{
  "id": 7635290,
  "title": "Most health systems deploy AI tools without formal IT approval. What are the risks?",
  "url": "https://urgent.news/2026/09/15/most-health-systems-deploy-ai-tools-without-formal-it-approval-what",
  "topic": "ai",
  "section": "AI",
  "published": "2026-09-15T19:25:04.000Z",
  "source": {
    "name": "Fierce Healthcare",
    "slug": "fierce-healthcare",
    "url": "https://www.fiercehealthcare.com/health-tech/imprivata-survey-finds-most-health-systems-deploy-some-ai-tools-without-formal-it"
  },
  "original_language": "en",
  "account": "A recent survey by Imprivata reveals that nearly three-quarters of healthcare organizations are deploying artificial intelligence tools or agents without formal IT approval. The survey, conducted by Vanson Bourne on behalf of Imprivata, polled 250 U.S. healthcare leaders responsible for identity security or AI strategy across various health systems, hospitals, and integrated delivery networks. Over a quarter of organizations have already implemented agentic AI in production, while 44% are piloting projects. Most respondents anticipate agentic AI to significantly impact clinical workflows, with 88% expecting AI agents to operate with varying degrees of autonomy. However, only 17% believe existing identity approaches are sufficient without modification.\n\nThe survey highlights several security risks associated with agentic AI. Nearly six in ten respondents rank security among their top three concerns when planning or adopting this technology. AI agents may interact with electronic health records, identity systems, clinical applications, medical devices, and other patient care-supporting technologies. Imprivata, a provider of identity management solutions for healthcare and mission-critical industries, suggests establishing clear controls based on defined risk rather than implementing broad restrictions. Organizations should define identity, authorization, and monitoring controls before adopting agentic AI. Fundamental questions to address include which actions an AI agent can perform independently versus with clinician approval, when step-up authentication is required, and the consequences when an agent behaves outside expected parameters.\n\nDespite these concerns, many healthcare systems remain reluctant to adopt new security technologies. Imprivata's CEO, Fran Rosch, noted that few healthcare systems deploy new security tools proactively, often waiting for major breaches or incidents to drive change. Rosch referred to the Hugging Face hack as an example, emphasizing that a similar coordinated attack on a health system would be unlikely to be detected within hours. Even Imprivata's existing customers have not yet applied security management solutions to their AI agents. The company currently has about a dozen customers serving as design partners to test these solutions. Imprivata aims to leverage existing security systems for AI agents, rather than requiring customers to purchase and deploy entirely new software.\n\nImprivata's Chief Medical Officer, Sean Kelly, M.D., expressed concerns about AI and advocated for government intervention to slow down its implementation. He believes homegrown AI tools co-developed by health systems are less secure than third-party large language models, even if they offer more transparency. However, simply having a business associate agreement with third parties is not sufficient security assurance, according to Rosch. Imprivata provides its clients with checklists outlining specific ways the company protects their data, which should ideally become a standard part of any organization's dealings with tech vendors.",
  "summary": "The survey found that most healthcare orgs deploy AI tools at least sometimes without formal IT approval, which Imprivata argues poses existential security risks. Only 17% of executives surveyed believe existing identity approaches are sufficient without adaptation.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}