In a strategic shift reflecting the rapid evolution of autonomous technology in clinical environments, Fran Rosch, the Chief Executive Officer of cybersecurity firm Imprivata, has proposed a rigorous new framework for managing artificial intelligence. Speaking at a media event in Manhattan on Thursday, Rosch argued that healthcare providers must stop viewing AI agents as internal tools and instead categorize them as untrusted third-party entities. This paradigm shift would require AI agents to undergo the same vetting, monitoring, and access-revocation protocols currently applied to temporary contract staff and external vendors.
The proposal comes at a critical juncture for the healthcare industry, which is grappling with an unprecedented surge in both AI adoption and sophisticated cyberattacks. By treating AI agents—entities capable of making decisions and executing tasks autonomously—as the digital equivalent of a "contract nurse," Rosch suggests that hospitals can leverage existing security infrastructure to mitigate the unique risks posed by autonomous software. This approach emphasizes the principles of Zero Trust, a security model that assumes no entity, whether inside or outside the network perimeter, should be granted access without continuous verification.
The "Contract Nurse" Analogy for Autonomous AI
The centerpiece of Rosch’s argument is a comparison between AI agents and the human "strangers" that hospitals have long managed. In high-pressure clinical settings, it is common for a facility to bring in a contract nurse on short notice or grant a remote technician from another country access to sensitive systems for maintenance. In these scenarios, the individual is a known risk: they are necessary for operations but lack a long-term, established trust profile with the institution.
Rosch suggested that the industry should apply this established logic to AI. "We can simply just think of an agent the same way you would think of that contract nurse," Rosch explained during the Manhattan briefing. "You don’t know him or her. You’ve never met them before. They’ve been recommended to you. How do you go through quick identity proofing? How do you give them credentials? How do you give them access to just what they need to do their job? How do you monitor access? Because you don’t really know them or trust them to be able to audit and identify behavioral matters that indicate risk. How do you revoke access? Are you ready to be able to do that?"
This "least privilege" approach ensures that an AI agent—designed, for example, to optimize patient scheduling or summarize clinical notes—cannot overstep its bounds to access billing records or pharmacy databases. By treating the agent as a temporary, high-risk user, the hospital maintains the ability to "kill" the connection the moment a task is completed or an anomaly is detected.
The Economic Reality of Healthcare Cybersecurity
A significant portion of Rosch’s strategy is rooted in the financial realities facing modern health systems. Following the COVID-19 pandemic, many hospitals are operating on razor-thin margins, with labor costs and inflation putting immense pressure on capital budgets. According to data from the American Hospital Association (AHA), more than half of U.S. hospitals ended 2023 with negative margins. Consequently, there is little appetite for "rip and replace" technology cycles or the introduction of complex, standalone security products dedicated solely to AI.
Imprivata’s solution involves extending its existing privileged access security gateway—a tool already utilized by administrators and high-risk human users—to govern AI agents. This eliminates the need for hospitals to engage in new vendor relationships or undergo lengthy implementation projects for specialized AI security suites.
Rosch noted that during a visit to a health system earlier the same day, leadership expressed a clear preference for extending current tools rather than purchasing new ones. This "platform extension" strategy addresses "vendor fatigue," a common sentiment among Chief Information Officers (CIOs) who are currently managing dozens, if not hundreds, of disparate software subscriptions.
Supporting Data: The Rising Cost of Healthcare Breaches
The urgency of this security evolution is underscored by the escalating costs of data breaches in the medical sector. According to the 2024 IBM Cost of a Data Breach Report, the healthcare industry continues to experience the highest average breach costs of any sector, reaching nearly $11 million per incident. This represents a significant increase over the past three years.
Furthermore, the nature of threats is changing. As hospitals integrate "agentic AI"—software that doesn’t just process data but acts upon it—the potential "blast radius" of a compromised credential expands. If an AI agent has "god-mode" access to an Electronic Health Record (EHR) system to perform data analysis, a hacker who hijacks that agent’s identity could potentially alter patient records, delete backups, or exfiltrate massive datasets at machine speed.
The move toward treating AI as a third party aligns with broader federal guidance. The Department of Health and Human Services (HHS) recently released its Healthcare and Public Health (HPH) Sector Cybersecurity Goals, which emphasize the importance of identity and access management (IAM) and the implementation of Zero Trust architectures to protect patient safety.
Chronology of AI Security Evolution in Healthcare
The journey toward Rosch’s proposed model has been marked by several distinct phases in the digital transformation of medicine:
- The EHR Transition (2009–2015): Following the HITECH Act, hospitals moved from paper to digital records. Security focused on basic password protection and physical terminal security.
- The Rise of Interconnectivity (2016–2020): The proliferation of IoT (Internet of Things) devices and remote telehealth necessitated more robust identity management for humans and devices.
- The Generative AI Explosion (2023–Present): Large Language Models (LLMs) entered the clinical workflow, primarily for documentation and research. Initial security concerns focused on data privacy and "leakage" into training sets.
- The Emergence of Agentic AI (Current): AI evolved from passive assistants to active "agents" that can execute API calls and interact with multiple software layers. This has created the "identity gap" that Imprivata is now seeking to bridge.
Currently, approximately a dozen health systems are acting as design partners with Imprivata. These organizations are testing the application of human-centric privileged access management (PAM) protocols to autonomous AI entities. These pilot programs are intended to refine the behavioral monitoring aspects of the tool, ensuring that the system can distinguish between an AI performing a complex legitimate task and an AI that has been compromised by a malicious actor.
Technical Implications of Agentic Identity Management
To implement Rosch’s vision, the technical architecture of healthcare IT must evolve to recognize AI agents as distinct "non-human identities." In traditional systems, software accounts (service accounts) often have static, long-lived credentials that are rarely rotated. This is a significant vulnerability.
Under the new model, an AI agent would be assigned a dynamic identity. When the agent needs to perform a task—such as cross-referencing a patient’s lab results with recent clinical trials—it would request access through the privileged access gateway. The gateway would verify the agent’s "identity" (the specific instance of the software), validate the scope of the request, and grant a time-limited token.
Moreover, the system would employ "behavioral analytics." Just as a security system might flag a contract nurse who suddenly tries to access the records of a thousand patients in five minutes, the gateway would flag an AI agent that deviates from its programmed mission. If the agent’s behavior indicates risk, the system can automatically revoke its credentials, effectively "quarantining" the AI until a human administrator can review the logs.
Broader Industry Impact and Future Outlook
While Rosch admits the market is in its infancy, he anticipates that the "AI-as-a-contractor" model will become the industry standard. The logic is defensive: by the time health systems have dedicated budgets for AI security, the risks may have already manifested in the form of catastrophic breaches.
"Imprivata’s job is getting ahead of a problem most hospitals haven’t had to solve yet," Rosch said. This proactive stance is echoed by other cybersecurity leaders who argue that the speed of AI deployment is outstripping the speed of security governance.
The implications of this shift extend beyond just security; they also touch upon clinical trust. For physicians to rely on AI-generated insights or autonomous administrative assistants, they must be certain that the data hasn’t been tampered with and that the AI is operating within its intended guardrails. By applying the same rigorous vetting to AI that is applied to a human colleague, hospitals can build a foundation of "verified trust."
As the pilot programs with the initial dozen health systems conclude, the industry will likely see a broader rollout of these "identity-centric" AI safeguards. For now, the message from Manhattan is clear: in the digital age of medicine, even the most advanced algorithms must be treated with the same healthy skepticism as a stranger in the hallway. Only through strict identity proofing, limited access, and constant vigilance can healthcare providers reap the benefits of AI without sacrificing the security of the patients they serve.
