Artificial Intelligence (AI) Protections Policy
| Human Resources | Safety/Security | Research Compliance | Compliance | Privacy/Information Security | Business Operations | Intellectual Property | Faculty |
Compliance Program | Compliance Hotline | Inspections/Investigations by Third Parties | Research Integrity | Export Control | Code of Conduct | Use of Human Anatomical Material | Clinical Research and Clinical Trial Professional and Technical Fee Billing | Contracts | Conflict of Interest | Red Flag Identity Theft Prevention Program | Principles of Financial Stewardship | Human Tissue Use and Transfer | Disclosing Foreign Support and International Activities | Health Care Vendor Interactions | Credit Hour Definition | Whistleblower | Electronic Digital Signatures and Records | UNMC AI Use Guidelines| Artificial Intelligence (AI) Protections Policy
Policy No.:
Effective Date: 06/2026
Revised Date: 06/2026
Artificial Intelligence (AI) Protections Policy - IM #73
1. PURPOSE
The purpose of this policy is to establish a framework for responsible and transformative use of artificial intelligence (AI) technologies to advance extraordinary patient care, operations, research, and education. AI is a strategic capability that can improve quality, safety, efficiency, and experience. At the same time, we have a duty to govern AI with rigor, transparency, fairness, and equity—protecting patients, workforce members, and enterprise. This policy establishes the protections, expectations, and institutional governance required to enable AI safely and confidently within Nebraska Medicine, UNMC, and the members of the Affiliated Covered Entity (ACE).
2. BASIS FOR POLICY
Nebraska Medicine/UNMC implements reasonable and appropriate controls for AI systems in alignment with National Institute of Standards and Technology (NIST) standards and guidance. NIST Special Publication 800-53, NIST CSF 2.0, and the HIPAA Privacy and Security Rules outline considerations for these controls.
FRAMEWORK REFERENCES
NIST SP 800-53 Rev 5: AC-2, AC-3, AU-2, AU-6, CM-2, CM-6, IR-4, IR-5, RA-3, RA-5, SI-3, SI-4, CP-2, CP-4
NIST CSF 2.0: PR.AC-1, PR.AC-4, PR.PT-1, DE.CM-7, PR.IP-1, PR.IP-3, RS.RP-1, RS.CO-1, ID.RA-1, ID.RA-3, PR.IP-2, DE.CM-4, RC.RP-1, RC.IM-1
HIPAA: 45 CFR 164.308, 164.312, 164.524, 164.526, 164.520
3. SCOPE
The Artificial Intelligence (AI) Protections Policy establishes the governance, protections, obligations, and expectations for the design, development, deployment, and use of AI systems across the enterprise. This policy supports innovation and improvement in care delivery, operations, research, and education while safeguarding privacy, equity, trust, and human oversight. This policy applies to all Artificial Intelligence (current and future) systems that are designed, developed, procured, deployed, operated, or used by Nebraska Medicine, UNMC, or on their behalf, regardless of whether such systems are used by members of the ACE workforce or by affiliated entities performing institutional functions.
For the purposes of this policy, “the institution” or “institutional” refers collectively to Nebraska Medicine, the University of Nebraska Medical Center (UNMC), and the members of the Affiliated Covered Entity (ACE), as applicable. This policy applies to internal AI models, third-party AI models, cloud-based AI models, and publicly available AI systems.
4. DEFINITIONS
Affiliated Covered Entity (ACE): The legally separate covered entities that designate themselves as a single covered entity for the purpose of HIPAA Compliance. Current Nebraska Medical ACE members are Nebraska Medicine, UNMC Physicians, UNMC, University Dental Associates, Bellevue Medical Center and Nebraska Pediatric Practice, Inc.
ACE membership may change from time to time. The Notice of Privacy Practices lists current ACE members.
Black Box Model: An AI system whose internal logic, decision-making processes, or feature contributions are not readily interpretable or explainable to users or stakeholders.
