS.RP-1, RS.CO-1, ID.RA-1, ID.RA-3, PR.IP-2, DE.CM-4, RC.RP-1, RC.IM-1


=== For Students ===
HIPAA: 45 CFR 164.308, 164.312, 164.524, 164.526, 164.520
In the UNMC curricula, students have opportunities to effectively leverage AI systems while developing a solid grounding in fundamental healthcare knowledge, critical thinking abilities, and strong ethics. AI literacy includes understanding AI's strengths, limitations, underlying principles, and responsible development and usage.


* Familiarize yourself with your instructors’ expectations regarding the use of AI tools in each course. If it is unclear whether AI tools are allowed in a particular course or for an assignment, review your course syllabus, Canvas course information, or ask your instructors directly. Faculty and instructor expectations will vary from course to course.  
* If you are permitted to use generative AI tools, you may be required to disclose your use and cite the tools you used. Cite AI-generated content word-for-word and describe use and paraphrasing generated by the tool.
* Entering queries or text into generative AI tools that have not been approved for use at UNMC will expose information publicly online. Treat what you enter into non-approved generative AI tools as if you were posting on a public forum.  
* Maintain academic integrity. Misuse of generative AI will be subject to the same policies and procedures as other academic misconduct.
* Contact the Division of Student Success for guidance if you have questions about generative AI and the academic misconduct process.


=== For Faculty and Instructors ===
UNMC encourages a flexible framework in which faculty and instructors can choose to prohibit, to allow with attribution, or to encourage use of generative AI tools. Describe the policy for the course clearly, and where relevant, the use that is permitted for each assignment.


Faculty and instructors can use Generative AI to create course instruction materials. They are not required to disclose its use, but it is recommended to model good practice by doing so.
'''3. SCOPE''' 


=== Use for Research ===
The Artificial Intelligence (AI) Protections Policy establishes the governance, protections, obligations, and expectations for the design, development, deployment, and use of AI systems across the enterprise. This policy supports innovation and improvement in care delivery, operations, research, and education while safeguarding privacy, equity, trust, and human oversight. This policy applies to all Artificial Intelligence (current and future) systems that are designed, developed, procured, deployed, operated, or used by Nebraska Medicine, UNMC, or on their behalf, regardless of whether such systems are used by members of the ACE workforce or by affiliated entities performing institutional functions.
UNMC’s research will explore new generative AI applications to solve healthcare challenges like personalized medicine, drug discovery, epidemic prevention, and chronic disease management. UNMC is committed to developing AI responsibly, ensuring rigorous validation, transparency, privacy protection and alignment with our humanistic values.


The widespread availability of generative AI tools offers new opportunities of creativity and efficiency and, as with any new tool, depends on humans for responsible and ethical deployment in research and society.
For the purposes of this policy, “the institution” or “institutional” refers collectively to Nebraska Medicine, the University of Nebraska Medical Center (UNMC), and the members of the Affiliated Covered Entity (ACE), as applicable. This policy applies to internal AI models, third-party AI models, cloud-based AI models, and publicly available AI systems.


When considering using generative AI in a research context, it is essential to investigate how much and what type is permitted. Funding agencies and journal publishers may have particular guidance. At a minimum, when you use generative AI output in scholarly works, disclose and describe how you used it and identify the sections of the work that include generative AI output.  
'''4. DEFINITIONS'''


