The AJH Informatics Review

A weekly digest of new research on EHRs, clinical AI, interoperability & health IT policy

Health IT policy & regulation

Every digest paper in this category, newest first.

002
Digital Health Readiness and Medicare Primary Care Spending: Nationwide County-Level Observational Analysis

Is community-level digital health readiness associated with lower Medicare primary care spending in safety net settings? This county-level observational study covered 2993 US counties from 2017 to 2023, using the Digital Health Index digitalization subindex against geographically adjusted per capita Medicare spending on federally qualified health center and rural health clinic services, with a hybrid within-between panel model. Between-county differences drove the association (β=−67.62, 95% CI −73.51 to −61.74), while within-county change was null (β=−2.72, P=.40). Highest versus lowest digitalization tertile differed by β=−165.05. In 2023 cross-sectional models, health care access showed the strongest inverse association (β=−71.13).

003
Leveraging a Locally Anchored Learning Health Care System Toward Equitable Telehealth: Assessing Broadband Access and Supporting Use of Federal Internet Subsidies in a Safety-Net Setting

What are the telehealth and broadband barriers facing patients in an urban safety-net clinic, and how aware are they of federal internet subsidies? Roots Community Health, operating as a community-anchored learning health system with a Telehealth Patient Advisory Council, screened 109 adult patients for Affordable Connectivity Program (ACP) eligibility and administered a 66-item cross-sectional survey to 99. Two-thirds (65/99) had used telehealth and 53% (52/99) wanted future telehealth visits. Barriers included slow internet (46/98), no internet access (40/99), and mobile data plan problems (31/98). Most (65/109) had not heard of ACP, though 60/109 were interested in applying.

004
Geographic Disparities in Access to Broadband, Ambulance Services, and Health Care and Implications for Telehealth

Can telehealth compensate for rural gaps in primary and emergency care where broadband is inadequate? This population-based cross-sectional study mapped broadband, ambulance, and health care deserts across 41 states (249.1 million people), combining FCC 2024 Broadband Data Collection data, ambulance and health care desert data from September 2021 to February 2022, and the 2020 Census. An estimated 11.9 million people (4.8%) lived in broadband deserts, 88.1% of them rural; 649 225 rural residents lived where all three deserts overlapped. Rural broadband subscription was 88.5% versus 92.6% urban; Western states had 31.9% of rural residents in broadband deserts.

005
Attitudes Toward Large Language Models in Health Care and Preferences for Their Adoption and Oversight Among Health Care Professionals: Cross-Sectional Survey

How do clinicians view large language models and who should govern them? A cross-sectional online survey recruited 335 health care professionals through a health care news mailing list, 68.7% (n=230) attending physicians and 77.9% practicing in the Northeast United States. Some 62.7% (n=210) reported current or contemplated LLM use, with users reporting higher self-rated knowledge than nonusers (P<.001) and no age association (\u03c1=-0.072; P=.19). Top applications were literature review (73.4%), decision support (57%), and patient communication (54.9%); 96.4% voiced bias concern, 65.4% preferred oversight by professional associations over technology companies (29%), and 66.6% reported no confidence in existing oversight. Convenience sample, low response rate.

006
The human factor in hospital cybersecurity: a high-reliability organization-based maturity model

Do cybersecurity incidents involving human factors recur within the same healthcare organizations, and can recurrence serve as a marker of persistent vulnerability? The authors analyzed 5,752 cyber incidents reported by U.S. healthcare organizations, comprising 3,740 human-factor and 2,012 non-human-factor incidents, classifying human involvement with a deterministic rule-based approach applied to incident metadata and defining recurrence as a later incident in the same category and organization within three years. Human-factor incidents recurred significantly more often, a pattern holding across alternative windows, stricter classification, and organization-level and paired analyses; the abstract reports no effect sizes. The authors propose a High Reliability Organization-informed maturity model.

007
International qualitative case studies of system-level approaches to promote the development, adoption, and implementation of artificial intelligence in healthcare

How are health systems moving AI beyond pilots to scale? This qualitative study conducted four case studies — Catalonia, Norway, Singapore, and Queensland — drawing on 60 documents, 34 interviews, and 5 focus groups with 50 strategic decision-makers, policymakers, and lead clinicians, analyzed first within-case thematically and then across cases using the Technology, People, Organization, and Macroenvironment framework. Scaling trajectories were shaped by existing digital strategies, digitalization histories, funding arrangements, and legacy infrastructure, with experimentation opportunities, incentives, and distribution of decision-making authority mattering alongside post-deployment monitoring, governance, and procurement. The authors frame scaling as multilevel orchestration rather than top-down versus bottom-up. No effect sizes are reported.

008
From prediction to reality: Five years of AI in healthcare. Adoption, impact, and the road ahead

How well did the 2020 EIT Health & McKinsey AI forecast track what actually happened? This structured narrative review compared the report's domain-level predictions against 2020–2025 evidence from peer-reviewed implementation studies, FDA regulatory data, national and international guidance, industry surveys, and foundation-model evaluations, classifying each prediction as realised, under-realised, exceeded, or unanticipated. Two predictions held: administrative automation and medical imaging led adoption, with ambient documentation moving from pilots to deployment and more than 1300 FDA-authorised AI/ML-enabled devices, mostly radiology. Remote monitoring and classical NLP decision support under-delivered, limited by interoperability, reimbursement, and workflow barriers; generative and multimodal foundation models were the largest unanticipated divergence.

009
Evaluating the Implementation of Social Determinants of Health Screening Across 18 Hospitals

How reliable are the data produced by mandated inpatient screening for health-related social needs? This observational study used EHR data from 197,305 adult inpatient encounters across 18 Atrium Health hospitals in the southeastern US, May–December 2024, applying a data quality framework plus mixed-effects logistic regression. Screens were completed for 172,519 encounters (87.4%), though completion ranged from 92.1% to 72.4% by market; 12.7% (21,900) screened positive for at least one need. Positive patients more often had Medicaid (23.1% vs 13.7%) and higher 30-day readmission (14.3% vs 11%, p<0.001). Intradomain correlation was moderate to strong (food insecurity Cramer V=0.87), interdomain weaker (0.44).

010
AI Adoption in US Cancer Centers: National Cross-Sectional Study of Institutional and Policy Determinants

What predicts publicly visible AI adoption at US cancer centers? This cross-sectional study assembled public-source data on 75 NCI-designated cancer centers, scoring adoption across screening, treatment, and patient care as a 0-3 composite index, with Moran I tests for spatial clustering and ordered logistic regression on institutional and contextual predictors. The mean adoption index was 1.37 (SD 0.86), highest for screening (0.86), then patient care (0.50) and treatment (0.22). Moran I showed no significant spatial autocorrelation. Physician workforce and bed capacity showed positive but modest associations; state socioeconomic indicators did not. Political-context findings were mixed; the abstract reports no effect sizes for regression estimates.

011
Harmonizing Safety and Speed: A Human-Algorithm Approach to Enhance the FDA’s Medical Device Clearance Policy

Can machine learning help the FDA cut recalls and review workload in the 510(k) substantial-equivalence pathway? The authors trained recall-risk models on submission-time information and embedded them in a data-driven policy recommending acceptance, rejection, or deferral to FDA committees for in-depth review, using an assembled data set of more than 31,000 submissions drawn from FDA and CMS sources. Against current practice (10.3% recall rate, workload normalized to 100%), a conservative evaluation showed a 32.9% improvement in recall rate and a 40.5% workload reduction, with estimated annual savings of roughly $1.7 billion from avoided replacement costs, about 1.1% of US medical device spending.

012
Deployer-side governance of medical imaging artificial intelligence: the regulatory readiness instrument (RRI-MI) for multi-jurisdictional and post-market compliance

How can hospitals operationalize post-market oversight of imaging AI when pre-market clearances test algorithms under static conditions? This conceptual paper proposes the Regulatory Readiness Instrument for Medical Imaging AI (RRI-MI), a deployer-side readiness assessment mapping 11 governance domains onto a provisional 22-point ordinal rubric, aligned with the FDA Predetermined Change Control Plan and the EU AI Act. The authors ground the framework in post-market evidence on scanner drift, protocol shifts, software updates, and demographic variation, illustrating it through a semiautonomous prostate cancer MRI case study covering local validation, human oversight, version control, monitoring, and incident response. No empirical validation or effect sizes are reported.

