AI
Hospital Staff Are Running Healthcare AI Without a Map
Cotiviti’s 2026 healthcare AI readiness index shows staff, not CIOs, putting unapproved tools into clinics while few groups can see or govern that use.
A Cotiviti survey of 70 healthcare leaders, taken over the summer of 2026, found more than 70% already using AI tools. Nearly 40% of health insurers now call AI a core part of the business. The same index found 64% of provider groups reporting staff on unauthorized, non-integrated tools, and fewer than 40% holding detailed rules for that use.
The 70 people answering those questions sit in the C-suite. The people pasting a progress note into a public chatbot on a busy shift do not.
Payers Call AI Core While Providers Stay Early
Cotiviti’s 2026 Healthcare AI Readiness Index splits the industry on official programs. Insurers are further along on paper. Provider groups, the ones closest to the chart and the bedside, still describe themselves as early.
That split matches other buyer surveys without copying them. A Bain and KLAS poll of 228 provider and payer executives in October 2025 found 70% of providers and about 80% of payers had an AI strategy in place or in development, up from 60% in both groups a year earlier. Strategy memos are not the same thing as production. The Healthcare Financial Management Association, drawing on 233 health systems, found 88% using AI inside the organization and only 18% with mature oversight and a fully formed plan.
PAYERS AND PROVIDERS IN THE COTIVITI INDEX
| Group | Official AI stance | Staff on unapproved tools | Very prepared for AI-assisted attacks |
|---|---|---|---|
| Health insurers (payers) | Nearly 40% call AI core to the business | 60% | 42% |
| Provider organizations | More than 70% still in early adoption | 64% | 32% |
The index is small, 70 leaders, and it is a self-report. It still draws a clean line. Payers are wiring AI into claims, payment integrity, and member operations. Hospitals and clinics are earlier on the official stack, and they post the weaker cyber score.
The People Who Already Use the Tools
Philips’s Future Health Index 2026, based on more than 2,000 clinicians and more than 20,000 patients across 10 countries from February to April 2026, measured the floor, not the press release. It found 64 percent of clinicians use personal tools when workplace options do not meet their needs. Close to half, 48%, already treat generative AI as a work buddy, naming products such as ChatGPT and Perplexity. Two-thirds, 65%, said organization-issued AI use rose in the prior year.
The same clinicians report a payoff when the tools work. Seventy-one percent saw better workflow. Half said AI raised their capacity to see patients, by a global average of 8 extra patients a week. Forty-six percent reported time savings of at least 132 hours a year, a median of 3 hours a week across a 44-week year. Eighty-three percent were optimistic that AI could improve outcomes. Seventy percent also said training for AI-enabled tools was unavailable, thin, or inconsistent.
CLINICIAN DEMAND IN THE PHILIPS SURVEY
- Personal tools: 64% reach for their own AI when the official kit falls short.
- Work buddy: 48% use generative AI as a professional sidekick.
- Training gap: 70% call AI training unavailable, inadequate, or inconsistent.
- Time back: 46% save at least 132 hours a year, about 3 hours a week.
Nutanix’s healthcare cut of its Enterprise Cloud Index puts the same behavior on the infrastructure side. It found employees in non-IT functions deploying AI at 79% of healthcare organizations, as apps or agents stood up outside IT. Eighty-three percent of leaders said that lack of oversight threatens data sovereignty and regulatory compliance. Eighty-eight percent said current kit is not fully ready for on-premises AI at the bedside, where a lag is not a minor annoyance.
A later Black Book sample of 228 U.S. health system employees, 136 of them on the front line, put a clock on the habit. Fifty-eight percent of frontline staff said they use generic tools such as ChatGPT, Gemini, or Copilot for work at least once a month. Thirty-nine percent said they do it at least once a week. Seventeen percent said they sometimes or often enter identifiable patient data. Douglas Brown, president of Black Book Research, called the pattern mainstream in shops where official tools lag and policy is vague or missing.
HOW SHADOW AI SHOWS UP ON A SHIFT
- Personal accounts: A clinician opens ChatGPT, Gemini, or Copilot on a phone or a home login and drafts a note, a letter, or a prior-auth summary.
- Pasted charts: Diagnosis details, SOAP notes, or discharge language leave the electronic record and enter a consumer model with no business associate agreement.
- Browser add-ons: Unvetted extensions sit on top of the web EHR and send selected text to a model the hospital never reviewed.
