
Share
A new Imprivata survey shows nearly three-quarters of health systems let AI tools operate without formal IT sign-off, raising questions about who is watching these systems inside hospitals that handle sensitive patient data.
Imagine a new employee walking into a hospital, given access to patient records, medical devices, and clinical systems, but never formally vetted, badged, or supervised. That is essentially what is happening at many health systems today, except the "employee" is an AI agent, and its actions are often invisible until something goes wrong.
A new survey from Imprivata, an identity management vendor, found that nearly three-quarters of healthcare organizations deploy AI tools or agents without formal IT approval at least some of the time. The findings come from a poll of 250 U.S. healthcare leaders responsible for identity security or AI strategy, conducted by Vanson Bourne on Imprivata's behalf. Some respondents may have been existing Imprivata customers, though the company says they were not intentionally targeted.
The numbers paint a picture of an industry moving quickly, perhaps too quickly, into a new technological era. Over a quarter of organizations already have agentic AI in production. Another 44% are piloting projects. These are not simple chatbots answering scheduling questions. Agentic AI refers to systems that can take independent action: booking appointments, flagging abnormal lab results, or even initiating changes in electronic health records without a human clicking "approve" at every step.
Nearly 80% of respondents expect this technology to have a transformative or significant impact on clinical workflows. Almost 90% expect these AI agents to operate with at least some degree of autonomy. That is a remarkable level of trust for a technology that, according to the same survey, only 17% of respondents believe existing identity systems are prepared to manage safely.
Think of it like handing over car keys to a new driver, one who might occasionally take the wheel entirely on their own, without knowing exactly what roads they are permitted to drive on or what to do if they hit trouble.
The risks here are not abstract. AI agents in healthcare settings may interact directly with EHRs, identity systems, clinical applications, and even medical devices, all of which support real patient care. Nearly six in ten survey respondents ranked security among their top three concerns when planning or adopting agentic AI. That concern is well-founded. An AI agent with too much access, or too little oversight, could misroute sensitive data, make an unauthorized change to a patient's chart, or become a target for attackers looking for a quiet way into hospital systems.
Imprivata's recommendation is not to slam the brakes on innovation, but to build guardrails based on actual risk rather than blanket restrictions. That starts with basic organizational awareness. Which AI agents currently exist across the enterprise? What systems and data can each one access? Who owns or sponsors it? What authority has been delegated? What actions has it taken, and can those actions be reconstructed later during an audit?
These are not exotic questions. They are the same kind of accountability checks any responsible organization would apply to a new hire with access to sensitive systems. Yet many health systems, in the rush to adopt promising new tools, have skipped this step entirely.

From there, organizations need policies addressing when an AI agent can act independently versus when it needs a clinician's sign-off, when extra identity verification should kick in, and what the response plan looks like if an agent behaves unexpectedly. Without these guardrails, hospitals are essentially operating with an invisible workforce whose actions are difficult to trace and even harder to correct after the fact.
Fran Rosch, Imprivata's president and CEO, put the industry's broader hesitancy around new security technology bluntly at a recent gathering of reporters in New York City. "Very, very, very few healthcare systems today are deploying new security technology," he said. "Unfortunately, sometimes it takes a major breach or a major incident to drive change."
Rosch pointed to the Hugging Face security incident from July 2026 as a cautionary tale, and also as an example of AI's potential when used defensively. In a public blog post, Hugging Face described how its AI-driven anomaly detection helped it uncover a breach: "Our anomaly-detection pipeline uses LLM-based triage over security telemetry to separate real signals from the daily noise, and it was the correlation of those signals that flagged the compromise." Though it took Hugging Face several days to notice the intrusion, its tools allowed the company to map the damage within hours once detected.
Rosch noted that a health system facing a similarly coordinated, AI-driven attack would likely struggle to detect and understand it as quickly. That gap in preparedness should concern anyone whose medical records, or family members' records, sit inside these systems.
Even Imprivata's own customers have been slow to apply existing security management tools to their new AI agents. The company currently has about a dozen customers serving as design partners, testing these protections in real time. Long term, Imprivata hopes health systems will extend security frameworks already built for other high-risk users, rather than purchasing entirely new software for AI oversight. "How do we use the assets already before them to look at this as a new type of identity, with its own new challenges," Rosch said, "and that I think is what's going to allow us to do this very cost-effectively for our customers."
Rosch was candid about his own unease. "I am personally concerned, and I wish the government would step in and slow things down," he said, referring to the pace of AI adoption broadly. In the meantime, he said, the company's role is to help customers implement these tools as safely as possible.
He also raised a point that deserves more attention: homegrown AI tools built in-house by health systems may actually pose more risk than third-party large language models, despite offering more transparency into how they work. And having a business associate agreement with a vendor, a standard legal safeguard in healthcare data sharing, is not sufficient assurance on its own. Imprivata provides clients with a checklist detailing exactly how it protects their data, a practice Rosch believes should become standard whenever a health system partners with any technology vendor.
Patients trust hospitals to protect their most sensitive information, often without knowing what technology operates behind the scenes. As AI agents take on more independent roles in clinical and administrative workflows, the absence of formal oversight is not just an IT problem, it is a patient safety and trust issue. Closing that governance gap now, before a major incident forces the issue, is the more responsible path forward.
Tags
Original Sources
Most health systems deploy AI tools without formal IT approval. What are the risks?
↗ https://www.fiercehealthcare.com/health-tech/imprivata-survey-finds-most-health-systems-deploy-some-ai-tools-without-formal-it
About the author
Amara's entry point into AI was an epidemiology role at a London research hospital, where she spent five years studying how digital health tools reached — or conspicuously failed to reach — underserved communities. Watching early algorithmic systems in healthcare quietly entrench existing inequalities, she redirected her career toward the systemic consequences of AI at scale. She covers AI through an unflinching lens: who benefits, who bears the cost, and what evidence actually says versus what the press release claims. Her writing is calm and precise, but she doesn't mistake balance for neutrality.
More from The Steward →This Week's Edition
16 September 2026
31 articles
Related Articles

Documents Show Medicare's AI Prior Authorization Pilot Was Rushed Into Launch
Policy & Regulation · 5 min

Ballad Health's Medicare Advantage Fight With UnitedHealth Heads to Arbitration, Not Court
Policy & Regulation · 5 min

When AI Insiders Warn of Extinction Risk, How Seriously Should We Take Them?
Policy & Regulation · 5 min
Related Articles

Documents Show Medicare's AI Prior Authorization Pilot Was Rushed Into Launch
Policy & Regulation · 5 min

Ballad Health's Medicare Advantage Fight With UnitedHealth Heads to Arbitration, Not Court
Policy & Regulation · 5 min

When AI Insiders Warn of Extinction Risk, How Seriously Should We Take Them?
Policy & Regulation · 5 min
More Stories
© 2026 Cedar & Bloom. All rights reserved.