Everyone is reading the Mayo Clinic whistleblower lawsuit as an AI story. Some of the headlines include the number of a 67% error rate, and there is a reason why the number getting quoted.
The complaint also alleges Mayo authorized a high-risk investigational medical device for use in cardiac surgery, and that the procedure had never obtained Institutional Review Board review.
Somebody was on that operating table.
And read that line again: the procedure had never obtained Institutional Review Board (IRB) review. That is not a missed internal formality. IRB approval for an investigational device is a federal legal requirement under 21 CFR 812, and for a significant-risk device, which a cardiac device almost certainly is, FDA authorization is required on top of it.
The IRB is not paperwork standing between a researcher and their timeline. It is the mechanism by which a stranger's interests get represented in a room they will never enter.
A narrow emergency-use exception exists for a single life-threatening case with no alternative treatment — but it still requires reporting to the IRB within five working days, and it cannot cover repeat use.
A person with a name and a family in a waiting room, who signed a stack of paperwork believing every safeguard the American research system provides had been applied to them. If the allegation is accurate, one had NOT been. And that person may still not know.
I want to look at this case from that angle; not did the AI work, but who bore the cost, and what would have protected them?
What’s established, and what isn’t
Traci Tamiko Eto filed suit against Mayo Clinic on July 6, 2026, in federal court in Minnesota, under the retaliation provision of the False Claims Act, the ADA, and the FMLA.
Mayo on the other hand states it is committed to the responsible development and deployment of AI, with privacy, security, transparency and compliance embedded throughout its processes, and that its research and clinical innovation are conducted in accordance with applicable laws and regulations. Mayo does not comment on active litigation and has reportedly moved to dismiss.
These are allegations from a complaint — a one-sided document by design. None have been proven, YET. And no proven patient injury has been reported in this case.
But there is a difference between harm and being exposed to risk without your knowledge or consent. The second is the injury research ethics exists to prevent. We don’t get to wait for a body to decide whether a control mattered.
The people in this story
Patients whose samples moved. The complaint alleges IRB review was bypassed in connection with data de-identification and the sale of patient biospecimens to a commercial entity. These are people who gave a tissue sample during the worst week of their lives and were never asked about the second use. That’s what review boards are for, not slowing things down, but putting someone in the room to represent a person who can’t be there.
Clinicians. Nobody writes about them, and they’re the most professionally exposed. A clinician acting on output from a tool their institution validated is putting their license behind that validation. If unfavorable results were deleted, as alleged, then clinicians were deciding based on a reliability picture the institution knew was wrong.
Staff who were pressured. The complaint alleges staff were pressured to approve informed consent waivers or forgo documenting them. Picture the junior coordinator: comply and carry it, or refuse and become a problem. That’s moral injury. We track fines. We don’t track the people who spend a decade knowing what they signed.
The nine other reporters. Ten whistleblower reports, per the complaint. One person sued. The others are presumably still working, and they watched what happened to the one who pushed hardest.
Eto. As alleged: was excluded from leadership meetings, was put on a corrective action plan citing “poor cultural fit,” was demoted, had a depressive episode, then FMLA initially denied and granted only after she retained counsel, eventually there was a reduction in force eliminating only her role in December 1, 2025.
The harm nobody can sue over
Every compliance professional in American healthcare read this story.
This month they learned what raising an issue it can cost them, with a name and a timeline attached.
Some will raise concerns anyway. Some won’t. We’ll never know which, but the retaliation risk is real. That’s what makes this harm so easy to ignore: a chilled workforce never shows up as an incident. It shows up as an absence of incidents reported, until it shows up as a catastrophe.
Five things that would have protected these people
1. A short list of decisions no one can waive. Programs usually fail not because a control is missing, but because competing interests come first and a legitimate exception gets used to clear the path. Define the handful of decisions with no exception route — first-in-human use, investigational devices in invasive procedures — so going around them means visibly breaking a rule instead of quietly using one.
2. Quarterly review of exemptions, not studies. You can’t review everything. You can review every waiver: who requested, how often, which projects, who approved. Concentration is the signal. Highest-yield, lowest-effort analytic in compliance, and almost nobody runs it.
3. Validation results that reach users unfiltered. Performance data usually passes through the team that built the tool before reaching decision-makers. That’s a structural conflict; it doesn’t require bad faith to go wrong. If you’d be uncomfortable telling clinicians the real error rate, that discomfort is the finding.
4. A way to document “I was told to.” A required field, a second signature — something lower-stakes than the hotline that converts private pressure into an organizational fact.
