The healthcare industry is currently undergoing a rapid technological pivot as organizations move beyond static artificial intelligence models toward "agentic AI"—systems capable of autonomous decision-making and executing complex, multi-step workflows with minimal human oversight. While this transition promises to revolutionize clinical efficiency and administrative accuracy, a new report from identity security firm Imprivata reveals a significant disconnect between the speed of adoption and the robustness of existing governance frameworks. As healthcare leaders integrate these autonomous agents into critical systems, they face an escalating landscape of security vulnerabilities, including the rise of "shadow AI" and the potential for rapid-scale clinical errors.
The Shift Toward Autonomous Healthcare Systems
Agentic AI represents a fundamental evolution in artificial intelligence. Unlike traditional generative AI, which primarily focuses on producing text, images, or data summaries based on user prompts, agentic systems are designed to act as independent entities. These agents can navigate various software environments, access internal databases, and execute actions—such as submitting an insurance claim or updating a patient’s electronic health record (EHR)—on behalf of a human user.
According to data compiled by market research firm Vanson Bourne on behalf of Imprivata, the adoption of these systems is no longer a futuristic prospect but a current operational reality. The survey of healthcare IT and clinical leaders found that 26% of organizations have already implemented agentic AI in some capacity. The momentum is expected to accelerate, with 44% of respondents currently conducting pilot programs or proof-of-concept trials, and an additional 21% planning to deploy agentic tools within the next 12 months. This high rate of adoption is driven by a near-unanimous belief among executives—roughly 90%—that agentic AI will have a "transformative" impact on both clinical and operational workflows.
Strategic Applications: From Back Office to Bedside
The primary driver for agentic AI investment has been the administrative burden that currently plagues the U.S. healthcare system. Organizations are prioritizing "back office" use cases where autonomous agents can handle repetitive, high-volume tasks that are prone to human error and delay.
- Prior Authorization: This has historically been a point of friction between providers and payers. Agentic AI can autonomously gather clinical documentation, check it against payer rules, and submit requests, significantly reducing the time patients wait for approved care.
- Revenue Cycle Management (RCM): Agents are being deployed to manage the entire billing lifecycle, from coding medical procedures to following up on denied claims. By navigating complex financial systems independently, these agents can optimize cash flow and reduce administrative overhead.
- Clinical Decision Support: While still in the earlier stages of deployment compared to administrative tools, agentic AI is moving toward the clinical sphere. The Advanced Research Projects Agency for Health (ARPA-H) recently announced a $62 million investment to develop an agentic AI agent specifically for heart care, highlighting the federal interest in pushing these tools into direct patient care roles.
The Governance Gap and the Risk of "Shadow AI"
Despite the enthusiasm for these tools, the Imprivata report highlights a troubling lack of centralized oversight. Many healthcare organizations are managing AI deployments through fragmented departmental efforts rather than a unified enterprise strategy. In some instances, IT departments oversee certain tools, while security teams manage others, leading to "siloed" governance that can overlook cross-system vulnerabilities.
A particularly pressing concern is the prevalence of "shadow AI"—the unauthorized use of AI tools by employees without the knowledge or approval of the organization’s IT or security leadership. A separate study by Wolters Kluwer found that 40% of medical workers and administrators are aware of colleagues using unsanctioned AI tools. Perhaps more alarming, nearly 20% of respondents admitted to using such tools themselves to assist with their professional duties.
In an agentic context, shadow AI is significantly more dangerous than in a generative context. If an employee uses an unauthorized autonomous agent that has been granted access to sensitive systems, that agent could potentially move data across the network or make changes to patient records without any logged oversight or "kill switch" mechanism.
Security Implications of Autonomous Agency
The transition from human-led software to autonomous agents introduces a new class of security risks. Traditional software operates on a "request-response" model where the human is the primary actor. Agentic AI, however, functions as a "proxy actor."