=== Use for Administration and Other Purposes ===
* '''Affiliated Covered Entity (ACE):''' The legally separate covered entities that designate themselves as a single covered entity for the purpose of HIPAA Compliance. Current Nebraska Medical ACE members are Nebraska Medicine, UNMC Physicians, UNMC, University Dental Associates, Bellevue Medical Center and Nebraska Pediatric Practice, Inc. ACE membership may change from time to time. The Notice of Privacy Practices lists current ACE members.
UNMC embraces an interdisciplinary, collaborative paradigm that brings clinicians, computer scientists, ethicists, and stakeholders together to maximize the use of generative AI tools. Our generative AI solutions will be human-centered, aiming to reduce burnout and administrative burdens on faculty, staff and students, while elevating premier education, outstanding research, and the highest quality patient care, access, and outcomes. The use of generative AI for administration purposes must comply with the guidelines of the UNMC IT Services.
* '''Black Box Model:''' An AI system whose internal logic, decision-making processes, or feature contributions are not readily interpretable or explainable to users or stakeholders.
* '''Hallucination (AI Hallucination):''' A phenomenon in which an AI system generates outputs that are factually incorrect, fabricated, or not grounded in source data while appearing plausible or authoritative.
* '''Interpretability:''' The degree to which a human can understand how an AI system produces its outputs, including the ability to trace inputs, logic, and contributing factors.
* '''Extractive AI:''' AI methods that identify, retrieve, or extract existing information from source data without generating new content (e.g., search, classification, summarization using source text).
* '''Retrieval-Augmented Generation (RAG):''' An AI architecture that enhances model outputs by retrieving relevant information from external knowledge sources (e.g., documents, databases) and incorporating that information into the response generation process.
* '''Workforce:''' All faculty, staff, volunteers, trainees, students, independent contractors, and other persons who perform services for, participate in programs of, or act on behalf of the institution, or whose activities are under the direct control of the institution, whether or not they are compensated by the institution.
* '''Developer/Designer:''' Workforce members who create AI systems (including model design, coding, prompt engineering, training, testing, and evaluation).
* '''Provisioner:''' Workforce members permitted by the developer to integrate AI into applications, tools, or workflows (e.g., connecting data sources, managing ingestion pipelines).
* '''Deployer/User:''' Workforce members who implement AI systems into production or use them in day-to-day work to generate content or support decision-making.
* '''Artificial Intelligence (AI):''' A machine-based system that performs tasks requiring human intelligence (e.g., pattern recognition, prediction, reasoning, and recommendation generation).
* '''Artificial Intelligence System (AI System):''' Any data system, software, model, application, or utility that operates in whole or in part using AI. This excludes rules based or deterministic systems that do not perform learning, inference, or probabilistic reasoning.
* '''Bias:''' A systematic tendency or error in judgment, data, or decision-making that can result in unfair, inaccurate, or inequitable outcomes.
* '''AI Bias:''' Bias that arises when an artificial intelligence system produces unfair, misleading, or harmful outcomes due to factors such as training data, algorithm design, system configuration, or human interpretation.
* '''Machine Learning (ML):''' A subset of AI where models learn patterns from data, improving performance over time with limited human intervention.
* '''Deep Learning:''' A subset of ML using multi-layer neural networks capable of processing complex, unstructured data.
* '''Generative AI:''' AI systems that generate original content (text, code, images, audio, etc.) based on learned patterns from training data.
* '''Large Language Model (LLM):''' A type of AI model trained on large-scale text data to interpret and generate natural language.
* '''Foundation Model:''' A large, pre-trained AI model trained on broad and diverse data that can be adapted to perform a wide range of downstream tasks.
* '''Model Drift:''' Deterioration in model performance due to changes in data, environment, or context over time.
* '''Intelligent Automation:''' The use of software systems to automate tasks or workflows, which may combine rules-based logic, robotic process automation, and artificial intelligence to execute actions with limited or no human intervention.
* '''Robotic Process Automation (RPA):''' A form of automation that uses software “bots” to execute predefined, rules-based tasks by interacting with applications and systems in the same manner as a human user.
* '''Intelligent Document Processing (IDP):''' An automation technology that applies artificial intelligence, including machine learning and natural language processing, to extract, classify, and validate information from unstructured or semi structured documents. Intelligent automation technologies, including RPA and IDP, are considered AI systems under this policy when they perform decision-making, data transformation, classification, or autonomous actions affecting institutional operations, data, or individuals.


== Additional Information ==
'''5. POLICY'''


*Designated policy owner, [mailto:emily.glenn@unmc.edu Emily Glenn], 402-559-4085
'''5.1 AI Governance Model'''
* [mailto:sarah.glodencarlson@unmc.edu Chief Compliance Officer], 402-559-9576


Institutional Leadership shall establish an AI Governance Model to oversee, coordinate, and monitor enterprise use of artificial intelligence across clinical, operational, research, and educational domains.


The AI Governance Model is designed to support consistent, risk-based, and accountable AI adoption while leveraging existing institutional decision-making structures.


'''5.1.1 Governance Functions'''


