Healthcare Sector Struggles to Secure AI Agents and Non-Human Identities
Seventy-nine percent of healthcare organizations currently lack comprehensive governance for non-human identities, a vulnerability that leaves sensitive patient data exposed to unauthorized access. According to new research from Netwrix, the rapid integration of AI agents into legacy infrastructure is outpacing the industry’s ability to manage complex permission structures.

The healthcare industry faces a distinct security crisis, with 31% of organizations reporting unauthorized access to sensitive data over the past year. This figure significantly outpaces the 24% average observed across other sectors. When breaches occur, the financial impact is often severe; 33% of healthcare providers report incident costs exceeding $250,000, dwarfing the 21% rate seen in general industry benchmarks.
Security professionals in the field express low confidence in their underlying infrastructure. Only 14% of respondents believe their Active Directory environments are free of privilege escalation risks, the lowest level of confidence among 16 industries studied. Jeff Warren, Chief Product Officer at Netwrix, notes that the problem stems from long-standing legacy systems where AI agents inherit years of accumulated, unmonitored permissions.
Data visibility remains a critical hurdle, as 77% of organizations cannot immediately identify who has access to specific sensitive files. With 75% of respondents confirming that AI and automation have heightened identity-related risks, security teams are struggling to keep pace. Darryl Baker, a senior researcher at Netwrix, warns that organizations must map existing access pathways before deploying new agents, as even seemingly limited accounts can provide lateral movement opportunities to highly sensitive resources.
Comments (0)
No comments yet. Be the first!