The State of AI in Healthcare Cybersecurity, Right Now

The State of AI in Healthcare Cybersecurity, Right Now

You don’t have to look far to clearly witness the fact that AI evolution and use is outpacing governance frameworks and human systems in healthcare and beyond. This wheel is spinning faster and faster as organizations scramble to make good use of it, to mitigate the risks, to innovate, to keep up. We all can see it; we all can feel it.

It can be easy to just keep barreling along, blindered eyes on the prize of innovation and growth, without looking down at where we’re stepping because it feels like that will just slow us down.

But, just as an early part of Kuma’s work with a new client is often getting the true lay of the land through a risk assessment, getting clear on what’s actually happening—and exactly where the gaps between AI’s growth and current capacity lie—is a massively important piece of creating sustainable growth and success as AI usage continues to evolve.

Over the past few weeks, several independent research reports have quantified exactly where that gap is showing up in healthcare. Read together, they tell a consistent story with a surprisingly hopeful narrative: most of what’s driving these numbers turns out to be entirely fixable.

AI is already running through healthcare, sanctioned or not

We can’t fully prepare ourselves for unprecedented times before we’re in them, so we begin—now, perhaps somewhere in the middle of the beginning—by pausing to look at where we actually stand.

A Wolters Kluwer Health survey of 518 hospital and health system providers and administrators found that 58% of frontline staff had used a generic, free AI tool for work in the previous month, with 39% using one weekly or more. 57% had either encountered or personally used an unauthorized “shadow AI” tool within their organization.

That’s a majority of the workforce filling a gap that formal policy hasn’t caught up to yet, simply because the tools are useful and the guidance often isn’t there.

That activity runs on infrastructure built for a different era

A new report from network provider Nile, “The State of Networking, Security & AI in Healthcare” (August 2026, surveying 300+ healthcare IT leaders and security practitioners globally), found that the networks carrying all of this new AI activity have largely outgrown the architectures they were built on. Hospitals, clinics, imaging centers, and remote sites are now stitched together with tens of thousands of connected medical and IoT devices—many of which can’t be patched or run standard security agents, yet sit on the same network as electronic health records and, increasingly, AI tools.

The strain of this misalignment shows up directly in the numbers:

 
  •  85% of healthcare organizations experience periodic network or security disruptions that affect both patient care and patient privacy; 38% experience them at least weekly.
 
  • 66% of healthcare IT teams describe themselves as stressed or constantly “firefighting.” Only 18% say they’re comfortably managing operations—and notably, that strain persists even at fully staffed organizations, suggesting the core issue is rooted in architectural complexity, not headcount.
 
  • Only 20% of organizations are confident their network could contain a security incident, and only 38% have even partial Zero Trust architecture in place.
 

The cost of getting this wrong, and why it’s preventable

IBM’s Cost of a Data Breach Report 2025 found that the average AI security breach in healthcare cost $7.42 million in 2025, and that AI breaches are often the longest of any breach type to identify and contain.

That’s a huge number, but we see the most useful ones sitting right next to it:

97% of organizations that had an AI-related security incident had lacked proper AI access controls beforehand. And 63% of organizations had no AI governance policy in place at all.

This means that a specific, buildable, entirely knowable gap almost universally preceded these incidents.

Why the people closest to the risk are the most concerned

The same Wolters Kluwer survey found that concern scales sharply with organization size. Across all respondents,

 

  • 30% ranked data breaches as a top-two AI risk; among health systems with 25,000+ employees, that jumps to 57%.

 

  • Privacy concerns follow the same pattern, rising from 33% overall to 46% among administrators at the largest hospitals.

 

  • Administrators (CEOs, CMOs, CIOs) were consistently more concerned about privacy than clinical providers, and CFOs ranked it highest of all, at 37%. 

 

The executives with the clearest view of financial and reputational exposure are the ones sounding the loudest alarm, because they understand the gravity of the potential consequences.

What does all of this mean for you?

AI adoption in healthcare has moved fast, and in most cases it’s moved faster than the governance built to manage it. That’s true whether you’re looking at frontline staff reaching for a free chatbot, a network architecture designed before AI workloads existed, or the 63% of organizations still operating without a written AI policy.

What’s consistently missing is a consciously crafted foundation underneath to support strong, safe, and sustainable scaling: consistent access governance, real-time visibility into what AI systems are actually doing, and tested (not assumed) incident containment.

This is the hopeful piece that we alluded to earlier, and the gem of an opportunity hiding in all this data: Most AI incidents trace back to one specific, buildable control that nobody got around to yet.

Consider this a to-do list rather than a five-alarm fire, and remember that you don’t have to do it alone!

Figuring out exactly where your organization sits against this data and what to do next is precisely the kind of conversation we have with healthcare leaders every week. 

Sources:

  • Nile, “The State of Networking, Security & AI in Healthcare” (August 2026)
  • IBM, “Cost of a Data Breach Report 2025”
  • Wolters Kluwer Health, shadow AI and AI risk survey (fielded December 2025, published January 2026)
Share This Post:
Facebook
Twitter
Pinterest
LinkedIn
Start Here

Send us a message

Please take a moment to submit your information. A member of our consulting team will be in touch shortly.