Care Operating Model
- Legacy
- The EHR is fully deployed but AI touches no clinical or revenue-cycle workflow.
- Autonomous
- Care and revenue operations are AI-native, self-monitoring, and compounding across the system.
AIR rates how deliberately your health system embeds AI across care delivery, reimbursement, workforce, governance, and tooling, then shows the next rung to climb.
Ambient documentation, clinical decision support, and agentic tools are already in clinician hands, so the gap between governed adoption and ungoverned drift is widening into measurable patient-safety, privacy, and audit exposure.
The same five pillars of AI readiness, framed in the work, systems, and stakes that health-system and provider executives actually face.
Whether AI is embedded at named points in clinical and operational workflows with measured gains, or trapped in a few champions and pilot units.
Whether AI improves outcomes, access, and documentation that the organization can actually code, bill, and defend, or quietly absorbs cost without funding itself.
How broadly clinicians, nurses, and operations staff use AI confidently in their roles, with owned reskilling rather than a handful of self-taught enthusiasts.
Whether AI use is governed by enforced policy, PHI controls, clinical validation, and bias monitoring, or left to hope across a regulated, audited environment.
Whether the AI stack is a deliberately selected, BAA-covered, owned portfolio with visible spend, or sprawling shadow tools no one tracks.
AIR places Healthcare on a six-tier readiness ladder from 0 to 100, overall and for every pillar. The climb runs from digital but not intelligent, to a compounding, AI-native edge.
AI-native advantage. Compounding intelligence and speed, a durable edge competitors can't copy fast.
Woven through the business. AI shapes the operating model, pricing, and talent, and ROI is proven.
AI in the core, governed. Embedded at named steps with SOPs, policy, and measured gains.
Pockets, not a system. Real use in places, uneven and undocumented.
Experimenting at the edges. Scattered pilots that live in a few people's heads, ungoverned.
Digital, not intelligent. AI is absent or anecdotal, work is hour-priced, the stack sprawls, and no policy exists.
One score tells you that you are behind; five tiers tell you exactly where to start.
The matrix is a 5-by-6 grid: your five pillars of AI readiness scored against the same six tiers, from Legacy to Autonomous. A single overall score tells you roughly where you sit; it hides where you are dangerously behind and where you are quietly ahead. Reading a tier per pillar turns one vague number into five specific, fixable verdicts, so you act on the truth instead of an average.
How Healthcare's regulatory reality maps onto AIR readiness. Each row is a control your governance pillar has to carry.
| Regime | Pillar | What AI readiness requires |
|---|---|---|
| HIPAA Privacy and Security Rules | P4 | AI tools touching PHI must operate under a Business Associate Agreement, with access controls, audit logging, and a minimum-necessary basis for every data flow. |
| HITECH Act | P4 | Breach notification and heightened enforcement extend to AI vendors, so PHI exposure through prompts or vendor model training must be prevented and detectable. |
| FDA oversight of clinical AI (SaMD and clinical decision support) | P4 | AI that diagnoses, drives treatment, or functions as device software must be evaluated against FDA SaMD and CDS criteria before it is wired into care decisions. |
| ONC information-blocking rule (21st Century Cures Act) | P4 | AI-assisted documentation and data exchange must not impede patients' or providers' lawful access to electronic health information. |
| ONC HTI-1 algorithm transparency (Predictive DSI) | P4 | Certified-EHR predictive decision support requires documented source attributes and fairness measures, so deployed clinical models carry transparency artifacts. |
| NIST AI Risk Management Framework | P4 | AI deployments should be inventoried and mapped to govern, map, measure, and manage functions, with accountable owners and ongoing validation. |
| State privacy and consumer-health laws (e.g. CCPA/CPRA, Washington My Health My Data) | P4 | Consumer and non-HIPAA health data routed to AI tools must honor state consent, sale, and sensitive-data rules beyond the HIPAA perimeter. |
| CMS conditions and payer documentation integrity | P2 | AI-generated clinical notes and coding must remain accurate and attributable to a clinician, so reimbursement stays defensible under audit and avoids upcoding risk. |
Illustrative mapping for AI-readiness planning, not legal or compliance advice; validate against current federal and state regulation and your accreditation requirements with qualified counsel.
A clinician or biller pasting patient identifiers, notes, or images into a free chatbot creates a reportable HIPAA breach. Without enforced enterprise tooling and a never-paste control, this happens quietly and is discovered only after the fact.
Hallucinated medication details, fabricated citations, or an unvalidated risk score can influence a care decision if no clinical review checkpoint stands between AI output and the chart.
Models trained on skewed data can systematically under-serve patients by race, language, sex, or payer, exposing the system to harm and equity-of-care scrutiny if performance is never monitored by subgroup.
AI scribe and summarization output that is signed without genuine clinician review erodes note accuracy and creates documentation-integrity and reimbursement-audit exposure under payer and CMS rules.
AI features embedded across the EHR, point solutions, and expensed subscriptions accumulate without BAAs, security review, or an owner, leaving the data perimeter undefined and indefensible in an audit.
Concrete first moves you can make before the full diagnostic, one per pillar where it matters most.
Publish a one-page policy naming approved tools, banning PHI in consumer AI, and routing clinical-use AI through review, then have every clinician and staff member acknowledge it.
List every AI tool and embedded EHR feature touching patients or PHI, confirm a BAA exists for each, and assign it to a standing AI governance committee chaired by the CMIO.
Require attending or clinician sign-off as a defined checkpoint on every AI-generated note, summary, or recommendation before it enters the chart or reaches a patient.
Pick one service line on ambient documentation and baseline note turnaround, clinician time-in-notes, and after-hours charting so the operating gain is proven, not assumed.
Give each major service line a champion with protected time to train peers on validated AI workflows, converting a few enthusiasts into broad, role-specific fluency.
Standardize on one vetted enterprise AI platform per job-to-be-done, retire shadow subscriptions, and assign an owner who applies security, integration, and BAA criteria to new tools.
The old transformation is finished. The new one is scored.