The AI Governance Model shall ensure the following functions are defined and continuously performed:
* Establish, maintain, and periodically review institutional AI policies, standards, and procedures.
* Provide guidance and recommendations on appropriate AI use across clinical, operational, research, and educational domains.
* Maintain an enterprise inventory of AI systems in use across the institution, including:
** Use-case and workflow classification (e.g., clinical decision support, documentation, monitoring, operations, revenue cycle, research, education).
** AI category or capability type (e.g., predictive, generative, automation, decision support).
** Promote clear ownership and accountability for AI systems, including:
*** IT or system owner
*** Operational or business owner
*** Responsible governance or decision-making body, where applicable.
** Promote a risk-based AI governance approach, with differentiated oversight expectations for lower- and higher-risk AI use cases, as defined in institutional standards or guidance.
** Provide visibility into AI-related risk assessment expectations and outcomes (e.g., privacy, compliance, cybersecurity, ethics, bias, equity).
** Monitor emerging risks, incidents, trends, or concerns related to AI systems and coordinate escalation to appropriate operational, compliance, security, or governance authorities when needed.
** Review aggregate reporting on AI-related incidents, concerns, or suspected policy violations to inform governance priorities and policy updates.
** Support efficient adoption of lower-risk AI use cases through streamlined governance pathways, as defined in institutional standards or guidance.
'''5.1.2 Governance Structure and Participation'''
The AI Governance Model may be supported by one or more coordinating bodies, councils, or working groups as designated by Institutional Leadership. These bodies serve an advisory and coordination role and do not independently approve, authorize, or deploy individual AI systems.
Clinical validation, patient safety determinations, and clinical decision-making authority remain within established clinical governance structures.
Membership and participation may include representatives from:
* Data, Analytics & AI Engineering
* Clinical Informatics
* Clinical Operations
* Information Security
* Privacy
* Enterprise Risk Management
* Compliance and Legal Affairs
* Platform/DevOps Engineering
* Workforce Training and Education
* Research and Academic Governance
* Library and Information Services
* Marketing and Communications
Standing clinician representation shall be incorporated to ensure clinical workflow, safety, and care delivery perspectives are included.
Ad hoc subject-matter experts may participate as needed based on AI use cases, domains, or risk profiles.
'''5.2 Workforce Responsibilities'''
'''5.2.1 Developers/Designers:'''
* Ensure data quality and lawful data use.
* Document model purpose, performance characteristics, limitations, and appropriate    use context, including known risks and conditions under which the model should not be relied upon.
* Proactively assesses potential failures and mitigation strategies.
* Evaluate bias and equity impacts prior to deployment.
'''5.2.2 Provisioners:'''
* Ensure accurate and secure data flows into AI systems.
* Ensure systems are integrated only with approved data sources.
* Ensure privacy, security, and governance controls remain intact.
'''5.2.3 Deployers/Users:'''
* Understand the limitations of the AI system.
* Review AI-generated outputs for accuracy, appropriateness, and fairness.
* Do not rely on AI output as the sole basis for clinical or operational    decision-making.
* Escalate concerns or unsafe results to the appropriate governance authority.
Clinical validation, determination of clinical accuracy, and assessment of patient safety impact are performed through established clinical governance processes and are not the responsibility of individual developers or end users acting alone.
'''5.3 Branding and Institutional Identity'''
Workforce members may not use AI systems to generate, replicate, modify, or approximate official Nebraska Medicine or University of Nebraska Medical Center (UNMC) logos, emblems, seals, trademarks, or other protected brand assets. All use of official logos and branding elements must continue to follow established Marketing and Brand Governance processes, including formal logo requests and approvals.
'''6. PRINCIPLES AND PRACTICAL REQUIREMENTS'''
The institution’s approach to AI is guided by principles. Each principle includes required practices.
'''6.1 Principle: AI must protect privacy, confidentiality, and security.'''
* 6.1.1    No Protected Health Information (PHI), confidential operational information, proprietary information, or internal restricted data may be entered into any public or unapproved AI application.
* 6.1.2    Access to AI systems that process institutional data must comply with institutional account, device, and security requirements.
** 6.1.2.a Nebraska Medicine: Use of personal email accounts, personal phone numbers, personal cloud accounts, or personal devices to access or process institutional data through AI systems is prohibited unless specifically authorized.
** 6.1.2.b University of Nebraska Medical Center (UNMC): Use of personal devices to access or process institutional data through AI systems is permitted for UNMC workforce members and students when accessed via approved UNMC accounts and in compliance with institutional security, privacy, and data protection requirements.
* 6.1.3    Any AI system used with institutional data must meet institutional security standards and (where applicable) HIPAA requirements.
* 6.1.4    Vendors must not use or share institutional data for purposes beyond what is contractually approved and must be under appropriate legal agreements (e.g., BAA, DUA, MSA/SOW) prior to receiving data access.
'''6.2 Principle: AI must preserve human accountability.'''
A qualified human (“learner intermediary”) must remain responsible for interpreting AI outputs and making final decisions.
* 6.2.1    AI may not act as the final decision-maker in place of clinicians, operational leaders, and other professionals.
* 6.2.2    Workforce members must review AI output before acting on it.
* 6.2.3    Patients have the right to request human review of decisions influenced by AI. Any documentation or records generated in connection with such requests are subject to applicable institutional    record-retention and privacy requirements.
* 6.2.4    AI systems must include human oversight appropriate to their level of risk. Oversight mechanisms may be adjusted for use cases based on risk classification, system performance, and validation; however, a qualified human remains accountable for outcomes and decisions influenced by AI.
'''6.3 Principle: AI must be safe, accurate, reliable, fair, and monitored.'''
* 6.3.1    AI systems must be designed, deployed, and used in a manner that    prioritizes safety and minimizes the risk of harm to patients, workforce members, and operations, consistent with the institution’s Zero Harm commitment.
* 6.3.2    Developers must evaluate model performance prior to deployment.
* 6.3.3    Red-teaming, scenario testing, or stress testing must be conducted for models used in sensitive contexts.
* 6.3.4    Model performance must be re-evaluated periodically to detect drift, degradation, and bias.
