Healthcare professional working at a desk with a laptop, clipboard, and digital security shield graphic representing medical data protection.

Report Finds Healthcare Identity Governance Lagging AI Adoption

Nearly one-third of healthcare respondents reported unauthorized identities accessed sensitive data during the previous year.

Seventy-nine percent of healthcare organizations said their non-human identities are not fully governed, according to new research from Netwrix.

The healthcare findings came from 145 respondents, most of whom were based in the United States, within a broader survey of 2,317 security professionals.

Of the respondents, 75% said AI and automation had increased identity-related risk to sensitive data over the previous two years, and 70% said their data-access governance trailed AI adoption.

Thirty-one percent of healthcare respondents said unauthorized identities had accessed sensitive data, compared with 24% in other industries. Among affected healthcare organizations, 33% estimated the cost at more than $250,000, compared with 21% elsewhere.

Seventy-seven percent could not immediately identify who had access to a specific piece of sensitive data, and 48% named compromised identities as the most common starting point for unauthorized access.

Confidence in Active Directory security was lower in healthcare than in any of the other 15 industries assessed. Only 14% of healthcare respondents were fully confident their environments contained no privilege-escalation risks, compared with 26% across all industries.

About the Author

Danielle Naidu is assistant editor for Security Today, Campus Security Today, Occupational Health & Safety and Environmental Protection Online.

Featured