
What are Common HIPAA Security Violations?
Most HIPAA problems do not come from a single dramatic breach. They come from small
Not sure where to start? Schedule a consultation
Not sure where to start? Schedule a consultation
Not sure where to start? Schedule a consultation
Your employees are already using AI. The real question is whether anyone has told them what is allowed. AI governance gives your organization a written answer. It defines which tools are approved, what company information can go into them, who reviews the output before it leaves the building, and what happens when something goes wrong.
MDL Technology builds that framework for businesses across Kansas and Missouri, then helps leadership and IT apply it the same way in every department.
AI governance is the set of policies, approvals, and responsibilities that control how artificial intelligence is used inside your company.
It answers four questions your staff are guessing at right now:
Which tools are approved. A named list, not a general rule. ChatGPT Enterprise, Microsoft 365 Copilot, and a free browser plugin are three different risk profiles, and your policy should say so.
What data can go in. Client records, patient information, contract language, source code, pricing, and employee files each need a clear yes or no.
Who checks the output. Human review requirements for anything that goes to a customer, a regulator, a court, or a contract file.
Who owns the decision. A named person who approves new tools, fields questions, and handles incidents.
Without those answers in writing, every employee makes their own call. That is where most of the risk lives.
The gap between how much AI your staff use and how much of it you can see has widened quickly.
Usage is already widespread. Verizon’s 2026 Data Breach Investigations Report found regular AI use on corporate devices tripled in a single year, from 15% to 45%. Of those users, 67% were signing in with non-corporate accounts your company cannot control or audit.
Most leaders know it is happening. In a Gartner survey of 302 cybersecurity leaders, 69% either had evidence or suspected that employees were using prohibited public generative AI tools. Gartner expects more than 40% of enterprises to hit a security or compliance incident tied to shadow AI by 2030.
Sensitive data goes with it. Gartner’s 2026 cybersecurity trends research found 57% of employees use personal generative AI accounts for work, and 33% admit entering sensitive information into unapproved tools. Other surveys put the rate higher, depending on how the question is asked, but every one of them lands in the same place: this is normal behavior, not fringe behavior.
Breaches cost more when AI is involved. IBM’s breach research is consistent on the pattern: the organizations breached through an AI tool overwhelmingly had no governance policy and no adequate access controls in place beforehand. We keep the current figures in one place, on the cost of getting AI adoption wrong.
Bans do not work. Organizations that block AI outright usually find usage continues on personal phones and home computers. The only thing that changes is that IT can no longer see it.
Governance is the practical middle ground. Your team keeps the productivity, and you keep control of the data.
We build the program around how your business actually operates, the data you hold, and the regulations you answer to. A typical engagement includes:
We find what is already in use, including free accounts, browser extensions, and AI features quietly switched on inside software you already pay for.
The employee-facing rulebook. It covers scope, approved tools, prohibited uses, and plain-language examples people can apply without calling IT first.
We map your information into tiers and state exactly which tier may be used with which tool. This is the single most violated rule in most companies, usually because nobody wrote it down. The labeling and permission work behind these tiers is delivered through our AI data readiness and security governance service.
A short path for staff to get a new tool reviewed. When there is no legitimate route, people find their own.
Requirements for verifying AI output before it is used in client work, hiring decisions, financial documents, or anything filed with a regulator.
Training that explains the reasoning, not just the restrictions, with a completion record you can show an auditor or an insurer.
Policy on paper is not a control. We align identity, access, data loss prevention, and licensing so the rules hold up in practice, tied into your existing cybersecurity and compliance program.
A defined path for reporting accidental disclosure, plus scheduled reviews so the policy keeps pace with the tools.
We do not improvise policy. Our work is grounded in established standards and mapped to the requirements you already carry. Governance is one layer of a larger foundation; see what AI infrastructure includes for the rest of it.
NIST AI Risk Management Framework (AI RMF 1.0). The US federal baseline, built on four functions: Govern, Map, Measure, and Manage. It is voluntary, and it is referenced across dozens of agency guidance documents.
ISO/IEC 42001:2023. The first international standard for an AI management system, and the certifiable counterpart to the NIST framework. It is increasingly showing up as a vendor requirement in enterprise procurement.