* 6.3.5    Workforce users must escalate concerns or anomalies through appropriate institutional reporting mechanisms, which may include Information Security, Privacy, Clinical Safety, or the AI Oversight Committee, depending on the nature of the issue.
* 6.3.6    AI systems must be monitored over time to ensure they are fit for their intended use. Evaluation criteria and performance expectations must be appropriate to the use case, risk level, and context of use.
'''6.4 Principle: AI use must be transparent.'''
* '''6.4.1    Patient-Facing AI Disclosure''': When AI is used in patient-facing contexts, the involvement of AI must be disclosed.
** '''6.4.1.a      Definition of Patient-Facing AI''': For purposes of this policy, patient-facing refers to AI-generated content, recommendations, or interactions that are presented directly to a patient without substantive clinician modification and that may influence a patient’s understanding, decisions, or actions related to their care.
* '''6.4.2    Clinician-Mediated Content''': Use of AI to assist clinicians in drafting, summarizing, or documenting content (e.g., ambient clinical    documentation, draft patient instructions, or draft patient portal    messages) does not require disclosure when the final content is reviewed, edited, and approved by a clinician and presented as clinician-authored.
* '''6.4.3    Written Disclosure Mechanisms''': Written disclosure of AI usage may be included within institutional Notice of Privacy Practices or similar patient-facing materials, as appropriate.
* '''6.4.4    External Use Attribution''': When AI-generated content is used externally (e.g., presentations, media, publications), attribution to the system used must be clearly noted.
* '''6.4.5    Transparency for Decision-Support Outputs''': When AI systems generate outputs intended to inform clinical, operational, research, or academic decision-making, the system must provide sufficient transparency to allow users to evaluate and validate the output, including access to source references, citations, or supporting context where technically feasible.
* '''6.4.6    Non-Authoritative Presentation of AI Outputs''': For AI systems used in decision-support contexts, outputs must not be presented as authoritative or definitive without appropriate citations, source    references, or explanatory context to support human review and judgment.
'''6.5 Principle: AI use must be aligned to mission and values.'''
* 6.5.1    AI must not be used to generate or disseminate unlawful, fraudulent, harmful, plagiarized, inappropriate, or discriminatory content.
* 6.5.2    AI must not be used to create misinformation or content that misrepresents the institution.
* 6.5.3    AI must be designed, deployed, and used in ways that reflect the institution’s values and ethical standards.
'''6.6 Principle: AI must be accessible and inclusive.'''
* 6.6.1    AI systems, tools, interfaces, and AI-generated outputs must comply with applicable accessibility requirements, including the Americans with Disabilities Act (ADA) and institutional digital accessibility standards.
* 6.6.2    AI systems that are patient-facing, learner-facing, workforce-facing, or used in clinical, educational, or operational workflows must be designed and configured to support equitable access for individuals with disabilities.
* 6.6.3    Accessibility considerations must be included as part of AI system intake and risk assessment, and accessibility risks must be mitigated prior to deployment.
'''6.7 Governance of Principles'''
* 6.7.1    Changes to the Principles and Practical Requirements defined in Section 6 require review and approval by the AI Oversight Committee and must follow established institutional policy governance and approval processes.
* 6.7.2    Material changes that alter risk posture, regulatory obligations, or clinical or operational safety requirements may require additional review or approval by executive leadership, Legal Affairs, Compliance, or other governance bodies, as appropriate.
* 6.7.3    AI Embedded in Approved Enterprise Platforms: AI capabilities embedded within approved enterprise platforms (e.g., EHR, analytics, productivity, or operational systems) are subject to institutional AI governance. Initial review and approval may leverage existing platform, clinical, or operational governance processes. Introduction of new AI models or capabilities, material changes to intended use, data sources, autonomy, or risk profile may require additional review and approval under this policy.
'''7. ENFORCEMENT, TRAINING, AND REPORTING'''
'''7.1 Training Requirements'''
* 7.1.1    Workforce members may be required to complete assigned AI education prior to receiving access to AI systems.
* 7.1.2    Ongoing training, refreshers, and/or attestations may be required as systems evolve.
'''7.2 Reporting'''
* 7.2.1    Any suspected misuse, unsafe output, adverse event, or potential violation related to AI systems must be reported promptly through appropriate institutional reporting mechanisms, which may include Information Security reporting channels and/or the Safety Event Reporting System (SOS – RL Solutions), as applicable.
* 7.2.2    Reported AI-related concerns or incidents will be reviewed and triaged to the appropriate oversight area based on the nature of the issue, which may include Information Security, Privacy, Compliance, Ethics, Clinical Safety, Patient Safety, Research Integrity, or other    relevant governance bodies.
* 7.2.3    Workforce members must not attempt to conceal AI-related incidents, output    anomalies, or errors.
'''7.3 Enforcement'''
* 7.3.1    Violations of this policy may result in disciplinary action consistent with institutional HR policy.
* 7.3.2    Significant violations (e.g., privacy breach, safety risk, intentional misuse) will be escalated to Executive Leadership, Compliance, Legal Affairs, and/or Information Security as appropriate.
'''7.3.3 Response to Escalated AI Concerns'''
* Upon escalation of an AI-related concern, incident, or identified risk, the AI Oversight Committee will review the issue and determine an appropriate course of action based on severity, risk, and impact.    Actions may include, but are not limited to:
** Requesting additional evaluation, validation, or monitoring
** Requiring remediation or modification of the AI system or workflow
** Temporarily suspending or restricting use of the AI system
** Referring the issue to appropriate governance bodies (e.g., Information Security, Privacy, Compliance, Patient Safety, or Clinical Governance)
** Recommending continuation, modification, or retirement of the AI system to the appropriate responsible authority
** Final decisions and enforcement actions are executed by the responsible operational, clinical, compliance, or executive governance bodies.
Escalated issues involving patient safety, regulatory compliance, or legal risk will be coordinated with executive leadership and appropriate institutional authorities.
Information Security will periodically review and update this policy as new technologies and risks are identified.
'''STAFF ACCOUNTABILITY'''
Chief Information Security Officer
Vice President, Information Technology
'''Department Approval'''    
Signed: Lisa Bazis
Title: Chief Information Security Officer
'''Administrative Approval'''
Signed: Keith Rivera
==== '''Title: Vice President, Information Technology''' ====




