Artificial Intelligence (AI) Protections Policy: Difference between revisions

No edit summary
No edit summary
Line 19: Line 19:
[[Compliance Program]] | [[Compliance Hotline]] | [[Inspections/Investigations by Third Parties]] | [[Research Integrity]] | [[Export Control]] | [[Code of Conduct]] | [[Use of Human Anatomical Material]] | [[Clinical Research and Clinical Trial Professional and Technical Fee Billing]] | [[Contracts]] | [[Conflict of Interest]] | [[Red Flag Identity Theft Prevention Program]] | [[Principles of Financial Stewardship]] | [[Human Tissue Use and Transfer]] | [[Disclosing Foreign Support and International Activities]] | [[Health Care Vendor Interactions]] | [[Credit Hour Definition]] | [[Whistleblower]] | Electronic Digital Signatures and Records | [[Utilizing Generative AI|UNMC AI Use Guidelines]]| [https://wiki.unmc.edu/index.php?title=Artificial_Intelligence_(AI)_Protections_Policy&action=edit Artificial Intelligence (AI) Protections Policy]
[[Compliance Program]] | [[Compliance Hotline]] | [[Inspections/Investigations by Third Parties]] | [[Research Integrity]] | [[Export Control]] | [[Code of Conduct]] | [[Use of Human Anatomical Material]] | [[Clinical Research and Clinical Trial Professional and Technical Fee Billing]] | [[Contracts]] | [[Conflict of Interest]] | [[Red Flag Identity Theft Prevention Program]] | [[Principles of Financial Stewardship]] | [[Human Tissue Use and Transfer]] | [[Disclosing Foreign Support and International Activities]] | [[Health Care Vendor Interactions]] | [[Credit Hour Definition]] | [[Whistleblower]] | Electronic Digital Signatures and Records | [[Utilizing Generative AI|UNMC AI Use Guidelines]]| [https://wiki.unmc.edu/index.php?title=Artificial_Intelligence_(AI)_Protections_Policy&action=edit Artificial Intelligence (AI) Protections Policy]


Policy No.:


Effective Date: 06/2026
Effective Date: 06/2026
Line 30: Line 29:


The purpose of this policy is to establish a framework for responsible and transformative use of artificial intelligence (AI) technologies to advance extraordinary patient care, operations, research, and education. AI is a strategic capability that can improve quality, safety, efficiency, and experience. At the same time, we have a duty to govern AI with rigor, transparency, fairness, and equity—protecting patients, workforce members, and enterprise. This policy establishes the protections, expectations, and institutional governance required to enable AI safely and confidently within Nebraska Medicine, UNMC, and the members of the Affiliated Covered Entity (ACE).  
The purpose of this policy is to establish a framework for responsible and transformative use of artificial intelligence (AI) technologies to advance extraordinary patient care, operations, research, and education. AI is a strategic capability that can improve quality, safety, efficiency, and experience. At the same time, we have a duty to govern AI with rigor, transparency, fairness, and equity—protecting patients, workforce members, and enterprise. This policy establishes the protections, expectations, and institutional governance required to enable AI safely and confidently within Nebraska Medicine, UNMC, and the members of the Affiliated Covered Entity (ACE).  




Line 35: Line 35:


Nebraska Medicine/UNMC implements reasonable and appropriate controls for AI systems in alignment with National Institute of Standards and Technology (NIST) standards and guidance. NIST Special Publication 800-53, NIST CSF 2.0, and the HIPAA Privacy and Security Rules outline considerations for these controls.
Nebraska Medicine/UNMC implements reasonable and appropriate controls for AI systems in alignment with National Institute of Standards and Technology (NIST) standards and guidance. NIST Special Publication 800-53, NIST CSF 2.0, and the HIPAA Privacy and Security Rules outline considerations for these controls.




Line 44: Line 45:


HIPAA: 45 CFR 164.308, 164.312, 164.524, 164.526, 164.520
HIPAA: 45 CFR 164.308, 164.312, 164.524, 164.526, 164.520




Line 54: Line 56:
'''4. DEFINITIONS'''
'''4. DEFINITIONS'''


'''Affiliated Covered Entity (ACE):''' The legally separate covered entities that designate themselves as a single covered entity for the purpose of HIPAA Compliance. Current Nebraska Medical ACE members are Nebraska Medicine, UNMC Physicians, UNMC, University Dental Associates, Bellevue Medical Center and Nebraska Pediatric Practice, Inc.
* '''Affiliated Covered Entity (ACE):''' The legally separate covered entities that designate themselves as a single covered entity for the purpose of HIPAA Compliance. Current Nebraska Medical ACE members are Nebraska Medicine, UNMC Physicians, UNMC, University Dental Associates, Bellevue Medical Center and Nebraska Pediatric Practice, Inc. ACE membership may change from time to time. The Notice of Privacy Practices lists current ACE members.
 
