Shadow AI Is Already in Healthcare. Do You Know Where It Is?
- Team MDA Solutions LLC

- 2 days ago
- 6 min read

The overlooked tools, extensions, recordings, and workarounds creating risk inside physician offices, clinics, and hospitals
By Michele D. Alexander | Founder, MDA Solutions LLC | August 2026
The most dangerous AI in a healthcare organization may not be the system approved by the board. It may be the browser extension a staff member installed to rewrite patient messages, the meeting bot invited to a care-management call, the free transcription app used during an encounter, or the chatbot receiving a copied section of a medical record.
None of these employees may believe they are creating a compliance problem. They are often trying to work faster, reduce documentation burden, translate information, prepare an appeal, or help a patient. That is precisely why shadow AI is difficult to manage: it usually enters through convenience, not misconduct.
The issue is no longer theoretical. In 2026, more than 80% of physicians reported using AI professionally, according to the American Medical Association. As adoption grows, healthcare leaders must look beyond the AI products they intentionally purchased and ask a more difficult question: What AI is already touching our work without our knowledge?
The Leadership question: Can We identify every aI tool being used what information it receives, who approved it, what happens when it is wrong?
What shadow AI actually means
Shadow AI is any AI capability used for organizational work without formal approval, security review, contracting, or governance oversight. It includes obvious tools such as public chatbots, and also includes AI embedded in software employees already use: browsers, email, meeting platforms, document tools, cloud storage, scheduling systems, coding applications, and smartphones.
In healthcare, shadow AI should be treated as more than an acceptable-use issue. It can become a data-disclosure, privacy, clinical-safety, billing, employment, operational, and governance problem at the same time.
Ten places shadow AI may be hiding
Public AI chatbots
A clinician, biller, care manager, or front-desk employee pastes information into a consumer chatbot to draft a letter, summarize a record, answer a clinical question, create discharge instructions, or analyze a spreadsheet. Even when a name is removed, dates, diagnoses, locations, images, identifiers, and narrative context may still identify the patient.
AI meeting assistants
An automated notetaker joins a utilization-review meeting, case conference, supervision session, or leadership call. The bot may capture audio, participant names, clinical discussions, treatment decisions, chat messages, and action items, then send that information to an external service.
Browser extensions and page copilots
Writing assistants, page summarizers, screen readers, and 'ask this page' extensions may be able to read webpage content, form fields, URLs, clipboard data, or material displayed within an EHR or patient portal. Their access can be broader than the user realizes.
Unapproved ambient scribes
A clinician uses a mobile or web transcription tool to reduce documentation time. The tool may record the patient conversation and transmit audio or transcripts to a vendor that has not been assessed for consent, retention, access, deletion, or business-associate obligations.
AI clinical-answer and decision-support tools
Staff upload an image, pathology result, medication list, patient history, or note to obtain a quick answer. The result may be incomplete, biased, unvalidated for the intended population, or presented with more confidence than the evidence supports.
PDF and document-analysis tools
Employees upload referrals, prior-authorization files, complaints, policies, contracts, or medical records to a 'chat with your document' service. The visible text may not be the only concern; PDFs can also contain metadata, hidden text, comments, or attachments.
Translation, captioning, and accessibility tools
Live translation, speech-to-text, text-to-speech, and call transcription can transmit spoken patient information outside the approved environment. Errors can also change clinical meaning or create inaccurate patient instructions.
Low-code agents and automation tools
An employee connects an AI workflow builder to email, calendars, cloud drives, forms, spreadsheets, CRM systems, or EHR exports. A small departmental experiment can quietly create broad access permissions, undocumented data flows, and automated actions no one is monitoring.
Coding, claims, and revenue-cycle copilots
AI tools draft appeals, recommend codes, analyze denials, or generate prior-authorization language. Beyond privacy concerns, inaccurate or unsupported content can create repayment, payer-contract, audit, and false-claims exposure.
AI added through ordinary software updates
A familiar vendor activates an AI feature, pilot, plug-in, or default setting. Because the underlying product was already approved, the organization may not reassess the new data flows, subprocessors, model behavior, audit capability, or human-review requirements.
Removing the patient's name may not remove the risk
A common assumption is that information is safe to paste into an AI tool once the patient's name is deleted. HIPAA de-identification is more demanding than removing a name. Dates, geographic details, medical-record numbers, photographs, device identifiers, rare diagnoses, distinctive events, and free-text combinations may still make a person identifiable.
