In the rapidly evolving landscape of healthcare cybersecurity, a new class of digital entities has emerged, promising to revolutionize clinical efficiency: the autonomous AI agent. These sophisticated software entities can navigate electronic health records (EHRs), interpret complex diagnostic data, and execute administrative workflows with minimal human oversight. However, for hospital CIOs and Chief Information Security Officers (CISOs), this innovation brings a familiar, yet escalated, anxiety. How does one maintain a "Zero Trust" environment when the "user" is not a person, but a lines of code capable of independent decision-making?
Fran Rosch, CEO of the digital identity and cybersecurity firm Imprivata, believes the answer lies in a strategy healthcare providers have perfected over decades: the rigorous vetting and management of temporary human labor.
The Paradigm Shift: From Human Contractors to Agentic AI
For years, healthcare institutions have operated under a complex web of credentialing. Whether it is a contract nurse stepping onto a floor an hour before a shift or a remote vendor logging into a network from a different continent, the process remains the same: identify, verify, grant limited access, monitor, and revoke.
According to Rosch, treating an AI agent as a privileged user—rather than just another piece of software—is the missing link in modern healthcare security. "We can simply just think of an agent the same way you would think of that contract nurse," Rosch explained during a recent media briefing in Manhattan. "You don’t know him or her. You’ve never met them before. They’ve been recommended to you. How do you go through quick identity proofing? How do you give them credentials? How do you give them access to just what they need to do their job? How do you monitor access?"
This philosophy shifts the focus from "securing the code" to "governing the identity." In this model, an AI agent is subjected to the same audit trails, behavioral monitoring, and access-revocation protocols that a human contractor would face. If an agent’s behavior deviates from its predefined operational parameters, the system should be prepared to pull the plug instantly.
Chronology: The Evolution of Access Management in Healthcare
To understand why Imprivata’s approach is gaining traction, one must look at the historical trajectory of healthcare IT security:
- The Perimeter Era (2000s): Healthcare IT was defined by the "castle and moat" strategy. As long as a user was inside the hospital’s physical network, they were generally trusted.
- The Remote Access Expansion (2010s): The rise of telehealth and vendor-managed services forced hospitals to open their networks to the outside world. This led to the adoption of Multi-Factor Authentication (MFA) and Identity and Access Management (IAM) tools.
- The Zero Trust Transition (2020s): The COVID-19 pandemic necessitated rapid digital transformation, leading to the "Zero Trust" framework—never trust, always verify.
- The Agentic AI Frontier (2025–Present): Healthcare is now entering an era where software agents perform tasks previously reserved for human clinicians and administrators. This has created an identity crisis, as traditional security tools are designed to manage human credentials, not autonomous, machine-driven workflows.
Imprivata’s strategy is a direct evolution of the Zero Trust framework, adapted specifically for the non-human digital workforce.
Supporting Data: The Financial and Operational Hurdles
The challenge for hospitals today is not merely technological—it is financial. Following years of thin margins and the economic fallout of the pandemic, healthcare systems are notoriously averse to "rip-and-replace" strategies.
"They don’t want to buy another new product," says Rosch. "They are stretched thin."
Industry data supports this reluctance. Recent surveys from health IT research firms indicate that hospital leadership is prioritizing the optimization of existing cybersecurity investments over the procurement of new, niche solutions. By extending its existing "privileged access security gateway"—a tool already used to manage high-risk human users like system administrators—Imprivata is effectively lowering the barrier to entry for AI security.
Currently, Imprivata is working with approximately a dozen health systems acting as design partners. These institutions are stress-testing the framework, attempting to map out how an AI agent’s behavior can be "profiled" to identify potential risks before they cause a data breach or compromise patient safety.
Official Responses and Strategic Vision
During his Manhattan briefing, Rosch was candid about the current state of the market. "The model is well-established for human users, but not widely deployed yet for agents," he noted.
The strategy relies on a few key pillars:
- Identity Proofing: Every agent must have a verifiable "digital identity," much like a badge-carrying employee.
- Least Privilege Access: Agents are granted access only to the specific data points required for their function—a process known as "entitlement management."
- Behavioral Analytics: By monitoring how an agent accesses the EHR, security teams can flag anomalies, such as an agent attempting to export data outside of its programmed scope.
- Automated Revocation: The ability to instantly kill an agent’s credentials once a task is completed or if a risk threshold is breached.
While Imprivata is currently in the pilot phase with its design partners, the company believes this approach will become the industry standard. As health systems begin to formalize their budgets for AI integration in the coming fiscal years, security—not just capability—will be the primary gatekeeper for deployment.
Implications for the Future of Healthcare
The implications of this "Agent-as-a-Contractor" model are profound for both the tech industry and the clinical world:
1. The Death of the "Black Box"
If AI agents are forced to operate through a managed identity gateway, they lose their status as "black boxes." By logging every action an agent takes, healthcare providers can ensure that algorithmic decisions are transparent and auditable, which is essential for regulatory compliance and malpractice protection.
2. Standardization of AI Security
As Imprivata and other vendors push for this identity-centric approach, we are likely to see the emergence of standardized protocols for "Machine Identity Management." This will create a unified language for how different AI tools communicate with sensitive hospital databases.
3. Mitigating the Insider Threat
Ironically, treating AI as a human contractor also helps mitigate the risk of "insider threats." If an agent is compromised or programmed with malicious intent, the same monitoring tools that keep track of a disgruntled employee can alert the CISO to the AI’s anomalous behavior.
4. Financial Stability for IT Departments
By leveraging existing infrastructure, hospitals can integrate AI at a pace that matches their operational readiness. This prevents the "vendor fatigue" that has plagued hospital IT departments for years, allowing them to focus on clinical outcomes rather than managing an ever-growing stack of disparate software products.
Conclusion: Preparing for the Invisible Workforce
As we look toward the next five years, the integration of agentic AI into healthcare is no longer a question of "if," but "how." The technology promises to alleviate burnout, streamline administrative burdens, and potentially improve diagnostic accuracy. However, without the guardrails of robust identity management, these agents represent an uncontrolled vulnerability.
Imprivata’s strategy—treating the machine with the same scrutiny as the man—is a pragmatic, albeit cautious, approach to a high-stakes environment. By bridging the gap between legacy security protocols and future-forward AI, healthcare providers may find a way to embrace innovation without sacrificing the integrity of their most precious asset: patient data.
For now, the industry is in a waiting game. As the dozen pilot health systems continue to refine their protocols, the rest of the healthcare world watches closely. The lesson is clear: in the digital age, trust is not something that is given to software; it is something that must be earned, monitored, and—when the job is done—immediately revoked.
