Netwrix 1Secure는 데이터와 아이덴티티 전반에 걸쳐 통합된 가시성을 제공합니다 - 14일간 무료로 전체 액세스가 가능합니다.무료 평가판 시작

Resource centerNews

Netwrix Research: 79% of Healthcare Organizations Face Security Risks Due to Gaps in Governing AI Agents and Other Non-Human Identities

Netwrix Research: 79% of Healthcare Organizations Face Security Risks Due to Gaps in Governing AI Agents and Other Non-Human Identities

Sep 30, 2026

FRISCO, Texas – September 30, 2026 – Netwrix, a recognized leader in identity and data security, today released new healthcare findings from its 2026 Data and Identity Security Report. Thirty-one percent of healthcare organizations experienced unauthorized identities accessing sensitive data in the past year, compared with 24% in other industries. Among those that experienced an incident, 33% put the cost above $250,000, compared with 21% in other industries.

Healthcare also ranked lowest among 16 industries for confidence that its Active Directory (AD) environments are free of privilege escalation risks, with 86% lacking full confidence in their Active Directory security. Only 14% of healthcare organizations said they were fully confident, compared with 26% across all industries.

In healthcare, nobody is starting from a clean slate, said Jeff Warren, Chief Product Officer at Netwrix. These environments are built on decades of legacy systems, typically underpinned by Active Directory and all the permissions that have accumulated in it. Instead of inheriting the access you meant to give it, an AI agent inherits what's already there.

AI is adding identities faster than healthcare can govern them

Seventy-nine percent of healthcare organizations said their non-human identities are not fully governed. Seventy-five percent said AI and automation have increased identity-related risk to sensitive data over the past two years, and 70% said their data access governance is behind the speed of AI adoption.

Most healthcare organizations can't immediately see who has access

Seventy-seven percent can't immediately determine who has access to a specific piece of sensitive data, a challenge that AI is likely to exacerbate as agents proliferate. Sixty-one percent said it would take hours and multiple tools. Forty-eight percent said a compromised identity is the most common starting point for unauthorized access to sensitive data.

An account with limited permissions in Active Directory can still have a route to more sensitive resources through relationships such as delegation and group membership. Permissions that are no longer needed can make those paths harder to identify. Netwrix PingCastle assesses Active Directory environments for security risks and provides remediation guidance.

Before adding more AI agents and other non-human identities, healthcare organizations need to understand the access that's already there,” said Darryl Baker, Senior Staff Security Researcher at Netwrix. “An account can appear to be pretty limited and still have a route to something much more sensitive. Proactively discovering privilege escalation paths and cleaning up permissions give you a much clearer view of what you're handing to a new identity.

Methodology

The Netwrix 2026 Data and Identity Security Report is based on a global survey of 2,317 security professionals conducted in early 2026. The research benchmarked 1,889 organizations across more than 60 industries and 12 security dimensions.

The healthcare findings are based on 145 healthcare respondents, primarily in the United States. Sixteen industries had sufficient representation for industry-level comparisons. Healthcare responses were compared with responses from other industries where noted.

Additional Resources

Download the Netwrix 2026 Data and Identity Security Report

Assess Active Directory security risks with Netwrix PingCastle

Data, Identity & AI Security Assessment: A free benchmarking tool that evaluates organizations across 12 security dimensions and five maturity tiers for AI readiness.

Share on