Ep. 136: When the Patient Owns the Agent: The Case for Individual-First AI Governance
#shifthappens in the Digital Workplace Podcast
Healthcare organizations say patient data is secure. Paul Swider, CEO and Chief AI Officer of RealActivity, argues that security and patient control are not the same thing. In this episode, he explains why centralized healthcare systems remain attractive ransomware targets, why patients often have limited visibility into how their data is used, and why the next phase of AI governance starts when the patient owns the agent. He also explores why the 21st Century Cures Act has already redrawn the perimeter, and what that means for AI hasn't fully landed in most governance conversations yet.
Paul walks through how he granted an AI agent access to his medical record, why a single-patient agent has a smaller attack surface than a centralized electronic health record (EHR) system, and why healthcare leaders should evaluate AI against today's care outcomes rather than on the expectation of perfection.