AI agents can book appointments, take payments and support clinical work. Healthcare teams should give them the right access — and no more. Companion deep dive: long article.
Healthcare teams are moving past AI pilots. Agents can work out what a patient wants, pick a tool, connect to systems and take action: appointments, billing questions, payments and clinical support. That creates a new security problem. Normal software follows a fixed path. An agent does not — the path changes with the conversation. Near Protected Health Information (PHI) or payment data, the key question is least privilege, not model trust.
Three ideas for healthcare leaders
- Keep sensitive data away from the AI. On a bill-pay call, the agent needs intent and payment status — not the card number. Use DTMF or a locked digital payment flow; return only a token or “approved”. Context must be chosen on purpose, not passed by default.
- Do not use the AI as your security guard. Let the model understand language. Let fixed controls decide login, permissions and high-risk actions.
- Track what the agent did, not just what it said. Audit agent, workflow, tools, permission decisions, boundary crossings and results — without dumping PHI into logs and analytics.
For national and regional programmes, citizens still need spontaneous, dynamic answers — appointments, guidance, capacity messaging — while charts and payment data stay behind purpose-bound feeds, tokenisation and governance. A BAA (HIPAA) and AOC (PCI DSS) are starting points, not the whole design.