This page maintained by [Mailto:mhurlocker@unmc.edu mh].
This page maintained by [Mailto:mhurlocker@unmc.edu mh].

Latest revision as of 15:11, September 9, 2026

Human Resources Safety/Security Research Compliance Compliance Privacy/Information Security Business Operations Intellectual Property Faculty

Compliance Program | Compliance Hotline | Inspections/Investigations by Third Parties | Research Integrity | Export Control | Code of Conduct | Use of Human Anatomical Material | Clinical Research and Clinical Trial Professional and Technical Fee Billing | Contracts | Conflict of Interest | Red Flag Identity Theft Prevention Program | Principles of Financial Stewardship | Human Tissue Use and Transfer | Disclosing Foreign Support and International Activities | Health Care Vendor Interactions | Credit Hour Definition | Whistleblower | Electronic Digital Signatures and Records | UNMC AI Use Guidelines| Artificial Intelligence (AI) Protections Policy


Effective Date: 06/2026

Revised Date: 06/2026

Artificial Intelligence (AI) Protections Policy - IM #73

1. PURPOSE

The purpose of this policy is to establish a framework for responsible and transformative use of artificial intelligence (AI) technologies to advance extraordinary patient care, operations, research, and education. AI is a strategic capability that can improve quality, safety, efficiency, and experience. At the same time, we have a duty to govern AI with rigor, transparency, fairness, and equity—protecting patients, workforce members, and enterprise. This policy establishes the protections, expectations, and institutional governance required to enable AI safely and confidently within Nebraska Medicine, UNMC, and the members of the Affiliated Covered Entity (ACE).  


2. BASIS FOR POLICY

Nebraska Medicine/UNMC implements reasonable and appropriate controls for AI systems in alignment with National Institute of Standards and Technology (NIST) standards and guidance. NIST Special Publication 800-53, NIST CSF 2.0, and the HIPAA Privacy and Security Rules outline considerations for these controls.


FRAMEWORK REFERENCES

NIST SP 800-53 Rev 5: AC-2, AC-3, AU-2, AU-6, CM-2, CM-6, IR-4, IR-5, RA-3, RA-5, SI-3, SI-4, CP-2, CP-4

NIST CSF 2.0: PR.AC-1, PR.AC-4, PR.PT-1, DE.CM-7, PR.IP-1, PR.IP-3, RS.RP-1, RS.CO-1, ID.RA-1, ID.RA-3, PR.IP-2, DE.CM-4, RC.RP-1, RC.IM-1

HIPAA: 45 CFR 164.308, 164.312, 164.524, 164.526, 164.520


3. SCOPE

The Artificial Intelligence (AI) Protections Policy establishes the governance, protections, obligations, and expectations for the design, development, deployment, and use of AI systems across the enterprise. This policy supports innovation and improvement in care delivery, operations, research, and education while safeguarding privacy, equity, trust, and human oversight. This policy applies to all Artificial Intelligence (current and future) systems that are designed, developed, procured, deployed, operated, or used by Nebraska Medicine, UNMC, or on their behalf, regardless of whether such systems are used by members of the ACE workforce or by affiliated entities performing institutional functions.

For the purposes of this policy, “the institution” or “institutional” refers collectively to Nebraska Medicine, the University of Nebraska Medical Center (UNMC), and the members of the Affiliated Covered Entity (ACE), as applicable. This policy applies to internal AI models, third-party AI models, cloud-based AI models, and publicly available AI systems.