Dr. Sean Kelly, chief medical and growth officer at Imprivata, emphasized that the autonomous nature of these systems means that errors can propagate at "machine speed." In a traditional clinical environment, a human error in a medical record is typically localized. If an autonomous agent with excessive permissions makes a mistake—such as misinterpreting a lab result and subsequently altering a medication dosage across multiple patient files—the damage could be widespread before a human supervisor even realizes an action has been taken.
Key security risks identified by experts include:
- Privilege Escalation: Agents may be granted broad "administrative" permissions to ensure they can navigate between different software systems. If the agent’s identity is compromised, it provides an attacker with an autonomous tool to traverse the entire healthcare network.
- Lack of Audit Trails: Many current AI implementations lack a clear "identity" for the agent. When an action is taken in an EHR, the system may log it under the name of the doctor who authorized the agent, rather than the agent itself, making it difficult to perform forensic audits if something goes wrong.
- Operational Boundary Violations: Agents may operate outside their intended scope if their "guardrails" are not strictly defined. For example, an agent designed for scheduling might inadvertently access sensitive diagnostic data if the two systems are linked.
Chronology of AI Evolution in Healthcare
To understand the current urgency regarding agentic AI, it is helpful to view the timeline of AI integration in the sector:
- 2010–2018: The Era of Predictive Analytics. AI was primarily used for "big data" analysis, such as predicting patient readmission rates or identifying high-risk populations using static algorithms.
- 2019–2022: Early Generative AI and Chatbots. Healthcare began experimenting with Natural Language Processing (NLP) for medical transcription and basic patient-facing chatbots for symptom checking.
- 2023: The LLM Explosion. The release of advanced Large Language Models (LLMs) led to a surge in "GenAI" applications, focusing on drafting clinical notes and summarizing research.
- 2024–Present: The Rise of the Agent. The industry shifts toward "Agentic AI," where the focus moves from generating content to executing actions. This period is marked by heavy investment from firms like Deloitte and federal agencies to build autonomous systems for specialized care.
Industry Responses and Patient Safety Concerns
The potential for agentic AI to impact patient safety has not gone unnoticed by safety watchdogs. ECRI, a prominent nonprofit focused on healthcare quality and safety, recently named the "insufficient governance of AI" as one of its top 10 patient safety concerns for 2025. The organization warned that without standardized validation processes, AI tools—especially those that act autonomously—could introduce "hidden" risks into the clinical environment.
In response to these concerns, industry consortia are working to establish "playbooks" for responsible implementation. The Coalition for Health AI (CHAI), which includes thousands of healthcare systems and technology providers, has issued guidance focused on transparency, bias mitigation, and the necessity of "human-in-the-loop" (HITL) requirements.
Dr. Kelly noted that the level of human oversight must be proportional to the clinical risk. "Oversight must match the level of clinical risk," Kelly stated. "Agents need clearly defined identities, permissions, and boundaries, with human review for higher-risk activities and an audit trail for accountability."
Analysis of Future Implications
The move toward agentic AI represents a permanent shift in the healthcare operating model. As the workforce continues to face burnout and staffing shortages, the pressure to automate complex tasks will only increase. However, the "agentification" of healthcare requires a fundamental rethink of cybersecurity.
Healthcare organizations will likely need to move toward a "Zero Trust" architecture specifically tailored for AI agents. This involves treating every autonomous agent as a distinct identity that must be constantly verified and restricted to the "least privilege" necessary to perform its specific task.
Furthermore, the legal and liability landscape is set to become more complex. If an autonomous agent makes a clinical error, the industry must determine where the liability lies: with the developer of the AI, the hospital that deployed it, or the clinician who "supervised" it. Until these legal and governance questions are answered, the "transformative" impact of agentic AI will remain shadowed by the risk of catastrophic systemic failure.
In the coming years, the success of agentic AI in healthcare will not be measured by the sophistication of the algorithms, but by the strength of the guardrails built to contain them. As organizations move from pilots to full-scale deployment, the focus must shift from "what the agent can do" to "how the agent is controlled."

