HIMSSCast · 2026-08-04 · 13 min
Key moments - from our scoring
Substance score
57 / 100
Five dimensions, 20 points each
Healthcare organizations face a critical security gap as 81% of employees use unapproved AI tools, often uploading sensitive patient data and PHI into consumer LLMs like ChatGPT - creating direct HIPAA violations and enabling unauthorized model training. Jamin Patel, identity strategist at SailPoint, explains why traditional identity and access management models fail for AI agents: these non-human identities operate dynamically, make independent decisions, and possess both outbound access (to data/systems) and inbound access (from other agents or humans), creating indirect privilege escalation risks. The conversation covers SailPoint's three-pillar security model - Discover and Visualize (using Entra Security capabilities to surface shadow AI and vault secrets), Govern and Monitor (applying policy-based controls and automated certification), and Protect and Respond (detecting anomalous behavior like bulk data exports at 2am). Healthcare leaders need a tiered risk framework based on clinical impact: Tier 1 covers high-risk agents touching PHI in Epic, Cerner, and Meditech; Tier 2 includes medium-risk read-only agents; Tier 3 covers low-risk productivity bots. Every agent must have assigned human ownership with zero standing privileges.
Yes, putting patient data into public AI tools like ChatGPT is a direct HIPAA violation because the data gets used to train future public models, making patient privacy impossible to recover or control.
AI agents have both outbound access (to data and systems) and inbound access (from humans or other agents), allowing them to independently interpret instructions, chain tools together, and create sub-agents - meaning other identities can indirectly access data through an agent that they wouldn't normally have access to.
Traditional identity and access management systems lack visibility into agents spun up out-of-band in cloud environments, cannot see unmanaged integrations or high-entropy secrets, and don't analyze access intent - leaving shadow AI connections and exposed API keys completely undetected.
75% of employees admit to sharing sensitive data with unauthorized AI tools, while 57% actively hide this activity from their organization.
Organizations should use a tiered risk framework: Tier 1 for high-risk agents touching PHI in systems like Epic and Meditech requiring human-in-loop authentication; Tier 2 for medium-risk read-only internal systems; and Tier 3 for low-risk productivity bots, with every agent assigned a human owner to prevent orphan agents.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers solid, concrete insights about shadow AI risks in healthcare and non-human identity management that a healthcare leader would find useful, including the triple threat framework (compliance, security, patient safety) and the discovery-govern-protect model. However, much of the content is built around Sailpoint's product positioning rather than independent analysis, and several points are stated but not deeply explored (e.g., the actual mechanics of how AI agents create secondary risks).
Putting patient data into public AI tools is a direct HIPAA violation. Once the data is fed into a consumer LLM like ChatGPT and others, it can be used to train future public models, making the patient privacy impossible to bring back or get control of.
AI agents are similar to traditional human identity as they are granted access to data and systems to complete a task... What makes them different is that AI agents also have inbound access.
The framing of shadow AI as 'shadow IT on steroids' and the distinction between outbound and inbound access for AI agents shows some freshness, but the core thesis - that unmanaged tools and identities create compliance risk - is familiar ground. The tiered risk framework and discovery-govern-protect model are sensible but not particularly novel or counterintuitive.
Shadow AI is just like a modern hyper accelerated version of shadow it.
You cannot treat a patient facing triage bot the same way you treat an internal cafeteria scheduling assistant.
Jamin Patel is identified as an 'identity strategist at Sailpoint,' which suggests product expertise rather than independent practitioner or operator experience. While the guest demonstrates knowledge of identity and access management frameworks, there is no evidence of hands-on operational leadership at a healthcare organization or direct experience managing the problems being discussed at scale outside a vendor context.
I'm Marianne Bohr. With HIMS today I'm joined by Jamin Patel, identity strategist at Sailpoint
I always say this, if you cannot see it, you cannot govern it.
The episode cites several statistics (81% of employees using unapproved tools, 75% sharing sensitive data, 57% hiding it, 80% of agents taking unintended actions) but provides minimal concrete examples of real incidents, company names, or quantified outcomes. The Hugging Face breach is mentioned briefly but not detailed. Most recommendations remain at the framework level without specific implementation metrics or case studies.
As you mentioned, 81% of employees say they use unapproved AI tools.
If a developer spins up a shadow agent in AWS or connects a third party AI tool to Microsoft 365 standard tools won't even register it.
The host asks relevant, structured questions that move the conversation forward logically, but rarely pushes back, challenges claims, or probes deeper into contradictions or limitations. Questions are largely open-ended invitations for the guest to explain Sailpoint's approach. There is no genuine disagreement, skepticism, or follow-up that tests the guest's assertions.
Can you tell us what is shadow AI and why are the numbers like 81% of employees using unapproved tools?
Can you walk us through Sailpoint's discover and govern strategy?
Computed from the transcript - who did the talking, and the words that came up most.
