Curie Brief
Turn on cookies to sign in
Signing in saves your progress to your Curie account. We can only do that with cookies on — turn them on to continue.

AI agents are spreading through hospitals faster than anyone can govern them. A new Imprivata survey found that 72% of health organizations deploy AI tools without formal IT approval — and experts warn the consequences could range from HIPAA violations to altered medication orders. The industry is scrambling to build guardrails before a major incident forces the issue.
Healthcare's AI adoption is moving fast — but its security frameworks aren't keeping up. A new survey by digital identity firm Imprivata of 250 U.S. health security and AI strategy leaders found that 72% of healthcare organizations deploy AI tools or agents without formal IT approval at least some of the time. Meanwhile, 28% already have agentic AI in production, and 88% expect these systems to operate with at least some autonomy in clinical and administrative work.
The stakes are real. Unlike traditional software, AI agents can independently make plans, launch workflows, access electronic health records, and even modify doctors' orders — all without a human in the loop. Real-world incidents are already piling up: an Otter meeting bot transcribed confidential patient discussions at an Ontario hospital and emailed the summary to 65 people, and an OpenAI agent reportedly breached non-public Australian government health data this past summer.
By the Numbers:
Why it matters: Unchecked AI agents aren't just a tech problem — they're a patient safety and legal liability issue. From HIPAA violations to altered medication records, the risks are concrete. Experts are urging health systems to establish time-limited agent permissions and clearly defined access boundaries before a major breach forces a reckoning.