Finding the AI in Your Hospital Nobody Told Security About
Shadow AI in mid-market hospitals is more pervasive than most security teams estimate. SaaS vendors embed AI features into tools clinicians already use, departments adopt AI-augmented tooling without IT or compliance review, and clinical staff paste PHI into public LLM interfaces. Armorstack’s shadow-AI discovery work — Pillar 1 of the AI Adoption Security Framework — produces a complete, healthcare-specific inventory in 30 days.
Shadow AI in hospitals shows up in four places: SaaS-embedded AI features, departmental tooling adopted outside IT review, clinical staff pasting PHI into public LLMs, and third-party clinical AI vendors integrated through Epic or Oracle Health. Discovery combines API, network, and endpoint telemetry with a clinically-calibrated staff survey — and typically finds two to four times more AI in use than IT estimated.
Where Shadow AI Hides in Mid-Market Healthcare
Shadow AI in hospitals appears in four distinct places, and each carries a different discovery challenge and a different HIPAA exposure profile.
1. SaaS-Embedded AI Features
AI features vendors quietly enable inside tools already licensed — Microsoft 365 Copilot, Google Workspace Gemini, Slack AI, Notion AI, Zoom AI Companion, Webex AI Assistant — often touching PHI and often invisible in standard SaaS admin consoles.
2. Departmental AI Tooling
Clinical departments adopting AI scribing tools, marketing adopting AI content generation, HR adopting AI resume screening, finance adopting AI invoice processing — each potentially touching PHI in workflows security never reviewed.
3. Public LLM Use by Clinical Staff
ChatGPT, Claude, Gemini, Perplexity, and similar tools on work or personal devices. Staff paste discharge summaries for summarization, documentation for editing help, and patient questions for AI-drafted responses.
4. Third-Party Clinical AI Vendors
AI vendors integrated into Epic or Oracle Health (Cerner) via FHIR APIs or EHR partner programs, each processing PHI under BAA terms that may not contemplate the vendor’s AI feature set.
What Healthcare-Specific Shadow-AI Discovery Looks Like
Pillar 1 discovery work, applied to mid-market hospitals, combines four signal sources into a single inventory.
API-Based Discovery
Against the major SaaS administrative consoles the organization uses — Microsoft 365, Google Workspace, Slack, Zoom, and the specific clinical SaaS in the environment.
Network Telemetry Analysis
Against known AI service domains, identifying traffic to public LLM endpoints and AI-vendor APIs from organizational devices.
Endpoint Telemetry
Browser extension and application usage data that identifies AI tools in active use across clinical and administrative devices.
A Structured Staff Survey
Calibrated to clinical operations — not a generic “do you use AI” question, but a workflow-specific battery that surfaces use cases staff don’t consciously categorize as “AI.”
The output is an inventory classified by department, by data type (PHI / non-PHI), by vendor authorization status, and by clinical workflow involvement. Mid-market hospital discovery exercises typically find an inventory two to four times larger than what the IT team estimated before the exercise began.
Frequently Asked Questions — Shadow AI in Healthcare
How does shadow AI become a HIPAA issue?
Can we just ban AI use by clinical staff?
Will the discovery work identify our clinical AI vendors?
How does shadow-AI discovery feed into Joint Commission preparation?
What happens with the inventory after the assessment?
See What AI Is Actually Inside Your Hospital
Apply for the free 30-day AI Risk Assessment. Pillar 1 discovery alone is worth the engagement — a complete, healthcare-specific shadow-AI inventory, classified by department, data type, and vendor authorization status.
Not in healthcare? Read the general Shadow AI Detection guide or the full Shadow AI Governance Framework.