Most health systems deploy AI tools without formal IT approval. What are the risks?

Nearly three-quarters of healthcare organizations deploy AI tools or agents without formal IT approval at least sometimes, a new Imprivata survey finds.

The survey (PDF) was conducted by Vanson Bourne on behalf of Imprivata, a provider of identity management solutions, reaching 250 U.S. healthcare leaders responsible for identity security or AI strategy across U.S. health systems, hospitals and integrated delivery networks. Some of these may have been Imprivata customers, though they were not intentionally targeted. 

The survey comes at a time when organizations are increasingly implementing agentic AI in new ways, with the potential to reshape clinical and operational workflows, a report on the findings noted.

The survey found over a quarter of organizations report having agentic AI in production today. Another 44% are piloting projects. Most respondents (79%) expect agentic AI to have a transformative or significant impact on clinical workflows. And even more (88%) expect AI agents to operate with at least some degree of autonomy. Yet only 17% believe existing identity approaches are sufficient without adaptation. 

The security risks are multifold. AI agents may interact with EHRs, identity systems, clinical apps, medical devices and other tech supporting patient care. Nearly six in 10 respondents ranked security among their top three concerns when planning or adopting agentic AI. But what sort of governance and contingency strategies should organizations have when it comes to agentic AI?

Imprivata, which provides these and other solutions to healthcare and other mission-critical industries, suggests establishing clear controls based on defined risk rather than broad restrictions. To achieve this, organizations must clearly define identity, authorization and monitoring controls in the first place.

The report recommended that organizations answer fundamental questions around their use of agentic AI. These include: 

  • Which AI agents currently exist across the enterprise? 
  • What systems and data can they access? 
  • Who owns or sponsors each agent? 
  • What authority has been delegated to them? 
  • What actions can or have they performed? 
  • Can those actions be reconstructed during an audit?

From there, healthcare organizations need policies that answer questions like which actions can an AI agent perform independently versus with clinician approval; when should step-up authentication be required; and what happens when the agent behaves outside expected parameters.

Broadly, hospital adoption of new security tools remains infrequent, Imprivata’s chief executive told reporters at an in-person gathering in New York City last week.

“Very, very, very few healthcare systems today are deploying new security technology,” Fran Rosch, president and CEO of Imprivata, said at the gathering. “Unfortunately, sometimes it takes a major breach or a major incident to drive change.”

Rosch spoke about the shocking new revelations about the Hugging Face hack and noted the company is highly sophisticated for having used AI agents in its own security defenses. This was detailed in a Hugging Face blog post, where the company described how AI helped detect the incident. "Our anomaly-detection pipeline uses LLM-based triage over security telemetry to separate real signals from the daily noise, and it was the correlation of those signals that flagged the compromise," the post said. Though it took Hugging Face days to notice the attack, its advanced capabilities enabled it to map out the impact in hours. Had a health system undergone a similar coordinated agentic AI attack, it is highly unlikely it would have been caught and understood so quickly, Rosch noted. 

Even Imprivata’s existing customers have not yet applied security management solutions to their AI agents. The company has about a dozen customers acting as design partners, testing those now. Long-term, Imprivata wants customers to leverage security systems for AI agents that already exist for other high-risk users, instead of having to buy and deploy entirely new software. 

“How do we use the assets already before [them] to look at this as a new type of identity, with its own new challenges, and that I think is what’s going to allow us to do this very cost-effectively for our customers,” Rosch said.

Imprivata’s Chief Medical Officer Sean Kelly, M.D., sits on the board of the College of Healthcare Information Management Executives (CHiME). The organization has a public policy team that works with members, a policy steering committee and the board to inform and influence federal policy on health IT. 

“I am personally concerned, and I wish the government would step in and slow things down,” Rosch said of AI. “What we can do is help our customers as they are implementing their tools.”

When it comes to homegrown AI tools that are co-developed by a health system, Rosch believes these are less secure than third-party LLMs, even if they offer more transparency. At the same time, having a business associate agreement alone with third parties is also not enough of a security assurance, in Rosch’s view. Imprivata gives its clients a checklist outlining the specific ways it protects their data, and this should ideally be a standard part of any organization doing business with a tech vendor.