A survey of 250 US healthcare leaders found 17% believe their existing identity controls would work for AI agents without change.

 

What happened

Close to three-quarters of healthcare organizations deploy AI tools or agents without formal IT approval at least some of the time, Fierce Healthcare reported on September 15, 2026. The survey reached 250 US healthcare leaders responsible for identity security or AI strategy across health systems, hospitals, and integrated delivery networks, and Vanson Bourne conducted it on behalf of an identity management vendor. More than a quarter of those organizations already run agentic AI in production, meaning software that acts on its own rather than waiting for each instruction, and another 44% are piloting it. Expectations run well ahead of controls, with 79% anticipating a transformative or major effect on clinical workflows and 88% expecting agents to operate with at least some autonomy, against 17% who believe their current identity approaches would work without adaptation.

 

Going deeper

Agents interact with electronic health records, identity systems, clinical applications, and medical devices, which puts them in the position of a privileged user rather than a piece of software someone opens. Nearly six in ten respondents ranked security among their top three concerns when planning adoption. The report recommends organizations answer six questions before going further: which agents exist across the enterprise, what systems and data each can reach, who owns or sponsors each one, what authority has been delegated, what actions they can perform or have performed, and whether those actions can be reconstructed during an audit. Most organizations cannot currently answer the first.

 

In the know

The Joint Commission and the Coalition for Health AI published guidance on responsible AI use in September 2025, covering governance structures, patient privacy and transparency, data security, safety event reporting, and risk and bias assessment, in the first installment of a joint program. It recommends a governance committee drawing from compliance, IT, clinical programs, operations, and data privacy, with regular reporting on AI usage to the board. CHAI followed in May 2026 with governance playbooks built around eight elements, developed through workshops involving more than 150 clinicians and health AI leaders, according to Healthcare Dive. Those cover setting up an oversight structure, managing third-party developers, assessing risk, and monitoring model performance after deployment. The Joint Commission has since introduced a voluntary certification recognizing organizations that have those processes running.

 

The big picture

NIST's AI Risk Management Framework organizes the work into four functions, with Map establishing the context around a specific AI system before risks can be assessed and Govern setting the policies, accountability, and third-party oversight the rest depends on, in the framework's core structure. Neither function can run against a system nobody has registered, which is where the survey's inventory finding bites. An AI agent with delegated authority over an electronic health record also reads and acts on protected health information, placing it inside the Security Rule's requirements for access control, audit controls, and information system activity review whether or not anyone classified it as a user. Compliance teams should start from the inventory question, since an agent nobody recorded cannot be covered by a risk analysis, monitored for unusual activity, or reconstructed for a regulator afterward. Business associate agreements deserve separate attention where the agent comes from a third party, particularly on what the vendor may do with data the agent processes.

 

FAQs

What separates agentic AI from the AI tools already in hospitals?

Earlier tools produce an output a person then acts on, such as a draft note or a risk score. An agent carries out a sequence of actions itself, which can include reading records, updating systems, and triggering other software, so it needs permissions of its own rather than borrowing a clinician's.

 

How should an AI agent be represented in an access control system?

As a distinct identity with its own credentials, scoped permissions, and audit trail, rather than running under a shared service account or a staff member's login. Without that separation, activity cannot be attributed, and permissions cannot be narrowed to what the agent actually needs.

 

Does the Security Rule apply to AI agents?

The rule applies to electronic protected health information regardless of what reaches it. An agent that creates, receives, maintains, or transmits that information falls within the same requirements for access control, audit logging, and activity review as any other system component.

 

What is step-up authentication and where does it fit?

Requiring additional verification before a particularly sensitive action proceeds, such as a clinician approving an agent's proposed change to a medication record. It allows routine actions to run without friction while keeping a person in the loop for decisions carrying clinical or financial weight.