Eighty-one percent of physicians now use AI professionally, more than double the rate three years ago. Almost none of it went through a governance review. So the AI keynote speaker your health system needs is not the one with the slide about the future of medicine. It is the one who can tell your board which AI is already running in your building, who approved it, and what happens when it fails.
Most healthcare AI keynotes are the wrong talk delivered well. A futurist shows an algorithm reading a scan better than a radiologist, the room nods, and nobody changes a control on Monday. That talk has run at every health system conference since 2023. It has not moved a governance program an inch.
Here is what nobody on that stage says. In healthcare, the AI question and the security question are the same question, and almost nobody is qualified to answer both.
The adoption already happened. The governance did not.
Start from first principles. What is true in a hospital right now?
The American Medical Association surveyed roughly 1,700 physicians for its 2026 Physician Survey on Augmented Intelligence. The findings are not ambiguous.
- 81% use AI professionally, more than double the 2023 rate.
- 39% summarize medical research with it. 30% draft discharge instructions, care plans, or progress notes. 28% use it on billing codes, charts, and visit notes. 19% draft patient portal responses.
- 85% want to be consulted or directly involved in AI adoption decisions.
- 88% report concern about AI-related skill loss. 70% worry about the residents being trained right now.
Read those together and the picture is uncomfortable. Four in five doctors use AI. Nearly nine in ten want a say in how it gets adopted. Which tells you most are not getting one.
That gap has a name. It is not innovation. It is unmanaged change in a regulated environment. Your clinicians did the rational thing. They found tools that cut the documentation load burning them out, and used them. The governance that should have sat in front of that decision was not there. So it got made anyway, one physician at a time, and the institution owns the consequences.
The bill arrives on the security side
Healthcare has been the most expensive industry for data breaches for 14 consecutive years. IBM's 2025 Cost of a Data Breach report puts the healthcare average at $7.42 million, against a global all-industry average of $4.44 million. Containment takes 279 days.
Then the volume. 2025 was the worst year on record. HHS Office for Civil Rights logged 772 breaches of 500 or more records, exposing the protected health information of 139,721,832 individuals. That beat the 2023 record by 3.49%. Network servers accounted for 61.5%, compromised email another 24.9%. OCR closed 21 enforcement cases, collecting $8,330,066.
Now put the two together. Your physicians are pasting clinical context into AI tools at scale, in the most breached and most expensive-to-breach industry in the economy. Every one of those workflows is a new path for PHI to leave the building, and most were never mapped, reviewed, or written into a business associate agreement.
That is not a future risk. It is the current state, and it is what a healthcare AI keynote is supposed to name.
What separates a healthcare AI speaker who helps from one who performs
I have sat in the chair. Five times as a CEO, CIO, and CISO. I have run more than 150 executive tabletops, a good share in healthcare, with the CMO, the CISO, general counsel, and compliance in one room arguing about a scenario that had not happened yet.
The pattern shows up every time. The plan is fine on paper. It dies in the first hour on one question. Who decides? Not what the policy says. Who, by name, at 2am, when the EHR is degraded and legal thinks the 60-day HIPAA notification clock already started. The organizations that handle it well practiced the argument. The ones that struggle practiced the document.
Now add AI to that hour. The triage tool is producing output nobody can explain. The agent with write access to scheduling is doing something nobody approved. And the honest answer to "where did the model get that data" is that nobody knows.
That is the talk healthcare needs. Not the future of medicine. The next 72 hours.
So here is what to demand.
| What most speakers bring | What you should require |
|---|---|
| A trend deck on AI in medicine | A named framework your team can use the next morning |
| AI expertise or security expertise | Both, because in healthcare they are the same problem |
| Research and citation | The operator seat, someone who has been accountable when it broke |
| Generic compliance mentions | Specific HIPAA mechanics, chain of custody, BAAs, the notification clock |
| Inspiration | A decision your board makes differently as a result |
Most speakers clear two. Very few clear all five, and the reason is structural. The AI speakers do not have the security scars. The security speakers do not have the AI depth. Healthcare needs the overlap, and the overlap is thin.
The framework, applied to a health system
I bring the Enterprise AI Trust Score to healthcare audiences. Five dimensions, each mapping to something you are already accountable for.
Data lineage. Where the data came from, where it went, who touched it. This is HIPAA-aligned chain of custody, and where most AI programs fail an audit. If you cannot trace the output back to the source record, you cannot defend the workflow to a regulator.