013
Privacy, security, and reliability risks of artificial intelligence in healthcare: a systematic review of empirical evidence

What empirical evidence exists for privacy, security, and reliability risks from AI in clinical care? This systematic review searched PubMed, Embase, Web of Science, Scopus, IEEE Xplore, and ACM Digital Library for empirical studies published January 2015 to November 2025 evaluating AI use or misuse in diagnosis, treatment, or decision-making. Of 7,285 records plus 205 from citation screening, 22 studies met inclusion criteria, mostly medical imaging. Five recurring threat categories emerged: re-identification, membership inference, unauthorized access and adversarial exploitation, input manipulation, and misuse or overinterpretation of outputs. Models encoded latent biometric signals, limiting anonymization and synthetic data. Findings were synthesized narratively; the abstract reports no pooled effect sizes.

014
Ethics of Autonomous AI Clinical Trials: Delphi Study

How should the NIH's 7 principles of ethical clinical research be adapted for trials of autonomous AI? Using a modified Delphi approach over 6 months, investigators convened 14 multidisciplinary panelists (AI, data science, ophthalmology, policy, law, bioethics, patient advocacy) across two survey rounds anchored to a vignette and a final virtual meeting, with participation of 12/14 (85.7%), 10/14 (71.4%), and 13/14 (92.9%). Round 2 produced 9 strong-agreement, 2 moderate-agreement, and 4 divisive statements. Recommendations covered transparency on training and validation data, pre-deployment bias and inequity assessment, performance across clinical settings, informed consent, comparison with standard of care, downstream access, and cost.

015
1,357 AI medical devices cleared, 3 actually tested on patient outcomes

How much clinical evidence supports FDA-cleared AI medical devices? This systematic analysis catalogued all 1,357 AI/ML-enabled devices cleared through December 5, 2025 using the FDA device database and the ACR Data Science Institute catalogue, with linked searches of ClinicalTrials.gov and PubMed for registered trials and publications. Only 34 devices (2.5%) were linked to registered prospective trials, 12 (0.9%) posted results, 12 (0.9%) had peer-reviewed publications, and 3 (0.2%) evaluated patient-centered outcomes such as mortality, morbidity, or readmissions. Most studies (62%) were observational with small, homogeneous cohorts and frequent exclusion of vulnerable populations. The authors cite misaligned incentives and predicate-based pathways as barriers.

016
Clinical Specialty Expansion of AI-Enabled and Machine Learning-Enabled Medical Devices Authorized by the US Food and Drug Administration From 1995 to 2025: Longitudinal Content Analysis

Has radiology's dominance of FDA-authorized AI/ML medical devices persisted or begun to loosen? This longitudinal content analysis covered all 1430 devices in the FDA AI-Enabled Medical Devices registry with final authorization decisions through December 2025, stratified by advisory-committee specialty across four eras (1995-2015, 2016-2019, 2020-2022, 2023-2025). Annual authorizations rose from a mean of 2.0 to 264, with 331 in 2025; 96.2% used the 510(k) pathway. Radiology's share peaked at 85.5% (347/406) in 2020-2022, then fell to 77.5% (614/792) in 2023-2025 (P=.001), with the Herfindahl-Hirschman Index declining from 0.738 to 0.612. Start-ups (OR 5.09) and technology companies (OR 50.62, based on 13 devices) had higher odds of nonradiology authorization.

017
Public Reporting Systems in Health Care and the Underconceptualized Technical Substrate, a Core Information Systems Dimension: Scoping Review

How much does the literature on public reporting systems in health care address their technical foundations? This scoping review followed Joanna Briggs Institute guidance and PRISMA-ScR, searching seven databases (PubMed, Web of Science, Scopus, IEEE, ACM, AIS eLibrary, Cochrane) for articles published 2000-2026. Of 1882 records identified and 1127 screened after deduplication, 233 studies were included; 157 (67.4%) came from the United States and 43 (18.4%) from Europe, with 60.5% (n=141) quantitative, 24.0% qualitative, and 15.5% mixed methods. Coding across six information systems dimensions—architecture, interoperability, data governance, APIs, usability, technical performance—found the technical substrate underexplored; the abstract reports no dimension-level counts.