As healthcare organizations increasingly embrace AI, including AI agents, “shadow AI,” or the use of unauthorized tools by clinicians and staff, poses a rising threat to cybersecurity and compliance. Join Jaimin Patel, identity strategist at SailPoint, as he discusses how an identity security approach can help organizations identify unmanaged AI agents and other risks, assign agent ownership, and protect data by enforcing access policies.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Putting patient data into public AI tools is a direct HIPAA violation. Once the data is fed into a consumer LLM like ChatGPT and others, it can be used to train future public models, making the patient privacy impossible to bring back or get control of.
Speaker B: Hi, I'm Marianne Bohr. With HIMS today I'm joined by Jamin Patel, identity strategist at Sailpoint and we'll be talking about how healthcare can secure AI tools and non human identities. And before we start, I do want to say thank you to Sailpoint for sponsoring this podcast. Jamin, thank you for joining us today.
Speaker A: Thank you for having me Marianne.
Speaker B: Now, shadow AI is a big topic these days. The pressing concern for healthcare organizations. Can you tell us what is shadow AI and why are the numbers like 81% of employees using unapproved tools? Why are those numbers so alarming?
Speaker A: Shadow AI is just like a modern hyper accelerated version of shadow it. Shadow it has been around for so many years, decades. And now it's shadow AI in single line and in healthcare. When you think about healthcare organizations, it usually involves well meaning clinicians trying to reduce administrative burnout and be more efficient in their day to day life. So think about when a doctor or a nurse bypasses it to use a consumer grade tool like ChatGPT to draft a ladder of medical necessity, summarize a complex patient chart or write a discharge notes. All of these are just part of the shadow IT use cases from a recent survey. As you mentioned, 81% of employees say they use unapproved AI tools. What makes 81% so alarming is the sheer velocity of exposure. I use this in many of my presentation and LinkedIn post. If it has access, it has risk. And if it uses AI, the risk can scale faster. So unlike traditional software, consumer AI is like a two way street. Employees aren't just asking using it to get information, but they're also actively feeding into it. When 75% of employees admit to sharing sensitive data and 57% are um, actively hiding it, it means corporate IP and PHI protected health information of patients are constantly leaking out of perimeter into the models we don't control. Think about this, are all the public models creating a massive compliance and a privacy breaches for the healthcare organization?
Speaker B: Well, that kind of dovetails. On my next question. When employees share sensitive patient data or company data with these consumer grade AI tools, can you talk a little bit about what kind of risk that creates for a healthcare organization?
Speaker A: Yeah. So in healthcare this creates a triple threat of compliance, fines, security and direct impact on patient Safety, let's take it one at a time. So first, from regulatory standpoint, putting patient data into public AI tools is a direct HIPAA violation. Once the data is fed into a consumer LLM like ChatGPT and others, it can be used to train future public models, making the patient privacy impossible to bring back or get control of. Second, there's a whole massive threat of non human identity compromise. A developer building a quick AI tool might accidentally paste and copy API keys or database credentials of the EMR at the hospital organization into a prompt, exposing their keys to the kingdom. And finally, the third part here is the poisoning and hallucination. Risk explanations rely on unratted, unmonitored consumer AI tools for decision support. They risk acting on incorrect and fabricated medical data. In our industry, a data leak isn't just a financial penalty. It directly impacts human lives if bad data makes it into the patient record.
Speaker B: Now that AI agents are part of nearly every healthcare organization, 80% report their agents have taken unintended actions. What makes these AI agents so different from other identities that we've governed in the past?
Speaker A: For decades, Healthcare identity security governs static access. You give a human access to a specific system, they perform a predictable task. Humans hold onto this access like doctors and nurses hold onto this access until they change their role and move to a different role or when they leave the organization. AI agents. I always consider AI agents as a hybrid identity. They don't just query data, they interpret instructions. They chain multiple tools together, make independent decisions, and even create other sub agents to complete a task. So AI agents are similar to traditional human identity as they are granted access to data and systems to complete a task. This is what we call outbound access. What makes them different is that AI agents also have inbound access. Think about who can access this agent. It can be a human who connects this agent. It could be another agent that can access this agent. It is critical that human or another agent accessing this agent does not indirectly get access to data or system through this agent, which otherwise they wouldn't have. And that's the use case that happens across so many organizations today. One of the most latest news that happened over the last few days is the hugging face breach. This was an end to end by an autonomous AI agent system. So when 80% of organizations report that agents are taking unintended actions, it's because these agents are operating with dedicated authority. They might use a human's credential to cross a system boundary. But because they lack human common sense, they can very rapidly access or share Data they shouldn't be. They are highly dynamic. These agents are dynamic self propagating class of non human identity that traditional static governance was never bid to handle. In such cases, and this is something we always talk about is that all these AI agents should always have zero standing privileges.
