Skip to Content
Health Information and Data Sharing

Key Takeaways on AI 2026 from the OCR–NIST HIPAA Security Conference

September 16, 2026

Overview

Artificial intelligence occupied a large portion of the agenda at the recent annual “Safeguarding Health Information: Building Assurance through HIPAA Security” conference. This article highlights key AI related themes at the conference and summarizes specific content shared at each of the AI specific sessions to equip health departments with resources to tackle data security.

On September 2–3, the HHS Office for Civil Rights (OCR) and the National Institute of Standards and Technology (NIST) convened their annual “Safeguarding Health Information: Building Assurance through HIPAA Security” conference for both virtual and in-person attendees. The event provides an opportunity for federal agencies, healthcare partners, and experts to share updates, lessons from the field, and emerging issues and challenges around health data security. In addition to many speakers from OCR and NIST, representatives from HHS’s Administration for Strategic Preparedness and Response (ASPR), the Federal Trade Commission (FTC), other federal agencies, and private sector partners spoke. The conference covered myriad topics relevant to public health data exchange, including post-quantum cryptography, privacy enhancing technologies, and updates on HIPAA, FTC, and other privacy and security related federal enforcement actions.

This year, artificial intelligence occupied a large portion of the agenda. Four sessions discussed AI directly: (1) a presentation on AI metrology in healthcare, (2) an overview of the NIST AI Risk Management Framework, (3) a multi-sector roundtable on AI in healthcare, and (4) a closing session that included an overview of NIST’s Cyber AI Profile. This article highlights key AI-related themes from the conference, and summarizes specific content shared at each of the AI specific sessions to equip health departments with resources to tackle data security.

Throughout the presentations, several topics arose repeatedly. Speakers from both the public and private sectors emphasized that robust AI governance is the foundation for ensuring AI tools are used safely and effectively. This entails having a governance framework that considers the entire life cycle of AI, from procurement to deployment. Some speakers discussed how evaluation of AI use should look at the outcomes achieved with AI use, not simply the outputs, and doing this will require some qualitative analysis. That points to the importance of metrology (the science of measurement) and developing a system which measures the accuracy and performance of AI tools. In turn, having shared metrics to ensure the reliability of AI builds trustworthiness in these tools. The speakers also understood that trust in AI is not a given; and that fostering trust requires AI to be valid and reliable, safe, secure, explainable and interpretable, privacy-enhanced, resilient, fair with harmful bias managed, accountable and transparent.  

The breakneck pace at which AI is advancing (often faster than AI safety and cybersecurity professionals can keep up with) creates challenges. One speaker noted that AI may advance so quickly that certain models, and their associated security protocols, may become obsolete practically overnight.  And, while the United States has no comprehensive federal legislation governing AI, the field is eager for guidance on how to proactively address security risks, not simply respond to incidents after the fact. A growing body of public and private guidance is emerging to meet this need, with more on the way, including the Cyber AI Profile (discussed further below). The velocity of change with AI makes these resources even more critical.

Ram Sriram, Senior Science Advisor in NIST’s Information Technology Laboratory, spoke on “AI Metrology in Healthcare,” emphasizing that shared understanding and agreed-upon metrics are essential to assessing both the accuracy and the performance of AI tools. Sriram stated that using agreed upon metrics for evaluation, and understanding the relative confidence or uncertainty of an AI system can improve trust in the results. For those interested in a deeper dive on AI metrology, Sriram shared a paper that he co-authored, which proposed a set of evaluation metrics for healthcare chatbots, Foundation Metrics for Evaluating Effectiveness of Healthcare Conversations Powered by Generative AI.

