Enterprise AI Policy for Pharmacy
A regional pharmacy enterprise of forty sites, three lines of business, and one ambition stood in a conference room and discovered it had eleven different AI policies. The retail division had written one for the counseling tools its district managers had quietly adopted. The hospital pharmacy had a separate one buried inside the health system's clinical informatics governance. The specialty pharmacy, chasing prior-authorization turnaround, had drafted its own to satisfy a payer audit. Three individual stores had policies their managers wrote from a vendor template. And the rest had nothing at all. When the chief pharmacy officer asked a simple question, can a pharmacist at any of our sites paste a patient's chart into a public chatbot, the honest answer was that it depended entirely on which building they were standing in. That is not a governance posture. That is forty experiments running in parallel, each one a potential patient-safety event or a HIPAA breach waiting for its moment, and no one able to say across the enterprise what was true. This lesson is about the alternative: a single, coherent enterprise AI policy for pharmacy that holds across retail, hospital, and specialty, one governance core strong enough to be the same in every building and flexible enough to survive the real differences between them.
Why One Policy, Not Eleven
The instinct that produced eleven policies is not stupidity, it is the natural result of an enterprise growing faster than its governance. Each division solved its own problem with the tools and rules in front of it, and each policy, read alone, was reasonable. The failure is not in any single policy; it is in their multiplicity, because an enterprise that governs AI eleven different ways cannot answer for AI at all. The first thing a coherent policy buys is the ability to say, with confidence, what is true everywhere. When the question is whether a pharmacist may feed protected health information (PHI), the patient's identity connected to their health data, into an unsanctioned tool, the answer cannot be "it depends on the site." A patient's protection cannot vary by zip code, and a regulator, an accreditor, or a plaintiff's attorney will not accept that it does. The Health Insurance Portability and Accountability Act (HIPAA), the federal law governing PHI protection, applies identically to every site the enterprise operates, so the policy that operationalizes it has to as well.
There is also a practical, unglamorous argument that lands hard with anyone who has run an enterprise: eleven policies are eleven things to maintain, reconcile, train against, and defend, and they will inevitably contradict each other. One division's policy permits a tool another's forbids. One requires a verification step another never mentions. One was updated last year and one has not been touched since adoption. When a regulator, an accreditor, or opposing counsel lines those policies up side by side, the contradictions become the story, because an organization that holds itself to inconsistent standards has implicitly admitted that some of its patients were governed to a lower one. A single policy is not only safer to operate, it is dramatically cheaper to maintain and far easier to defend, because there is one thing to keep current, one standard to train, and one answer to give when someone asks what the enterprise requires. The cost of fragmentation is paid continuously, in maintenance and in exposure, long before any incident makes it visible.
The deeper reason is that the failure modes of pharmacy AI do not respect divisional boundaries. A hallucinated renal dose is a patient-safety event whether the patient is in a hospital bed or picking up at a retail counter. A fabricated coverage criterion delays therapy whether the prior authorization (PA) ran through the specialty pharmacy or the community store. PHI leaving the protected environment is a breach regardless of which line of business leaked it. The risks are common because the underlying machine is common: the same kind of model, doing the same confident plausible-text generation, can place the same false clinical information into the path of a patient in any of the three settings. A policy fragmented across divisions implicitly pretends the risks are divisional, and they are not. The enterprise carries one consolidated risk, and it needs one consolidated answer.
An enterprise that governs AI eleven different ways cannot answer for AI at all. Patient protection cannot vary by zip code, so the governance core that protects the patient cannot vary by division.
The Coherent Governance Core
The solution is not to flatten every division into one identical workflow; that would be both impossible and wrong, because a hospital order-verification process genuinely is not a retail counseling process. The solution is to separate the policy into two layers: a governance core that is identical everywhere, and a layer of divisional implementation that adapts the core to each setting without ever weakening it. The core is the small set of non-negotiable commitments that hold for every pharmacist, technician, site, and line of business in the enterprise, no exceptions, no local override. Getting the core right, and keeping it genuinely fixed, is what makes the policy coherent rather than merely uniform-looking.
The governance core contains a handful of load-bearing rules. First, the cardinal rule: AI supports the pharmacist's judgment and never replaces it, so the human who verifies and signs owns the clinical decision in every setting. Second, the verification requirement: every AI-touched clinical figure, criterion, dose, and interaction is verified against the source of truth, the chart, the formulary, the published payer criteria, before it reaches a patient, because invented criteria, wrong doses, and fabricated interactions are the failure modes the whole program exists to catch. Third, the PHI rule: patient information goes only into tools the enterprise has sanctioned and that are bound by a business associate agreement (BAA), the contract under which a vendor handling PHI is legally obligated to protect it, and never into unsanctioned public tools. Fourth, the sanctioned-tools rule: only tools that have cleared the enterprise's evaluation, with a BAA, a clear data posture, and adequate security, may touch patient information at all. These four commitments are the spine. They do not change between retail and hospital and specialty, because the patient-safety asymmetry that justifies them does not change.
