Senior test manager points to record breach costs, the rise of "shadow AI," and slow vulnerability patching as the industry races to deploy artificial intelligence across clinical and administrative workflows.
The warning comes as healthcare data breaches reach historic levels. In 2024, the industry recorded 739 data breaches affecting more than 276 million patient records — the worst year on record, according to the HIPAA Journal. The average healthcare breach now costs $7.42 million to contain, more than any other industry for the 14th consecutive year, per research firm Cobalt. The Change Healthcare ransomware attack alone exposed the data of an estimated 192.7 million people, or roughly two-thirds of the U.S. population, according to federal disclosures from the U.S. Department of Health and Human Services.
Gajjar said the greater risk often isn't the AI tool an organization vets and deploys carefully. It's the tools adopted faster than governance can keep pace, sometimes called "shadow AI." A December 2025 survey commissioned by Wolters Kluwer Health found that 40% of healthcare professionals and administrators had encountered an unauthorized AI tool in their organization, and nearly one in five admitted to using one themselves. A companion analysis conducted with the Coalition for Health AI put the combined share of respondents who had encountered or used shadow AI at 57%. A clinician under deadline pressure will reach for whatever tool gets the job done, often without knowing where the SSNs and health details they just typed in are actually going, who can see them, or how long they're retained. Even AI tools built specifically for healthcare aren't automatically safe. Audits of some clinical AI scribe tools have found data routed to third-party analytics platforms that weren't fully accounted for when the tool was approved. That's exactly the kind of gap a thorough security and compliance review should catch before a tool ever touches a patient's confidential information, not after.
The same technology accelerating AI adoption is also accelerating attackers. Roughly 83% of phishing emails now contain AI-generated content, and healthcare has the highest phishing-susceptibility rate of any major industry, according to research. Newly disclosed vulnerabilities are increasingly exploited within days of becoming public, while the median time healthcare organizations take to remediate a critical vulnerability still runs closer to a month, per Health-ISAC. An estimated 99% of hospitals are running at least one connected device with a known, exploitable vulnerability on its network, according to Ordr. Business-associate involvement in reported healthcare breaches has averaged roughly a third over the past several years and climbed above 40% in early 2026, according to the HIPAA Journal - multiplying the exposure around a single patient's data.
Gajjar said protecting patient data in an AI-driven environment isn't about slowing adoption. It is about matching that pace with equal investment in the controls around it. Based on his experience validating healthcare systems, he recommends organizations: Apply the same scrutiny to every AI vendor that could touch Social Security numbers or health history as they would any core system, including a signed Business Associate Agreement before that data goes near a model. Give staff sanctioned, secure tools that are good enough to compete with the free consumer options they would otherwise reach for, since policy alone won't stop someone under deadline pressure. Build real visibility into where sensitive data flows once an AI tool is in use, rather than discovering the gap during a compliance audit after the fact. Encrypt and limit access to confidential fields such as Social Security numbers and addresses by default, so a compromised or misused AI tool doesn't leave the most damaging data exposed. Fund security in proportion to the risk. Healthcare organizations still spend a small, single-digit share of IT budgets on security - roughly half the level common in financial services - even as breach costs and ransomware-linked disruptions keep climbing. Adopt a multi-layered cybersecurity framework that combines technical safeguards, administrative controls and physical protections to meet regulatory compliance requirements. Run regular vulnerability management, including automated scans and annual penetration testing, to identify and close security gaps before they are exploited. Train staff to recognize AI-enabled threats, including deepfake audio requests, sophisticated phishing links and malicious QR codes. None of this is exotic. It's the same discipline security teams already apply to core clinical and claims systems, extended to cover the AI layer sitting on top of them. The organizations getting this right aren't necessarily spending more in total. They're refusing to treat AI procurement as separate from security procurement, so a new tool never goes live faster than the controls around it can be put in place. Regulators have begun to respond: the U.S. Department of Health and Human Services has floated voluntary frameworks addressing AI governance, patient privacy and data security. But Gajjar said voluntary guidance won't force the change on its own. From what I've observed testing and validating the systems healthcare depends on, the organizations that treat data security as a first-class part of every AI rollout - not an afterthought bolted on later - are the ones that will keep their patients' trust intact. The ones that don't will find out the hard way that in healthcare's AI era, a single exposed database of Social Security numbers and health records does more lasting damage than any efficiency gain can make up for.