September 15, 2026

Agentic AI in healthcare means governing action, not just access

Agentic AI in healthcare

AI agents can reduce administrative burden across healthcare, but their ability to act autonomously introduces new risks. Effective governance requires healthcare organizations to understand not only what an agent can access, but what it’s authorized to do, where that authority applies, and when human oversight is needed.

Healthcare is moving quickly toward agentic AI, and there’s good reason for the excitement.

Unlike AI tools that primarily generate information or recommendations, agentic AI can take action. It can potentially schedule an appointment, initiate a prior authorization, help manage patient flow, support discharge planning, or perform any number of tasks that consume enormous amounts of clinician and staff member time.

In an industry where people are already stretched thin, that’s a compelling opportunity. Our new research reflects that momentum: 28% of surveyed healthcare organizations say they already have agentic AI in production, 44% are piloting it, and another 21% expect to implement it within the next 12 months.

As a physician, I’m excited about what that could mean. I also believe we need to be precise about the risks and realistic about the safeguards required to manage them.

One mistake would be to assume that, because an AI agent is performing an administrative or operational task, the consequences are somehow non-clinical. In healthcare, that line is rarely so clear.

There’s no such thing as a completely “non-clinical” workflow

Consider a task as routine as patient scheduling.

On the surface, scheduling is an administrative function. But what happens if an AI agent schedules a patient with the wrong specialist? What if it changes the timing of an appointment without recognizing its clinical urgency? Or if it fails to account for a test that needs to happen before the appointment?

Scheduling may be administrative, but the decisions involved can directly affect patient care.

The same is true for prior authorization, billing, claims adjudication, patient flow, and discharge planning. These processes may happen outside the exam room, but they can influence whether a patient gets treatment, how quickly care is delivered, whether a patient can safely leave the hospital, and what happens next.

That’s what makes agentic AI in healthcare particularly interesting — and challenging. We aren't simply giving technology access to information. We’re giving it the ability to act. And once an agent can act, we need to think carefully about the authority we’re giving it.

Healthcare workflows don't stop at the EHR

There’s another layer of complexity to agentic AI that I don't think gets enough attention: most healthcare workflows span multiple systems.

A prior authorization may begin in the EHR, move into another application or payer workflow, require access to clinical information, generate additional documentation, and ultimately come back into the care team's workflow. Discharge planning may involve the EHR, case management systems, pharmacy, post-acute providers, scheduling, transportation, and other services.

Humans navigate these boundaries constantly. Training, experience, and an understanding of the patient’s needs help us recognize what information matters, when something doesn’t look right, and when a routine process requires judgment.

An AI agent has to navigate the same boundaries without the same training, experience, or situational awareness.

That raises some very practical questions. If an agent originates in one system, what should it be allowed to access in another? How does the receiving system know who or what is making the request? What authority has been delegated to that agent? How long should that authority last? And what happens when two agents operating in different systems need to interact?

These aren't theoretical security questions. They’re healthcare workflow questions with security, privacy, compliance, legal, operational, and potentially clinical consequences.

That’s why identity is crucial to AI agent governance.

Every AI agent should have a unique, governable identity, just as any human interacting with sensitive healthcare systems would. An agent’s permissions should reflect the specific task it’s been authorized to perform, and its access should be limited accordingly. Its actions should be monitored and auditable, with clear safeguards around what it can and cannot do.

Those controls also need to account for context. An agent’s authority should not automatically expand simply because it has moved into another application. Nor should an agent retain access indefinitely after a task is complete.

Healthcare workflows are full of judgment calls and exceptions. A human performing a task may recognize when a seemingly minor choice could have unintended consequences or know when a situation falls outside the normal process.

We can’t assume that AI agents will recognize those boundaries on their own. Organizations have to deliberately establish them.

The confidence gap concerns me

Three statistics in our research jumped out at me.

Eighty-six percent of respondents expressed confidence that their organizations have or will soon have visibility into AI agent activity. The same percentage expressed confidence that they can already fully control and govern AI agent actions.

Yet 72% reported AI tools or agents are deployed without formal IT approval at least occasionally.

Those findings are difficult to reconcile. They suggest that some organizations may be more confident in their ability to safely use AI agents than their current environments warrant.

That isn't a criticism of healthcare IT teams. They are dealing with technology that is new, complex, and evolving quickly. New capabilities are being embedded into applications organizations already use. Individual departments are experimenting with tools independently. Vendors are introducing agents into existing workflows. There are so many ways that AI agents can slip through the cracks of security policies and processes that weren’t designed with them in mind.

The basic issue is simple: you cannot govern what you cannot see.

An organization may have strong policies on paper and still lack a complete picture of which agents are operating, which systems they can reach, what permissions they have, and what actions they’re taking.

As these systems become more autonomous, that visibility gap becomes much more consequential.

Governance should make AI safer, not harder to use

Healthcare organizations are being asked to do more with limited resources, and better tools can help. Agentic AI has the potential to take on time-consuming work across clinical, administrative, and operational workflows, allowing people to focus their time and expertise where they’re needed most.

But that value can disappear quickly if an agent takes inappropriate action, creates more work, disrupts an important process, or causes harm — even in a workflow that appears removed from patient care.

The answer isn’t to avoid innovation because it introduces risk. It’s to put safeguards in place that allow healthcare organizations to use these technologies responsibly without adding unnecessary friction to workflows that already demand speed.

The goal should be to help organizations move faster with confidence, and we can do so by defining identities for AI agents, implementing least-privilege access, establishing delegated authority, ensuring appropriate human oversight, enabling continuous monitoring, and maintaining reliable audit trails.

And these controls need to reflect the interconnected reality of healthcare workflows rather than treating each application as an island.

If an agent is going to cross systems, its identity and authority need to travel with it in a way the next system can understand and enforce. If an agent only needs access to a narrow set of information for a specific task, it shouldn't inherit broad access simply because that’s easier to implement. And if an action could have meaningful clinical consequences, organizations need to determine where human review belongs in the process.

These may sound like technical details. They aren't. They’re essential guardrails that will help determine whether AI agents can become trusted participants in healthcare delivery.

We have to govern the action, not just the access

For years, healthcare cybersecurity has focused heavily on a fundamental question: Who should have access to what?

Agentic AI adds another key question: What should this identity be allowed to do?

That distinction matters.

An AI agent that can read a patient's record presents one level of risk. An agent that can use that information to schedule care, submit an authorization, initiate an order, modify a workflow, or communicate with another system presents another.

The more autonomy we give these technologies, the more precise we need to be regarding identity, authority, oversight, and accountability.

I remain optimistic about agentic AI in healthcare. There is enormous potential here to reduce administrative burden and make healthcare work better for the people delivering and receiving care.

But healthcare has taught us repeatedly that seemingly small workflow decisions can have significant downstream consequences. We need to bring that same understanding to agentic AI.

The question isn't simply whether an agent can perform a task. We have to know who authorized the agent, which systems it can access, what it’s allowed to do, when a human needs to remain in the loop, and how we’re going to prevent unintended harm.

If we can answer those questions consistently, governance won't stand in the way of agentic AI in healthcare. It will give organizations a foundation for using AI agents safely, and give patients and clinicians more reason to trust them.

Read the full report, The Agentic AI trust gap: Why healthcare needs identity-led governance, here, and learn more about Imprivata Agentic Identity Management here.

You are currently browsing

Product availability varies by region. Would you like to choose a different region?

No thank you, I'd like to continue