What makes the core hold is that it is written as principle, not as procedure. The principle "every AI-touched dose is verified against the source before it reaches the patient" is true in every setting; the procedure for doing it differs, because the source of truth and the verification step look different in an inpatient order-verification system than at a retail counseling window. By fixing the principle and delegating the procedure, the enterprise keeps the core identical without forcing a fiction of identical work. The mistake to avoid is letting a divisional exception erode a core commitment: the moment one line of business is allowed to skip verification "because their workflow is different," the core has fractured, and the enterprise is back to governing AI eleven ways. The core is the part of the policy that the enterprise will defend to a board and an accreditor as the same everywhere, and it earns that defense only by actually being the same everywhere.
Adapting Without Fragmenting
If the core is what stays fixed, the implementation layer is what flexes, and the discipline of an enterprise policy is keeping the flex below the core rather than inside it. Retail pharmacy lives in the dispensing system and the counseling window, with high patient volume and AI most often drafting patient-facing explanations and speeding routine PAs. Hospital pharmacy lives in the electronic health record (EHR) medication module and the order-verification queue, with AI surfacing renal function, labs, and interaction signals to support the pharmacist's clinical review. Specialty pharmacy lives in the prior-authorization portal and the access-coordination workflow, with AI assembling clinical justifications for high-cost therapies where a fabricated criterion can deny a patient a ten-thousand-dollar-a-month treatment. These are real differences in workflow, in the systems involved, and in where AI sits, and the implementation layer is where the policy meets them.
The implementation layer answers the "how" questions for each setting while inheriting the core's answers to the "what" and "whether" questions. It specifies which sanctioned tools each division uses, what the verification step concretely looks like in that division's workflow, who signs off and where, and how the documentation is captured in that division's systems. A retail implementation might say verification of an AI-drafted counseling sheet means the pharmacist confirms the warnings and dosing against the label and the monograph before the patient hears it; a hospital implementation might say verification of an AI-surfaced renal signal means the pharmacist treats it as a prompt to check the chart's actual renal data and labs, never a verdict to rubber-stamp; a specialty implementation might say verification of an AI-assembled PA justification means every clinical assertion and every cited criterion is confirmed against the chart and the published payer rule before submission. All three are the same core verification commitment, expressed in the work each division actually does.
The test for whether an implementation choice belongs in the flexible layer or threatens the fixed core is simple and worth applying ruthlessly: does it change how a core commitment is met, or whether it is met? Choosing a different sanctioned tool changes how the PHI rule is met; it is fine. Letting a busy site use an unsanctioned tool changes whether the PHI rule is met; it is forbidden, and the policy must name it as such. An enterprise policy that cannot tell its divisions apart will be too rigid to adopt and quietly ignored; one that lets each division redefine the rules will be too soft to protect anyone. The coherent policy is the one that adapts everything about the "how" and nothing about the "what," so that a pharmacist moving from the hospital to the specialty side of the enterprise finds the procedures different and the principles identical.
Who Owns the Policy and How It Holds
A policy with no owner is a document, not a governance instrument, and the difference shows the first time a hard case arrives. The coherent enterprise policy needs a single accountable owner at the enterprise level, typically an AI governance function or committee chaired by a senior clinical leader, with the authority to set the core, approve the divisional implementations, sanction tools, and rule on exceptions. The reason ownership must sit at the enterprise level rather than in the divisions is the same reason the core must: if each division owns its own policy, the enterprise is back to eleven policies wearing one cover. Centralized ownership of the core, with delegated authorship of the implementations, is the structure that keeps the two layers in their proper relationship.
Holding the policy is mostly the work of governing its edges: new tools, new use cases, and exception requests. When a division wants to adopt a new AI tool, the enterprise evaluates it against the sanctioned-tools standard, the BAA, the data posture, the security review, before it can touch PHI anywhere, so that a tool sanctioned for one division is sanctioned under the same bar as for any other. When a division proposes a new use case, the governance function checks it against the core: where does AI sit, what gets verified, who signs, where does the PHI go. And when a site asks for an exception, the answer is governed by a bright line: exceptions to the implementation layer are routine and delegable, exceptions to the core are not granted, because an exception to verification or to the PHI rule is not a workflow accommodation, it is a patient-safety or privacy hole. An enterprise that grants core exceptions under operational pressure will find that the pressure never stops and the core dissolves one reasonable-sounding waiver at a time.
