Health care's emerging risk: unauthorized AI agents

Hospitals and other organizations will have to think about security in new ways to avoid exposing personal information.

Health care's emerging risk: unauthorized AI agents

TL;DR

  • 72% of health industry leaders report AI tools or agents are being deployed without formal IT approval.
  • 28% of health organizations currently use agentic AI, with 44% piloting or testing it.
  • 88% expect AI agents to operate with some autonomy in clinical and administrative work.
  • Unauthorized AI actions could lead to exposure of personal health information, modified records, and security breaches.
  • Examples include an Otter agent transcribing patient information and an OpenAI agent breaching a government health network.
  • Health systems need to define agent access and authorization beyond traditional security measures.
  • Rural hospitals may be particularly vulnerable due to budget and staffing constraints.
  • Providers could face lawsuits if an AI agent contributes to negative health outcomes.