4. DEFINITIONS

  • Affiliated Covered Entity (ACE): The legally separate covered entities that designate themselves as a single covered entity for the purpose of HIPAA Compliance. Current Nebraska Medical ACE members are Nebraska Medicine, UNMC Physicians, UNMC, University Dental Associates, Bellevue Medical Center and Nebraska Pediatric Practice, Inc. ACE membership may change from time to time. The Notice of Privacy Practices lists current ACE members.
  • Black Box Model: An AI system whose internal logic, decision-making processes, or feature contributions are not readily interpretable or explainable to users or stakeholders.
  • Hallucination (AI Hallucination): A phenomenon in which an AI system generates outputs that are factually incorrect, fabricated, or not grounded in source data while appearing plausible or authoritative.
  • Interpretability: The degree to which a human can understand how an AI system produces its outputs, including the ability to trace inputs, logic, and contributing factors.
  • Extractive AI: AI methods that identify, retrieve, or extract existing information from source data without generating new content (e.g., search, classification, summarization using source text).
  • Retrieval-Augmented Generation (RAG): An AI architecture that enhances model outputs by retrieving relevant information from external knowledge sources (e.g., documents, databases) and incorporating that information into the response generation process.
  • Workforce: All faculty, staff, volunteers, trainees, students, independent contractors, and other persons who perform services for, participate in programs of, or act on behalf of the institution, or whose activities are under the direct control of the institution, whether or not they are compensated by the institution.
  • Developer/Designer: Workforce members who create AI systems (including model design, coding, prompt engineering, training, testing, and evaluation).
  • Provisioner: Workforce members permitted by the developer to integrate AI into applications, tools, or workflows (e.g., connecting data sources, managing ingestion pipelines).
  • Deployer/User: Workforce members who implement AI systems into production or use them in day-to-day work to generate content or support decision-making.
  • Artificial Intelligence (AI): A machine-based system that performs tasks requiring human intelligence (e.g., pattern recognition, prediction, reasoning, and recommendation generation).
  • Artificial Intelligence System (AI System): Any data system, software, model, application, or utility that operates in whole or in part using AI. This excludes rules based or deterministic systems that do not perform learning, inference, or probabilistic reasoning.
  • Bias: A systematic tendency or error in judgment, data, or decision-making that can result in unfair, inaccurate, or inequitable outcomes.
  • AI Bias: Bias that arises when an artificial intelligence system produces unfair, misleading, or harmful outcomes due to factors such as training data, algorithm design, system configuration, or human interpretation.
  • Machine Learning (ML): A subset of AI where models learn patterns from data, improving performance over time with limited human intervention.
  • Deep Learning: A subset of ML using multi-layer neural networks capable of processing complex, unstructured data.
  • Generative AI: AI systems that generate original content (text, code, images, audio, etc.) based on learned patterns from training data.
  • Large Language Model (LLM): A type of AI model trained on large-scale text data to interpret and generate natural language.
  • Foundation Model: A large, pre-trained AI model trained on broad and diverse data that can be adapted to perform a wide range of downstream tasks.
  • Model Drift: Deterioration in model performance due to changes in data, environment, or context over time.
  • Intelligent Automation: The use of software systems to automate tasks or workflows, which may combine rules-based logic, robotic process automation, and artificial intelligence to execute actions with limited or no human intervention.
  • Robotic Process Automation (RPA): A form of automation that uses software “bots” to execute predefined, rules-based tasks by interacting with applications and systems in the same manner as a human user.
  • Intelligent Document Processing (IDP): An automation technology that applies artificial intelligence, including machine learning and natural language processing, to extract, classify, and validate information from unstructured or semi structured documents. Intelligent automation technologies, including RPA and IDP, are considered AI systems under this policy when they perform decision-making, data transformation, classification, or autonomous actions affecting institutional operations, data, or individuals.

5. POLICY

5.1 AI Governance Model

Institutional Leadership shall establish an AI Governance Model to oversee, coordinate, and monitor enterprise use of artificial intelligence across clinical, operational, research, and educational domains.

The AI Governance Model is designed to support consistent, risk-based, and accountable AI adoption while leveraging existing institutional decision-making structures.

5.1.1 Governance Functions

The AI Governance Model shall ensure the following functions are defined and continuously performed:

  • Establish, maintain, and periodically review institutional AI policies, standards, and procedures.
  • Provide guidance and recommendations on appropriate AI use across clinical, operational, research, and educational domains.
  • Maintain an enterprise inventory of AI systems in use across the institution, including:
    • Use-case and workflow classification (e.g., clinical decision support, documentation, monitoring, operations, revenue cycle, research, education).
    • AI category or capability type (e.g., predictive, generative, automation, decision support).
    • Promote clear ownership and accountability for AI systems, including:
      • IT or system owner
      • Operational or business owner
      • Responsible governance or decision-making body, where applicable.
    • Promote a risk-based AI governance approach, with differentiated oversight expectations for lower- and higher-risk AI use cases, as defined in institutional standards or guidance.
    • Provide visibility into AI-related risk assessment expectations and outcomes (e.g., privacy, compliance, cybersecurity, ethics, bias, equity).
    • Monitor emerging risks, incidents, trends, or concerns related to AI systems and coordinate escalation to appropriate operational, compliance, security, or governance authorities when needed.
    • Review aggregate reporting on AI-related incidents, concerns, or suspected policy violations to inform governance priorities and policy updates.
    • Support efficient adoption of lower-risk AI use cases through streamlined governance pathways, as defined in institutional standards or guidance.

5.1.2 Governance Structure and Participation

The AI Governance Model may be supported by one or more coordinating bodies, councils, or working groups as designated by Institutional Leadership. These bodies serve an advisory and coordination role and do not independently approve, authorize, or deploy individual AI systems.

Clinical validation, patient safety determinations, and clinical decision-making authority remain within established clinical governance structures.

Membership and participation may include representatives from:

  • Data, Analytics & AI Engineering
  • Clinical Informatics
  • Clinical Operations
  • Information Security
  • Privacy
  • Enterprise Risk Management
  • Compliance and Legal Affairs
  • Platform/DevOps Engineering
  • Workforce Training and Education
  • Research and Academic Governance
  • Library and Information Services
  • Marketing and Communications

Standing clinician representation shall be incorporated to ensure clinical workflow, safety, and care delivery perspectives are included.

