AI Governance, Security + Risk Management

Ensemble’s commitment to responsible, secure and transparent AI — protecting client and patient data at every layer of our operations

Client Data Protection First

Client + patient data privacy takes precedence over innovation, speed or convenience.

Security by Design

AI tools and systems are evaluated and implemented with embedded security + risk controls.

Responsible + Ethical Use

AI augments human decision-making. It doesn't replace accountability or professional judgment.

Transparency + Oversight

AI usage is governed through documented policies, approvals + continuous monitoring.

Associate Productivity Use

Everyday office tasks + internal workflows

Data Privacy

  • PHI, PII, client confidential and proprietary data are strictly prohibited from entry into public or unapproved AI tools
  • Data minimization required; anonymization enforced where applicable
  • Approved enterprise platforms evaluated to prevent external model training on organizational data

Security Controls

  • Risk-based security and privacy review required before tool enablement
  • Role-based access with least-privilege principles applied
  • Usage monitored for anomalous behavior and policy compliance
  • AI-related events handled through established incident response processes

Accountability

  • Associates governed by documented AI Acceptable Use, Data Protection and Information Security policies
  • Human review of all AI-generated content prior to use
  • Training provided on responsible use, data minimization and emerging AI risks

Data Privacy

  • Logical client/tenant isolation with defined environment boundaries
  • Client data is never used to train shared models without explicit approval and contractual permission
  • All data inputs, outputs and integrations documented, reviewed and restricted to approved systems
  • Retention and disposal aligned to client, regulatory and contractual requirements

Security Controls

  • Secure SDLC with defined development, testing and security review standards
  • Tightly controlled and monitored service accounts, APIs and agent permissions
  • Model updates, prompt changes and logic modifications require documented review, testing and approval
  • Failsafe and rollback mechanisms to ensure continuity if degradation is detected

Accountability + Oversight

  • Human-in-the-loop verification required for outputs affecting patients, reimbursement, compliance or clinical/financial workflows
  • Accuracy, reliability and operational impact periodically assessed with manual fallback procedures maintained
  • Explainable outputs and client-facing reporting to support client oversight

AI Governance Framework

Intake + Classification

  • Each AI use case formally reviewed, risk-classified and approved before deployment
  • Risk level, data sensitivity and operational impact all evaluated upfront
  • Privacy-by-design and HIPAA review integrated into data flow assessments

Lifecycle Management

  • NIST-aligned AI risk management across governance, measurement and operations
  • Model versioning, retraining, validation and decommissioning follow defined processes
  • Continuous monitoring of accuracy, drift and bias with full audit logging

Vendor + Third-Party Controls

  • Third-party AI capabilities reviewed to meet Ensemble standards
  • Formal oversight structure integrating security, privacy, legal, compliance and business leadership
  • Change management controls applied to all model and logic modifications

Standards Alignment + Assurance

HITRUST Certification

Ensemble is actively pursuing HITRUST certification inclusive of AI governance, data protection + security controls.

Control Mapping + Audit Readiness

AI safeguards are mapped to recognized security and privacy frameworks. Evidence is maintained to support client inquiries + compliance audits.

Continuous Improvement

Governance and controls evolve as technologies, regulations and industry best practices mature — ensuring ongoing relevance + protection.

Ensemble views AI as a strategic enabler — used thoughtfully, securely and responsibly. We're committed to protecting client and patient data, maintaining strong security and governance, and ensuring full transparency in both how our associates use AI tools and how AI applications support your service delivery. We welcome ongoing dialogue on AI risk management, governance expectations and assurance needs.