- Rogue agents: Non-IT teams stand up small automations in email, coding, or scheduling that security never put on an asset list.
HIPAA still treats that paste as a disclosure to a third party. Consumer chatbot accounts do not sign a business associate agreement. An enterprise contract with a model vendor covers the seats in that contract. It does not cover the personal account a nurse created at 2 a.m.
Governance Committees Still Cannot See the Tools
Boards have been adding AI committees. Visibility has not followed. The Healthcare Cybersecurity and AI Benchmarking Study 2026, a March 2026 self-assessment of 54 provider organizations backed by Censinet, the American Hospital Association, Health-ISAC, the Health Sector Coordinating Council, the Scottsdale Institute, and the University of Texas at Austin, measured that gap against the NIST AI Risk Management Framework.
Seventy percent reported an AI governance committee. Sixty-seven percent reported a formal approval process. Only 30% kept an enterprise-wide AI inventory at 30 percent, and just 15% had an enterprise-wide way to detect the tools. That is a 40-point drop from committee to inventory, and a 55-point drop from committee to detection.
WHAT 54 HEALTH SYSTEMS CAN ACTUALLY SEE
| Control | Share of organizations |
|---|---|
| AI governance committee | 70% |
| Formal approval process | 67% |
| Enterprise-wide AI inventory | 30% |
| Enterprise-wide detection method | 15% |
No AI RMF function cleared 38% coverage. Govern led at 38%, then Map at 28%, Manage at 22%, and Measure at 18%. Asset management and supply-chain risk have ranked as the weakest NIST Cybersecurity Framework categories for three years running, which is the boring reason AI lists stay incomplete. You cannot catalog a model you never added to the asset register, and you cannot govern vendor-embedded features you discover from a release note.
The pace problem is already in production. More than one in four of those 54 organizations were running agentic AI live. Twenty-seven percent of groups with no committee, no formal approval process, and no defined oversight structure were running it anyway. Twenty-three percent said adoption was moving faster than oversight could follow, and that complaint came most often from groups that already had a committee.
How Ready Are Hospitals for AI-Assisted Attacks?
Cotiviti asked a narrower cyber question than most AI scorecards. Only 42% of payers and 32% of providers said they were “very prepared” to respond to AI-assisted cyberattacks. Put the other way, 58% of payers and 68% of providers were not.
On September 1, 2026, Black Book Research warned hospital security leaders that AI is widening the breach surface while also making phishing, credential theft, and social engineering cheaper to scale. Its CISO respondents said every model, agent, embedded feature, or clinical pilot should be treated as a new information system and a new trust boundary, and should not receive production credentials, protected health information, images, claims data, or operational access until it passes an AI-specific security review.
The report listed six layers where a hospital can leak: user prompts and uploads, models and AI apps, retrieval stores, autonomous agents and connected tools, vendors and plugins, and cloud or API infrastructure. It also drew a line security teams keep blurring. A platform that uses AI to speed the security operations center does not, by itself, find shadow AI, inspect prompts, stop sensitive data from leaving, test models, or constrain agents.
Censinet’s 54 organizations look stronger on classic response than on knowing what they own. Seventy-four percent sat at NIST CSF Tier 2 (Risk-Informed) and 17% at Tier 3 (Repeatable). Respond and Detect led. Govern and Identify trailed. That is a shop that can run an incident call and still fail a simple question: which models touched which records this morning?
Fewer Than 40 Percent Wrote the Rules
Cotiviti’s policy number is the one that turns shadow use from a training issue into a records issue. Fewer than 40% of the 70 leaders said their organization had detailed policies governing employee use of AI. Sixty percent of payers and 64% of providers still reported unauthorized or non-integrated tools in the building.
Ric Sinclair, who became chief executive of Cotiviti in 2026 after operating roles at Waystar, framed the gap as a trust problem in the index statement.
AI is quickly becoming part of the infrastructure of healthcare, but the security and governance around it have to advance just as quickly. As health plans and healthcare organizations rely on AI across more critical workflows, they need confidence that the technology and partners throughout their ecosystems meet the same high standards for security, governance and responsible use. Trust will be foundational to realizing AI’s full potential in healthcare.
Ric Sinclair, CEO, Cotiviti, on the 2026 Healthcare AI Readiness Index
A policy that only says “do not share patient data” does not name the tools. Staff still need a written line on which products may touch protected health information, which are banned, when a slip has to be reported as a breach, and who owns the review of AI-written clinical text before it hits the chart. Without that, the compliance file and the actual Tuesday night workflow describe two different hospitals.