Hallucination (AI Hallucination): A phenomenon in which an AI system generates outputs that are factually incorrect, fabricated, or not grounded in source data while appearing plausible or authoritative.
Interpretability: The degree to which a human can understand how an AI system produces its outputs, including the ability to trace inputs, logic, and contributing factors.
Extractive AI: AI methods that identify, retrieve, or extract existing information from source data without generating new content (e.g., search, classification, summarization using source text).
Retrieval-Augmented Generation (RAG): An AI architecture that enhances model outputs by retrieving relevant information from external knowledge sources (e.g., documents, databases) and incorporating that information into the response generation process.
Workforce: All faculty, staff, volunteers, trainees, students, independent contractors, and other persons who perform services for, participate in programs of, or act on behalf of the institution, or whose activities are under the direct control of the institution, whether or not they are compensated by the institution.
Developer/Designer: Workforce members who create AI systems (including model design, coding, prompt engineering, training, testing, and evaluation).
Provisioner: Workforce members permitted by the developer to integrate AI into applications, tools, or workflows (e.g., connecting data sources, managing ingestion pipelines).
Deployer/User: Workforce members who implement AI systems into production or use them in day-to-day work to generate content or support decision-making.
Artificial Intelligence (AI): A machine-based system that performs tasks requiring human intelligence (e.g., pattern recognition, prediction, reasoning, and recommendation generation).
Artificial Intelligence System (AI System): Any data system, software, model, application, or utility that operates in whole or in part using AI. This excludes rules based or deterministic systems that do not perform learning, inference, or probabilistic reasoning.
Bias: A systematic tendency or error in judgment, data, or decision-making that can result in unfair, inaccurate, or inequitable outcomes.
AI Bias: Bias that arises when an artificial intelligence system produces unfair, misleading, or harmful outcomes due to factors such as training data, algorithm design, system configuration, or human interpretation.
Machine Learning (ML): A subset of AI where models learn patterns from data, improving performance over time with limited human intervention.
Deep Learning: A subset of ML using multi-layer neural networks capable of processing complex, unstructured data.
Generative AI: AI systems that generate original content (text, code, images, audio, etc.) based on learned patterns from training data.
Large Language Model (LLM): A type of AI model trained on large-scale text data to interpret and generate natural language.
Foundation Model: A large, pre-trained AI model trained on broad and diverse data that can be adapted to perform a wide range of downstream tasks.
Model Drift: Deterioration in model performance due to changes in data, environment, or context over time.
Intelligent Automation: The use of software systems to automate tasks or workflows, which may combine rules-based logic, robotic process automation, and artificial intelligence to execute actions with limited or no human intervention.
Robotic Process Automation (RPA): A form of automation that uses software “bots” to execute predefined, rules-based tasks by interacting with applications and systems in the same manner as a human user.
Intelligent Document Processing (IDP): An automation technology that applies artificial intelligence, including machine learning and natural language processing, to extract, classify, and validate information from unstructured or semi structured documents.
Intelligent automation technologies, including RPA and IDP, are considered AI systems under this policy when they perform decision-making, data transformation, classification, or autonomous actions affecting institutional operations, data, or individuals.
5. POLICY
5.1 AI Governance Model
Institutional Leadership shall establish an AI Governance Model to oversee, coordinate, and monitor enterprise use of artificial intelligence across clinical, operational, research, and educational domains.
The AI Governance Model is designed to support consistent, risk-based, and accountable AI adoption while leveraging existing institutional decision-making structures.
5.1.1 Governance Functions
The AI Governance Model shall ensure the following functions are defined and continuously performed:
- Establish, maintain, and periodically review institutional AI policies, standards, and procedures.
- Provide guidance and recommendations on appropriate AI use across clinical, operational, research, and educational domains.
- Maintain an enterprise inventory of AI systems in use across the institution, including:
- Use-case and workflow classification (e.g., clinical decision support, documentation, monitoring, operations, revenue cycle, research, education).
