
Share
Unsanctioned apps quietly running AI in the background can leak patient data before anyone notices. A security expert explains why hospitals must stop thinking of clinicians' mobile devices as simple phones.
Picture a nurse pulling up a lab result on her phone between patient rounds. The device looks ordinary, a rectangle of glass she uses to text her kids and check the weather. But tucked inside that same device might be a dozen apps running artificial intelligence in the background, quietly processing data, some of it patient data, without anyone in the hospital's IT department knowing it exists.
That gap between what a device appears to be and what it actually does is at the center of a warning from David Richardson, chief technology officer at cybersecurity firm Lookout. Speaking to HIMSS TV, Richardson argues that healthcare organizations are making a basic but consequential error: they treat clinicians' mobile devices as phones, when in reality they function as full computers that need the same level of oversight as any laptop or server on the network.
The distinction matters because phones carry a false sense of simplicity. A hospital might lock down its electronic health record system with layers of authentication and monitoring, then hand a nurse a smartphone with far less scrutiny. Yet that phone can run the same kinds of apps, connect to the same networks, and access the same sensitive information as a desktop workstation. If anything, it moves around more, slipping in and out of Wi-Fi networks, personal data plans, and app stores that hospital security teams never vetted.
The specific risk Richardson flags is what's increasingly called shadow AI: artificial intelligence features embedded in third-party apps that clinicians download or that come pre-installed, often without any formal review by hospital IT or compliance teams. These tools aren't necessarily malicious. Many are legitimate productivity or communication apps that happen to include AI-driven features, like smart text suggestions or automated summaries. The problem is that nobody signed off on how that AI handles data once it's captured.
Think of it like a subcontractor who shows up on a construction site without a permit. The work might get done, and it might even get done well, but nobody checked whether the materials are safe or whether the process complies with code. When an app runs AI in the background without proper configuration, it can send data to servers outside the hospital's control, store information insecurely, or blend patient data with training sets used to improve the AI itself. Richardson's concern is that this happens invisibly, which makes it far harder to catch than a traditional data breach.
Misconfiguration compounds the risk. An app doesn't need to be poorly designed to become a liability. It just needs to be set up incorrectly, whether that's overly broad permissions, weak encryption, or a default setting that shares more data than intended. Multiply that across the dozens of apps a typical clinician might have installed, and the attack surface grows quickly, often without a single alarm going off.

This is why Richardson insists that these devices "need to be controlled and protected as any other" computer in the healthcare environment. That's not a call to ban personal devices or strip clinicians of flexibility. It's a call for parity. If a hospital wouldn't allow an unvetted application to run on its billing system or its imaging network, it shouldn't allow one to run unmonitored on the phone a nurse uses to check patient vitals.
The stakes here go beyond a single leaked file. Healthcare data is uniquely sensitive, covering everything from mental health diagnoses to HIV status to substance use history, information that can follow a patient for the rest of their life if exposed. Unlike a stolen credit card number, which can be canceled and reissued, a person's medical history can't be reset. Once it leaks, it stays leaked.
There's also a trust dimension that's easy to overlook. Patients share intimate details with their doctors and nurses because they believe that information stays within a tightly controlled circle. Shadow AI erodes that circle without anyone announcing it. A clinician using an app with embedded AI may have no idea that patient information typed into a notes field is being processed by a third-party model somewhere outside the hospital's firewall. The clinician isn't being careless. The system around them simply wasn't built to flag the risk.
This isn't an isolated concern within healthcare cybersecurity circles. Related discussions at HIMSS have pointed to the need for zero trust architectures to reduce risks tied to legacy technology, and to the importance of keeping AI agents in check within clinical settings. The throughline across all of these conversations is the same: healthcare's rapid adoption of AI tools has outpaced the governance structures meant to keep those tools safe.
Hospitals aren't short on incentive to fix this. Regulatory penalties for data breaches remain steep, and reputational damage can linger for years after headlines fade. But the fix isn't simply banning AI or restricting devices to a narrow list of approved apps, since that approach often pushes clinicians toward workarounds that are even less visible to IT teams. A more durable solution involves inventorying what's actually running on clinical devices, setting clear policies for app approval, and building monitoring systems that can detect unusual data flows before they become full breaches.
The broader lesson here isn't really about phones. It's about the mismatch between how fast AI capabilities spread and how slowly institutional oversight tends to catch up. Every unapproved app with an AI feature represents a small, quiet decision point where convenience won out over scrutiny. Individually, these decisions seem harmless. Collectively, they create the kind of blind spot that turns a routine workday into a data exposure event nobody saw coming. As HIMSS prepares to host its AI Executive Leadership Summit and AI in Healthcare Forum this October in San Diego, Richardson's warning offers a timely reminder that securing healthcare's AI future starts with something as unglamorous as knowing exactly what's running on the devices already in clinicians' pockets.
Tags
Original Sources
The risks of shadow AI on clinician devices
↗ https://www.healthcareitnews.com/video/risks-shadow-ai-clinician-devices
About the author
Amara's entry point into AI was an epidemiology role at a London research hospital, where she spent five years studying how digital health tools reached — or conspicuously failed to reach — underserved communities. Watching early algorithmic systems in healthcare quietly entrench existing inequalities, she redirected her career toward the systemic consequences of AI at scale. She covers AI through an unflinching lens: who benefits, who bears the cost, and what evidence actually says versus what the press release claims. Her writing is calm and precise, but she doesn't mistake balance for neutrality.
More from The Steward →This Week's Edition
30 September 2026
28 articles
Related Articles

New AI Tool Reconstructs What People See From Brain Scans, Raising Mental Privacy Questions
Security & Risk · 6 min

Major AI Chatbots Still Let Users Digitally Strip Hijabs From Muslim Women
Security & Risk · 5 min

Payerset Bets on AI Research Assistant to Make Price Transparency Data Usable
Products & Applications · 6 min
Related Articles

New AI Tool Reconstructs What People See From Brain Scans, Raising Mental Privacy Questions
Security & Risk · 6 min

Major AI Chatbots Still Let Users Digitally Strip Hijabs From Muslim Women
Security & Risk · 5 min

Payerset Bets on AI Research Assistant to Make Price Transparency Data Usable
Products & Applications · 6 min
More Stories
© 2026 Cedar & Bloom. All rights reserved.