Identity and access for AI agents. An agent is a user. It needs an identity, entitlements, and an audit trail. Most health systems have not decided who owns that, so agents inherit the permissions of whoever configured them.
Adversarial resilience. The ransomware crews have AI too, the lures are clean now, and 24.9% of your industry's breaches start in a compromised email account. Resilience is not the firewall. It is whether the clinical operation runs when the systems do not.
Clinical accountability. Who signs off. Not the policy, the person. If an AI-assisted decision harms a patient, the org chart has to answer before the incident, not during it.
Governance that survives contact. A policy nobody has read is not governance. It is documentation.
Boards do not need convincing that AI matters. They need to know which questions to ask, and someone willing to give the honest answer, including when that answer is that nobody knows.
Questions healthcare planners actually ask
What makes an AI keynote speaker right for a healthcare audience?
Fluency in both AI and security, plus real operating accountability. Healthcare's AI problem is a governance and privacy problem wearing a clinical costume. A speaker who only knows the technology misses the HIPAA mechanics.
Can one speaker cover AI, HIPAA, and cybersecurity in a single keynote?
Yes, and in healthcare they should not be separated. Splitting them is how you end up with an AI strategy the security team has never seen.
What should a healthcare board take away?
A short list of questions for their CIO and compliance officer, and the ability to tell a real answer from a comfortable one. If the board leaves inspired but asks nothing different, the keynote failed.
How far in advance should we book?
Three to six months for major healthcare conferences. I take a limited number each year, in person, virtual, or hybrid. Book at marklynd.com/speaking or see the healthcare keynote page.
The honest counterargument
There is a real case against what I just said, and it deserves a hearing.
Some of the best healthcare AI speakers are clinicians and researchers, and they bring something I do not. A physician who has deployed a diagnostic model in a real clinical workflow understands that reality in a way no CISO does. If your goal is to move clinical practice, book that person. My own list of the top 10 AI keynote speakers for healthcare in 2026 is full of them, and they earned it.
The distinction is what your event needs to accomplish. Inspiring clinical adoption is one job. Governing what your clinicians already adopted is a different chair, and it is the one I have sat in. Most 2026 healthcare agendas are heavy on the first and light on the second. That imbalance is why 81% adoption arrived without governance.
What to do with this
Find out what AI is running in your organization right now. Not the approved list. The real one. Ask a physician what they used this week to draft a discharge summary. Then ask who reviewed it, where the data went, and whether a BAA covers it. Whatever comes back is your starting point.
Then run one test at your next board meeting. Pick any AI tool in active clinical use. Ask who approved it and where that approval is written down. If the room goes quiet, you have your answer.
The AI in your health system is not coming. It is in the building, and the governance conversation is late. That is a reason to start this quarter, not during the incident.
If you want that conversation on your stage, book the keynote at marklynd.com/speaking. If the insurance side is where your board's attention sits, A Leader's Playbook for Cyber Insurance is the deeper read.
One question for your next board meeting. If an AI-assisted decision harmed a patient tomorrow, who in this room would be accountable, and do they know it yet?
Sources
- American Medical Association, "More than 80% of physicians use AI professionally: AMA survey," March 12, 2026, reporting the 2026 Physician Survey on Augmented Intelligence (approximately 1,700 physicians). https://www.ama-assn.org/practice-management/digital-health/more-80-physicians-use-ai-professionally-ama-survey
- American Medical Association, 2026 Physician Survey on Augmented Intelligence (PDF). https://www.ama-assn.org/system/files/physician-ai-sentiment-report.pdf
- IBM, Cost of a Data Breach Report 2025. Healthcare average $7.42M, highest of any industry for the 14th consecutive year, 279-day containment. Global all-industry average $4.44M. https://www.ibm.com/think/insights/cost-of-a-data-breach-healthcare-industry
- HIPAA Journal, "Average Cost of a Healthcare Data Breach Falls to $7.42 Million." https://www.hipaajournal.com/average-cost-of-a-healthcare-data-breach-2025/
- HIPAA Journal, 2025 Healthcare Data Breach Report. 772 breaches of 500+ records, 139,721,832 individuals affected, worst year on record, exceeding the 2023 record of 746 by 3.49%. Network servers 61.5%, email accounts 24.9%. OCR resolved 21 cases for $8,330,066 in penalties. https://www.hipaajournal.com/2025-healthcare-data-breach-report/
- HHS Office for Civil Rights Breach Portal. https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
- Mark Lynd primary experience, more than 150 executive tabletop exercises across enterprise, SLED, and healthcare organizations.