
Micky Tripathi, Ph.D., moved from leading the federal Office of the National Coordinator for Health IT to become Mayo Clinic’s chief artificial‑intelligence implementation officer, a role that puts him at the center of the health system’s fast‑growing AI portfolio.
From federal oversight to Mayo’s AI office
At the Department of Health and Human Services, Tripathi’s chief AI officer duties involved setting up a rapid‑cycle review system for AI tools used across agencies such as CMS, NIH and the Indian Health Service. An executive order required any AI solution without prior review to be shut down by year‑end, prompting a “broad scan” of existing tools.
He recalls that the Indian Health Service head warned of five clinical AI tools already in use, making an immediate shutdown impossible. The pressure to create a functional framework then mirrors the task he now faces at Mayo.
Adapting governance to Mayo’s culture
Mayo’s governance was historically decentralized. The institution’s founders encouraged “bringing together different parts” to create solutions, a mindset that persists today.
With low‑code and no‑code platforms, the clinic now sees a surge of bottom‑up projects. Tripathi notes roughly 450 solutions in the pipeline and 128 already deployed in clinical practice. The existing review steps—security, privacy, technical integration—were spread across multiple departments, causing delays and occasional gaps.
“People would say, ‘Okay, wait a minute, we need to figure it out,’” he said, describing how unique AI issues fell between departmental lines.
In response, the CEO asked Tripathi to design a governance model that would act as both filter and accelerator, ensuring safe, swift delivery of AI tools to clinicians.
While Mayo encourages unrestricted innovation, scaling a solution enterprise‑wide now triggers a centralized review. This hybrid approach reflects the institution’s belief that “unbridled innovation” can coexist with strong oversight.
Read Also: Peter Embí to Lead National Library of Medicine
From a broader view, large health systems must reconcile two competing imperatives: supporting rapid invention while protecting patients from untested technology. When hundreds of AI prototypes surface, a single, well‑defined gatekeeper can prevent bottlenecks and keep the focus on clinical benefit.
Building a unified review process
Tripathi eliminated many ad‑hoc committees, arguing that a strategic AI initiative deserves an executive leader who can cut across risk, IRB and other functions. He now heads a dedicated department that vets every incoming solution.
The team evaluates privacy, security, performance and patient‑safety considerations, using a unified policy set. Accountability rests with the AI office, which reports directly to the clinic’s CEO, Dr. Gianrico Farrugia.
“Having an executive‑level decision point lets us balance what’s most important for patients with risk mitigation,” Tripathi explained.
He also stresses that product creators remain responsible for their tools throughout the lifecycle. They must define intended use, set performance benchmarks against current standards of care, and submit post‑deployment monitoring plans.
Handling third‑party and home‑grown tools
The review workflow does not differentiate between vendor‑supplied, co‑developed or internally built AI. Third‑party risk management first checks financial stability and contracts; then the AI office conducts the technical assessment.
If a vendor fails to provide adequate evaluation data, Mayo adds extra safeguards until its own data confirm safety. “We’re not going to take anyone’s word for it if they say ‘Trust us, it’s fine,’” Tripathi said.
The clinic’s approach contrasts with smaller systems that may rely heavily on a single electronic‑health‑record vendor, shifting liability through contracts rather than internal testing.
Read Also: Rural paramedic programs expand under new plans
Future of monitoring and platforms
Mayo does not use a single, vendor‑provided monitoring platform. Instead, it follows a federated model where each product team implements its own post‑deployment tracking according to Mayo’s policies.
Tripathi acknowledges the appeal of platforms like AI governance tools, but notes the complexity of integrating a unified system across multiple sites and architectures.
He says the organization is building more automated infrastructure to ease the monitoring burden, though a single platform may still be years away.
Balancing speed with safety
Tripathi finds the role rewarding because Mayo’s leadership “truly believes these technologies are transformative.” He was surprised to learn that the clinic is building its own multimodal foundation models rather than relying solely on external large language models.
The biggest challenge, he says, is keeping pace with new AI capabilities while ensuring each tool meets high‑performance standards. New agentic products often test policy limits, forcing rapid development of fresh guidelines.
Another hurdle involves redundancy. With dozens of solutions arriving from Epic, internal teams and external vendors, deciding which to adopt can be tricky. “We don’t want to overload clinicians with multiple tools that do the same thing,” Tripathi noted.
Clinical leaders, not just IT staff, make final adoption calls. “In a regular business, the business owner decides, not the technology people,” he argued, emphasizing the need for clinical benefit to drive decisions.