How to use this file. Score it on screen by clicking the boxes, and the total and tier update as you go. To produce the distributable PDF, print from Chrome using Letter, margins set to None, and Background graphics turned on. The screen note you are reading now does not print.
HLTHWORKS Redefining Healthcare Performance

A preliminary maturity instrument for AI leadership

The Preliminary
AI MaturityAssessment


Thirty five items. Seventy points. One number you can put in front of your board.

For medical groups, health systems, health plans, payers, plus healthcare vendors and investors.
This assessment covers business and administrative AI.
Clinical and medical device AI assessment and foundation setting will be released on September 15, 2026.
7
Domains
35
Scored items
70
Points available
20
Minutes

Scoring transparency

This assessment awards points for evidence rather than for intention, which means most organizations score lower than they expect on the first attempt. That is the design. A low score is not a finding about your organization. It is a measure of how much of your practice is currently written down, and honesty is the only starting position that leads to credible, measurable oversight.

hlthworks.comPage 1
HLTHWORKSPreliminary AI Maturity Assessment

How to score this

This is a preliminary instrument. It establishes a position quickly and internally. It does not verify one, and a self assessment is not evidence of anything to an outside reviewer. Treat the result as a starting point for the conversation, not as a conclusion about the organization.

Score each item zero, one, or two. Score it as an auditor would score it, not as you would describe it in a board meeting. The difference between a one and a two is evidence. If you cannot produce the document, the log, or the record within a working day, the item is a one.

0
Not in place
Does not exist, or exists only as an intention.
1
Partial or undocumented
Happens in practice but is not written, not consistent, or not evidenced.
2
In place and evidenced
Written, operating, and provable to an outside reviewer.

Score it alone first, then score it again with your counterparts in the room. Technology, security, data, artificial intelligence leadership, and the operational owners of the affected functions will each score domains you cannot see from your own chair. The gap between the two totals is more informative than either number. In most organizations the functions closest to governance score lower than the functions closest to delivery by ten points or more, and that gap is the actual finding.

The seven domains

No.DomainPoints
01Mandate and accountability10
02Data security10
03Data governance10
04Governance and ethical use10
05Inventory10
06Deployment controls, business and administrative10
07Oversight and audit operating system10

Who should see the completed assessment. This is a cross functional instrument and it does not belong to one office. The seven domains sit across compliance, technology, security, data, artificial intelligence leadership, and operations, and each of those executives holds part of the answer. Include clinical leadership wherever an administrative tool reaches into clinical workflow, which is more often than the org chart suggests. Circulate the completed assessment to all of them. A score that only one function has seen is a score that only one function will act on.

Include your counsel, internal or external, in that circulation. Several domains cover ground counsel is already accountable for, including vendor terms, data use, patient disclosure, and how tools are classified. Counsel may also have a view on how an internal assessment of controls should be handled and retained, and that view is easier to act on before the assessment is completed than afterward.

One item decides more than the other thirty four. Item 7.5 asks whether anything has ever actually been stopped, paused, or removed from production. A program that has never stopped anything has never been tested, and an untested program is a description rather than a control. Score that item honestly before you score anything else.

hlthworks.comPage 2
HLTHWORKSPreliminary AI Maturity Assessment
01

Mandate and accountability

Who owns this, and does the ownership exist on paper
10 points
02

Data security

What has to be true before a model touches a record
10 points
hlthworks.comPage 3
HLTHWORKSPreliminary AI Maturity Assessment
03

Data governance

The standard the data has to meet before it feeds anything
10 points
04

Governance and ethical use

Whether the governing body can actually stop something
10 points
hlthworks.comPage 4
HLTHWORKSPreliminary AI Maturity Assessment
05

Inventory

The first thing a regulator, an accreditor, or a plaintiff attorney asks for
10 points
06

Deployment controls

Business and administrative. What happens at the point of use
10 points
hlthworks.comPage 5
HLTHWORKSPreliminary AI Maturity Assessment
07

Oversight and audit operating system

An inventory is a noun. Oversight is a verb
10 points

Your score

0
out of 70
0 to 24Ad hoc Adoption is ahead of structure. Practices exist individually rather than as a program.
25 to 41Documented Policy is written. Practice trails the policy, and evidence trails both.
42 to 55Operating Controls function. Coverage is uneven and monitoring is lighter than the policy describes.
56 to 70Mature Controls are written, operating, evidenced, and reviewed by a party independent of the operator.

Most healthcare organizations scoring themselves honestly for the first time land between twenty and forty. That is not a grade and it is not a finding. It is the ordinary consequence of adopting artificial intelligence faster than any governance function was funded to follow. What separates organizations from here is not the score, it is whether the next ninety days are planned or improvised.

hlthworks.comPage 6
HLTHWORKSPreliminary AI Maturity Assessment

The next ninety days

Find your tier. Do these four things. Do not start anywhere else.