018
Beyond fax: provider perspectives on data sharing in substance use disorder care

What blocks health information exchange in substance use disorder care, as providers experience it? A qualitative study convened 11 focus groups (n=31) and 5 validation interviews (n=5) with behavioral health providers (52% prescribers) from 4 SUD treatment organizations across 14 US states, using HEDIS-based scenarios analyzed thematically and via Unified Modeling Language workflow diagrams. Incomplete data access at the point of care routinely forced manual exchange by fax, phone, and secure email, and confusion about HIPAA, 42 CFR Part 2, and state release requirements was ubiquitous. UML modeling of 4 care scenarios identified 3 shared data-sharing subprocesses. Providers prioritized interoperable consent management, HIE/PDMP-EHR integration, and harmonized privacy rules. No effect sizes are reported.

019
Expansion of State Medicaid Policies Related to Telehealth, 2018-2023: A National Legal Mapping Study

Which state factors explain how quickly Medicaid programs adopted telehealth policies? This legal mapping study (50-state survey) identified state laws and policies governing Medicaid telehealth delivery in effect through December 31, 2023, with two researchers independently abstracting policies and multivariable regressions testing state-level correlates of monthly policy counts from 2018 to 2023. States averaged 2.7 telehealth policies in effect (SD 1.4; range 0-6), with most adoption concentrated in 2020-2021; audio-only reimbursement spread fastest, from 0 to 43 states over five years. Adoption was unrelated to rurality, health professional shortage, Medicaid expansion, broadband availability, demographics, income, unemployment, or COVID-19 cases and deaths.

020
Patient Viewing and Comprehension of Immediately Released Test Results

How do patients view and understand test results released immediately to them under information-blocking rules? This JAMA Network Open study examines patient access to and comprehension of immediately released test results. No abstract was available, so the study's design, population, and findings — including any magnitudes — cannot be summarized here.

021
The Promises and Pitfalls of Real-time Benefit Tools: A Qualitative Study of Primary Care Providers

How do primary care providers experience federally mandated real-time benefit tools (RTBTs) that display medication out-of-pocket costs in the EHR? Researchers conducted a qualitative descriptive study with semi-structured interviews of 35 PCPs at primary care clinics affiliated with two academic health systems sharing one EHR, using thematic analysis. Most participants were physicians (25/35), female (23/35), and had at least 10 years' experience (19/35). Three themes emerged: minimal RTBT training with openness to more; perceived potential to support cost conversations and reduce administrative burden; and pitfalls including incomplete information, inaccurate cost estimates, and clinically inappropriate lower-cost suggestions. The abstract reports no effect sizes.

022
Regulatory Approaches to Cybersecurity Risk Management for AI-Enabled Medical Device Software in Korea, the United States, and the European Union: Comparative Document Analysis

How do regulators define and operationalize cybersecurity for AI-enabled medical device software? This qualitative comparative document analysis examined 10 jurisdiction-specific regulatory and guidance documents (Korea's MFDS n=2, FDA n=4, EU/MDCG n=4), plus cross-sectoral instruments and peer-reviewed literature, mapping conceptual scope, premarket artifacts (threat modeling, software bills of materials, vulnerability management plans), and postmarket monitoring and update governance. All three jurisdictions converged on confidentiality, integrity, and availability but differed architecturally: MFDS stressed ISO 14971 documentation, FDA framed cybersecurity as total product life cycle design controls under FD&C Act 524B, and the EU treated it as a safety extension under MDR/IVDR with NIS2 and GDPR overlays. Vigilance pathways remained patient-harm triggered, leaving vulnerabilities to parallel processes. Being document-based, the study reports no effect sizes.

