View Press Releases
New Clearwater Report Finds 91% of Healthcare Organizations Cannot Verify AI Governance For Their Organization
The 2026 Healthcare AI Security and Governance Benchmark finds that 42% rank sensitive data leaking through AI tools as their top internal concern but can't prove the technical controls behind them work
NASHVILLE, Tenn., Oct. 8, 2026 /PRNewswire/ -- Clearwater Security & Compliance, healthcare's largest pure-play cybersecurity and compliance firm, today released Closing the AI Governance Gap: The 2026 Healthcare AI Security and Governance Benchmark, a new industry study examining how well healthcare organizations can verify, not just describe, their AI governance controls.
Drawing on responses from 105 organizations including hospitals and health systems, physician and dental groups, health plans, and the software and technology companies that serve them, the study finds that healthcare has largely completed the policy phase of AI governance: committees have been chartered, acceptable-use policies written, and vendor contracts updated. Most still can't prove that these controls actually work.
Among the report's key findings:
- 91% of healthcare organizations cannot verify what AI is actually running in their environments.
- Nearly half of healthcare organizations have AI policies without technical enforcement behind them.
- 42% identify sensitive or proprietary data leaking through AI tools as their greatest internal AI-related concern, compared with 30.8% who cite employees using unapproved AI tools without oversight.
- 46% identify AI introduced through third parties as their greatest external AI concern, ahead of AI-powered attacks at 34.6%, yet only 14.3% fully validate their vendors' AI controls.
- Two-thirds of respondents (66%) identify security and privacy concerns as their leading hurdle to AI adoption.
- 80% of organizations either spend less than 5% of their security budget on AI security or don't know how much they spend.
- Just 4 in 10 healthcare organizations can demonstrate that they control how data is sent to AI tools.
- Only 14% of healthcare organizations can demonstrate that their vendors' AI controls are fully verified.
"Healthcare organizations are at different points in their AI governance journey, but the next phase is about demonstrating that policies, controls, and oversight are working in practice," said Clearwater President Baxter Lee. "The question now is not simply whether organizations have governance in place, but whether it is producing the intended result. This report looks at that question through the data. What we see is an industry that has made meaningful progress in establishing governance but still has work to do in building the technical capabilities needed to validate and enforce it. Closing that gap will become increasingly important as today's guidance evolves into tomorrow's expectation."
The report also examines the healthcare technology ecosystem itself, finding that software and technology companies serving healthcare face the same third-party visibility challenges as their clients — inheriting AI risk from foundation-model providers, cloud platforms, and subprocessors in much the same way health systems inherit it from their vendors and business associates.
"What stands out to me isn't a lack of effort; it's a mismatch in pace," said Harry Lu, Vice President of Consulting - AI Solutions at Clearwater. "AI adoption in healthcare has moved from pilot to production in a handful of budget cycles, and it's accelerating, especially with agentic AI. Seventy-four percent of respondents are already exploring or running agentic systems, but far fewer can tell you which credentials those agents hold or whether that access has ever been revisited since launch. Governance built for a pilot doesn't hold up under production-scale risk. Closing that gap requires continuous discovery, enforceable technical controls, and evidence, not another policy document."
The study closes with a call to action for boards, executives, and security teams: treat AI as a core business function rather than a technology project, extend governance from policy into enforceable technical control, and measure progress by proof, not self-reported compliance. A self-assessment tool included in the report allows organizations to score their own AI governance maturity against the same framework used in the survey.
Closing the AI Governance Gap: The 2026 Healthcare AI Security and Governance Benchmark is available now at www.ClearwaterSecurity.com/aireport.
About Clearwater
Clearwater helps organizations across the healthcare ecosystem move to a more secure, compliant, and resilient state so they can achieve their missions. The company provides a deep pool of experts across a broad range of cybersecurity, privacy, and compliance domains, purpose-built software that enables efficient identification and management of cybersecurity and compliance risks, managed cloud services, and a 24/7 Security Operations Center with managed threat detection and response capabilities. To learn more, please visit www.clearwatersecurity.com.