- AI category or capability type (e.g., predictive, generative, automation, decision support).
- Promote clear ownership and accountability for AI systems, including:
- IT or system owner
- Operational or business owner
- Responsible governance or decision-making body, where applicable.
- Promote a risk-based AI governance approach, with differentiated oversight expectations for lower- and higher-risk AI use cases, as defined in institutional standards or guidance.
- Provide visibility into AI-related risk assessment expectations and outcomes (e.g., privacy, compliance, cybersecurity, ethics, bias, equity).
- Monitor emerging risks, incidents, trends, or concerns related to AI systems and coordinate escalation to appropriate operational, compliance, security, or governance authorities when needed.
- Review aggregate reporting on AI-related incidents, concerns, or suspected policy violations to inform governance priorities and policy updates.
- Support efficient adoption of lower-risk AI use cases through streamlined governance pathways, as defined in institutional standards or guidance.
5.1.2 Governance Structure and Participation
The AI Governance Model may be supported by one or more coordinating bodies, councils, or working groups as designated by Institutional Leadership. These bodies serve an advisory and coordination role and do not independently approve, authorize, or deploy individual AI systems.
Clinical validation, patient safety determinations, and clinical decision-making authority remain within established clinical governance structures.
Membership and participation may include representatives from:
- Data, Analytics & AI Engineering
- Clinical Informatics
- Clinical Operations
- Information Security
- Privacy
- Enterprise Risk Management
- Compliance and Legal Affairs
- Platform/DevOps Engineering
- Workforce Training and Education
- Research and Academic Governance
- Library and Information Services
- Marketing and Communications
Standing clinician representation shall be incorporated to ensure clinical workflow, safety, and care delivery perspectives are included.
Ad hoc subject-matter experts may participate as needed based on AI use cases, domains, or risk profiles.
5.2 Workforce Responsibilities
5.2.1 Developers/Designers:
- Ensure data quality and lawful data use.
- Document model purpose, performance characteristics, limitations, and appropriate use context, including known risks and conditions under which the model should not be relied upon.
- Proactively assesses potential failures and mitigation strategies.
- Evaluate bias and equity impacts prior to deployment.
5.2.2 Provisioners:
- Ensure accurate and secure data flows into AI systems.
- Ensure systems are integrated only with approved data sources.
- Ensure privacy, security, and governance controls remain intact.
5.2.3 Deployers/Users:
- Understand the limitations of the AI system.
- Review AI-generated outputs for accuracy, appropriateness, and fairness.
- Do not rely on AI output as the sole basis for clinical or operational decision-making.
- Escalate concerns or unsafe results to the appropriate governance authority.
Clinical validation, determination of clinical accuracy, and assessment of patient safety impact are performed through established clinical governance processes and are not the responsibility of individual developers or end users acting alone.
5.3 Branding and Institutional Identity
Workforce members may not use AI systems to generate, replicate, modify, or approximate official Nebraska Medicine or University of Nebraska Medical Center (UNMC) logos, emblems, seals, trademarks, or other protected brand assets. All
use of official logos and branding elements must continue to follow established Marketing and Brand Governance processes, including formal logo requests and approvals.
6. PRINCIPLES AND PRACTICAL REQUIREMENTS
The institution’s approach to AI is guided by principles. Each principle includes required practices.
6.1 Principle: AI must protect privacy, confidentiality, and security.
- 6.1.1 No Protected Health Information (PHI), confidential operational information, proprietary information, or internal restricted data may be entered into any public or unapproved AI application.
- 6.1.2 Access to AI systems that process institutional data must comply with institutional account, device, and security requirements.
- 6.1.2.a Nebraska Medicine: Use of personal email accounts, personal phone numbers, personal cloud accounts, or personal devices to access or process institutional data through AI systems is prohibited unless specifically authorized.
- 6.1.2.b University of Nebraska Medical Center (UNMC): Use of personal devices to access or process institutional data through AI systems is permitted for UNMC workforce members and students when accessed via approved UNMC accounts and in compliance with institutional security, privacy, and data protection requirements.
