From concerns to frameworks: Mapping 2021 healthcare professional concerns about AI to post-2021 U.S. governance responses
A 2021 quantitative study of 281 U.S. healthcare professionals and HIPAA officers identified six recurring concerns about artificial intelligence (AI), HIPAA, and the privacy and security of protected health information (PHI): regulatory gaps, HIPAA’s perceived obsolescence, vendor accountability outside HIPAA’s covered-entity perimeter, re-identification risk, limited workforce AI literacy, and lack of operational guidance. This paper uses a structured document analysis to map those concerns to major post-2021 U.S. governance responses, including NIST AI RMF, ONC HTI-1, HHS OCR actions, the proposed HIPAA Security Rule update, FDA guidance, FTC enforcement, and selected state laws. Using a four-point rubric (addressed, partially addressed, not yet addressed, and contested), the analysis finds that none of the six concerns is fully resolved by the binding U.S. instruments reviewed as of May 2026. Five are partially addressed through layered, jurisdiction-specific mechanisms, while re-identification remains materially unresolved. The findings characterize the U.S. response as a regulatory mosaic rather than a unified regime and highlight continuing gaps in accountability, coordination, and implementation as AI adoption in healthcare continues to accelerate.