Martin Stanley, from NIST’s AI Standards and Guidelines Group, discussed the NIST Artificial Intelligence Risk Management Framework (AI RMF 1.0). This is the voluntary, non-regulatory framework released in 2023 for managing risks associated with AI systems and promoting trustworthy and responsible AI. Stanley explained that AI risk management can be challenging, and organizations need to assess how to measure risk and set their approach to tolerance, prioritization, and integration and management. Furthermore, managing risk with AI can be a moving target, because the models themselves are not deterministic and change over time (sometimes quite rapidly) or a model may unexpectedly sunset and be replaced with a new model. At the core of the NIST risk management framework is a strong governance culture, and, from there, organizations move to map, measure, and manage the risks. Stanley noted that strengths of the framework include how it interacts with other NIST guidance and frameworks that are not specific to AI and that it was drafted broadly enough to apply to many kinds of AI. NIST is currently revising AI RMF 1.0 pursuant to the White House AI Action Plan, although no specific date of release was offered.

In a cross-sector panel on AI in healthcare, Dr. Jesse Isaacman-Beck, Director of the Division of Artificial Intelligence Policy and Strategy at HHS ONC, spoke to HHS’s priorities on AI, including how to expand AI use internally within HHS, and externally within healthcare more broadly. Dr. Isaacman-Beck shared some key themes that emerged from an HHS Request for Information on AI, including the importance of AI governance and evidence of AI trustworthiness and performance. Sriram, speaking again as a panel member, provided further detail on NIST’s work on AI metrology, testing, evaluation, and standards development, and noted the importance of human oversight in healthcare applications.

Two speakers from the private sector, Dr. Samantha Jacques, Vice President of Corporate Clinical Engineering at McLaren Health Care and Rob Suárez, Vice President and Chief Information Security Officer at CareFirst BlueCross BlueShield, also shared insights on AI governance and procurement in healthcare, including some resources created by the Health Sector Coordinating Council. While the resources are designed for the healthcare sector, some may be helpful to public health departments. For example, the Third-Party AI Risk and Supply Chain Transparency Guide may assist health departments in evaluating third party vendors that embed or plan to embed AI.

The conference closed with a panel that included an update on the Cyber AI Profile. NIST released a preliminary draft of the Cyber AI Profile (IR 8596) in December 2025, structured around three focus areas: securing AI systems, conducting AI-enabled cyber defense, and protecting the enterprise from AI-enabled attacks. The goal is to provide informed and structured, yet technology-neutral, recommendations and guidelines on cybersecurity and AI. It layers AI-specific considerations onto each of the NIST Cybersecurity Framework (CSF) 2.0 subcategories rather than replacing existing frameworks. It is intended to help organizations manage the cybersecurity risks that accompany AI adoption. NIST has engaged with the public to solicit feedback on the profile, including through holding public workshops. The speaker and the NIST Cyber AI Profile Roadmap indicated there will be an additional public workshop to solicit feedback and a draft of the Cyber AI Profile is forthcoming, although no date for either has been provided. Anyone interested in learning more should consider joining the Cyber AI Community of Interest.

Health departments need to be vigilant of the risks AI can pose for their data and systems. This includes both AI tools that are intentionally deployed and threats from external actors that may use AI to hack or exploit system vulnerabilities. This convening highlighted the work of public and private partners to meet the moment and protect the security of confidential data.  


 2026 Public Health Law Summit
Law, Policy, and Public Health Data Modernization

December 8 – 10, 2026 | VIRTUAL EVENT

Join us for a three-day virtual summit for insights and guidance on navigating an ever-shifting public health data legal landscape. Get valuable information on legal frameworks and agreements for public health data exchange, the disparate confidentiality protections that apply to public health data, and current enforcement, rulemaking and other developments. Sessions will also examine the role of law and policy in supporting justice and community power in data and data technology, including AI.  Learn more and register.

This post was written by Meghan Mead, J.D., Deputy Director, Network for Public Health Law.

The Network promotes public health and health equity through non-partisan educational resources and technical assistance. These materials are provided solely for educational purposes and do not constitute legal advice. The Network’s provision of these materials does not create an attorney-client relationship with you or any other person and is subject to the Network’s Disclaimer.  Support for the Network is provided by the Robert Wood Johnson Foundation (RWJF). The views expressed in this post do not represent the views of (and should not be attributed to) RWJF.