Leadership1 distinct publisher3 min readPublished
Practitioners on the Forbes Technology Council put billing and coding at the top of both the payback list and the risk list, and most of their prescriptions land on retrieval and retention rather than on a human reviewer.
The Board Room · Leadership desk
science
HIPAA Covers Less Than You Think, And "Anonymized" Is Not A Legal Shield1 distinct publisher
leadership
Nobody ran an AI rollout at Buyers Edge. Its 1,200 employees did it themselves.1 distinct publisher
build
Fabric's customer-managed keys now reach Spark shuffle and spill, closing a compliance line item1 distinct publisher
build
Same-day GPT-5.6 on Azure kills the parity argument, leaving auth and residency to decide1 distinct publisher
Compiled by The Board RoomSomething wrong?How this is made
Mark Francis of CaregiverZone treats a billing code as two documents at once, an instruction to a payer and an assertion about a patient, which is why he puts the coding workflow's failure modes in both columns: unsupported upcoding and leaked PHI on one side, and patient files carrying misleading diagnoses and treatments on the other [3]. That is a different shape of error from a bad forecast, which is absorbed by the system that produced it. Here the artifact stays in the record and is read by the next clinician.
Read the roundup for what its contributors ask for rather than what they warn about, and the human-in-the-loop framing narrows. Of the seven entries with complete commentary, two ask explicitly for human oversight: Francis on coding [3], and Dan Sorensen of Nexus Security Advisors on remote patient monitoring, who wants AI reviewing mundane tasks rather than replacing human intervention [9]. The other five prescribe controls at the data layer instead, including isolated datasets and purpose-limited retrieval, per-message-type constraints on what a model reads, retention decisions taken before the first call is answered, and message obfuscation rules [13]. A reviewer sitting at the output of the model cannot see any of those.
Dr Chiranjiv Roy of C5i.ai names the reason that gap matters. To draft a single patient portal reply the model reads the whole record, so a workflow that once touched one message now touches everything, and the minimum necessary standard can degrade with no breach to signal it [5]. No leak occurs, so no alert fires, and the only log kept tracks what the model read, not what it wrote [5].
Gating the coding workflow with a human on every claim would return the process to the cost it was bought to remove, which is why the live question is which classes of output get reviewed rather than what share of them do. The record supplied here does not settle it: the roundup carries no error rate for AI-generated codes, no audit finding and no enforcement action [14], and its authority is the judgment of members of an invitation-only technology council [1]. Anyone setting a sampling rate this quarter is pricing an unmeasured error rate, and we do not know yet what fraction of automated codes would fail a payer review.
Two of the exposures described run on someone else's calendar. Ganesh Ariyur of Transform Smarter notes that voiceprints are treated as biometric data with their own consent rules in several states, so the audio retention decision taken at go-live is the one produced later [6]. Konstantin Klyagin of Redwerk describes embeddings that survive deletion of the source file, which means a right-to-delete request arriving next year tests a pipeline built this year [4]. The roundup's own framing asks leaders to evaluate data access, vendor relationships, security controls and oversight before deploying at scale [10]; scale is the step that converts each of those from a design question into a disclosure.
Ranked by verification strength, evidence, and original report placement.
Members of the Forbes Technology Council, an invitation-only community for CIOs, CTOs and technology executives, discussed healthcare workflows where AI could improve efficiency and outcomes but also create cybersecurity, privacy or accuracy risks if leaders move too quickly.
Mark Francis of CaregiverZone says billing and revenue cycle management is a healthcare workflow where AI can add real value, citing faster claims, fewer denials and accelerated time-to-money.
Francis says unsupported upcoding, leaked protected health information and incorrect coding through hallucinations could result in higher audit risk and also compromise patient files with misleading diagnoses and treatments, and that human-in-the-loop oversight is critical in healthcare.
The roundup states that healthcare organizations must carefully evaluate data access, vendor relationships, security controls and oversight before deploying AI at scale, and that AI can introduce errors or inappropriate automated actions where organizations do not build in adequate safeguards and human oversight.
Two of the seven complete entries call explicitly for human oversight (Francis on billing and coding, Sorensen on remote patient monitoring); the other five prescribe controls on data access, retrieval, retention or delivery channel.
The roundup contains no quantified error rate for AI-generated coding, no named audit finding and no named enforcement action.
Distinct publishers with included, body-backed reporting in this cluster.
forbes.com
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One contributed roundup, zero measurements
Everything rests on a single Forbes council post, and its sharpest passages are mechanism arguments offered bare. Klyagin says embeddings survive a deletion request and can be inverted; Roy says one portal draft reads the whole chart; Ariyur says several states regulate voiceprints without naming one. Each is specific enough to be checked, and nothing in this reporting checks any of them.
No deployment is described
Not one health system, vendor rollout, patient volume or go-live date is named. The workflows are discussed as things leaders are weighing, so there is no uptake to size — and inferring any from the confidence of the advice would be inventing it.
Caution asserted as confidently as payback
A risk piece usually lands below its evidence, not above it, and this one nearly does. What pushes it over is symmetry of certainty: 'hackers can reverse-engineer those leftover AI files' arrives with the same flatness as 'faster claims, fewer denials'. Both directions are unpriced, and stating a threat model as an event is its own kind of overreach.
Every prescription has a vendor attached
The council is invitation-only and paid, and the post carries its own 'Do I qualify?' membership pitch mid-text. Beyond that, the remedies track the day jobs: a security advisory firm wants every device-to-cloud hop mapped and vetted, a development shop warns that compliance bolted on later means rebuilding, a services integrator wants purpose-limited retrieval verified continuously. None of that makes the advice wrong; it does mean the advice and the sales motion point the same direction, and the reader is never told so.
Trust the shape, not the count
Our earlier tally of this piece was off — eleven named workflows rather than eight, and the sentence that breaks off belongs to clinical documentation, not clinical decision support — which is a precision problem, not a substance one. The qualitative shape survives it intact: billing leads on both payback and audit exposure, and controls are prescribed far more often than reviewers. What no amount of careful reading can supply is a second source.