Protected health information is not limited to a structured EHR field. It can appear in a prompt, transcript, screenshot, image description, spreadsheet, audio recording, email, PDF, or copied patient-portal message. Leaders should be especially cautious when employees describe information as 'de-identified' without applying an established de-identification method and verifying the result.
A BAA is necessary in many relationships, but it is not the whole answer
HHS explains that when a vendor performs services for a covered entity and creates, receives, maintains, or transmits PHI, the organization generally needs satisfactory assurances through a compliant business associate agreement. That requirement can extend to downstream subcontractors.
But a vendor's statement that it is 'HIPAA compliant' does not answer the operational questions. The organization still needs to understand the permitted use, data flow, retention, deletion, model-training terms, subprocessors, access controls, audit logs, security incidents, breach notification, and whether the tool is appropriate for the specific workflow. A BAA is a control; it is not a substitute for governance.
The risk goes beyond HIPAA
Shadow AI can create several kinds of exposure simultaneously:
Clinical safety: fabricated details, missed context, incorrect attribution, unsafe recommendations, translation errors, and overreliance on output.
Quality and equity: untested performance across populations, hidden bias, inconsistent results, and no process for appeal or escalation.
Revenue integrity: unsupported coding, inaccurate appeals, downcoding or upcoding, and flawed documentation entering the legal health record.
Cybersecurity: excessive permissions, unauthorized browser extensions, compromised credentials, insecure APIs, and external data transfer.
Workforce and legal risk: opaque screening or scheduling decisions, exposure of accommodation information, and unauthorized recording of sensitive conversations.
Operational accountability: no named owner, no approval record, no monitoring plan, and no clear response when the system changes or fails.
Five questions leaders should ask this week
What AI tools, extensions, assistants, scribes, and embedded features are employees actually using - including free trials and personal accounts?
Which of those tools can access PHI, patient communications, claims, credentials, employee information, contracts, or confidential operational data?
Which vendors have been reviewed for the exact use case, including BAA coverage, data retention, subprocessors, model training, audit logs, and breach obligations?
Where is human review required before AI-generated content affects documentation, care, coding, payment, patient communication, or an adverse decision?
Who has authority to approve, restrict, monitor, remediate, and retire each AI use?
What to do in the first 30 days
Healthcare organizations do not need to solve every AI governance problem at once. They do need to establish visibility and accountability.
Publish an interim rule: do not enter, upload, dictate, paste, screen-share, or connect PHI to an AI service unless it is approved for that exact use case.
Create one intake pathway for AI tools, extensions, pilots, embedded features, APIs, and free trials.
Build a living inventory that records the tool, owner, use case, data involved, vendor, risk level, approval status, and next review date.
Give staff a simple approved / prohibited / ask-first list, along with a fast way to request help.
Prioritize high-risk discoveries involving patient recordings, EHR access, images, clinical decisions, coding, claims, cloud-drive connections, and personal accounts.
Review contracts and BAAs for AI-specific data use, retention, model training, subprocessors, logging, and incident terms.
Define required human review and escalation for clinical, documentation, coding, prior-authorization, and patient-communication workflows.
Report findings to leadership and assign named decision rights rather than leaving responsibility with an undefined committee.
The goal is not to ban AI
Employees adopt shadow AI because the approved route is often slow, unclear, or unavailable. A policy that only says 'do not use AI' may drive activity onto personal devices and private accounts, making the risk harder to see.
The more effective message is: AI use is not automatically prohibited; unreviewed data sharing and unvalidated use are. Organizations should pair clear boundaries with secure alternatives, practical training, a rapid intake process, and a culture that encourages early reporting without retaliation.
Healthcare did not become safer by pretending AI had not arrived. It will become safer when leaders can see where AI is being used, evaluate the risk, assign authority, deploy controls, monitor outcomes, and adapt as tools and rules change.
Start with visibility. MDA Solutions complimentary Healthcare AI Readiness Assessment helps leaders identify early gaps in vendor governance, HIPAA safeguards, PHI handling internal policy and accountability.
About the author
Michele D. Alexander is the founder of MDA Solutions LLC, a healthcare consulting practice specializing in AI governance, HIPAA readiness, quality and compliance, EHR optimization, and operational performance. She brings more than 20 years of experience across hospitals, ambulatory care, and behavioral health.




Comments