Hospitals wrestle with AI tools doctors adopt on their own

Clinicians are reaching for free AI assistants before IT has approved anything, leaving hospitals to govern tools that already hold patient detail.

MedRisk Staff
By
2 Min Read

A governance gap is opening inside hospitals, and it is being created by the people hospitals trust most. Clinicians facing heavy documentation loads are turning to free, general-purpose AI assistants on their own, outside any institutional review.

Writing in MedCity News, one physician describes the shift plainly: survey data cited in the piece found that a majority of frontline healthcare workers now use generic AI tools for work at least monthly, nearly 40 percent weekly, and about 10 percent admit using AI in direct patient care, shaping diagnoses and follow-up. A separate survey reported by Fierce Healthcare found most health systems have deployed at least some AI tools without formal IT sign-off.

The security problem is the data, not the model. Prompts that include a patient’s medications, lab values, or history move protected health information into environments with no business associate agreement, no retention controls, and no audit trail. Under HIPAA, that exposure does not need an intrusion to be a problem; it needs only the data to leave the covered environment.

Practical steps for security and compliance teams: inventory the AI tools clinicians already use, publish an approved list with a route to request new ones, block unsanctioned tools at the network and mobile-management layers where policy allows, and train staff on what never belongs in a prompt. Accountability has to be assigned before an incident forces the question.

Share This Article