* '''Black Box Model:''' An AI system whose internal logic, decision-making processes, or feature contributions are not readily interpretable or explainable to users or stakeholders.
ACE membership may change from time to time. The Notice of Privacy Practices lists current ACE members.
* '''Hallucination (AI Hallucination):''' A phenomenon in which an AI system generates outputs that are factually incorrect, fabricated, or not grounded in source data while appearing plausible or authoritative.
 
* '''Interpretability:''' The degree to which a human can understand how an AI system produces its outputs, including the ability to trace inputs, logic, and contributing factors.
'''Black Box Model:''' An AI system whose internal logic, decision-making processes, or feature contributions are not readily interpretable or explainable to users or stakeholders.
* '''Extractive AI:''' AI methods that identify, retrieve, or extract existing information from source data without generating new content (e.g., search, classification, summarization using source text).
 
* '''Retrieval-Augmented Generation (RAG):''' An AI architecture that enhances model outputs by retrieving relevant information from external knowledge sources (e.g., documents, databases) and incorporating that information into the response generation process.
'''Hallucination (AI Hallucination):''' A phenomenon in which an AI system generates outputs that are factually incorrect, fabricated, or not grounded in source data while appearing plausible or authoritative.
* '''Workforce:''' All faculty, staff, volunteers, trainees, students, independent contractors, and other persons who perform services for, participate in programs of, or act on behalf of the institution, or whose activities are under the direct control of the institution, whether or not they are compensated by the institution.
 
* '''Developer/Designer:''' Workforce members who create AI systems (including model design, coding, prompt engineering, training, testing, and evaluation).
'''Interpretability:''' The degree to which a human can understand how an AI system produces its outputs, including the ability to trace inputs, logic, and contributing factors.
* '''Provisioner:''' Workforce members permitted by the developer to integrate AI into applications, tools, or workflows (e.g., connecting data sources, managing ingestion pipelines).
 
* '''Deployer/User:''' Workforce members who implement AI systems into production or use them in day-to-day work to generate content or support decision-making.
'''Extractive AI:''' AI methods that identify, retrieve, or extract existing information from source data without generating new content (e.g., search, classification, summarization using source text).
* '''Artificial Intelligence (AI):''' A machine-based system that performs tasks requiring human intelligence (e.g., pattern recognition, prediction, reasoning, and recommendation generation).
 
* '''Artificial Intelligence System (AI System):''' Any data system, software, model, application, or utility that operates in whole or in part using AI. This excludes rules based or deterministic systems that do not perform learning, inference, or probabilistic reasoning.
'''Retrieval-Augmented Generation (RAG):''' An AI architecture that enhances model outputs by retrieving relevant information from external knowledge sources (e.g., documents, databases) and incorporating that information into the response generation process.
* '''Bias:''' A systematic tendency or error in judgment, data, or decision-making that can result in unfair, inaccurate, or inequitable outcomes.
 
* '''AI Bias:''' Bias that arises when an artificial intelligence system produces unfair, misleading, or harmful outcomes due to factors such as training data, algorithm design, system configuration, or human interpretation.
'''Workforce:''' All faculty, staff, volunteers, trainees, students, independent contractors, and other persons who perform services for, participate in programs of, or act on behalf of the institution, or whose activities are under the direct control of the institution, whether or not they are compensated by the institution.  
* '''Machine Learning (ML):''' A subset of AI where models learn patterns from data, improving performance over time with limited human intervention.
 
* '''Deep Learning:''' A subset of ML using multi-layer neural networks capable of processing complex, unstructured data.
'''Developer/Designer:''' Workforce members who create AI systems (including model design, coding, prompt engineering, training, testing, and evaluation).
* '''Generative AI:''' AI systems that generate original content (text, code, images, audio, etc.) based on learned patterns from training data.
 
* '''Large Language Model (LLM):''' A type of AI model trained on large-scale text data to interpret and generate natural language.
'''Provisioner:''' Workforce members permitted by the developer to integrate AI into applications, tools, or workflows (e.g., connecting data sources, managing ingestion pipelines).  
* '''Foundation Model:''' A large, pre-trained AI model trained on broad and diverse data that can be adapted to perform a wide range of downstream tasks.
 
* '''Model Drift:''' Deterioration in model performance due to changes in data, environment, or context over time.
'''Deployer/User:''' Workforce members who implement AI systems into production or use them in day-to-day work to generate content or support decision-making.  
* '''Intelligent Automation:''' The use of software systems to automate tasks or workflows, which may combine rules-based logic, robotic process automation, and artificial intelligence to execute actions with limited or no human intervention.
 
* '''Robotic Process Automation (RPA):''' A form of automation that uses software “bots” to execute predefined, rules-based tasks by interacting with applications and systems in the same manner as a human user.
'''Artificial Intelligence (AI):''' A machine-based system that performs tasks requiring human intelligence (e.g., pattern recognition, prediction, reasoning, and recommendation generation).  
* '''Intelligent Document Processing (IDP):''' An automation technology that applies artificial intelligence, including machine learning and natural language processing, to extract, classify, and validate information from unstructured or semi structured documents. Intelligent automation technologies, including RPA and IDP, are considered AI systems under this policy when they perform decision-making, data transformation, classification, or autonomous actions affecting institutional operations, data, or individuals.
 
