top of page

Upgrade your security strategy for the AI era.

Suspect a Breach? 

!

Contact Us:

Pondurance_Logo_R-10pxMargin_312px_REV-wordmark.png

Your Practice Already Adopted AI. Nobody Signed Off on the Risk.

Gartner_Resources-Tout_AI-SOC-Agents_2x (1).png
Doug Howard
August 3, 2026

The most disruptive technology wave in the history of medical practice isn't on its way. It's already inside your building, running on your clinicians' phones, listening in your exam rooms, drafting your notes, and increasingly touching your coding and your revenue cycle. And if you're like most practice leaders I talk with, you couldn't draw me a map of where it all lives.


That's not a criticism. It's the defining condition of this moment, and it's worth understanding before we talk about what to do about it.


The fastest adoption healthcare has ever seen

Ambient AI scribes went from novelty to near-default in about eighteen months. The Peterson Health Technology Institute put it plainly last year: in an industry famous for long sales cycles and glacial implementation timelines, no technology in recent memory has been adopted more enthusiastically by clinicians or scaled so fast, and it did so with no regulatory mandate forcing anyone's hand. By early 2025 there were already more than sixty vendors selling into that single use case. Large groups are logging millions of ambient documentation sessions and reclaiming thousands of physician hours.


I want to be clear about something: this is largely a good story. Documentation burden is a real driver of burnout, and burnout is a real driver of physician attrition, medical error, and the quiet erosion of care quality. If AI gives your clinicians their evenings back and their attention back to the patient in front of them, that's a win worth having.


But notice what happened. Your practice adopted a powerful new technology, one that ingests the most sensitive conversations you have, through the front line, clinician by clinician, often before any policy, contract review, or security assessment caught up. The tool arrived as a productivity decision. It should have arrived as a risk decision too. In most practices, it didn't.


And the vendors have already moved the goalposts. What launched as a burnout remedy is now being sold as a revenue engine: ambient tools that don't just write your note but suggest your codes and drive your billing. That's a different animal entirely, with different compliance exposure, and the payers have noticed. Some are already auto-adjusting higher-level claims downward. The technology you adopted to save time is now quietly reshaping your audit risk.


AI didn't create a new problem. It industrialized the old ones.

Here's the part I most want practice leaders to sit with.


Every one of these tools is a new door into your most regulated data. Every AI vendor is a new third party in your chain of custody for protected health information. Every "free trial" a clinician started is a place your patient data may now live that isn't on anyone's inventory. AI didn't invent a novel category of cyber risk. It took the fundamental risks that have always defined healthcare security, where does the data live, who can reach it, would you even know if something went wrong, and it multiplied them, accelerated them, and hid them behind a friendly interface.


The users you can't see: non-human identities

There's a newer layer to this that most practice leaders have never been asked to think about, and it deserves its own paragraph: non-human identities, or NHIs.


Every AI scribe, every EHR integration, every automation and API connection in your practice logs in with something: a service account, an access token, an API key. Those credentials are identities, just like your employees' logins, except no human is behind them. And they are now the majority population in your environment. Across the industry, non-human identities outnumber human users many times over in the typical organization and the gap is widening fastest exactly where AI is being adopted. Agentic AI, software that doesn't just answer questions but takes actions, is accelerating the curve.


Here's why that should get your attention. Your entire identity playbook was built for people. People get onboarded and offboarded. People use multi-factor authentication. People behave in patterns you can monitor, and when they leave, HR tells IT to shut off their access. Non-human identities do none of that. They authenticate around the clock, they carry permissions that would trigger alarms if a human account held them, and when the vendor relationship or the free trial ends, their credentials frequently live on, unowned, unrotated, and unwatched. Attackers have noticed: compromised machine credentials are now among the most common paths into an organization, precisely because nobody is watching them the way we watch people.


So when I say AI industrialized the old problems, this is what I mean in the most literal sense. The oldest question in security, who has access to my data, now has an answer that is mostly not people. If your access reviews only cover humans, you're governing the minority of your identities.


The stakes were already the highest in the economy

Healthcare has been the single most expensive industry for data breaches for fourteen consecutive years running, according to IBM's latest figures, an average of $7.42 million per incident. Worse, healthcare takes the longest of any sector to figure out it's been hit: an average of 279 days to identify and contain a breach. That's roughly nine months during which an intruder is inside your data before you know. And the newest wrinkle is measurable: breaches involving unsanctioned "shadow AI", the tools nobody approved, now carry a meaningful cost premium, precisely because almost none of them sat behind proper access controls.


If you want the systemic version of this, look no further than the Change Healthcare attack, which took down claims processing for a substantial share of the country and cost its parent company billions. That wasn't exotic. It was the fundamentals failing at scale.


Back to basics, because the basics are what AI is stress-testing

When I served in the Air Force and later at the Pentagon, I watched new capability arrive constantly. New systems, new tempo, new threats. Not once did any of it retire the fundamentals. If anything, faster and more complex operations made drilling the basics more non-negotiable, not less. You don't respond to a more dangerous environment by chasing every shiny new threat vector. You respond by getting ruthlessly good at the questions that were always the right questions.


That's the entire premise of the conversation I want to have with practice leaders. The security questions that matter in this new AI world are not new questions. They're the ones many organizations quietly skipped when the basics felt boring, and AI has now made skipping them expensive.


A preview of the ones I'd start with:


Do you know where your patient data actually lives today, including the new places AI just put it? If you can't inventory it, you can't protect it.


Who, and now what, has access to it? Every AI agent, integration, and service account is a non-human identity with its own credentials and permissions, and in most organizations they now outnumber the humans. Are you inventorying and governing them the way you govern people? And when a tool goes away, does its access go with it?


When a vendor's AI touches your PHI, whose breach is it, and is that in writing? A signed business associate agreement is not a formality. It's the difference between their problem and yours.


If something went wrong right now, how long before you'd know? If the industry average is nine months, what's yours, and have you ever actually measured it?


If you were down tomorrow, do you have a plan you've tested or a document nobody has opened since it was written? An untested incident response plan is a comforting fiction.


None of those require you to be a technologist. They require you to be a leader who insists on knowing the answers before an incident forces the question.


The point

AI is going to keep flooding into your practice, whether or not you have a strategy for it. The organizations that come through this well won't be the ones with the most advanced tools. They'll be the ones whose leaders never let the fundamentals slip, who treated every new capability as a new question to answer, not just a new efficiency to celebrate. That includes the newest population on your network: the identities that aren't people at all.


That's the discussion I'm looking forward to having with a room full of practice leaders soon: going back to the basics of cybersecurity, and the questions every leader should be asking in this new AI world. If you lead a medical group, I'd encourage you to start asking a few of them this week. The answers tend to be more revealing than anyone expects.

wave pattern background

Featured Posts

Your Practice Already Adopted AI. Nobody Signed Off on the Risk.

August 3, 2026

Cyber101: What Are Immutable Backups, and Why Are They Important?

July 29, 2026

July Cyber Threat Download™

July 20, 2026

bottom of page