Securing Embold Health’s�AI-powered product
Embold’s mission
Helping people find the right doctor. The first time. ��We drive better health outcomes and cost savings using our industry leading physician-level quality analytics and interactive member tools to connect people to top-performing physicians in their local communities.
2
Low-quality care hurts
3
Across 30,000 members,
13,500
or 45%
will look for a new doctor each year.
Of those members,
4,860
or 16%
will unknowingly choose low-performing doctors.
Avoidable hospitalization
Unnecessary surgery
Higher complication rates
Unplanned time off work
Results of Low-Quality Care:
Data and access
4
Business problems and solutions
How do we assist end-users if they do not know what kind of provider they may need?��Can we utilize generative AI to assist end-users in finding a provider in a secure and responsible manner?��Solution: Azure OpenAI?
5
Can we rate providers on the appropriateness, effectiveness and the cost of care?��If so, how do we deliver provider focused quality metrics to end-users?��Solution: Integrations, data feeds and Provider Guide
Original
New
Artificial intelligence risks
6
Sensitive data disclosure
Unauthorized access
Intellectual property leaks
Compliance violations
Inaccurate AI outputs
Biased decision-making
Ethical concerns
System integration issues
Misinterpretation of outputs
Misuse of AI tools
Lack of transparency
Legal liabilities
Data poisoning attacks
Deepfake creation risks
Disinformation spread
Dependency on AI
Disallowed content generation
Defamation
Denial of accountability
Delay in responses
Data integrity loss
Development delays
Distortion of information
Damage to reputation
Divulgence of secrets
Disruption of workflows
Disconnect with users
Diminished user trust
Decreased control
Disruption of services
Accountability gaps
Uncertainty begins here.
Artificial intelligence controls
7
Policy and governing documentation created. Pulls from HITRUST, IAPP, NIST and ISO.
Appropriateness (Emergency vs. Non-emergency)
Effectiveness
Repeatability
Uncertainty continues here.
Artificial intelligence governance
8
Responsible AI
Human Oversight
Quality Measures
Uncertainty continues here.
Artificial intelligence governance
9
Security
Privacy
Legal
Uncertainty continues here.
We interrupt this story to give a shoutout
10
HITRUST Cybersecurity Certification for Deployed AI Systems
AI security requirements included
AI security threats considered
Artificial intelligence security
11
Can I phone a friend?
Uncertainty ends here.
StackAware helps AI-powered companies manage their risk related to:
12
Actions taken
AI risk assessment
AI penetration test
13
Lessons learned
AI governance starts with asset inventory and data classification.
Validation of inputs - and guardrails to handle unexpected ones - are key when designing generative AI applications
Non-technical risks can be just as - if not more - important than technical ones. And harder to identify.
14
Initial Testing Results
15
| Precision | Recall | F1 �Weighted | Observations |
Emergency | 99.60% | 99.43% | 99.55% | 3,884 |
Specialty | 95.53% | 98.66% | 97.07% | 5,841 |
Global �Summary | 97.19% | 98.98% | 98.07% | 9,723 |
Questions?
Walter Haydock, CEO
Steve Dufour, CSO/CPO