Speaker B: Makes a lot of sense. It sounds like this is kind of a wild west of AI agents spread across cloud platforms. So can you tell us why do traditional security models fall short here?
Speaker A: Definitely. So traditional security models rely a lot on sitting in line. Think about like within firewalls or proxies or waiting for a human to manually request a car. But in AI agents case AI agents and the underlying non human identities are often spun out of band directly Inside Cloud Environment SaaS applications by researchers department it's and so on. So traditional identity and access management has a massive blind spot here. It cannot see what it does not know exist. If a uh, developer spins up a shadow agent in AWS or connects a third party AI tool to Microsoft 365 standard tools won't even register it. Furthermore, the traditional models don't look at the intent of the access. This is exactly where our latest acquisition of Entra security come into play. Traditional security fails because it cannot discover this hidden high entropy secrets and unmanaged non human identities. To secure the wild west in complex hospital network you need a solution that goes out of band to automatically discover hidden high entropy secrets and unmanaged integrations before they become breach vectors.
Speaker B: I see. So Jamin, can you walk us through Sailpoint's discover and govern strategy? Can you tell us how do organizations find agents that they may not even know they have?
Speaker A: And then this is a very common scenario as well. As we see it, it starts with shifting from a reactive posture, uh, to an automated discover and govern lifecycle with Sailpoint agentic fabric. What we do is we bring complete visibility to the enterprise. The very first step is what we call a discovery soak. By linking identity provider and scanning endpoints cloud boundaries, our system automatically discovers unmanaged AI agents and maps them back to the human owners. And this is the key part. They aren't just left in the wild. We pull them into Sailpoint's identity graph. So now this is the place where AI agents are sitting alongside all the human employees machine accounts allowing you and the organization to instantly visualize exactly who created the agent, what data it has access to and what permission it is exercising in real time.
Speaker B: Sounds like something that every organization would want to know now of course not all AI agents carry the same Level of risk. So how should healthcare leaders think about classifying agents and assigning the ownership of those agents?
Speaker A: This is Gai Kwaisha. Healthcare leaders must adopt a tier based risk framework driven by clinical impact and data sensitivity. Meaning this is a huge one. This is a most common scenario with healthcare organizations. You cannot treat a patient facing triage bot the same way you treat an internal cafeteria scheduling assistant. So let's look at those tiered. So tier one is very high risk. So agents that touch Phi smart systems like Epic center and Meditech or have the authority to write to medical records. These require strict monitoring, human in the loop authentication authorization and frequent certification. Tier 2 is a medium risk agents with read only access to internal non clinical business systems. Low risk. This is the third tier is standard productivity bots. So the golden rule of agentic security is every agent must have a human owner attached to it. There can be no orphan agent if an agent is discovered without an owner. Sailpoint agentic fabric automatically routes a micro certification to the most likely creator to establish accountability right away.
Speaker B: Now can you explain how SailPoint's three pillar model discovers, governs and protects and how those three pillars work together?
Speaker A: So we look at AI security as a continuous lifecycle represented by three pillars. As you said, so pillar one is the Discover and visualize. I always say this, if you cannot see it, you cannot govern it. The first pillar is Discover Visualize. This is where the shadow AI remediation and the new entra security capabilities shine for us. We scan the entire ecosystem to instantly surface over thousand plus non human identities, Shadow AI connection and vault secrets. We put them all on a single map which gets us to the next peer of govern and on it. Once we see them, we govern them. We apply policy based access controls and run automated access reviews. Just like you certify a nurse's access every quarter you certify your AI aging whether this access still needed or it should still be out there. That brings us to third one. Now the protect and respond pillar. Third pillar is the real time safety net. If an uh, AI agent suddenly exhibits anomalous behavior like adapting to bulk export thousands of patient charts at 2am in the morning, the agentic fabric solution detects this intent shift and can immediately revoke its tokens isolating the threat without disrupting the hospital operations. So together they turn security from a roadblock into a business enabler.
Speaker B: I have one more question for you Jamin. For leaders in our audience whose organizations are just beginning this journey, what is the first practical step they can take to secure AI tools and non human identities.
Speaker A: So the absolute first step is very simple. Get a baseline of all your non human and AI footprint. You cannot secure what you do not know exist. Most hospital IT leaders estimate they have a few dozen integrations running but when we run a discovery scan the real number is often in thousands. My recommendation is to initiate out of band identity discovery assessment. Find out where your shadow AI connections are, uncover where API keys to your clinical systems are exposed and get a clear picture of your actual risk. Once you have that visibility you can systematically apply governance to protect your patients and the organization. Don't wait for an audit or an incident to tell you where your vulnerabilities are.
Speaker B: Excellent Jaemin, thank you for joining us today and thanks so much for sharing your insights with us.
Speaker A: Appreciate it and thank you for having me.
Speaker B: And special thanks to Sailpoint for sponsoring this podcast. Have uh a fantastic rest of your uh, day.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.