Risk Management Tools & Resources

 

The Hidden Dangers of "Shadow AI" in Healthcare

The Hidden Dangers of

Laura M. Cascella, MA, CPHRM

The quick proliferation of artificial intelligence (AI) across many industries, including healthcare, signals the critical need for regulations, governance policies, ethical standards, and best practices. Yet AI is moving at a transcendent pace that disrupts the ability to forecast its risks and proactively establish guardrails.

In healthcare, the stakes for appropriate and successful AI implementation are high. The fallout from irresponsible, insufficient, or passive approaches to managing the technology could have catastrophic consequences, including patient harm, financial losses, reputational damage, and more. Unfortunately, weaknesses and gaps have already emerged that suggest AI risks could quickly escalate and be difficult to manage.

Research shows that only 18 percent of healthcare systems have comprehensive AI governance and strategy policies.1 The absence of these policies as well as other factors have given rise to "shadow AI." In healthcare, shadow AI refers to unauthorized programs and tools that healthcare workers are using without the knowledge or approval of their organizations. A recent Wolters Kluwer survey of healthcare providers and administrators found that 57 percent of participants had encountered or used an unauthorized AI tool in their organizations.2

Using AI applications to assist with tasks, particularly when done on personal devices, may seem innocuous and even resourceful. However, the risk is becoming increasingly apparent. Data privacy and security are emerging as a top concern. Shadow AI has many vulnerabilities that can expose proprietary and protected information and lead to data breaches. These tools "can introduce unsecured APIs, unmanaged integrations, or other vulnerabilities that attackers can exploit."3

A 2025 IBM report on data breaches across multiple industries, including healthcare, found that 1 in 5 organizations that experienced a breach said it involved shadow AI. The report also notes that security incidents involving shadow AI are more frequent, costly, and have broader consequences than incidents involving sanctioned AI.4

Beyond data privacy and security issues, other concerns related to shadow AI include accuracy and efficacy of tools, vendor vetting and assessment, scope of knowledge and training (e.g., whether an individual is using the application correctly), informed consent, and documentation/audit trails.5

Due to the preponderance of concerns related to these unsanctioned applications, healthcare leaders should prioritize creating safe frameworks for assessing, implementing, and monitoring AI within their organizations. The following strategies may prove useful in these efforts:

  • Develop comprehensive policies related to AI selection, validation, use, and governance as well as guidance and expectations for compliance with these policies. Include representatives from key departments in policy development and AI implementation (e.g., information technology, cybersecurity, operations, legal, and risk management staff). Engage clinicians and staff members in AI policy development as well. Lack of inclusion or awareness about corporate AI policies may lead individuals to use AI tools that have not been properly vetted.
  • Cultivate open lines of communication with providers and staff members to create a culture of ethical and responsible AI use. Ask workers what AI programs they are using or want to use and how those applications might be helpful. Doing so "could be useful in highlighting the gaps in your technology stack and governance policies. This allows you to either optimize your workflows or find a way of integrating the tool into them . . ."6
  • Educate the workforce about risks associated with unapproved AI applications, including concerns related to patient safety, privacy, cybersecurity, data breaches, corporate compliance, informed consent, transparency, and more. Individuals using shadow AI may appreciate its convenience but not realize the complexity of its risks.
  • Make sure all providers and staff members are aware of their obligations under HIPAA and state privacy laws, how AI intersects with these regulations, and how shadow AI may lead to regulatory violations. HIPAA training should occur during onboarding and at least annually — or sooner if systems, processes, or roles change.
  • Reinforce the importance of good cyber hygiene and offer strategies and reminders that reinforce strong security practices on organizational systems and devices. Examples include using multi-factor authentication, passkeys or passphrases, and implementing access controls.
  • Clearly communicate to providers and staff the organization's mission, goals, and progress related to AI adoption. Shadow AI may arise because providers perceive a lack of approved tools or lack of progress with adopting AI.
  • Consider using AI-enabled security tools to monitor AI usage, identify suspicious or unusual activity on organizational networks, pinpoint security gaps and at-risk data, and more quickly detect breaches.7

For more information about AI implementation and governance, see MedPro's resources titled The Essential Role of Governance in Ensuring the Safety and Quality of Artificial Intelligence in Healthcare and Implementing Artificial Intelligence in Healthcare Organizations.

To learn more about other AI topics, see MedPro's Risk Resources: Artificial Intelligence.

Endnotes


1 Healthcare Financial Management Association. (2025, August 24). Health system adoption of AI outpaces internal governance and strategy. Retrieved from www.hfma.org/press-releases/health-system-adoption-of-ai-outpaces-internal-governance-and-strategy/

2 Wolters Kluwer. (2026). Shadow AI: A hidden risk to healthcare. Retrieved from https://assets.contenthub.wolterskluwer.com/api/public/content/shadow-ai-a-hidden-risk-to-healthcare-pdf

3 Byron, J. (2025, August 5). Importance of addressing shadow AI for HIPAA compliance. American Institute of Healthcare Compliance. Retrieved from https://aihc-assn.org/importance-of-addressing-shadow-ai-for-hipaa-compliance/

4 IBM. (2025). Cost of a data breach report 2025: The AI oversight gap. Retrieved from www.ibm.com/reports/data-breach

5 Olsen, E. (2026, January 22). ‘Shadow AI' use is widespread in healthcare: Survey. Healthcare Dive. Retrieved from www.healthcaredive.com/news/shadow-unauthorized-ai-/810191/; Geller, E. (2026, January 13). Healthcare breaches double as shadow AI, vendor risks proliferate. Healthcare Dive. Retrieved from www.healthcaredive.com/news/healthcare-cyber-breaches-fortified/809593/; SoapNoteAI.com. (2026). Shadow AI in healthcare 2026: What clinicians need to know. Retrieved from www.soapnoteai.com/soap-note-guides-and-example/shadow-ai-healthcare-2026/

6 Byron, Importance of addressing shadow AI for HIPAA compliance.

7 Olsen, ‘Shadow AI' use is widespread in healthcare: Survey; Geller, Healthcare breaches double as shadow AI, vendor risks proliferate; Morse, S. (2026, January 26). Shadow AI tools and chatbots have widespread use in hospitals. Healthcare Finance. Retrieved from www.healthcarefinancenews.com/news/shadow-ai-tools-and-chatbots-have-widespread-use-hospitals; Byron, Importance of addressing shadow AI for HIPAA compliance; Wolters Kluwer, Shadow AI: A hidden risk to healthcare; SoapNoteAI.com, Shadow AI in healthcare 2026: What clinicians need to know.