Axios Future of Health Care

October 05, 2026
Happy Monday, everyone. AI agents are assuming increasingly complex roles in hospitals and other health settings — often without an IT sign-off or safety checks.
🚨 Situational awareness: The White House is monitoring reports of a suspected plague case in Russia and the response, and assessing its options, a Trump administration official told Axios yesterday.
THE AXIOS SHOW: Treasury Secretary Scott Bessent speaks with Axios' Mike Allen about his fiery Cabinet confrontations, his view of the Iran war and the administration's battle against inflation. Watch on YouTube.
Today's newsletter is 1,041 words, a 4-minute read.
1 big thing: The risk of unchecked AI agents
Health systems that are scrambling to protect themselves against cyberattacks and data breaches have a new problem: unchecked AI agents.
The big picture: The expanding use of agents in health care is outpacing the industry's ability to police the technology, posing new safety and privacy concerns.
- Digital security professionals are warning that hospitals and other organizations will have to think about safeguards in new ways to keep agents from exposing personal health information and violating laws like the Health Insurance Portability and Accountability Act.
Stunning stat: 72% of health industry leaders said AI tools or agents are being deployed without formal IT approval, according to a new survey for digital security company Imprivata.
- That's creating a trust gap for some of the executives, who say their oversight is struggling to keep up as agents shift from fetching information to helping coordinate care.
- The survey of 250 health security and AI strategy officials found 28% of health organizations have agentic AI in production today, with another 44% piloting or testing new uses.
- 88% expect AI agents to operate with at least some autonomy doing clinical and administrative work.
Threat level: Many health systems are trying to establish guardrails. But it's a unique challenge since the agents, unlike traditional software, can make plans, launch workflows and act independently.
- Giving them broad access to electronic health records, billing systems and communications platforms could lead to situations where information is removed, passwords are changed and doctors' orders get modified.
- It's also possible that a bot under a physician's supervision could be commandeered by an outside actor who injects it with prompts to look up sensitive information and move across clinical systems, experts say.
- "What we're advocating for is a paradigm shift, a plea to get out ahead of this before it's too late," said Sean Kelly, Imprivata's chief medical and growth officer and an emergency physician.
Between the lines: Health care has lagged other industries in adopting new technology. AI is changing that, giving providers a way to streamline administrative tasks, ease clinician burnout and improve the coordination of care.
- But unapproved deployments and fragmented security strategies can leave holes. There's particular concern about agents initiating tasks entirely on their own, or taking unauthorized actions that their human operators didn't request.
- In 2024, an Otter meeting agent joined a meeting of hospital physicians in Ontario, Canada, via a recurring calendar invitation, transcribed discussions about seven patients' personal health information, then emailed a summary to the 65 people on the invite, some of whom were no longer at the hospital, authorities said.
- This summer, an OpenAI agent researching public health spending data in Australia breached non-public parts of a government network containing information on the country's universal health program and appeared to try to conceal its tracks, according to the Cloud Security Alliance.
"As these agents start accessing systems and taking action, health care organizations need to know what they can access, what they're allowed to do, and how they're being monitored. That's going to become a much bigger part of the security conversation," said Jaren Day, group director of cybersecurity at KLAS Research.
The Imprivata survey says health care organizations will have to go beyond verifying who or what can access information to defining what an agent is authorized to do after it's granted access.
- Kelly said health systems should consider creating a "moat of credentials" so that an agent can only do a task for a specified time. "It's almost a case of guilty until proven innocent," he said.
What we're watching: Rural hospitals and clinics with tight budgets and overworked staff may need AI solutions the most, but could be especially vulnerable.
- States are using rural health funding from last year's GOP reconciliation law for more AI deployment. Some like Utah and Missouri are also focusing on risk management and security training.
- Providers also could face major lawsuits if an agent contributes to a bad health outcome.
2. Cost protection for Medicare enrollees
Protecting patients from exorbitant out-of-pocket costs in traditional Medicare would cost the federal government as much as $96 billion a year, according to a new analysis published in JAMA Health Forum.
Why it matters: One of traditional Medicare's major disadvantages relative to Medicare Advantage is the absence of any kind of limit to what beneficiaries could be required to spend in any given year.
State of play: The lack of a cap — and the resulting financial strain for some seniors — could end up in the political spotlight should Democrats regain control of Congress next year.
- A memo from House Democrats' Cost-of-Living Healthcare Working Group suggests capping out-of-pocket costs at $5,000 within the first 100 hours of reclaiming the House.
By the numbers: That'd cost taxpayers $70 billion a year but would save seniors $1,138 annually, according to the analysis in JAMA.
- Capping out-of-pocket spending at $3,000 a year would reduce beneficiary spending by $1,568 and cost taxpayers $96 billion. Raising the cap to $10,000 would save beneficiaries $707 in a year and cost taxpayers $39 billion annually.
- Adding a cap, especially a more generous one, "would substantially shift beneficiaries from [Medicare Advantage] to" traditional Medicare, the authors conclude.
Between the lines: Private Medicare plans are increasingly under political scrutiny, both for their cost to the federal government relative to traditional Medicare and for reported heavy-handed use of prior authorization or claims denials.
- But they've become very popular with seniors, in part due to their caps on out-of-pocket spending.
- Policymakers frustrated with the MA program may view bolstering traditional Medicare as one way to address the issue.
Thanks for reading Axios Future of Health Care, and to editor Kate Marino and copy editor Matt Piper. Please ask your friends and colleagues to sign up.
Sign up for Axios Future of Health Care




