Shadow AI in the clinic: healthcare's quiet patient-data leak
The most common AI deployment in an Indian hospital today is not the radiology triage tool the board approved. It is the resident pasting a discharge summary into a free chatbot at 2 a.m.
The most common AI deployment in an Indian hospital today is not the radiology triage tool the board approved. It is the resident pasting a discharge summary into a free chatbot at 2 a.m.
The most common AI deployment in an Indian hospital today is not the radiology triage tool the board approved. It is the resident pasting a discharge summary into a free chatbot at 2 a.m. to rewrite it in plainer language — patient identifiers and all.
Healthcare is uniquely exposed to shadow AI because the pressure is clinical and the data is the most sensitive category there is. Surveys through 2025–2026 consistently find a majority of knowledge workers using unsanctioned AI, around a third receiving no employer training on it, and a large share routing through personal accounts that bypass any monitoring. In a hospital, each of those interactions can carry diagnoses, identifiers and treatment histories — special-category data under India's DPDP Act and, for ABDM-linked systems, data flowing through a regulated health-data architecture.
The governance problem is that none of this is visible. A hospital can hold an impeccable DPIA for its sanctioned clinical-decision-support vendor while dozens of unmonitored consumer-AI sessions process the same patient data daily. The approved system is governed; the actual behaviour is not. And unlike a finance leak, a healthcare leak is effectively irreversible — you cannot reissue a patient's medical history the way you reissue a card.
There is a hopeful pattern in the data, though: one 2026 healthcare survey found that unauthorised AI use dropped sharply once an approved, in-workflow alternative was offered. Clinicians are not trying to break rules; they are trying to finish notes. Give them a compliant tool inside the EHR and the shadow usage largely evaporates.
A workable program pairs three things: a sanctioned, DPDP-aligned AI tool embedded where clinicians already work; a plain, role-specific policy on what may never be entered into any external tool; and discovery telemetry so the data-protection officer can see real usage, not assumed usage. Govern the behaviour you have, not the architecture you wish you had.
How do you build trust in AI at enterprise scale? AramGRC co-founder Anand shares a practical third-party AI assurance framework — inventory, governance, conformance, red teaming and independent reporting — built for the US and India.
What is an AI audit — and why does "AI audit" mean five different things to five different people? AramGRC co-founder Anand breaks down the types of AI audit, what a good one covers, and exactly what a strong audit report should include.
How do Indian AI companies win global trust? AramGRC co-founder Anand explains AI assurance for India — the DPDP Act, MeitY's AI guidelines, and what US and EU buyers actually expect from Indian AI vendors.