• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer

How eClinicalWorks Agentic AI Is Helping Revenue Cycle Leaders Improve Financial Performance
  • Opinion
  • Health IT
    • Behavioral Health
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Patient Engagement
    • Population Health Management
    • Revenue Cycle Management
    • Social Determinants of Health
  • Digital Health
    • AI
    • Blockchain
    • Precision Medicine
    • Telehealth
    • Wearables
  • Life Sciences
  • Investments
  • M&A
  • Value-based Care
    • Accountable Care (ACOs)
    • Medicare Advantage

Imprivata Report Reveals 72% of Healthcare Organizations Run Unapproved AI as Autonomous Agents Enter Clinical Care

by Fred Pennic 09/15/2026 Leave a Comment

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print
Imprivata Report Reveals 72% of Healthcare Organizations Run Unapproved AI as Autonomous Agents Enter Clinical Care

What You Should Know

  • Healthcare access management and identity security leader Imprivata released national research conducted by independent research firm Vanson Bourne, surveying 250 U.S. healthcare leaders responsible for identity security and AI strategy across health systems, IDNs, and academic medical centers.
  • The Shadow AI Crisis: 72% of healthcare organizations report that AI tools or agents are deployed without formal IT approval at least occasionally, while 37% cite an ad hoc or unapproved approach to AI agent provisioning.
  • Active Production Deployments: Agentic AI is no longer theoretical, with 28% of healthcare organizations reporting agentic AI already live in production, another 44% piloting or running proofs-of-concept, and 21% planning deployments within the next 12 months.
  • Accelerating Clinical Infiltration: AI agents are currently involved in 33% of clinical workflows and 37% of operational workflows, projected to expand to 41% and 46%, respectively, over the next 12 to 18 months; 79% of leaders expect transformative clinical impact.

Why 88% of Health Systems Face Governance Gaps Over Autonomous Agent Credentials

While healthcare systems rapidly adopt autonomous software to address clinical staffing deficits and documentation backlogs, an enterprise governance gap is emerging: AI agents are actively executing tasks across clinical and operational environments without formal IT vetting or distinct digital identities.

According to a nationwide research report released by access management company Imprivata—conducted by Vanson Bourne across 250 U.S. healthcare IT and security leaders—72% of healthcare organizations report that AI tools or agents are deployed without formal IT approval at least occasionally, underscoring widespread “shadow AI” across provider networks.

The report, titled The Agentic AI Trust Gap: Why Healthcare Needs Identity-Led Governance, reveals a sharp divide between executive confidence and operational reality: while 86% of leaders feel confident they can fully control and govern AI agent actions, 88% expect agents to operate with some degree of autonomy, and only 17% believe existing identity and access management (IAM) frameworks are sufficient without adaptation.


Production Deployments and Clinical Workflow Penetration

The transition from passive, prompt-and-response AI assistants to multi-step autonomous agents is already underway:

  • Live in Production: 28% of healthcare organizations already have agentic AI in production and active use, with another 44% piloting or conducting proofs-of-concept, and 21% planning deployments within the next 12 months.
  • Clinical Workflow Reach: AI agents currently touch 33% of clinical workflows (projected to reach 41% over the next 12 to 18 months) and 37% of operational workflows (projected to hit 46%).
  • Perceived Enterprise Impact: 79% of respondents anticipate agentic AI will have a transformative or significant impact on clinical operations, compared to 73% for operational workflows.

The Non-Human Identity Dilemma: Service Accounts vs. Delegated Authority

A central vulnerability highlighted in the findings is how health systems authenticate and track autonomous agents within clinical systems. When agents interact with electronic health records (EHRs), issue clinical orders, or extract protected health information (PHI), their operational footprint is managed through fragmented identity models:

  • 46% use a mixture of service accounts and delegated identity.
  • 35% operate under a clinician’s delegated credentials.
  • 16% authenticate through generic or shared service accounts.

Relying on opaque service accounts or piggybacking on a physician’s credentials obscures clinical auditability. If an agent misinterprets clinical context, initiates unauthorized data exports, or alters care pathways, IT teams struggle to determine who or what authorized the action—blurring institutional accountability and regulatory liability under HIPAA.


Human Oversight and the “Shadow AI” Paradox

The research demonstrates that organizational ownership alone does not prevent unvetted AI proliferation. Among health systems with a dedicated Chief AI Officer, 73% still reported AI tools deployed without IT or security clearance, as did 54% of systems led by a CIO and 44% led by a CISO.

