Tom Tolleson
AI risk and governance in regulated industries — healthcare, insurance, and financial services.
New York/tomtolleson@gmail.com/LinkedIn/GitHub
I work on the governance side of AI: deciding whether a system should be deployed, under what controls, with what human oversight, and how it gets monitored once it is live.
Fifteen years of program leadership in regulated environments preceded this — building a HIPAA and SOC 2 compliance framework with legal and executive leadership, assessing systems against DoD security standards, and aligning technical roadmaps with regulatory requirements at Aetna and Benefits Data Trust.
Enough fluency with LLM and retrieval systems to challenge a vendor's claims without waiting for an engineer to interpret them.
- AIGP — Artificial Intelligence Governance Professional, IAPP (in progress)
- CPHIMS — Certified Professional in Healthcare Information and Management Systems, HIMSS (in progress)
- CompTIA Security+
- Position of Public Trust (SSA) and DoD Secret clearances, active
- MSIS, Information Science — University of North Carolina at Chapel Hill
- BA, English Language and Literature — University of New Mexico
NIST AI Risk Management Framework, ISO/IEC 42001, the NAIC model bulletin on insurer AI use, HIPAA, SOC 2, and the growing body of state law governing AI in utilization review and prior authorization.
- Conceptions of Features and Semantic Clusters as Search Mechanisms: A Pilot Study UNC School of Information and Library Science, 2004
- Use of a 3D Graphic Environment in Superimposition Analysis University of North Carolina at Chapel Hill, 2003