
What You Should Know
- Healthcare access management and identity security leader Imprivata released national research conducted by independent research firm Vanson Bourne, surveying 250 U.S. healthcare leaders responsible for identity security and AI strategy across health systems, IDNs, and academic medical centers.
- The Shadow AI Crisis: 72% of healthcare organizations report that AI tools or agents are deployed without formal IT approval at least occasionally, while 37% cite an ad hoc or unapproved approach to AI agent provisioning.
- Active Production Deployments: Agentic AI is no longer theoretical, with 28% of healthcare organizations reporting agentic AI already live in production, another 44% piloting or running proofs-of-concept, and 21% planning deployments within the next 12 months.
- Accelerating Clinical Infiltration: AI agents are currently involved in 33% of clinical workflows and 37% of operational workflows, projected to expand to 41% and 46%, respectively, over the next 12 to 18 months; 79% of leaders expect transformative clinical impact.
Why 88% of Health Systems Face Governance Gaps Over Autonomous Agent Credentials
While healthcare systems rapidly adopt autonomous software to address clinical staffing deficits and documentation backlogs, an enterprise governance gap is emerging: AI agents are actively executing tasks across clinical and operational environments without formal IT vetting or distinct digital identities.
According to a nationwide research report released by access management company Imprivata—conducted by Vanson Bourne across 250 U.S. healthcare IT and security leaders—72% of healthcare organizations report that AI tools or agents are deployed without formal IT approval at least occasionally, underscoring widespread “shadow AI” across provider networks.
The report, titled The Agentic AI Trust Gap: Why Healthcare Needs Identity-Led Governance, reveals a sharp divide between executive confidence and operational reality: while 86% of leaders feel confident they can fully control and govern AI agent actions, 88% expect agents to operate with some degree of autonomy, and only 17% believe existing identity and access management (IAM) frameworks are sufficient without adaptation.
Production Deployments and Clinical Workflow Penetration
The transition from passive, prompt-and-response AI assistants to multi-step autonomous agents is already underway:
- Live in Production: 28% of healthcare organizations already have agentic AI in production and active use, with another 44% piloting or conducting proofs-of-concept, and 21% planning deployments within the next 12 months.
- Clinical Workflow Reach: AI agents currently touch 33% of clinical workflows (projected to reach 41% over the next 12 to 18 months) and 37% of operational workflows (projected to hit 46%).
- Perceived Enterprise Impact: 79% of respondents anticipate agentic AI will have a transformative or significant impact on clinical operations, compared to 73% for operational workflows.
The Non-Human Identity Dilemma: Service Accounts vs. Delegated Authority
A central vulnerability highlighted in the findings is how health systems authenticate and track autonomous agents within clinical systems. When agents interact with electronic health records (EHRs), issue clinical orders, or extract protected health information (PHI), their operational footprint is managed through fragmented identity models:
- 46% use a mixture of service accounts and delegated identity.
- 35% operate under a clinician’s delegated credentials.
- 16% authenticate through generic or shared service accounts.
Relying on opaque service accounts or piggybacking on a physician’s credentials obscures clinical auditability. If an agent misinterprets clinical context, initiates unauthorized data exports, or alters care pathways, IT teams struggle to determine who or what authorized the action—blurring institutional accountability and regulatory liability under HIPAA.
Human Oversight and the “Shadow AI” Paradox
The research demonstrates that organizational ownership alone does not prevent unvetted AI proliferation. Among health systems with a dedicated Chief AI Officer, 73% still reported AI tools deployed without IT or security clearance, as did 54% of systems led by a CIO and 44% led by a CISO.
Health systems are responding by moving toward tiered, risk-adjusted oversight rather than blanket restrictions:
- 53% require mandatory human review for high-risk clinical actions.
- 40% require human sign-off for high-risk operational actions.
- 26% rely on spot audits or exception-based reviews, while 25% permit fully autonomous agent execution within bounded parameters.
Imprivata’s Five Foundational Pillars for Agentic Governance
To mitigate security, regulatory, and patient-safety risks while enabling autonomous scaling, the report outlines five core operational controls:
- Catalog Every Agent: Maintain a dynamic inventory documenting every active agent’s business owner, connected clinical systems, integration pathways, and clinical scope.
- Assign Governable Digital Identities: Treat every AI agent as an independent non-human identity, avoiding shared credentials and managing each agent from onboarding through decommissioning.
- Enforce Dynamic Least Privilege: Restrict data access and execution rights strictly to the agent’s specific workflow, applying time-bound and context-aware session permissions.
- Establish Explicit Step-Up Guardrails: Require deterministic human approval or step-up authentication whenever an agent encounters PHI exports, order entry, or high-risk clinical recommendations.
- Build Native Action-Level Auditability: Ensure every autonomous action, tool invocation, and API call produces an immutable audit log linking the decision to its underlying authority.

