link rel="stylesheet" href="https://unpkg.com/@phosphor-icons/web@2.1.1/src/regular/style.css"

Healthcare's Shadow AI Problem: Where PHI Is Quietly Leaking

Brian Gallagher
President, Koniag Cyber
min. read
August 6, 2026
View on Original Source
min. read
Blocking Claude on corporate networks does not stop employees from using it on personal devices. It just pushes usage outside your visibility, which is worse, not better.

A clinical documentation specialist at a regional health system was drowning. Her patient volume had increased 30 percent over the previous year, and the time she spent writing visit notes had not decreased. So she did what felt like a reasonable solution: she started pasting clinical summaries into ChatGPT, asking it to restructure and clean up her notes before entering them into the EHR.

She was not trying to circumvent policy. Her organization did not have an AI policy. She was trying to do her job.

She is not unusual. In a 2024 survey by Salesforce, 55 percent of healthcare workers reported using AI tools not sanctioned by their employer. In many of those cases, the data they were working with, including clinical notes, patient names, and treatment details, was protected health information. It left the organization's environment entirely, entered a consumer-grade AI platform, and may have been retained by that platform's servers.

That is a HIPAA breach. Most of those organizations do not know it happened.

The anatomy of shadow AI in healthcare

Shadow AI, the use of AI tools outside of organizational knowledge or governance, is not primarily a technology problem. It is a gap problem. When organizations fail to provide approved, accessible AI solutions, employees find their own. They do it because the tools work and the pressure to perform is real.

In healthcare settings, the risk surfaces in several predictable places. Clinical staff summarize notes, patient calls, and discharge instructions using consumer AI tools. Administrative staff use AI to draft prior authorization letters, often including diagnosis codes and patient identifiers. Call center employees feed conversation transcripts into AI summarization tools to speed up documentation. The data flowing through these interactions is, in most cases, ePHI, and it is moving through systems that have no Business Associate Agreement, no data retention controls, and no audit trail.

The problem is compounding as AI tools become more capable and more embedded in daily work. Microsoft 365 Copilot, when properly governed, can legitimately transform clinical and administrative workflows. When employees access Copilot features that have not been properly configured for their data environment, or when they find workarounds to access AI capabilities outside of IT's visibility, the same tool becomes a governance gap.

Why "we'll just block it" does not work

The instinct to restrict AI access is understandable. It is also, in practice, ineffective.

Blocking Claude on corporate networks does not stop employees from using it on personal devices. Prohibiting AI tools in policy does not prevent staff from using them if the prohibition is not enforced technically. What blocking typically accomplishes is pushing usage outside organizational visibility, which is worse, not better, than unsanctioned use on managed devices.

What HIPAA requires organizations to know

The HIPAA Security Rule does not have an AI-specific provision. It does not need one. If a tool processes, stores, or transmits ePHI, and AI tools used with patient data clearly do, HIPAA's technical and administrative safeguard requirements apply. That means Business Associate Agreements, encryption controls, access governance, and audit logging.

HHS's proposed update to the Security Rule would sharpen this further by making all safeguards mandatory and requiring documented risk analyses that account for new technologies and workflows. An AI governance gap that would previously have been addressable with a policy statement now needs a technical control and an evidence trail.

Using Microsoft 365? Download our 2026 Practical Guide for HIPAA Compliance

A practical starting point

AI governance in healthcare starts with visibility: understanding which tools employees are actually using, what data is flowing through them, and where the exposure is. That requires discovery, not assuming you know, but actually finding out.

From there, the path forward is a governed AI environment with approved tools, data loss prevention integrations, and employee training that is practical rather than punitive. The goal is not to prevent AI use. It is to bring AI use inside organizational control before regulators or a breach force the issue.

The HIPAA 2026 Final Rule guide walks through the technical safeguard requirements that apply to AI and every other system touching ePHI in your environment, with a compliance checklist and action timeline built for Microsoft 365 organizations.


Find the content useful? 
Subscribe to The Catch, our exclusive weekly LinkedIn newsletter focused on real-life experiences doing cyber right in the most highly regulated industries.

About the resource
What you'll learn
Who is this resource for?
Download Healthcare's Shadow AI Problem: Where PHI Is Quietly Leaking
Download Resource
Thank you and enjoy the resource
View Resource
Oops! Something went wrong while submitting the form.