Artificial Intelligence & Machine Learning
,
HIPAA/HITECH
,
Next-Generation Technologies & Secure Development
Attorney Jordan Cohen of Akerman on AI Challenges Ahead
Marianne Kolbasuk McGee (HealthInfoSec) •
July 15, 2026
Jordan Cohen, partner, Akerman LLP
As healthcare organizations and their vendors develop and implement agentic artificial intelligence and other AI technology, they should conduct a thorough data inventory and have a solid understanding of what data can and cannot be used under HIPAA and other laws, said attorney Jordan Cohen of law firm Akerman LLP.
See Also: Know Thy Enemy: Threats to Cyber Resilience
“If you fall outside of a permissible use, then technically, if protected health information is involved, that can be considered a reportable breach,” he said in an interview with ISMG.
Many of the steps that HIPAA-regulated enterprises should take in their agentic AI implementations aren’t really “AI specific,” he said.
“A data flow inventory is going to be really important. So diagramming and accounting for how you’re ingesting data, processing it, storing it and how it’s leaving your systems, how vendors are touching it and what they’re doing to that data is going to be critical,” he said.
“Because if you don’t know what data you have, where it lives, who’s accessing it, then it’s really difficult to secure it and to protect patient privacy,” he said.
“These are practices that we’ve been discussing for years,” he said. But in the age of agentic AI and other AI deployments, they are especially important.
In this video interview with ISMG, Cohen also discussed:
Most common current uses of agentic AI for clinical and administrative purposes in healthcare, and the types of PHI, electronic health record and other data frequently being utilized;
Other legal and regulatory issues to consider in the deployment of AI;
Other critical AI issues to consider, including technical safeguards, incident, response, monitoring, transparency and consent of patients;
Opportunities for AI to improve data privacy and security in healthcare and other sectors.
Cohen is a partner at Akerman LLP and team leader of the firm’s digital health practice. He advises clients on transactions involving healthcare providers and other healthcare-related platforms. That includes providing legal counsel related to federal and state privacy and data security matters, including compliance with HIPAA’s Privacy, Security and Breach Notification Rules, as well as compliance with state breach notification laws. He also provides guidance on a broad range of healthcare regulatory matters, including compliance with fraud and abuse laws including the Anti-Kickback Statute and the Stark Law.