Inside HHS, the Inventory Came First
Private providers are not the only ones under a clock, and the federal clock already rang. It applies to HHS divisions, not to a community hospital. It still shows what “ready” looks like when someone is forced to count the systems.
THE HHS CLOCK ON HIGH-IMPACT AI
- April 3, 2025: The White House Office of Management and Budget issues Memorandum M-25-21 on accelerating federal AI use through innovation, oversight, and public trust, plus M-25-22 on buying AI.
- September 30, 2025: HHS Acting Chief Artificial Intelligence Officer Clark Minor issues the department’s compliance plan. HHS had reported 271 AI use cases in FY24 and expected that list could nearly double in FY25. Deputy Secretary Jim O’Neill chairs an AI Governance Board that meets at least twice a year.
- April 3, 2026: HHS divisions must apply minimum practices for high-impact AI under M-25-21. If a division cannot meet the date, it is told to stop the tool until it complies.
The plan also points divisions at NIST’s control overlays for securing AI systems as they rewrite IT policy. That is the sequence the Censinet cohort has inverted. Committees exist. The inventory, the detection method, and the high-impact controls lag. Washington at least started by counting 271 uses and putting a stop-the-tool date on the calendar.
Arman Sharma, HHS deputy chief AI officer, told industry groups in 2026 that providers want coordinated guidance, help standing up oversight, and a way to judge whether a product works. Those asks line up with the Cotiviti finding that tools are already in the workflow and the rulebook is not.
Give Staff a Path They Will Use
Clinicians are not waiting for the next committee packet. They hop models as the products change. Joshua Liu, a physician and chief executive of SeamlessMD, has described cycling from ChatGPT to Gemini to Claude on the same prompts in a matter of months, and warned that a multi-year lock-in on one enterprise chatbot is a bet that the chosen tool stays the best one. Patients do not care which vendor won the contract. They care whether the note is right and whether their data stayed inside a covered entity.
A hard ban does not settle that. It just moves the work onto personal logins that look like ordinary web traffic. Tim Gutwald, a healthcare attorney, put it in plain terms on a July 2026 AI and HIPAA panel.
You can’t actually stop your team from using it. A ban just pushes it out of sight. The fix is a safe, sanctioned path people are glad to stay inside.
Tim Gutwald, healthcare attorney, AI and HIPAA panel, July 2026
Nutanix’s healthcare findings point the same way on infrastructure: 57% of organizations expect agentic AI or autonomous agents in the next three years, and 86% already treat AI as the main reason to adopt containers so models can run at the point of care if the wide-area link drops. Staff will keep reaching for speed. The groups that put a logged, BAA-covered tool in that path will see the prompts. The groups that only write a policy will keep collecting 64% answers they cannot map to a system name.
Cotiviti’s 70 leaders described AI as infrastructure. The index’s own shadow-AI and “very prepared” scores say the people holding that infrastructure on a Tuesday are still the ones who were never in the room.
Disclaimer: This article is news reporting and analysis of published surveys and public agency documents. It is for information only and is not medical advice, legal advice, or a compliance review of any hospital, health plan, clinic, or vendor. Readers who need to set policy, assess HIPAA duties, or respond to a suspected disclosure should consult their privacy officer, qualified health-law counsel, and information-security leadership before acting. Figures and program statuses reflect the named studies and documents as they stood on the dates those sources give, and later surveys or rule changes can move them.
-
AI3 months agoOracle Cuts 21,000 Jobs in a Year, Cites AI in 10-K Filing
-
AI2 months agoFable 5 and Mythos 5 Return as US Lifts Anthropic Export Controls
-
AI3 months agoSpaceX’s Google Deal Turns a Rocket Company Into a Cloud Landlord
-
GAMING3 months agoCD Projekt Red Co-CEO: Redemption Arc Isn’t Done, Witcher 4 in 2027
-
CRYPTO3 months agoXPL Rallies 30% Ahead of Plasma One Card Tier Launch
-
NEWS3 months agoGoogle Search Profiles Build a Follow Graph Inside Discover
-
APPS3 months agoDGO App Brings Rs 549 Mobile Pass for FIFA World Cup 2026 in Nepal
-
AI3 months agoMoonshot AI Targets $30 Billion in China’s Fastest AI Funding Sprint
