A Florida lawsuit alleging that artificial intelligence contributed to a patient's delayed cancer diagnosis is drawing fresh attention to the legal responsibilities of healthcare organizations as AI-assisted diagnoses become more common. Medical malpractice attorney Rick Groffsky of Sommers Schwartz said health systems should assume AI-related litigation is coming and build governance, documentation, and training protocols now.
Shared responsibility
Groffsky said physicians remain at the center of malpractice analysis because courts still expect clinicians to exercise independent medical judgment. "An AI tool is one more input to consider in that judgment, but it is not a replacement for it," he said. "If a physician relies on a flawed recommendation without applying independent clinical judgment, the physician and the employing hospital will likely bear the responsibility."
That does not mean hospitals can shift responsibility entirely to individual clinicians. Hospitals decide which AI products to purchase, how extensively to validate them, whether staff receive adequate education, and how performance is monitored after deployment. Those institutional decisions occur long before a clinician sits down with a patient. "So, when a diagnosis is wrong, the cause often is not isolated to one party," Groffsky said. A physician may rely too heavily on AI while "the hospital may have handed that physician an AI tool it never adequately vetted or properly trained staff to use."
AI vendors also may face growing scrutiny. Historically, software companies have argued their products merely provide decision support rather than making clinical decisions. Groffsky believes that defense becomes less persuasive when product flaws themselves contribute to patient harm. He points to situations where training data underrepresents particular patient populations, causing an AI model to consistently miss conditions affecting those groups. In those circumstances, plaintiffs may pursue negligence or product liability claims directly against vendors because "the flaw was baked into the product itself."
The documentation dilemma
AI can both improve clinical documentation and increase legal exposure. "When a clinician overrides a correct AI warning, the documentation now works against them," Groffsky said. "There is a record that the system flagged the risk, and the provider has to explain why they disregarded it." The opposite scenario offers little protection. "The defense that 'the computer told me to' does not hold up, because the law still expects independent judgment."
For health systems, this creates a difficult balancing act. Clinicians cannot blindly accept AI recommendations, but they also cannot casually dismiss validated warnings without documenting sound clinical reasoning. Groffsky identifies automation bias as perhaps the greatest long-term concern. When software performs accurately most of the time, clinicians naturally become less skeptical. Those rare failures can then produce catastrophic consequences. "The organizations most at risk are the ones that have deployed these tools widely but have not given clinicians clear guidance on when to rely on them and when to question them," he said.
Governance and training before deployment
Groffsky argues that legal protection begins well before implementation. Hospitals should maintain thorough records documenting how AI products were evaluated, including the data used for training, validation across different patient populations, and measurable performance before clinical deployment. Governance deserves equal attention. Organizations should document who approved each tool, how oversight responsibilities are assigned, and how ongoing performance monitoring occurs after implementation. At the bedside, systems should preserve an accurate record of AI recommendations alongside the clinician's ultimate decision so reviewers can understand how human judgment influenced patient care.
Training must extend beyond basic software operation. "Clinicians need real training on the tool's limitations and failure modes, not just a software tutorial," Groffsky said, "so they know when to trust the output and when to push back." For healthcare leaders building AI for Healthcare programs, this means embedding risk management into implementation from the start. Validation should use the organization's own patient population, and clinical leadership should be involved early.
Looking ahead, Groffsky expects malpractice claims to emerge from both overreliance and underreliance on AI. Some cases will involve clinicians who accepted incorrect recommendations. Others may involve providers who ignored accurate AI warnings. Eventually, he believes, once certain diagnostic tools become accepted standards of care, organizations choosing not to adopt them could face scrutiny comparable to failing to use any other established clinical practice.
Why this matters for healthcare professionals
For CIOs, CMIOs, and other digital health leaders, preparation is the immediate priority. Groffsky's advice is direct: "Build the paper trail and governance before there is a problem, not after." Validate products thoroughly, involve risk management early, educate staff on failure modes, and keep patients informed about how AI participates in their care. AI for Executives & Strategy initiatives that establish strong oversight now will likely position organizations better when the first wave of AI-related malpractice cases reaches the courts.
Your membership also unlocks: