Healthcare organizations are giving AI agents more room to act, but their identity systems may not be keeping pace, according to new research.

Imprivata, a healthcare identity and access management vendor, has found that almost three-quarters (72%) of its respondents reported that they have deployed AI tools or agents without formal IT approval at least occasionally.

The “The Agentic AI Trust Gap: Why Healthcare Needs Identity-Led Governance” report is based on research conducted by Vanson Bourne for Imprivata.

The survey covered 250 U.S. healthcare leaders responsible for identity security, AI strategy or both across health and hospital systems, integrated delivery networks, single hospitals, academic medical centers and specialty hospitals.

Nearly one third (28%) of respondents said their organizations had agentic AI in production and another 44% were piloting it. Meanwhile, 88% expected AI agents to operate with some autonomy across clinical and operational workflows.

86% of respondents said they were fairly confident they could fully control and govern AI-agent actions, yet 72% reported AI tools or agents running without formal IT approval at least occasionally. Respondents also reported multiple provisioning approaches, including centralized IT, security teams, approved self-service tools and individual departments.

Agents create a different identity problem

Imprivata argues that traditional identity models were not designed for autonomous software that can make decisions, initiate workflows and act on behalf of clinicians or employees. Once an agent uses delegated clinical identities, service accounts or other credentials, security teams need to know what it can access, what actions it is allowed to take and whether those permissions still match its task.

Sean Kelly, Imprivata’s chief medical and growth officer, described the gap in those terms. Organizations need visibility into “what those systems can access, what they’re authorized to do,” he said, along with the ability to monitor and review their activity.

The survey also shows how organizations are authenticating agents in clinical workflows. 46% of respondents reported using a mix of service accounts and delegated identities, while 35% used delegated clinical identities and 16% relied on service accounts. Only 17% said their existing identity approaches were sufficient for healthcare AI agents without adaptation.

The survey is still vendor research

Imprivata sells identity and access management products to healthcare organizations and markets Agentic Identity Management for securing and governing AI-agent access. The survey therefore addresses a problem directly connected to the company’s commercial offering.

Separate KLAS research has found healthcare organizations building governance frameworks as they expand AI use. In Imprivata’s release, Jaren Day, KLAS Research’s group director of cybersecurity, said KLAS was hearing from healthcare CISOs that “agentic AI is creating a new identity problem.”

Personalized Feed
Personalized Feed