TL;DR: Healthcare employees are pasting PHI into consumer and embedded GenAI tools faster than most security programmes can see or govern, according to Cyberhaven. The control gap is not just detection, but data-level policy, BAA enforcement, and approved alternatives that reduce shadow AI pressure.
NHIMG editorial — based on content published by Cyberhaven: AI Security for Healthcare: How to Protect PHI When Employees Use GenAI Tools
By the numbers:
- One-third of employees access AI tools via personal accounts, including 58% of Claude users and 60% of Perplexity users.
- 509% in a single year., n adoption grew 509% in a single year.
Questions worth separating out
Q: What breaks when healthcare staff use GenAI tools without PHI controls?
A: PHI can leave governed systems through ordinary prompts, drafts, and copy-paste actions, even when the employee has no malicious intent.
Q: Why do consumer AI tools create so much risk for PHI governance?
A: Consumer tools often lack the contractual and technical safeguards needed for healthcare data, and employees may still use them because they are fast and convenient.
Q: How do security teams know whether AI authorization for ePHI is actually working?
A: Teams know it is working when they can reconstruct every AI access decision from request to outcome, including the policy version and contextual inputs used.
Practitioner guidance
- Implement data-context PHI detection Classify patient data at the source and inspect prompts, pasted text, and uploads before they reach external AI services.
- Gate AI use on BAA verification Require a valid BAA and documented AI handling terms before any tool is approved to process PHI.
- Separate approved tools from approved data types Allow a tool for low-risk summarisation or drafting only if policy can distinguish general clinical queries from PHI-bearing content.
What's in the full article
Cyberhaven's full article covers the operational detail this post intentionally leaves for the source:
- Data Lineage workflow examples showing how PHI movement is traced from source systems to external AI services
- Policy examples for allowing clinical AI use while blocking bulk patient data transfer to consumer tools
- HIPAA-focused decision points for BAA evaluation, audit logging, and breach assessment
- Capability details for Cyberhaven's AI Security feature set, including prompt detection and destination-based enforcement
👉 Read Cyberhaven's analysis of how healthcare teams can protect PHI in GenAI tools →
PHI in GenAI tools: are your controls keeping up with clinical use?
Explore further
PHI exposure through GenAI is really a data-governance failure, not a user-training failure. Security teams often frame these incidents as careless employee behaviour, but the repeated pattern is that people use tools that fit their workflow and bypass policy friction. When the control stack cannot see natural-language data movement, education alone cannot close the gap. The practitioner conclusion is that PHI governance must start with data visibility and policy enforcement, not awareness campaigns.
A question worth separating out:
Q: Who is accountable when PHI is sent to an AI tool without approval?
A: Accountability usually sits with the covered entity, even if the employee used the tool for convenience and the vendor's defaults were unclear. Legal, compliance, security, and data owners all have roles, but the organisation still needs an approval and enforcement model that stops unauthorised disclosure. HIPAA does not require intent to create reporting obligations.
👉 Read our full editorial: PHI exposure in GenAI tools is a governance problem, not just DLP