AI › Shadow AI review
Free · 45 minutes
Not whether your policy allows it, whether it is happening. Most leaders suspect staff are pasting clinical text into consumer chatbots to move work faster. Very few have looked, and a suspicion is not something you can act on or report.
Forty-five minutes with the people doing the work. You keep a one-page exposure map whether or not we ever work together.
Request a reviewWhat you leave with
A named list of AI-touching steps
Which tasks, which tools, which team, and what class of data passes through each one.
The paths that lack an agreement or a log
Ranked by how much patient data they carry, so you know what to address first.
A sanctioned alternative for the top one or two
Specific enough to act on: where the boundary sits, what gets logged, who approves output.
Something you can hand to compliance
Written factually, in the language a security questionnaire uses.
Why this is worth 45 minutes
If a regulator, an auditor, or your own board asks what patient data has passed through an unsanctioned AI tool, the answer most organizations can give today is that they do not know. That is a materially worse position than a small, documented, bounded disclosure.
And the behavior is rational from the staff side. A biller with a queue and a deadline found a tool that drafts an appeal in two minutes instead of twenty. Nobody told them where the line was in terms that applied to their actual job. Blocking a domain does not change the incentive; it just moves the activity onto a personal phone.
So the review is deliberately not an audit and not a disciplinary exercise. We are not looking for someone to blame. We are looking for the two or three workflows where the sanctioned path needs to become the fast one. That framing is also the only way people tell you the truth in the interview.
The 45 minutes
FIRST 10 MIN
What your policy says
Current stance on AI tools, who owns it, and whether staff know what it means for their own work. The gap between the two is usually the finding.
NEXT 20 MIN
Walk the actual tasks
Appeal drafting, policy lookups, chart summarization, correspondence. Where is the slow step, and what did someone find to get around it?
NEXT 10 MIN
Classify the exposure
For each path: is there an agreement, is there a log, does identifiable data leave, and could you establish scope after the fact?
LAST 5 MIN
Rank and agree next step
What to shut off, what to sanction, what to replace. We send the written map within two business days.
Bring one operational leader and one or two people who actually do the work. The second group is where the useful information is, and the session does not work without them.
Terms, plainly
Is this a sales call?
It is a real deliverable that we hope leads to work. Both things are true and we would rather say so. The map is yours regardless, and if the honest finding is that your exposure is minimal, we will write that down and you will have documentation saying it.
Do you need access to our systems?
No. This is a conversation, not a technical scan. No credentials, no network access, no patient data changes hands. If you later want the monitoring side done properly, that is a separate engagement with its own agreements.
Will this get our staff in trouble?
Not from us. The map describes workflows and data classes, not individuals. We will say this at the start of the session too, because otherwise nobody tells you anything useful and the whole exercise is theater.
What if we have genuinely banned AI?
Then the review is short and the finding is worth having in writing. Worth knowing: a ban does not remove the option of workflow automation, which is where most of the recoverable hours are anyway and involves no model at all.
The longer version of our position on all of this is on the AI page, including the de-identification boundary and where we think a model does not belong. This review is one of four ways to start with us.
Next step
Forty-five minutes, one operational area, no system access. You keep the exposure map either way.
Request a review