Ad hoc subject-matter experts may participate as needed based on AI use cases, domains, or risk profiles.

5.2 Workforce Responsibilities

5.2.1 Developers/Designers:

  • Ensure data quality and lawful data use.
  • Document model purpose, performance characteristics, limitations, and appropriate use context, including known risks and conditions under which the model should not be relied upon.
  • Proactively assesses potential failures and mitigation strategies.
  • Evaluate bias and equity impacts prior to deployment.

5.2.2 Provisioners:

  • Ensure accurate and secure data flows into AI systems.
  • Ensure systems are integrated only with approved data sources.
  • Ensure privacy, security, and governance controls remain intact.

5.2.3 Deployers/Users:

  • Understand the limitations of the AI system.
  • Review AI-generated outputs for accuracy, appropriateness, and fairness.
  • Do not rely on AI output as the sole basis for clinical or operational decision-making.
  • Escalate concerns or unsafe results to the appropriate governance authority.

Clinical validation, determination of clinical accuracy, and assessment of patient safety impact are performed through established clinical governance processes and are not the responsibility of individual developers or end users acting alone.

5.3 Branding and Institutional Identity

Workforce members may not use AI systems to generate, replicate, modify, or approximate official Nebraska Medicine or University of Nebraska Medical Center (UNMC) logos, emblems, seals, trademarks, or other protected brand assets. All use of official logos and branding elements must continue to follow established Marketing and Brand Governance processes, including formal logo requests and approvals.

6. PRINCIPLES AND PRACTICAL REQUIREMENTS

The institution’s approach to AI is guided by principles. Each principle includes required practices.

6.1 Principle: AI must protect privacy, confidentiality, and security.

  • 6.1.1 No Protected Health Information (PHI), confidential operational information, proprietary information, or internal restricted data may be entered into any public or unapproved AI application.
  • 6.1.2 Access to AI systems that process institutional data must comply with institutional account, device, and security requirements.
    • 6.1.2.a Nebraska Medicine: Use of personal email accounts, personal phone numbers, personal cloud accounts, or personal devices to access or process institutional data through AI systems is prohibited unless specifically authorized.
    • 6.1.2.b University of Nebraska Medical Center (UNMC): Use of personal devices to access or process institutional data through AI systems is permitted for UNMC workforce members and students when accessed via approved UNMC accounts and in compliance with institutional security, privacy, and data protection requirements.
  • 6.1.3 Any AI system used with institutional data must meet institutional security standards and (where applicable) HIPAA requirements.
  • 6.1.4 Vendors must not use or share institutional data for purposes beyond what is contractually approved and must be under appropriate legal agreements (e.g., BAA, DUA, MSA/SOW) prior to receiving data access.

6.2 Principle: AI must preserve human accountability.

A qualified human (“learner intermediary”) must remain responsible for interpreting AI outputs and making final decisions.

  • 6.2.1 AI may not act as the final decision-maker in place of clinicians, operational leaders, and other professionals.
  • 6.2.2 Workforce members must review AI output before acting on it.
  • 6.2.3 Patients have the right to request human review of decisions influenced by AI. Any documentation or records generated in connection with such requests are subject to applicable institutional record-retention and privacy requirements.
  • 6.2.4 AI systems must include human oversight appropriate to their level of risk. Oversight mechanisms may be adjusted for use cases based on risk classification, system performance, and validation; however, a qualified human remains accountable for outcomes and decisions influenced by AI.

6.3 Principle: AI must be safe, accurate, reliable, fair, and monitored.

  • 6.3.1 AI systems must be designed, deployed, and used in a manner that prioritizes safety and minimizes the risk of harm to patients, workforce members, and operations, consistent with the institution’s Zero Harm commitment.
  • 6.3.2 Developers must evaluate model performance prior to deployment.
  • 6.3.3 Red-teaming, scenario testing, or stress testing must be conducted for models used in sensitive contexts.
  • 6.3.4 Model performance must be re-evaluated periodically to detect drift, degradation, and bias.
  • 6.3.5 Workforce users must escalate concerns or anomalies through appropriate institutional reporting mechanisms, which may include Information Security, Privacy, Clinical Safety, or the AI Oversight Committee, depending on the nature of the issue.
  • 6.3.6 AI systems must be monitored over time to ensure they are fit for their intended use. Evaluation criteria and performance expectations must be appropriate to the use case, risk level, and context of use.

