The NHS is investing £10 billion in a digital overhaul that will bring AI-powered features to its app, aiming to reach over 200,000 patients by 2028. As healthcare providers adopt AI to personalise patient communications, they face mounting pressure to secure vast amounts of sensitive data while complying with an increasingly complex regulatory environment.
The challenge sits at the intersection of clinical need and technical risk. Allan Christian, SVP and General Manager of the Engage business unit at Precisely, spoke about this on the Health Tech World podcast. He outlined what responsible AI adoption looks like when healthcare organisations send automated, personalised messages to patients.
The data governance problem
Patient communications now carry more than appointment reminders. AI systems pull from electronic health records, treatment plans, and demographic data to tailor messages. Each data point adds value but also expands the attack surface. Christian said healthcare providers must treat data governance as a continuous discipline, not a one-time compliance check.
Regulatory frameworks like GDPR and NHS-specific data protection rules layer additional requirements on top of standard security practices. Organisations that rush to deploy AI without mapping where patient data flows through their systems risk breaches that carry both financial penalties and erosion of patient trust.
What responsible adoption requires
Christian pointed to three pillars: data accuracy, transparency, and human oversight. AI models that generate patient communications need clean, validated inputs. Garbage data produces confusing or incorrect messages - a dangerous outcome when dealing with medication instructions or test results.
Transparency means patients should know when they are interacting with an automated system. Christian said that disclosure is not optional under emerging regulations. Human oversight ensures that clinical communications retain a layer of review, particularly for high-stakes scenarios where an AI-generated message could be misinterpreted.
For healthcare teams working with AI for PR & Communications, the same principles apply. Message accuracy and audience trust are non-negotiable, whether the recipient is a patient or a stakeholder.
The scaling problem
The NHS target of 200,000 patients by 2028 represents a significant scaling challenge. Christian noted that security frameworks that work for a pilot programme often break under production loads. Each new integration point - a third-party messaging API, a cloud-based analytics tool - introduces potential vulnerabilities.
He recommended that healthcare organisations conduct threat modelling specific to AI communication pipelines. This means examining how an attacker might poison training data, intercept messages in transit, or exploit model outputs to extract sensitive patient information.
Professionals working in AI for Healthcare recognise that scaling AI safely requires more than faster infrastructure. It demands governance structures that keep pace with deployment speed.
Why this matters for healthcare professionals
Healthcare teams deploying AI-driven patient communications should audit their data pipelines now, before scaling. Map every system that touches patient data, document where AI makes decisions without human review, and test whether patients understand when they are receiving automated messages. Christian's core message is that security cannot be retrofitted. Build it into the communication workflow from the first pilot, and the path to 200,000 patients becomes a question of engineering, not crisis management.
Your membership also unlocks: