The Digital "Contract Nurse": Why Imprivata is Treating AI Agents as High-Risk Outsiders

In the rapidly evolving landscape of healthcare cybersecurity, the most significant threat to a hospital’s digital perimeter may not be a malicious hacker lurking in the shadows, but rather the very tools intended to drive efficiency: autonomous AI agents. As health systems scramble to integrate generative AI and autonomous workflows into clinical and administrative operations, a critical question of governance has emerged. How do you grant a piece of software the power to execute tasks without handing it the keys to the entire kingdom?

Fran Rosch, CEO of digital identity and cybersecurity firm Imprivata, believes the answer lies in a paradigm shift. Rather than inventing an entirely new category of security software, Rosch argues that the industry should treat AI agents exactly as it treats the most unpredictable, transient, and high-risk human actors in a hospital: the contract nurse or the remote third-party vendor.

The Paradigm Shift: AI as an Untrusted Third Party

For decades, healthcare organizations have refined the "Principle of Least Privilege." This security framework ensures that a contract nurse—hired on short notice to cover a shift—is granted access to only the specific patient records and digital systems required for their brief tenure. Once the shift ends, that access is revoked.

Rosch, speaking at a media gathering in Manhattan, proposed that AI agents—which are increasingly being empowered to autonomously read charts, update EHRs, and interact with billing systems—should be subject to the same stringent lifecycle management.

"We can simply think of an agent the same way you would think of that contract nurse," Rosch explained. "You don’t know him or her. You’ve never met them before. They’ve been recommended to you. How do you go through quick identity proofing? How do you give them credentials? How do you give them access to just what they need to do their job? How do you monitor access? Because you don’t really know them or trust them to be able to audit and identify behavioral matters that indicate risk. How do you revoke access? Are you ready to be able to do that?"

This philosophy moves AI security away from the abstract realm of "model monitoring" and into the concrete, battle-tested world of Identity and Access Management (IAM).

Chronology: From Human Governance to Autonomous Oversight

The journey to this moment in healthcare cybersecurity has been a decade-long evolution of digital identity management.

  • 2015–2019: The Era of Human Identity. Focus was largely on Single Sign-On (SSO) and ensuring that physicians could access workstations quickly without compromising security. The goal was clinical efficiency.
  • 2020–2022: The Rise of Remote Access. The COVID-19 pandemic forced a massive expansion of remote vendor access. Cybersecurity teams had to learn how to manage external contractors who were logging in from disparate, unsecured networks. This necessitated the development of privileged access management (PAM) gateways.
  • 2023–2024: The Generative AI Explosion. The arrival of Large Language Models (LLMs) changed the game. Suddenly, software was no longer static; it was agentic. These agents could perform complex reasoning and execute actions on behalf of users, creating a massive, undefined attack surface.
  • 2025–2026: The Maturation of Agentic Governance. We are currently in the phase where the industry is realizing that existing security stacks are ill-equipped to handle non-human, non-static actors. Imprivata’s current strategy—leveraging existing privileged access gateways for AI—represents the industry’s first attempt to normalize this chaotic new environment.

Supporting Data: The Financial and Operational Constraints

The healthcare sector is currently facing an unprecedented fiscal squeeze. Capital expenditures are under intense scrutiny, and IT departments are suffering from "vendor fatigue." Every new software procurement requires a lengthy vetting process, security assessment, and integration roadmap.

Imprivata’s internal research and client feedback highlight a clear trend: hospitals are increasingly resistant to buying "AI-specific" security platforms. Instead, they are demanding that their current vendors extend existing capabilities to cover AI use cases.

During his recent visit to a major health system, Rosch noted that leadership explicitly requested to build upon their current infrastructure rather than adopting a standalone product for AI security. By extending a privileged access security gateway—which is already used to govern high-risk human administrators—to manage AI agents, Imprivata is effectively removing the barrier to entry. This approach acknowledges that while the technology is new, the security requirement—identity, authentication, and authorization—remains fundamentally the same.

Official Responses and Strategic Implementation

The strategy is currently being stress-tested in the real world. About a dozen major health systems have signed on as "design partners," working closely with Imprivata to refine how these agents are vetted and monitored.

These design partnerships are essential because the market for agentic AI security is still in its infancy. While the framework for managing human users is well-established, there is no industry standard for what constitutes a "behavioral anomaly" in an AI agent. For instance, if an AI agent suddenly requests access to a patient record it has no business viewing, is that a malfunction, a hallucination, or a malicious exploit?

"We see Imprivata’s job as getting ahead of a problem most hospitals haven’t had to solve yet," Rosch stated. While he admits that the market is in its early stages, he is confident that once health systems begin formalizing their budgets for AI governance, this "identity-centric" model will become the industry standard.

Implications for the Future of Healthcare IT

The implications of this strategy extend far beyond simple password management. If Imprivata and its peers succeed in treating AI agents as "untrusted entities," it will force a fundamental redesign of how healthcare software is built.

1. The Death of Universal Permissions

Historically, applications were often built with "service accounts" that had broad, static permissions. If a piece of software needed to pull data from a database, it often had "admin" rights to simplify development. Under the new model, every agent must have a granular, temporary, and revokable identity.

2. Behavioral Auditing as a Clinical Safety Tool

If a security gateway is monitoring the "behavior" of an AI agent, that data becomes invaluable for patient safety. If an AI agent’s behavior deviates from its baseline, it doesn’t just represent a security risk—it represents a potential clinical error. Cybersecurity and clinical quality assurance, therefore, may begin to converge.

3. The "Identity-First" Defense

By treating AI agents as outsiders, organizations are building a "zero-trust" environment for software. This creates a defensive layer that is resilient even if the AI model itself is compromised. If an attacker manages to "jailbreak" an AI agent, they are still trapped within the constraints of that agent’s limited, role-based access. They cannot move laterally through the system because the identity gateway refuses to authorize actions outside of the agent’s pre-defined scope.

Conclusion: A Prudent Path Forward

As hospitals continue to embrace the promise of AI-driven clinical decision support and administrative automation, they must do so with their eyes open. The allure of increased efficiency must not override the basic tenets of cybersecurity.

Imprivata’s strategy of treating AI agents as temporary, untrusted, and highly-vetted "contractors" is not just a clever marketing pitch; it is a sober assessment of the risks inherent in autonomous computing. By leveraging existing privileged access frameworks, the company is offering a pragmatic solution to a complex, existential problem.

The industry may still be in the early stages of this transition, but the mandate is clear: in the future of healthcare, trust is not something to be assumed—it is something that must be verified, monitored, and revoked the moment the work is done. As Rosch aptly summarizes, whether the actor is a human nurse or an intelligent algorithm, the security principles that protect patient data and system integrity must remain absolute.

More From Author

The Winter Arc: A Strategic Blueprint for Offseason Transformation

Bridging the Gap: Bionews Launches "The Rare Journey" to Humanize the Rare Disease Experience