Human-Centric AI Governance
Available for project-based engagements — remote, U.S.-focused.
HC
AI
Tom Cole
Founder & Principal Consultant — Human-Centric AI Governance, LLC
M.S. Cybersecurity, Georgia Tech · CIPP/US · MLS(ASCP)

Helping healthtech companies navigate AI governance, compliance, and regulatory risk.

Services
What I help you build.

Regulatory Mapping, Gap Analysis & Operational Policy Design

I find exactly where your AI workflows and policies fall short of regulatory requirements — then deliver the policies that close those gaps. Two phases, one engagement: first the findings, then the solutions.

Phase 1
Regulatory Mapping & Gap Analysis I review existing policies and AI workflows against applicable regulations and deliver a written findings report with a prioritized list of what needs to be fixed and in what order.
Phase 2
Operational Policy Design Based on the Phase 1 findings, I write or revise the policies needed to close the gaps — practical, defensible, and ready for your team to use.

Third-Party AI Risk Assessment

I review the AI vendors and tools your organization is using or evaluating, mapped to HIPAA, federal and U.S. state privacy laws, and other applicable compliance requirements. The deliverable is a vendor risk profile your team can present to procurement, security review, or the board.

Writing
Published work.

Healthcare Data Governance and Privacy

Governance and privacy controls for protected health information in AI enabled healthcare environments.

Strategic Regulatory Reform: Third Party Risk Management

A framework for assessing and managing third party and vendor risk across healthcare organizations.

Strategic Regulatory Reform: HHS Memorandum

Executive recommendations on healthcare cybersecurity reform, delivered to HHS.

About

23 years inside clinical laboratory environments — HealthTech companies, hospital systems, diagnostic manufacturers, and medical device companies — provide the operational depth that policy-only consultants lack. That foundation, paired with a Georgia Tech M.S. in Cybersecurity and an active CIPP/US certification, is what I bring to AI governance and compliance work.

Contact
Let’s talk about your AI governance needs.

I work with healthtech startups and healthcare organizations on a project basis. If you are navigating AI compliance, facing enterprise procurement questions, or preparing for regulatory scrutiny — book a 30-minute consultation below or reach out by email.