Cybersecurity & AI Liability — The New Frontier of Partnership Risk

By
5 Minutes Read
The short answer. Most partnership agreements predate ransomware and clinical artificial intelligence, which leaves breach costs to be negotiated after the loss. The allocation that works treats a breach as a practice expense, with a narrow exception for willful misconduct or knowing violation of a written security policy, alongside stated cyber limits and a governance rule for tool adoption.

The practice opens on a Monday with no schedule. The EHR will not load, the phones are ringing, the staff are printing nothing because the printers are on the same network, and a partner is standing in the parking lot asking the only question the agreement cannot answer: who pays for this? Six weeks later, when the forensic invoice, the notification vendor’s bill, the legal fees, and the estimate of lost production have all arrived, that question will still be open—and by then it will be a dispute rather than a decision.

Most partnership agreements say nothing about cybersecurity, and nothing at all about artificial intelligence. That silence is not negligence so much as vintage. The documents were drafted before ransomware became an operating risk for a ten-person office and before a clinical decision-support tool could be enabled by a single physician on a single afternoon. Both gaps are now cheap to close and expensive to leave open.

Begin with the regulatory frame, because it sets the clocks that drive the costs. The HIPAA Security Rule requires safeguards that are “reasonable and appropriate”—a standard that names no product and no vendor, and that scales with the size and means of the practice. The Breach Notification Rule sets the obligations that follow a breach of unsecured protected health information, including notice to affected individuals without unreasonable delay and no later than 60 days from discovery, with additional obligations to the Department of Health and Human Services and, above a threshold, to the media. State breach-notification statutes layer on top with their own definitions, clocks, and content requirements, and some are shorter than the federal outer limit. Business associate agreements govern the vendors who touch the data, and a breach at a billing company or a portal vendor is still the practice’s notification problem. Cyber-insurance policies echo the same vague standard with language about “adequate and reasonable measures,” which is why the practice’s documentation is simultaneously its compliance defense and its insurance claim.

Then price the event, in categories, so the allocation provision has something to allocate:

  • Forensic investigation and incident response
  • Breach counsel and regulatory response, including any state attorney general inquiries
  • Patient notification, mailing, and the call center that answers the notified
  • Credit monitoring or identity protection where offered or required
  • System restoration, data recovery, and hardware replacement
  • Lost production and payroll during downtime, and the collections lag that follows it
  • Public relations and patient retention
  • The insurance deductible, plus any loss above the policy limit
  • The extortion question itself, which is a legal question before it is a financial one, given the sanctions exposure that can attach to a payment

The default allocation should be that a breach is a practice expense, borne the way any other operating loss is borne, with a narrow exception for loss caused by a partner’s willful misconduct or knowing violation of a written security policy. The narrowness is the point. An allocation rule that lets partners charge each other for clicking a convincing email produces exactly one behavior, and it is not better security—it is delayed reporting, which is the single most expensive thing anyone can do in the first hour of an incident. Write the provision so that the fastest phone call is also the safest one.

Insurance carries the rest. Require cyber liability coverage at stated minimum limits, with first-party coverage for restoration, business interruption, and extortion, and third-party coverage for liability and regulatory defense. Require annual review of the policy against the practice’s actual systems, and partner approval before any reduction in limits. Around the policy, build the governance the carrier will ask about after the fact: a named privacy and security officer, an annual written security risk assessment, current business associate agreements inventoried once a year, an incident-response protocol that names who investigates and who calls the carrier, and training completed by partners as well as staff. The partner who quietly skips the training is the one with the broadest access to the system.

Artificial intelligence raises three questions, and they are separable. First, who decides which tools enter the practice—ambient documentation, imaging triage, decision support, patient-facing chat—and on what review of the vendor’s security posture, data use, and business associate status. That belongs at the governance level of article 22, not with whichever partner saw the demonstration. Second, how the chart records the tool’s role, because documentation is the evidence in every case that follows. Third, how liability allocates. The clinical standard of care remains with the licensed clinician who signs the note; vendor agreements routinely disclaim clinical responsibility and cap damages; and whether reliance on a tool mitigates exposure, aggravates it, or eventually redefines the standard itself is unsettled, evolving, and jurisdiction-dependent. Nothing in that paragraph is a conclusion a practice may plan around. It is a reason to confirm the malpractice carrier’s written position on AI-assisted care and ambient documentation before deployment, and to have counsel read the vendor contract rather than the marketing.

Telehealth needs the same treatment for a simpler reason. Licensure generally follows the patient’s location, so a partner covering a family on vacation in another state may be practicing where she is not licensed. Define which partners may deliver telehealth, in which states, under whose coverage, and how responsibility attributes when the treating physician and the covering physician are different people. That is a paragraph, and it prevents a category of problem that has no cheap remedy.

Red flags. No cybersecurity provision, so allocation is negotiated after the loss. An AI tool in clinical use with no approval record and no defined liability protocol. Telehealth performed across state lines on assumption. Cyber coverage bought once and never re-read against a system that has doubled. No training requirement that binds partners. And no incident-response protocol, which means the first hour is spent deciding who to call.

The question is no longer whether the practice will face an incident. It is whether the agreement decided what happens next while everyone was calm.

Red Flags in a Cybersecurity and AI Provision

  • No cybersecurity provision, so allocation is negotiated after the loss.
  • An AI tool in clinical use with no approval record and no defined liability protocol.
  • Telehealth performed across state lines on assumption.
  • Cyber coverage bought once and never re-read against a system that has doubled.
  • No training requirement that binds partners.
  • No incident-response protocol, so the first hour is spent deciding who to call.

Frequently asked questions

Who pays for a ransomware attack in a medical partnership?

The default allocation treats a breach as a practice expense, borne the way any other operating loss is borne, with a narrow exception for loss caused by a partner’s willful misconduct or knowing violation of a written security policy. The narrowness is the point: a rule letting partners charge each other for clicking a convincing email produces delayed reporting rather than better security.

What does a practice owe after a breach of patient information?

The Breach Notification Rule sets the obligations that follow a breach of unsecured protected health information, including notice to affected individuals without unreasonable delay and no later than 60 days from discovery, with additional obligations to the Department of Health and Human Services and, above a threshold, to the media. State statutes layer on top, and some clocks are shorter.

Who decides which AI tools a medical practice adopts?

Tool adoption belongs at the governance level rather than with whichever partner saw the demonstration, on a review of the vendor’s security posture, data use, and business associate status. The clinical standard of care remains with the licensed clinician who signs the note, and whether reliance on a tool mitigates or aggravates exposure is unsettled, evolving, and jurisdiction-dependent.

Put the agreement to the test

The Partnership Agreement Analyzer scores an existing agreement against the framework this series is built on — or schedule a discovery call to work through it with PMI. The full framework, with the arithmetic, lives in the textbook Pediatric Practice Management: The Fundamentals.

Picture of Paul Vanchiere, MBA

Paul Vanchiere, MBA

For over 15 years, Paul has dedicated himself exclusively to addressing the financial management, strategic planning, and succession planning needs of pediatric practices. His background includes working for a physician-owned health network and participating in physician practice acquisitions for Texas's largest not-for-profit hospital network, giving him a distinctive insight into the healthcare sector. Paul is adept at conducting comprehensive financial analysis, physician compensation issues, and managed care contract negotiations. He established the Pediatric Management Institute to offer a wide range of services tailored to pediatric practices of all sizes and stages of development, with a focus on financial and operational challenges. Additionally, Paul is actively involved in advocacy efforts to ensure healthcare access and educational opportunities for children with special needs.

Author