6.4 Principle: AI use must be transparent.

  • 6.4.1 Patient-Facing AI Disclosure: When AI is used in patient-facing contexts, the involvement of AI must be disclosed.
    • 6.4.1.a Definition of Patient-Facing AI: For purposes of this policy, patient-facing refers to AI-generated content, recommendations, or interactions that are presented directly to a patient without substantive clinician modification and that may influence a patient’s understanding, decisions, or actions related to their care.
  • 6.4.2 Clinician-Mediated Content: Use of AI to assist clinicians in drafting, summarizing, or documenting content (e.g., ambient clinical documentation, draft patient instructions, or draft patient portal messages) does not require disclosure when the final content is reviewed, edited, and approved by a clinician and presented as clinician-authored.
  • 6.4.3 Written Disclosure Mechanisms: Written disclosure of AI usage may be included within institutional Notice of Privacy Practices or similar patient-facing materials, as appropriate.
  • 6.4.4 External Use Attribution: When AI-generated content is used externally (e.g., presentations, media, publications), attribution to the system used must be clearly noted.
  • 6.4.5 Transparency for Decision-Support Outputs: When AI systems generate outputs intended to inform clinical, operational, research, or academic decision-making, the system must provide sufficient transparency to allow users to evaluate and validate the output, including access to source references, citations, or supporting context where technically feasible.
  • 6.4.6 Non-Authoritative Presentation of AI Outputs: For AI systems used in decision-support contexts, outputs must not be presented as authoritative or definitive without appropriate citations, source references, or explanatory context to support human review and judgment.

6.5 Principle: AI use must be aligned to mission and values.

  • 6.5.1 AI must not be used to generate or disseminate unlawful, fraudulent, harmful, plagiarized, inappropriate, or discriminatory content.
  • 6.5.2 AI must not be used to create misinformation or content that misrepresents the institution.
  • 6.5.3 AI must be designed, deployed, and used in ways that reflect the institution’s values and ethical standards.

6.6 Principle: AI must be accessible and inclusive.

  • 6.6.1 AI systems, tools, interfaces, and AI-generated outputs must comply with applicable accessibility requirements, including the Americans with Disabilities Act (ADA) and institutional digital accessibility standards.
  • 6.6.2 AI systems that are patient-facing, learner-facing, workforce-facing, or used in clinical, educational, or operational workflows must be designed and configured to support equitable access for individuals with disabilities.
  • 6.6.3 Accessibility considerations must be included as part of AI system intake and risk assessment, and accessibility risks must be mitigated prior to deployment.

6.7 Governance of Principles

  • 6.7.1 Changes to the Principles and Practical Requirements defined in Section 6 require review and approval by the AI Oversight Committee and must follow established institutional policy governance and approval processes.
  • 6.7.2 Material changes that alter risk posture, regulatory obligations, or clinical or operational safety requirements may require additional review or approval by executive leadership, Legal Affairs, Compliance, or other governance bodies, as appropriate.
  • 6.7.3 AI Embedded in Approved Enterprise Platforms: AI capabilities embedded within approved enterprise platforms (e.g., EHR, analytics, productivity, or operational systems) are subject to institutional AI governance. Initial review and approval may leverage existing platform, clinical, or operational governance processes. Introduction of new AI models or capabilities, material changes to intended use, data sources, autonomy, or risk profile may require additional review and approval under this policy.

7. ENFORCEMENT, TRAINING, AND REPORTING

7.1 Training Requirements

  • 7.1.1 Workforce members may be required to complete assigned AI education prior to receiving access to AI systems.
  • 7.1.2 Ongoing training, refreshers, and/or attestations may be required as systems evolve.

7.2 Reporting

  • 7.2.1 Any suspected misuse, unsafe output, adverse event, or potential violation related to AI systems must be reported promptly through appropriate institutional reporting mechanisms, which may include Information Security reporting channels and/or the Safety Event Reporting System (SOS – RL Solutions), as applicable.
  • 7.2.2 Reported AI-related concerns or incidents will be reviewed and triaged to the appropriate oversight area based on the nature of the issue, which may include Information Security, Privacy, Compliance, Ethics, Clinical Safety, Patient Safety, Research Integrity, or other relevant governance bodies.
  • 7.2.3 Workforce members must not attempt to conceal AI-related incidents, output anomalies, or errors.

7.3 Enforcement

  • 7.3.1 Violations of this policy may result in disciplinary action consistent with institutional HR policy.
  • 7.3.2 Significant violations (e.g., privacy breach, safety risk, intentional misuse) will be escalated to Executive Leadership, Compliance, Legal Affairs, and/or Information Security as appropriate.

7.3.3 Response to Escalated AI Concerns

  • Upon escalation of an AI-related concern, incident, or identified risk, the AI Oversight Committee will review the issue and determine an appropriate course of action based on severity, risk, and impact. Actions may include, but are not limited to:
    • Requesting additional evaluation, validation, or monitoring
    • Requiring remediation or modification of the AI system or workflow
    • Temporarily suspending or restricting use of the AI system
    • Referring the issue to appropriate governance bodies (e.g., Information Security, Privacy, Compliance, Patient Safety, or Clinical Governance)
    • Recommending continuation, modification, or retirement of the AI system to the appropriate responsible authority
    • Final decisions and enforcement actions are executed by the responsible operational, clinical, compliance, or executive governance bodies.

Escalated issues involving patient safety, regulatory compliance, or legal risk will be coordinated with executive leadership and appropriate institutional authorities.

Information Security will periodically review and update this policy as new technologies and risks are identified.


STAFF ACCOUNTABILITY

Chief Information Security Officer

Vice President, Information Technology

Department Approval    

Signed: Lisa Bazis

Title: Chief Information Security Officer

Administrative Approval

Signed: Keith Rivera

Title: Vice President, Information Technology

This page maintained by mh.