The policy also has to be visible to be real. A governance core that lives only in a binder governs nothing; it has to be trained into every pharmacist and technician, surfaced in the workflow at the moment of use, and reflected in the competency documentation that the enterprise can show an accreditor. The Utilization Review Accreditation Commission (URAC), which launched the first national Health Care AI Accreditation with separate tracks for AI developers and AI users, expects exactly this of a user organization: not a policy on a shelf but evidence that staff across the enterprise are competent, governed users of AI. A coherent policy is the backbone of that evidence, because it lets the enterprise show one standard, applied everywhere, with the documentation to prove the application. The policy that holds is the one people know, the one the workflow enforces, and the one the enterprise can demonstrate it lives by.
The Cost of Incoherence and the Value of Coherence
It is worth being concrete about what the eleven-policy enterprise actually loses, because the cost is easy to underestimate until an incident makes it vivid. The first cost is that the enterprise cannot see its own risk. When governance is fragmented, no one can answer basic questions across the organization: which tools touch PHI, where verification is and is not happening, what the AI-related incident rate is, whether the same dangerous practice is recurring at multiple sites. The enterprise is blind to its own exposure precisely where the exposure is largest, and blindness at scale is how a single site's bad habit becomes an enterprise-wide breach before anyone notices the pattern.
A vivid way to feel the first cost is to imagine the incident that the eleven-policy enterprise cannot get ahead of. A pharmacist at one site develops a habit of pasting chart notes into a public chatbot to summarize complex medication histories, because it is fast and no local rule clearly stops it. The habit spreads to colleagues, then to a second site through a transferred employee, then to a third. Each instance is a PHI breach, and because no central governance is watching the pattern, the enterprise learns of it only when a patient complains or an audit surfaces it, by which point the practice has been running for months across multiple buildings and an unknown volume of patient data has left the protected environment into a system that may have retained or trained on it. The coherent policy does not just forbid the practice; it gives the enterprise a single place to see that the practice is happening and to stop it everywhere at once. Visibility is a governance capability, and fragmentation destroys it precisely when the enterprise needs it most.
The second cost is that incoherence makes every other governance task harder. Standing up incident response is harder when there is no common definition of an incident. Scaling a new tool is harder when each division evaluates vendors differently. Demonstrating accreditation readiness is harder when the enterprise has to reconcile eleven inconsistent records into one story. The coherent policy is not just safer, it is the foundation that makes the rest of the enterprise AI program buildable, because it gives every other function a single, shared set of definitions and commitments to operate from. The value of coherence, in the end, is that it converts a sprawl of local experiments into one governed program: the enterprise can finally say what is true everywhere, defend it to a board and an accreditor, see its own risk clearly, and capture the genuine value of pharmacy AI, the collapsed PA turnaround, the supported clinical review, the faster patient access, without the value coming at the cost of a patient's safety or privacy in some building no one was watching. That is what one policy, not eleven, makes possible.
Key Takeaways
- An enterprise that governs AI through many divisional policies cannot answer for AI at all; patient protection cannot vary by zip code, so the enterprise needs one coherent policy that holds across retail, hospital, and specialty, not eleven that hold separately.
- The failure modes of pharmacy AI (a hallucinated dose, a fabricated coverage criterion, PHI leaving the protected environment) do not respect divisional boundaries, because the underlying model is common across settings; the risk is consolidated, so the answer must be too.
- A coherent policy separates a fixed governance core, identical everywhere, from a flexible implementation layer that adapts the core to each division's real workflow without ever weakening it.
- The governance core contains four load-bearing commitments: the cardinal rule (AI supports, never replaces, the pharmacist's judgment), the verification requirement (every AI-touched clinical fact verified against the source), the PHI rule (PHI only into sanctioned, BAA-bound tools), and the sanctioned-tools rule (only evaluated, protected tools touch patient information).
- The core is written as principle and the implementation as procedure: the principle is identical in every setting, while the procedure for verification, sign-off, and documentation flexes to the dispensing window, the order-verification queue, or the PA portal.
- The test for the flexible layer is whether a choice changes how a core commitment is met (allowed) or whether it is met (forbidden); a divisional exception that skips verification or the PHI rule fractures the core and must be named as off-limits.
- The policy needs a single enterprise-level owner with authority over the core, the tool sanctioning, and exceptions; exceptions to the implementation layer are routine, but exceptions to the core are not granted, because they are patient-safety or privacy holes, not workflow accommodations.
- A coherent policy is the backbone of URAC user-track readiness and of the wider enterprise AI program: it lets the organization see its own risk, demonstrate one standard applied everywhere, and capture AI's value without trading a patient's safety or privacy in an unwatched corner of the enterprise.
Skill.re