- 6.1.3 Any AI system used with institutional data must meet institutional security standards and (where applicable) HIPAA requirements.
- 6.1.4 Vendors must not use or share institutional data for purposes beyond what is contractually approved and must be under appropriate legal agreements (e.g., BAA, DUA, MSA/SOW) prior to receiving data access.
6.2 Principle: AI must preserve human accountability.
A qualified human (“learner intermediary”) must remain responsible for interpreting AI outputs and making final decisions.
- 6.2.1 AI may not act as the final decision-maker in place of clinicians, operational leaders, and other professionals.
- 6.2.2 Workforce members must review AI output before acting on it.
- 6.2.3 Patients have the right to request human review of decisions influenced by AI. Any documentation or records generated in connection with such requests are subject to applicable institutional record-retention and privacy requirements.
- 6.2.4 AI systems must include human oversight appropriate to their level of risk. Oversight mechanisms may be adjusted for use cases based on risk classification, system performance, and validation; however, a qualified human remains accountable for outcomes and decisions influenced by AI.
6.3 Principle: AI must be safe, accurate, reliable, fair, and monitored.
- 6.3.1 AI systems must be designed, deployed, and used in a manner that prioritizes safety and minimizes the risk of harm to patients, workforce members, and operations, consistent with the institution’s Zero Harm commitment.
- 6.3.2 Developers must evaluate model performance prior to deployment.
- 6.3.3 Red-teaming, scenario testing, or stress testing must be conducted for models used in sensitive contexts.
- 6.3.4 Model performance must be re-evaluated periodically to detect drift, degradation, and bias.
- 6.3.5 Workforce users must escalate concerns or anomalies through appropriate institutional reporting mechanisms, which may include Information Security, Privacy, Clinical Safety, or the AI Oversight Committee, depending on the nature of the issue.
- 6.3.6 AI systems must be monitored over time to ensure they are fit for their intended use. Evaluation criteria and performance expectations must be appropriate to the use case, risk level, and context of use.
6.4 Principle: AI use must be transparent.
- 6.4.1 Patient-Facing AI Disclosure: When AI is used in patient-facing contexts, the involvement of AI must be disclosed.
- 6.4.1.a Definition of Patient-Facing AI: For purposes of this policy, patient-facing refers to AI-generated content, recommendations, or interactions that are presented directly to a patient without substantive clinician modification and that may influence a patient’s understanding, decisions, or actions related to their care.
- 6.4.2 Clinician-Mediated Content: Use of AI to assist clinicians in drafting, summarizing, or documenting content (e.g., ambient clinical documentation, draft patient instructions, or draft patient portal messages) does not require disclosure when the final content is reviewed, edited, and approved by a clinician and presented as clinician-authored.
- 6.4.3 Written Disclosure Mechanisms: Written disclosure of AI usage may be included within institutional Notice of Privacy Practices or similar patient-facing materials, as appropriate.
- 6.4.4 External Use Attribution: When AI-generated content is used externally (e.g., presentations, media, publications), attribution to the system used must be clearly noted.
- 6.4.5 Transparency for Decision-Support Outputs: When AI systems generate outputs intended to inform clinical, operational, research, or academic decision-making, the system must provide sufficient transparency to allow users to evaluate and validate the output, including access to source references, citations, or supporting context where technically feasible.
- 6.4.6 Non-Authoritative Presentation of AI Outputs: For AI systems used in decision-support contexts, outputs must not be presented as authoritative or definitive without appropriate citations, source references, or explanatory context to support human review and judgment.
6.5 Principle: AI use must be aligned to mission and values.
- 6.5.1 AI must not be used to generate or disseminate unlawful, fraudulent, harmful, plagiarized, inappropriate, or discriminatory content.
- 6.5.2 AI must not be used to create misinformation or content that misrepresents the institution.