023
Remote Patient Monitoring Adoption for Hypertension Management Among Medicare Beneficiaries

Does switching from Medicare fee-for-service to Medicare Advantage change remote patient monitoring (RPM) use for hypertension? This cohort study used a difference-in-differences design with propensity score matching on 2016-2022 Medicare enrollment, FFS claims, and MA encounter data, following 281,620 matched beneficiaries aged 65 or older with hypertension who switched to MA in January 2019 or remained in FFS through 2022. Switching was associated with lower 2022 RPM adoption (value-based contract proxy: OR, 0.55; -0.63 percentage points; non-VBC: OR, 0.73), more clinician loss without replacement (OR, 1.27; 3.41 percentage points), and more hypertension-related hospitalizations (OR, 1.75 and 1.94; 1.56 percentage points).

024
Who is doing informatics work in US governmental public health agencies?

Who actually performs informatics work in US governmental public health agencies? This cross-sectional analysis used weighted responses from the 2024 Public Health Workforce Interests and Needs Survey (PH WINS), mapping 9 of 77 public health job classifications to informatics or data-centric roles. Such roles comprised about 8% of the workforce (N = 4786), including epidemiologists (3.9%), information technology/computer science workers (2.1%), data analytics and related roles (1.7%), and public health informatics specialists (<1%). Informatics tasks were distributed across multiple job titles, and specialists supported a broad range of activities including surveillance. The abstract reports no effect estimates.

025
Risk-Tiered Governance for Hospital Artificial Intelligence: A Framework Synthesis and Implementation Pathway

How should hospitals calibrate oversight of AI tools embedded in EHR workflows, imaging, triage, documentation, and operations? The authors conducted a narrative review and framework synthesis drawing on peer-reviewed evidence, reporting guidelines, regulatory and policy sources, implementation studies, and applied governance case reports. The resulting framework has four components: a use-case inventory tagged by decision influence and workflow coupling; a six-domain risk taxonomy spanning clinical safety, privacy and data security, ethics and fairness, transparency, system stability, and compliance; a four-tier risk scheme keyed to harm, automation, reversibility, and coupling; and a governance architecture assigning roles to a committee, clinical owners, risk-control functions, and independent assurance. A lifecycle pathway runs from initiation and local validation through shadow mode, controlled go-live, monitoring, change control, and retirement. No effect sizes are reported; this is a conceptual framework, not an evaluation.

026
Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians' Free-Text Answers

For what purposes do physicians use unauthorized, non-conformity-assessed AI tools at work? This cross-sectional survey of physicians in Swedish health care organizations (N=357; response rate ~64%), fielded through a verified online panel between December 2023 and January 2024, applied qualitative content analysis to free-text responses, interpreted through the sociology of professions and paradox theory. Reported uses fell into four categories: clinical work and decision-making (second opinions, differential diagnoses, rare cases), administrative work (patient communication, documentation), research and professional development, and technological curiosity. Physicians framed such use as compensating for gaps in institutional systems and reducing workload. The abstract reports no effect sizes or usage prevalence.

027
Transparency in healthcare AI: Testing EU regulatory provisions against users' transparency needs

Do the transparency needs of healthcare AI users actually map onto the Instructions for Use (IFU) document that the EU AI Act (Directive 2024/1689) requires providers to give deployers? This cross-sectional online survey, administered via Qualtrics to four deployer groups \u2122 managers (N = 238), healthcare professionals (N = 115), patients (N = 229), and IT workers (N = 230) \u2122 asked participants to rate the relevance of a set of transparency needs and identify which IFU section would address each. Priorities differed across user types, and participants had difficulty locating some transparency information within the IFU structure; the abstract reports no effect sizes or magnitudes. The authors derive recommendations for locally meaningful IFUs.

028
Public support for regulating AI advice for mental health

How much do members of the public support regulating AI-delivered mental health advice? This Health Affairs Scholar paper takes up that question, but no abstract was available at the time of writing, so the study design, sample, and findings cannot be characterized here. Readers interested in public opinion on guardrails for consumer-facing chatbots and other AI tools offering psychological support should consult the full text for the survey methods, population sampled, and reported levels of support for specific regulatory approaches.