Healthcare has always been a favorite target for hackers, and in Urvish’s engineering experience and validating systems for a health insurance organization, Urvish watched AI adoption reshape that risk. AI is genuinely useful in healthcare. It speeds up documentation, flags risk, and lightens the load on clinicians who are already stretched thin. But the same tools that make workflows faster are also opening new, often invisible pathways into the most sensitive data an organization holds: Social Security numbers, health history, home addresses, insurance IDs. If that data isn’t protected with the same rigor as the AI tools that touch it, the efficiency gains aren’t worth the risk. And in an industry now racing to deploy AI across nearly every clinical and administrative workflow, that gap between adoption speed and security investment is where the real damage will happen.
Useful and dangerous at the same time
That’s the tension we keep coming back to. An AI tool that summarizes a patient encounter or automates a claims review is solving a real problem but it’s also a new door into a database that, once exposed, can’t be reissued the way a stolen credit card number can. A Social Security number doesn’t expire. A medical history doesn’t change. When healthcare organizations move fast to adopt AI without matching that speed with security investment, they’re opening more doors into that data without adding more locks. In 2024, healthcare recorded 739 data breaches affecting more than 276 million patient records the worst year the industry has ever logged. The average healthcare breach now costs $7.42 million to contain, more than any other industry, for the 14th consecutive year. The Change Healthcare ransomware attack alone exposed the data of roughly 192.7 million people nearly two-thirds of the US population according to federal disclosures.
Where AI adoption quietly increases exposure
In Urvish’s experience, the risk isn’t the AI tool an organization vets carefully and deploys with proper review. It’s the tools that get adopted faster than governance can keep up, what the industry now calls “shadow AI.” A survey Wolters Kluwer Health commissioned in December 2025 found that 40% of healthcare professionals and administrators had encountered an unauthorized AI tool in their organization, and close to one in five admitted to using one themselves; a companion analysis with the Coalition for Health AI put the combined share who had encountered or used shadow AI at 57%. A clinician under deadline pressure will reach for whatever tool gets the job done, often without knowing where the SSNs and health details they just typed in are actually going, who can see them, or how long they’re retained. Even AI tools built specifically for healthcare aren’t automatically safe. Audits of some clinical AI scribes tools designed to sit in on patient visits and draft notes have found data routed to third-party analytics platforms that weren’t fully accounted for when the tool was approved. That’s exactly the kind of gap a thorough security and compliance review should catch before a tool ever touches a patient’s confidential information, not after.
Data security
Attackers are moving faster too
While organizations work to keep pace with AI governance internally, the same technology is making attackers faster. Roughly 83% of phishing emails now contain AI-generated content, and healthcare has the highest phishing-susceptibility rate of any major industry. Newly disclosed vulnerabilities are increasingly exploited within days of becoming public, while the median time healthcare organizations take to remediate a critical vulnerability still runs closer to a month. An estimated 99% of hospitals are running at least one connected device with a known, exploitable vulnerability on its network. Layer in the supply chain: business-associate involvement in reported healthcare breaches has averaged roughly a third over the past several years and climbed above 40% in early 2026 and the exposure around a single patient’s data multiplies fast.
What solid security actually requires as per Urvish’s research
Protecting this data in an AI-driven environment isn’t about slowing AI adoption down. It’s about matching the pace of adoption with equal investment in the controls around it. Based on what I’ve seen work, that means:
- Treating every AI vendor that could touch Social Security numbers or health history with the same scrutiny as any core system including a signed Business Associate Agreement before that data goes near a model.
- Giving staff sanctioned, secure tools good enough to compete with the free consumer options they’d otherwise reach for, because policy alone won’t stop someone under deadline pressure.
- Building real visibility into where sensitive data flows once an AI tool is in use not discovering the gap during a compliance audit after the fact.
- Encrypting and limiting access to confidential fields like SSNs and addresses by default, so a compromised or misused AI tool doesn’t leave the most damaging data sitting exposed.
- Funding security proportionally to the risk. Healthcare organizations still spend a small single-digit share of IT budgets on security, roughly half the level common in financial services, even as breach costs and ransomware-linked disruptions keep climbing.
- To secure sensitive healthcare data effectively and maintain strict regulatory compliance, organizations must implement a multi-layered cybersecurity framework combining advanced technical safeguards, administrative controls, and physical protection.
- Vulnerability Management: Perform automated vulnerability scans and annual professional penetration testing to uncover and patch security loopholes before they are exploited.
- AI Defensive Training: Train staff to identify advanced generative AI threats, such as hyper-realistic deepfake audio requests, phishing links, and malicious QR codes.
- Dedicated digital suites streamline compliance tracking by automating tedious spreadsheets. Affordable resources like the Notion HIPAA Compliance Kit offer pre-built safeguard controls and breach playbooks for smaller startups. Mid-sized facilities frequently use platforms like the Cipher Medical Office Cybersecurity Assessment Plan to continuously grade their digital environment against real-world threat databases
Data Security in Healthcare
None of this is exotic. It’s the same discipline security teams already apply to core clinical and claims systems, extended to cover the AI layer sitting on top of them. The organizations getting this right aren’t necessarily spending more in total, they’re refusing to treat AI procurement as separate from security procurement, so a new tool never goes live faster than the controls around it can be put in place. What’s missing at most organizations isn’t the playbook; it’s the follow-through matching every new AI rollout with the vendor review, the access controls, and the monitoring that data this sensitive has always demanded.
Regulators are starting to respond HHS has floated voluntary frameworks addressing AI governance, patient privacy, and data security but voluntary guidance won’t force this change on its own. From what Urvish have observed testing and validating the systems healthcare depends on, the organizations that treat data security as a first-class part of every AI rollout, not an afterthought bolted on later, are the ones that will keep their patients’ trust intact. The ones that don’t will find out the hard way that in healthcare’s AI era, a single exposed database of secured data, Social Security numbers and health records does more lasting damage than any efficiency gain can make up for.
About Urvish Gajjar
Urvish Gajjar is a Senior Test Manager based in the United States, with a career focused on quality assurance and systems validation for a health insurance organization. His work centers on testing the reliability, security and compliance of the technology healthcare organizations depend on, including the AI tools now being deployed.