- 6.5.3 AI must be designed, deployed, and used in ways that reflect the institution’s values and ethical standards.
6.6 Principle: AI must be accessible and inclusive.
- 6.6.1 AI systems, tools, interfaces, and AI-generated outputs must comply with applicable accessibility requirements, including the Americans with Disabilities Act (ADA) and institutional digital accessibility standards.
- 6.6.2 AI systems that are patient-facing, learner-facing, workforce-facing, or used in clinical, educational, or operational workflows must be designed and configured to support equitable access for individuals with disabilities.
- 6.6.3 Accessibility considerations must be included as part of AI system intake and risk assessment, and accessibility risks must be mitigated prior to deployment.
6.7 Governance of Principles
- 6.7.1 Changes to the Principles and Practical Requirements defined in Section 6 require review and approval by the AI Oversight Committee and must follow established institutional policy governance and approval processes.
- 6.7.2 Material changes that alter risk posture, regulatory obligations, or clinical or operational safety requirements may require additional review or approval by executive leadership, Legal Affairs, Compliance, or other governance bodies, as appropriate.
- 6.7.3 AI Embedded in Approved Enterprise Platforms: AI capabilities embedded within approved enterprise platforms (e.g., EHR, analytics, productivity, or operational systems) are subject to institutional AI governance. Initial review and approval may leverage existing platform, clinical, or operational governance processes. Introduction of new AI models or capabilities, material changes to intended use, data sources, autonomy, or risk profile may require additional review and approval under this policy.
7. ENFORCEMENT, TRAINING, AND REPORTING
7.1 Training Requirements
- 7.1.1 Workforce members may be required to complete assigned AI education prior to receiving access to AI systems.
- 7.1.2 Ongoing training, refreshers, and/or attestations may be required as systems evolve.
7.2 Reporting
- 7.2.1 Any suspected misuse, unsafe output, adverse event, or potential violation related to AI systems must be reported promptly through appropriate institutional reporting mechanisms, which may include Information Security reporting channels and/or the Safety Event Reporting System (SOS – RL Solutions), as applicable.
- 7.2.2 Reported AI-related concerns or incidents will be reviewed and triaged to the appropriate oversight area based on the nature of the issue, which may include Information Security, Privacy, Compliance, Ethics, Clinical Safety, Patient Safety, Research Integrity, or other relevant governance bodies.
- 7.2.3 Workforce members must not attempt to conceal AI-related incidents, output anomalies, or errors.
7.3 Enforcement
- 7.3.1 Violations of this policy may result in disciplinary action consistent with institutional HR policy.
- 7.3.2 Significant violations (e.g., privacy breach, safety risk, intentional misuse) will be escalated to Executive Leadership, Compliance, Legal Affairs, and/or Information Security as appropriate.
7.3.3 Response to Escalated AI Concerns
- Upon escalation of an AI-related concern, incident, or identified risk, the AI Oversight Committee will review the issue and determine an appropriate course of action based on severity, risk, and impact. Actions may include, but are not limited to:
- Requesting additional evaluation, validation, or monitoring
- Requiring remediation or modification of the AI system or workflow
- Temporarily suspending or restricting use of the AI system
- Referring the issue to appropriate governance bodies (e.g., Information Security, Privacy, Compliance, Patient Safety, or Clinical Governance)
- Recommending continuation, modification, or retirement of the AI system to the appropriate responsible authority
- Final decisions and enforcement actions are executed by the responsible operational, clinical, compliance, or executive governance bodies.
Escalated issues involving patient safety, regulatory compliance, or legal risk will be coordinated with executive leadership and appropriate institutional authorities.
Information Security will periodically review and update this policy as new technologies and risks are identified.
STAFF ACCOUNTABILITY
Chief Information Security Officer
Vice President, Information Technology
Department Approval
Signed: Lisa Bazis
Title: Chief Information Security Officer
Administrative Approval
Signed: Keith Rivera
Title: Vice President, Information Technology
This page maintained by mh.