AI Governance, Security + Risk Management
Ensemble’s commitment to responsible, secure and transparent AI — protecting client and patient data at every layer of our operations
Guiding Principles
Client Data Protection First
Client + patient data privacy takes precedence over innovation, speed or convenience.
Security by Design
AI tools and systems are evaluated and implemented with embedded security + risk controls.
Responsible + Ethical Use
AI augments human decision-making. It doesn't replace accountability or professional judgment.
Transparency + Oversight
AI usage is governed through documented policies, approvals + continuous monitoring.
Associate Productivity Use
Everyday office tasks + internal workflows
Data Privacy
- PHI, PII, client confidential and proprietary data are strictly prohibited from entry into public or unapproved AI tools
- Data minimization required; anonymization enforced where applicable
- Approved enterprise platforms evaluated to prevent external model training on organizational data
Security Controls
- Risk-based security and privacy review required before tool enablement
- Role-based access with least-privilege principles applied
- Usage monitored for anomalous behavior and policy compliance
- AI-related events handled through established incident response processes
Accountability
- Associates governed by documented AI Acceptable Use, Data Protection and Information Security policies
- Human review of all AI-generated content prior to use
- Training provided on responsible use, data minimization and emerging AI risks
Developed + Operated AI Applications
Client-facing delivery + agent workflows
Data Privacy
- Logical client/tenant isolation with defined environment boundaries
- Client data is never used to train shared models without explicit approval and contractual permission
- All data inputs, outputs and integrations documented, reviewed and restricted to approved systems
- Retention and disposal aligned to client, regulatory and contractual requirements
Security Controls
- Secure SDLC with defined development, testing and security review standards
- Tightly controlled and monitored service accounts, APIs and agent permissions
- Model updates, prompt changes and logic modifications require documented review, testing and approval
- Failsafe and rollback mechanisms to ensure continuity if degradation is detected
Accountability + Oversight
- Human-in-the-loop verification required for outputs affecting patients, reimbursement, compliance or clinical/financial workflows
- Accuracy, reliability and operational impact periodically assessed with manual fallback procedures maintained
- Explainable outputs and client-facing reporting to support client oversight
AI Governance Framework
Intake + Classification
- Each AI use case formally reviewed, risk-classified and approved before deployment
- Risk level, data sensitivity and operational impact all evaluated upfront
- Privacy-by-design and HIPAA review integrated into data flow assessments
Lifecycle Management
- NIST-aligned AI risk management across governance, measurement and operations
- Model versioning, retraining, validation and decommissioning follow defined processes
- Continuous monitoring of accuracy, drift and bias with full audit logging
Vendor + Third-Party Controls
- Third-party AI capabilities reviewed to meet Ensemble standards
- Formal oversight structure integrating security, privacy, legal, compliance and business leadership
- Change management controls applied to all model and logic modifications
Standards Alignment + Assurance
HITRUST Certification
Ensemble is actively pursuing HITRUST certification inclusive of AI governance, data protection + security controls.
Control Mapping + Audit Readiness
AI safeguards are mapped to recognized security and privacy frameworks. Evidence is maintained to support client inquiries + compliance audits.
Continuous Improvement
Governance and controls evolve as technologies, regulations and industry best practices mature — ensuring ongoing relevance + protection.
Our Commitment to You
Ensemble views AI as a strategic enabler — used thoughtfully, securely and responsibly. We're committed to protecting client and patient data, maintaining strong security and governance, and ensuring full transparency in both how our associates use AI tools and how AI applications support your service delivery. We welcome ongoing dialogue on AI risk management, governance expectations and assurance needs.