TierThe next ninety days
Ad hoc
0 to 24
Name a single accountable executive in writing this month. Build the inventory before you build anything else, including policy, because policy written without an inventory governs an imaginary organization. Stop new deployments until intake exists. Report the honest position to the board rather than the improving position.
Documented
25 to 41
Test one control end to end and see whether it holds. Close the gap between the written policy and the observed practice on the three highest risk tools. Give the governing body written authority to stop a deployment, and then let it stop one. Set thresholds so that a metric triggers an action rather than a conversation.
Operating
42 to 55
Move from go live validation to continuous real world monitoring by site and by setting. Establish independence between the party that operates a tool and the party that reviews it. Extend coverage to the tools that entered through partners and affiliated sites. Retain supporting records on a defined schedule rather than by habit.
Mature
56 to 70
Have the position reviewed by an independent party, because a self assessment is not evidence of anything. Organize the supporting file so that it can be produced rather than assembled. Then turn the same discipline outward and make it an advantage in contracting, in diligence, and in the market.

The gap that matters is not the score. It is the distance between your score and the score your technology team would give you.

Run this assessment twice. Once alone, and once with technology, security, and operational leadership in the room. Where the two totals disagree by more than ten points, you do not have a governance problem. You have a shared understanding problem, and it has to be resolved before any control you write will hold.

hlthworks.comPage 7
HLTHWORKSPreliminary AI Maturity Assessment

Classify before you govern

Most oversight programs fail at the first step, which is not policy. It is classification. Two tools that look identical to the person using them can carry very different risk, and until a tool is classified, every control applied to it is a guess. Run every tool through these three questions in order and record the answer in the inventory record itself.

Does the tool make or directly inform a clinical determination, or is it regulated as a medical device?
Outside this assessment
Clinical and device artificial intelligence is governed under a different regime, including cleared indications for use, validation against your own patient population, post market performance monitoring, and adverse event reporting. Record the tool in your inventory, mark it as clinical, and govern it separately. A companion HLTHWORKS assessment covering clinical artificial intelligence and regulated devices, together with the corresponding foundation setting, will be released on September 15, 2026 at hlthworks.com.
Does the tool draft, structure, summarize, rank, or recommend, while a qualified person forms the judgment and takes the action?
Assistive
The controlling risks are automation bias, anchoring on a confident draft, and omission that the reviewer never sees because nothing appears on screen to disagree with. Requires evidence that the person who signs or submits the output understands what that signature covers, and that the review is real rather than a click.
Does the tool complete an action, close a task, or send an output to a patient, a payer, or the record without a person reviewing that specific instance?
Autonomous
Requires the highest tier of review regardless of how routine the individual task appears, and a named individual who can halt it immediately. Volume is the risk. An error in an autonomous process is not one error, it is every instance since the last review, and in coding, claims, and authorization work that arithmetic compounds quickly.

The question to ask the people using the tool. Can the person operating a given tool tell you whether it is assistive or autonomous? If the answer is no, the classification exists on your side of the organization only, and the person whose name goes on the output is carrying that risk without the information.

Two companion resources.

The AI inventory record template. The field structure behind a defensible inventory, ready to populate rather than design. This is the first action for any organization scoring in the lower two tiers.

Twelve questions every healthcare board should ask about AI. A governance brief written for directors, covering business, administrative, and clinical artificial intelligence, and the patterns of liability behind them. Written to be handed to a committee without a covering explanation.

Both available at hlthworks.com

hlthworks.comPage 8
HLTHWORKS Redefining Healthcare Performance

After the assessment

A score is a starting position,
not a program.


HLTHWORKS builds artificial intelligence governance, oversight, and audit readiness for medical groups, health systems, health plans, payers, and the vendors and investors serving them. Our executives have operated inside these institutions rather than advised them from outside, which is why our work arrives as controls that can be executed rather than frameworks that cannot.

AI governance assessment

An independent read of your position across all seven domains, with evidence tested rather than described, delivered as a board ready finding.

Inventory and classification

Discovery, classification, and an inventory record built to be produced on request rather than assembled under pressure. Template available at hlthworks.com.

Audit readiness

The oversight operating system: thresholds, monitoring, independence, escalation, and a supporting record organized to be produced on request.

Hear the conversation behind this assessment. Episode 5 of Redesigning Healthcare: Unfiltered, Medical Groups and AI: Building the Right Foundation, with Tim Burke, Chief Compliance Officer of Radiology Partners.

HLTHWORKS
hlthworks.com

This preliminary maturity assessment is provided for general informational purposes. It is not legal advice, it does not create an attorney client relationship, and completing it does not create a professional relationship with HLTHWORKS. It is not an audit, an accreditation, a certification, or an opinion, and it does not measure compliance with any statute, regulation, accreditation standard, or contractual requirement. Scores and tiers are descriptive of program maturity only and are not findings, conclusions, or representations about legal or regulatory position. Requirements applicable to artificial intelligence in healthcare vary by jurisdiction and change frequently. HLTHWORKS makes no warranty as to accuracy, completeness, or fitness for any purpose, and accepts no liability for actions taken or not taken in reliance on this document. Consult your own legal counsel and compliance leadership before relying on any position described here.

hlthworks.comPage 9