Curie Brief
Turn on cookies to sign in
Signing in saves your progress to your Curie account. We can only do that with cookies on — turn them on to continue.

Most healthcare organizations are rolling out AI tools without proper IT oversight, creating serious security vulnerabilities. A new Imprivata survey found that nearly three-quarters of health systems deploy AI agents without formal approval at least some of the time — even as AI takes on more autonomous roles in clinical workflows. Experts warn that without clear governance frameworks, health systems are dangerously unprepared for AI-driven cyberattacks.
Healthcare organizations are racing to adopt AI — but leaving the security door wide open. A new survey by Imprivata found that nearly three-quarters of health systems deploy AI tools without formal IT approval at least sometimes, even as these tools gain access to EHRs, clinical apps, medical devices, and sensitive patient data. Over a quarter of organizations already have agentic AI in production, and 44% are actively piloting it, yet only 17% believe their current identity and security approaches are adequate.
The stakes are high. Imprivata's CEO pointed to the recent Hugging Face hack as a cautionary tale — a sophisticated, AI-assisted cyberattack that took days to detect. He warned that a similar attack on a health system would likely go unnoticed far longer, given how few hospitals are proactively deploying new security technology.
Experts recommend that health systems establish clear governance frameworks before expanding AI use — defining which agents exist, what data they can access, who owns them, and what actions they're authorized to take.
By the Numbers:
Why it matters: As AI agents take on increasingly autonomous roles in healthcare, the gap between adoption speed and security readiness is growing — putting patient data and clinical operations at serious risk.