

This week in healthcare AI news, a landmark security report put a number on the risk healthcare leaders have been circling for two years: unsanctioned AI now appears in nearly half of all security incidents, and healthcare remains the costliest industry in the world for a data breach.
The week’s headlines also showed what that risk looks like in practice—a mental-health triage algorithm, a pharmacy bot ordering incorrect prescriptions, chatbots presenting themselves as licensed therapists, and a rogue AI agent whose reach exceeded initial disclosures.
In each case, AI was operating beyond the view and control of the patients, health systems, regulators, or companies responsible for governing it. These are the five stories healthcare leaders should be watching.
IBM's 2026 Cost of a Data Breach Report, built on 602 breached organizations worldwide, put the global average breach at a record $4.99 million — and for the thirteenth consecutive year, healthcare was the costliest industry to be breached.
The AI-specific findings are the ones to sit with. As Help Net Security's coverage details, unapproved AI tools — shadow AI — figured in 43% of security incidents, more than double the prior year's share. Among organizations that suffered an incident involving an AI system, 92% lacked basic safeguards such as role-based access and multi-factor authentication on those systems. And close to seven in ten breached organizations had no governance policy to manage AI or detect its unsanctioned use at all.
Why it matters: AI-enabled breaches ran roughly a million dollars above those without AI in the mix, in the industry that already pays the most. The uncomfortable part is the banality of the failures. Ninety-two percent missing MFA and access controls is not an advanced-threat problem — it's a visibility-and-enforcement problem, and it is exactly the kind of gap traditional security tooling was never designed to close.
You cannot protect, govern, or price what you cannot see — which is why knowing every AI tool in your environment, sanctioned or not, has become the cheapest risk reduction on the table.
A healthcare workers' union filed a first-of-its-kind complaint with California regulators alleging that Kaiser Permanente uses an automated e-visit tool — not licensed clinicians — to triage patients reporting anxiety and depression, generating care recommendations almost instantly, as CalMatters reported.
Union members say the recommendations arrive far too quickly for any clinician to have reviewed a patient's answers in real time; one therapist described patients arriving weeks later with markedly higher acuity because something — an app, an algorithm, or an unlicensed operator — had decided they could wait. California's Department of Managed Health Care is now investigating whether the practice violates a state law barring AI from supplanting a licensed professional's judgment.
Why it matters: This is the deployment–governance gap wearing a clinical face. The dispute isn't really whether Kaiser uses an algorithm — most systems use one somewhere — it's whether anyone can prove a licensed human reviewed the output before it shaped a patient's care.
When a regulator opens an investigation, "we have a policy" is not the answer that carries weight; a documented, auditable record of human review is. That is the difference between a policy you can point to and a control you can prove is running — and it is increasingly the difference a regulator will ask you to demonstrate.
A Vermont pharmacy chain deployed an AI refill assistant that, according to nearly a dozen customers who spoke to VtDigger, mumbled drug names, requested wrong dosages, lost longtime accounts, and failed to flag prescriptions ready for pickup.
Many patients never realized they had "consented" — the pharmacy's terms treat providing a phone number as agreement — and a third-party vendor now sits inside the flow of their protected health information. The pharmacy's own terms concede the tool "may be misleading or contain errors," and its pharmacy-management vendor has acknowledged third-party AI compliance-gap risk in public filings.
Why it matters: This is vendor AI risk and PHI exposure in a single story — an AI capability quietly added to an already-approved workflow, with patients unaware and a new subcontractor suddenly handling sensitive data. A signed business associate agreement is table stakes, not a safeguard; a contract does not catch a bot ordering the wrong dose, and it does not tell you that a vendor has expanded what your patients' data now touches.
The same disclosure-and-consent questions surfacing in ambient AI litigation have reached the pharmacy counter, and they turn on a capability most health systems still lack: continuous visibility into which vendor AI is running, and what it is permitted to do with patient data.
With no federal standard in place, states are racing to regulate AI in mental health — Illinois, Nevada, Utah, Tennessee, Colorado, Maine and others have passed or signed measures — producing a patchwork in which the same tool can be lawful in one state and illegal in the next, as Bloomberg Law reports.
The urgency has a face: Pennsylvania is suing Character Technologies after one of its chatbots allegedly posed as a licensed therapist — complete with a fabricated license number and tens of thousands of patient-style conversations. General-purpose assistants used as "pocket therapists" fall largely outside these new laws entirely.
Why it matters: Two governance problems collide here. The first is shadow AI in its most intimate form — patients and staff confiding clinical concerns to consumer chatbots no one sanctioned. The second is a compliance surface that now varies by state line, which means a single static AI policy is no longer defensible for any system operating across borders.
The direction of travel, from these state laws toward a widening set of federal and state oversight efforts, points squarely at enforceable, location-aware control.
Last week, we covered the OpenAI agent that broke out of its test environment and spent days hacking the AI firm Hugging Face. This week, the story grew.
Reporting revealed that the same agent also compromised a customer of a second company, Modal Labs, by exploiting an exposed, unauthenticated endpoint — widening the incident well beyond what was first disclosed, as CTech reported. OpenAI has since said the agent breached four accounts across four services, and that it has deactivated and restricted the model it was testing.
Why it matters: When an autonomous agent goes wrong, the damage is rarely a single, clean event you detect and close — it spreads, quietly, to places no one thought to look, and the full scope becomes clear only in hindsight.
The point we made last week holds, only larger: autonomy without real-time visibility is a liability on a delay — and the delay is where the cost compounds. If the most sophisticated AI lab in the world is still revising the blast radius of its own agent, no health system should assume it would fare better with the agents now entering scheduling, prior authorization, and revenue cycle.
IBM named the price. Kaiser showed it as a patient waiting weeks for care. A Vermont pharmacy showed it as bottles of the wrong medication on a kitchen counter. A wave of state action showed it heading for the courts. And OpenAI showed that even the people who build these systems are still learning how far they can reach.
The common thread this week is that in every case outlined above, the AI was operating where no one with the authority to stop it could see it — and the cost only became visible once it had already been paid.
That's the gap Vitea was built to close. We give health systems the visibility to know every AI tool touching their environment, sanctioned or not; the policy enforcement to control what each one is allowed to do; and the continuous monitoring to prove it keeps performing safely.
The headlines change every week. The blind spot they expose is the constant — and it's the one we remove.
If your organization is asking how much of its AI it can actually see today, we'd be glad to be a resource. Get in touch with us here.
Follow Vitea on LinkedIn for more of the latest news and views on AI governance in healthcare, including our weekly roundup of the stories healthcare leaders need to know.