
Share
As AI agents start touching patient data and clinical workflows, one cybersecurity CEO argues hospitals should extend existing identity controls rather than trust these systems by default, or buy new tools to manage them.
Picture a contract nurse walking into a hospital an hour before her shift starts. Nobody on staff has met her. She came recommended by an agency, badge in hand, ready to work. Before she touches a single patient chart, someone has to answer a string of uncomfortable questions: Who is she, really? What should she be allowed to see? Who's watching what she does once she's logged in? And when her shift ends, how fast can that access disappear?
Hospitals have spent years building systems to answer those questions for temporary staff, remote vendors, and outside contractors. Now, according to Imprivata CEO Fran Rosch, they need to start asking the same questions about artificial intelligence.
"We can simply just think of an agent the same way you would think of that contract nurse," Rosch said Thursday during a media lunch in Manhattan. "You don't know him or her. You've never met them before. They've been recommended to you." The identity and cybersecurity vendor believes AI agents, the software systems now being deployed to draft clinical notes, schedule procedures, or flag billing errors, deserve the same skepticism as a stranger walking through the door.
That framing matters because AI agents are quietly gaining the kind of access that used to be reserved for trusted employees. They can read patient records, trigger workflows, and make decisions with minimal human oversight. Yet most hospitals don't have a clear answer for the questions Rosch raised: How do you verify what an agent actually is? How do you limit it to only the data and systems it needs? How do you monitor its behavior for warning signs? And critically, how do you cut off its access the instant something looks wrong?
For a contract nurse, those safeguards are second nature to hospital compliance teams. For software making autonomous decisions inside clinical systems, they're still being figured out.
Here's where Rosch's pitch gets interesting, and arguably more realistic than a lot of the AI security chatter flooding the healthcare conference circuit. Imprivata isn't asking hospitals to buy a brand-new product built specifically for AI agents. Instead, the company is extending a privileged access security gateway it already runs for its highest-risk human users, think system administrators and outside vendors, so that it also governs AI agents.
That distinction is not just semantics. It's a bet on hospital budgets and bandwidth.
Rosch pointed to a health system visit earlier that same day as a case in point. Leadership there didn't want another vendor relationship or another software deployment to manage. They wanted to stretch the tools they'd already paid for and already trained staff to use. Given how thin financial margins run across much of the hospital sector, and how reluctant IT departments are to take on new implementation projects, that reluctance is entirely rational. Every new security tool comes with a learning curve, a maintenance cost, and a chance something breaks during rollout.

Think of it like a building that already has a badge system controlling who can enter the server room. Rather than installing a separate, parallel security system just for a new category of workers, you extend the existing badge system to recognize them too. The infrastructure, the audit trails, the revocation switches, they're already built. What's new is deciding who, or what, gets to carry a badge.
About a dozen health systems are currently working with Imprivata as design partners on this approach, testing it before it becomes something hospitals can budget for at scale. Rosch was candid that the market for securing AI agents this way is still in its early days. The underlying model, treating unfamiliar users as inherently risky until proven otherwise, is well established for humans. For autonomous software agents, it's largely untested at scale.
That gap is the opportunity Rosch says Imprivata is chasing, and he doesn't believe the company will stay alone in that pursuit for long. He expects similar approaches to agentic AI security to become fairly standard across the industry once hospitals actually start setting aside budget for it. For now, though, the goal is narrower: get ahead of a problem before most hospitals are forced to confront it during an actual security incident.
The stakes here go well beyond one vendor's product roadmap. Healthcare data is uniquely sensitive, and healthcare IT systems are chronically underfunded relative to the risks they carry. Every new AI tool that touches a patient record, a scheduling system, or a billing workflow introduces a fresh set of questions about who's accountable when something goes wrong.
Regulators have not yet caught up to agentic AI in healthcare settings. There's no widely adopted federal standard dictating how hospitals should vet, monitor, or revoke access for autonomous AI systems the way there is for, say, HIPAA-covered human access controls. That regulatory lag means vendors like Imprivata are, in effect, writing the early playbook themselves, one design partnership at a time.
That's not necessarily a bad thing. Practical, incremental approaches, ones that build on infrastructure hospitals already trust and understand, may prove more durable than sweeping new mandates that arrive after the technology is already embedded in clinical workflows. But it does mean the industry is largely self-regulating on this front, at least for now.
The contract nurse analogy is useful precisely because it's not abstract. Patients already trust hospitals to manage that kind of risk quietly and competently every day. The question now is whether hospitals can extend that same discipline to software that never clocks out, never asks for a break, and, unlike a human employee, has no instinct of its own for when something feels off.
Tags
Original Sources
Imprivata CEO: AI Agents Need the Same Scrutiny as an Unvetted Contract Nurse - MedCity News
↗ https://medcitynews.com/2026/09/imprivata-ai-agents
About the author
Amara's entry point into AI was an epidemiology role at a London research hospital, where she spent five years studying how digital health tools reached — or conspicuously failed to reach — underserved communities. Watching early algorithmic systems in healthcare quietly entrench existing inequalities, she redirected her career toward the systemic consequences of AI at scale. She covers AI through an unflinching lens: who benefits, who bears the cost, and what evidence actually says versus what the press release claims. Her writing is calm and precise, but she doesn't mistake balance for neutrality.
More from The Steward →This Week's Edition
11 September 2026
33 articles
Related Articles

As CMS and FDA Chart AI's Path Into Medicine, Clinicians Push Back on Autonomy
Policy & Regulation · 7 min

White House to Send $500 Refunds to Nearly 1 Million ACA Enrollees, Drawing on Leftover Exchange Fees
Policy & Regulation · 5 min

Hugging Face Attack Signals Wider Risks in the AI Infrastructure Everyone Relies On
Security & Risk · 5 min
Related Articles

As CMS and FDA Chart AI's Path Into Medicine, Clinicians Push Back on Autonomy
Policy & Regulation · 7 min

White House to Send $500 Refunds to Nearly 1 Million ACA Enrollees, Drawing on Leftover Exchange Fees
Policy & Regulation · 5 min

Hugging Face Attack Signals Wider Risks in the AI Infrastructure Everyone Relies On
Security & Risk · 5 min
More Stories
© 2026 Cedar & Bloom. All rights reserved.