ISO/IEC 27001. MDL operates under ISO 27001-aligned processes, so your AI controls connect to your information security management rather than sitting apart from it.
NIST SP 800-171 and CMMC. Consumer AI platforms are not authorized systems for Controlled Unclassified Information. We keep AI use inside the boundary you already defend through our CMMC readiness and NIST 800-171 assessment work.
HIPAA. Standard consumer AI tiers cannot be used with protected health information because no Business Associate Agreement is available. We identify which tiers can be covered and build the safeguards around them alongside our HIPAA security compliance service.
State and federal expectations. Missouri has no comprehensive AI statute, but the Missouri Merchandising Practices Act and state breach notification rules still apply to AI-driven activity. Kansas has an executive branch generative AI policy and an active legislative task force. We track both sides of the state line, so your policy does not go stale.
Five steps, built to move quickly without leaving gaps.
We inventory the AI tools in your environment and talk with department leads about how they are actually being used. This usually surfaces tools IT did not know about.
We match your data types to the tools touching them and flag where regulated information is at risk of leaving your control.
We draft the acceptable use policy, data rules, approval workflow, and review requirements. This connects directly to our policy and documentation development service, so the language holds up under assessment.
Leadership signs off, employees are trained, and acknowledgments are recorded. We pair this with security awareness and phishing training so AI risk is covered alongside everything else your team faces.
We put the technical controls behind the policy, monitor for new tools, and revisit the program on a set schedule as your environment and the regulations change.
Since 2003, MDL Technology has supported organizations across the metro in finance, healthcare, legal, manufacturing, and the public sector, where compliance is not optional.
MDL works with organizations throughout the metro and across both states. Our clients include defense suppliers, medical practices, accounting firms, and manufacturers, all of whom face different AI exposure.
See our full service area for every community we cover.
It is the set of written rules that says which AI tools your employees can use and what company information they are allowed to share with those tools. It also assigns responsibility for approving tools, reviewing output, and handling problems.
Yes, and often more than a large one. Small teams rarely have a compliance department, so a single employee pasting client data into a free chatbot can create a breach obligation with no one positioned to catch it.
That depends entirely on which version and what kind of client information. Free and consumer tiers offer no contractual protection for regulated data, which is exactly why the policy needs to name specific tools rather than speak generally about AI.
Copilot works within each user’s existing permissions, so it will surface anything a person could already technically access. Most organizations need a SharePoint and OneDrive permissions cleanup first, which is work we handle as part of Copilot readiness.
Neither state has passed a comprehensive AI statute as of 2026. Existing consumer protection, employment, and breach notification laws still apply to AI-driven activity, and both states have active legislative attention on the subject.
Yes, but only where the tool runs inside a properly scoped environment. Controlled Unclassified Information cannot be entered into standard commercial AI platforms, so the deciding factor is where the model runs, not which brand you picked.
The free, Plus, and Team tiers are not, because no Business Associate Agreement covers them. Certain enterprise and API arrangements can support HIPAA workloads under a signed BAA and the right technical safeguards, which we help evaluate.
Increasingly yes. Renewal applications now include questions about AI tool use, employee training, and documented policy, and inaccurate answers on an application can put a future claim at risk. Our cyber insurance readiness service covers this.
Discovery through rollout typically runs several weeks for a small to mid-sized organization, depending on how many tools are already in use. Ongoing review is scheduled after that.
Bans rarely reduce risk because usage moves to personal devices where IT cannot see it. Approving a short list of vetted tools with clear data rules gives you far more visibility than a prohibition nobody follows.
Right now, every person in your organization is deciding for themselves what is acceptable to share with an AI tool. Those decisions are being made without training, without a policy, and without anyone tracking the outcome.
We can change that in weeks, not quarters. Talk to our North Kansas City team about building an AI governance and acceptable-use program your leadership, your IT staff, and your auditors can all rely on.
MDL Technology has protected Kansas City businesses since 2003, and we are ready to bring that same standard to your AI governance.

Most HIPAA problems do not come from a single dramatic breach. They come from small
Every organization that handles patient data is expected to protect it, and the rules for

Most email attacks succeed because a business chooses protection that does not match its actual