Security

What should a hospital IT team ask an AI vendor about data security?

A hospital IT team should ask an AI vendor eight concrete things: where patient data is processed and what residency is guaranteed in the contract; whether data is encrypted in transit (TLS 1.3) and at rest; who inside the vendor can access it, under what least-privilege controls; how long data is retained and how deletion works; what audit logs the hospital itself receives; which independent certifications apply (such as ISO/IEC 27001) and what their scope covers; how incidents are detected and how quickly the hospital is notified; and which subprocessors touch the data. Ask for written evidence — a security whitepaper and the certification scope — not verbal assurance.

Each question exists because a common failure hides behind it. Residency decides which laws apply; encryption claims mean little without protocol versions and key-management detail; internal vendor access is where many real-world leaks start; retention terms determine what is still exposed years later; audit logs the hospital cannot see are audit logs it cannot use in front of a regulator; a certification without its scope statement may not even cover the product being sold; incident-notification clauses decide whether the hospital hears about a breach from the vendor or from the news; and every subprocessor extends the attack surface. A vendor that answers all eight in writing is showing its operating model, not its marketing.

Micromeet answers these questions in a published security whitepaper and holds ISO/IEC 27001:2022 certification for its AI application platform development, with encryption in transit (TLS 1.3 where supported) and at rest. Security and governance are two halves of the same evaluation: beyond protecting the data, governed healthcare AI also controls what the AI does with it — every clinical output from MCU CoPilot or AI Scribe (Voice-to-EMR) passes a doctor-review gate with an audit trail before it enters the record. AI writes. Doctors decide.

Related questions

Is ISO 27001 certification enough on its own?+
No. ISO/IEC 27001 proves the organization runs an audited Information Security Management System, not that every product or system is covered. Always request the certification scope, then pair it with penetration-test evidence and contractual terms on residency, retention, and breach notification.
Should we insist on on-premise deployment?+
Not automatically. The sharper questions are where data is processed, who can access it, and what controls and audit evidence apply. Residency guarantees, encryption, access control, and audit logs can be met in more than one deployment model — evaluate the controls, not the label.
What written evidence should the vendor hand over?+
At minimum: a security whitepaper describing architecture and controls, the certification with its scope statement, a recent penetration-test summary, and a data-processing agreement covering residency, retention, deletion, subprocessors, and incident notification.

Micromeet — AI for governed healthcare. MCU CoPilot, AI Scribe (Voice-to-EMR), AI Front Desk, Care Loop, Claim Readiness and AI Care Command Center — every output doctor-reviewed. AI writes. Doctors decide. See the public benchmark →