Health systems are responding by moving toward tiered, risk-adjusted oversight rather than blanket restrictions:

  • 53% require mandatory human review for high-risk clinical actions.
  • 40% require human sign-off for high-risk operational actions.
  • 26% rely on spot audits or exception-based reviews, while 25% permit fully autonomous agent execution within bounded parameters.

Imprivata’s Five Foundational Pillars for Agentic Governance

To mitigate security, regulatory, and patient-safety risks while enabling autonomous scaling, the report outlines five core operational controls:

  1. Catalog Every Agent: Maintain a dynamic inventory documenting every active agent’s business owner, connected clinical systems, integration pathways, and clinical scope.
  2. Assign Governable Digital Identities: Treat every AI agent as an independent non-human identity, avoiding shared credentials and managing each agent from onboarding through decommissioning.
  3. Enforce Dynamic Least Privilege: Restrict data access and execution rights strictly to the agent’s specific workflow, applying time-bound and context-aware session permissions.
  4. Establish Explicit Step-Up Guardrails: Require deterministic human approval or step-up authentication whenever an agent encounters PHI exports, order entry, or high-risk clinical recommendations.
  5. Build Native Action-Level Auditability: Ensure every autonomous action, tool invocation, and API call produces an immutable audit log linking the decision to its underlying authority.

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print

Tagged With: Artificial Intelligence, Imprivata

Tap Native

Get in-depth healthcare technology analysis and commentary delivered straight to your email weekly

Reader Interactions

Primary Sidebar

Subscribe to HIT Consultant

Latest insightful articles delivered straight to your inbox weekly.

Submit a Tip or Pitch

Featured Insights

Aligning IT & Clinical Teams: How to Reduce Friction and Improve Communication

Most-Read

M&A: Francisco Partners to Acquire Weave in $650M Take-Private Deal

Epic Launches One-Click Care Everywhere Diagnostic Image Exchange

Epic Launches One-Click Care Everywhere Diagnostic Image Exchange

Redesign Health Study: 71% of Health Systems Adopt an "Epic-First" AI Purchasing Strategy

Redesign Health Study: 71% of Health Systems Adopt an “Epic-First” AI Purchasing Strategy

iRhythm to Acquire VitalConnect for $287.5M to Build Broad Cardiac Intelligence Platform

M&A: iRhythm to Acquire VitalConnect for $287.5M to Build Broad Cardiac Intelligence Platform

CB Insights Q2 2026 State of Digital Health Report: Fewest Deals in Over a Decade as Median Sizes Rise

CB Insights Q2 2026 State of Digital Health Report: Fewest Deals in Over a Decade as Median Sizes Rise

mount-sinai-launches-epic-chart-with-art-nursing-ambient-ai

Mount Sinai Medical Center Extends Epic’s Ambient AI to Inpatient Nursing

M&A: Tempus AI to Acquire Personalis for $1.5B to Expand Precision Oncology and MRD Monitoring

M&A: Tempus AI to Acquire Personalis for $1.5B to Expand Precision Oncology and MRD Monitoring

Why Brain Health Is Entering Its Infrastructure Era

Brain Health’s Infrastructure Era: Proving Clinical Outcomes with Integrated Neuromotor Tracking

Why Catholic Health Inked a $500M Care Alliance with GE HealthCare to Automate Outpatient Triage

Catholic Health Inks $500M Care Alliance with GE HealthCare to Automate Outpatient Triage

KLAS Global HIT Trends 2026 Report: Artificial Intelligence Becomes the Top Investment Priority

KLAS Global HIT Trends 2026 Report: Artificial Intelligence Becomes the Top Investment Priority

Secondary Sidebar

Footer

Company

  • About Us
  • 2026 Editorial Calendar
  • Advertise with Us
  • Reprints and Permissions
  • Op-Ed Submission Guidelines
  • Contact
  • Subscribe

Editorial Coverage

  • Opinion
  • Health IT
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Population Health Management
    • Revenue Cycle Management
  • Digital Health
    • Artificial Intelligence
    • Blockchain Tech
    • Precision Medicine
    • Telehealth
    • Wearables
  • Startups
  • Value-Based Care
    • Accountable Care
    • Medicare Advantage

Connect

Subscribe to HIT Consultant Media

Latest insightful articles delivered straight to your inbox weekly

Copyright © 2026. HIT Consultant Media. All Rights Reserved. Privacy Policy |