5. Repetition that triggers something different. Ask your team what happens the tenth time the same concern arrives. For most programs the honest answer is: nothing different from the first time. Set a threshold at which the matter leaves the chain of command that has an interest in the outcome, regardless of how it was previously closed.
And the measure I’d add to every program: track what happens to people who report. At 18 and 36 months, compare their promotions, ratings, and exits to peers. If reporting correlates with career stall, you have a retaliation problem whether or not any single case would survive legal scrutiny. Your workforce has already run this analysis informally.
The layer that makes all five work: managers
Here is what I keep coming back to when I look at that list.
Every one of those controls depends on information arriving somewhere. And in almost every organization I’ve worked with, information does not travel to compliance first. It travels to a manager first — or it doesn’t travel at all.
By the time something becomes a formal report, it is usually late. The concern has hardened. Positions have been taken. Someone has already decided they are going to be the person who says it out loud, which means they have already calculated the cost. A hotline report is not an early warning system. It is what happens when the early warning system has already failed.
This is why I built the Integrity Playbook™ around three things managers can actually do: lead ethically in the small moments, keep an open door with a credible non-retaliation commitment behind it, and know how to escalate an issue rather than absorb it.
That last one matters more than people expect. Most managers do not suppress concerns out of malice. They suppress them out of uncertainty — they don’t know where the concern goes, they’re not sure it’s serious enough, they worry about looking like they can’t handle their own team. So they hold it. And the organization never learns.
What changes when managers have frequent, ordinary conversations with their teams:
Trust accrues before it’s needed. Nobody brings you a hard thing the first time you talk to them. They bring it on the twentieth conversation, because the previous nineteen established that you don’t punish messengers. A manager who checks in regularly has built the account they can draw on when something serious surfaces. A manager who only appears during performance reviews has not.
Concerns arrive earlier and smaller. “I’m not sure that validation number is right” is a manageable conversation. The same concern eighteen months later, after a deployment and a deleted result, is a lawsuit. The size of the problem is largely a function of how long it took to surface.
Escalation becomes routine rather than heroic. When managers are trained and expected to route issues upward, reporting stops being an act of individual courage and becomes part of how the organization operates. That distinction is everything. A system that only functions when someone is brave is a system that will eventually meet a person who is tired, or new, or has a mortgage.
Compliance gets a continuous risk signal instead of an annual snapshot. This is the part that connects back to AI governance directly. If manager escalations flow into compliance on an ongoing basis, and compliance reviews them as a running picture rather than case by case, patterns become visible while they’re still cheap to fix. Three managers independently mentioning that a tool “doesn’t seem to work right” is a finding. On a case-by-case intake model, it’s three closed tickets.
Retaliation gets harder to execute. Look at how the retaliation in this complaint allegedly occurred: exclusion from meetings, a corrective action plan, a demotion, a restructuring. Every one of those is a management action. Managers are the vector. Which means they are also the control, but only if they’ve been trained to recognize that a performance action taken shortly after a protected report is a decision requiring a second set of eyes, not a routine exercise of discretion.
None of this replaces the formal architecture. IRBs, hotlines, audit committees and independent review all still have to exist and have to work. But the formal architecture is the last line, not the first. The first line is a manager having a conversation on a Tuesday.
Why this belongs in the AI conversation
Every technical control we’ve built; model inventories, bias testing, validation protocols, vendor diligence; sits downstream of one human being willing to deliver unwelcome news to someone who doesn’t want to hear it.
Your inventory is only as good as the person willing to flag the system that isn’t in it. Your validation protocol is only as good as the analyst willing to report the result that kills the timeline.
Whistleblower protection isn’t an HR program running parallel to AI governance. It’s load-bearing infrastructure for it. When it fails, everything above it fails silently and you find out by reading a complaint.
The test was never whether the framework existed. It was whether the people inside it were safe enough to use it.
Evie Wentink is Founder and Principal Consultant of Ethical Edge Experts LLC and host of the podcast Let’s Talk About Ethics. This article discusses unproven allegations in pending litigation and is general commentary, not legal advice.
#AIGovernance #EthicsAndCompliance #PatientSafety #ResponsibleAI #Whistleblowers #ResearchIntegrity #Compliance #PatientPrivacy #SpeakUpCulture #HealthcareAI
Sources: MPR News · Medscape · Becker’s Hospital Review · Fierce Healthcare · FDA: Investigational Device Exemption · Eto v. Mayo Clinic, D. Minn., filed July 6, 2026.



This makes me concerned for both the patients and employees. It's hard to trust intimate bio samples to an org that allows secondary use. Then knowing these problems in an org that chills internal critique is also degrading. This just spawns more "bullshit" jobs for duct taping this mess through PR.