'''Artificial Intelligence System (AI System):''' Any data system, software, model, application, or utility that operates in whole or in part using AI. This excludes rules based or deterministic systems that do not perform learning, inference, or probabilistic reasoning.
 
'''Bias:''' A systematic tendency or error in judgment, data, or decision-making that can result in unfair, inaccurate, or inequitable outcomes.
 
'''AI Bias:''' Bias that arises when an artificial intelligence system produces unfair, misleading, or harmful outcomes due to factors such as training data, algorithm design, system configuration, or human interpretation.  
 
'''Machine Learning (ML):''' A subset of AI where models learn patterns from data, improving performance over time with limited human intervention.
 
'''Deep Learning:''' A subset of ML using multi-layer neural networks capable of processing complex, unstructured data.
 
'''Generative AI:''' AI systems that generate original content (text, code, images, audio, etc.) based on learned patterns from training data.  
 
'''Large Language Model (LLM):''' A type of AI model trained on large-scale text data to interpret and generate natural language.  
 
'''Foundation Model:''' A large, pre-trained AI model trained on broad and diverse data that can be adapted to perform a wide range of downstream tasks.  
 
'''Model Drift:''' Deterioration in model performance due to changes in data, environment, or context over time.
 
'''Intelligent Automation:''' The use of software systems to automate tasks or workflows, which may combine rules-based logic, robotic process automation, and artificial intelligence to execute actions with limited or no human intervention.  
 
'''Robotic Process Automation (RPA):''' A form of automation that uses software “bots” to execute predefined, rules-based tasks by interacting with applications and systems in the same manner as a human user.  
 
'''Intelligent Document Processing (IDP):''' An automation technology that applies artificial intelligence, including machine learning and natural language processing, to extract, classify, and validate information from unstructured or semi structured documents.
 
Intelligent automation technologies, including RPA and IDP, are considered AI systems under this policy when they perform decision-making, data transformation, classification, or autonomous actions affecting institutional operations, data, or individuals.


'''5. POLICY'''
'''5. POLICY'''
Line 160: Line 136:
'''5.2.1 Developers/Designers:'''
'''5.2.1 Developers/Designers:'''


* Ensure     data quality and lawful data use.
* Ensure data quality and lawful data use.
* Document     model purpose, performance characteristics, limitations, and appropriate    use context, including known risks and conditions under which the model     should not be relied upon.
* Document model purpose, performance characteristics, limitations, and appropriate    use context, including known risks and conditions under which the model should not be relied upon.
* Proactively     assesses potential failures and mitigation strategies.
* Proactively assesses potential failures and mitigation strategies.
* Evaluate     bias and equity impacts prior to deployment.
* Evaluate bias and equity impacts prior to deployment.


'''5.2.2 Provisioners:'''
'''5.2.2 Provisioners:'''


* Ensure     accurate and secure data flows into AI systems.
* Ensure accurate and secure data flows into AI systems.
* Ensure     systems are integrated only with approved data sources.
* Ensure systems are integrated only with approved data sources.
* Ensure     privacy, security, and governance controls remain intact.  
* Ensure privacy, security, and governance controls remain intact.


'''5.2.3 Deployers/Users:'''
'''5.2.3 Deployers/Users:'''


* Understand     the limitations of the AI system.  
* Understand the limitations of the AI system.
* Review     AI-generated outputs for accuracy, appropriateness, and fairness.
* Review AI-generated outputs for accuracy, appropriateness, and fairness.
* Do not     rely on AI output as the sole basis for clinical or operational    decision-making.
* Do not rely on AI output as the sole basis for clinical or operational    decision-making.
* Escalate     concerns or unsafe results to the appropriate governance authority.
* Escalate concerns or unsafe results to the appropriate governance authority.


Clinical validation, determination of clinical accuracy, and assessment of patient safety impact are performed through established clinical governance processes and are not the responsibility of individual developers or end users acting alone.
Clinical validation, determination of clinical accuracy, and assessment of patient safety impact are performed through established clinical governance processes and are not the responsibility of individual developers or end users acting alone.
Line 182: Line 158:
'''5.3 Branding and Institutional Identity'''
'''5.3 Branding and Institutional Identity'''


Workforce members may not use AI systems to generate, replicate, modify, or approximate official Nebraska Medicine or University of Nebraska Medical Center (UNMC) logos, emblems, seals, trademarks, or other protected brand assets. All
Workforce members may not use AI systems to generate, replicate, modify, or approximate official Nebraska Medicine or University of Nebraska Medical Center (UNMC) logos, emblems, seals, trademarks, or other protected brand assets. All use of official logos and branding elements must continue to follow established Marketing and Brand Governance processes, including formal logo requests and approvals.
 
use of official logos and branding elements must continue to follow established Marketing and Brand Governance processes, including formal logo requests and approvals.


'''6. PRINCIPLES AND PRACTICAL REQUIREMENTS'''
'''6. PRINCIPLES AND PRACTICAL REQUIREMENTS'''