Artificial Intelligence, Health Tech, Providers

Imprivata CEO: AI Agents Need the Same Scrutiny as an Unvetted Contract Nurse

Imprivata CEO Fran Rosch said AI agents should be treated similarly to the way hospitals treat a new contract nurse — vetted, monitored and then cut off as soon as the job is done.

A digitally generated image featuring an old-style computer monitor displaying the letters “AI” with neon business crowd. The scene blends retro computing with modern business aesthetics, symbolizing the journey of artificial intelligence from its early beginnings to its growing role in today’s corporate world. Ideal for illustrating themes of digital evolution, business transformation, AI adoption, and technology-driven innovation.

Healthcare providers have spent years figuring out how to grant strangers — such as a contract nurse called in an hour before shift or a remote vendor logging in from another country — just enough access to do their job safely. 

Imprivata CEO Fran Rosch thinks AI agents should be treated exactly the same way — as untrusted third parties that need to be vetted, watched and cut off the moment their work is done. 

“We can simply just think of an agent the same way you would think of that contract nurse. You don’t know him or her. You’ve never met them before. They’ve been recommended to you. How do you go through quick identity proofing? How do you give them credentials? How do you give them access to just what they need to do their job? How do you monitor access? Because you don’t really know them or trust them to be able to audit and identify behavioral matters that indicate risk. How do you revoke access? Are you ready to be able to do that?” Rosch said Thursday during a media lunch held in Manhattan.

presented by

He noted that this type of thinking is central to the pitch at Imprivata, which is a vendor for cybersecurity and digital identity tools. 

Instead of asking hospitals to buy and deploy an entirely new product for AI agents, Imprivata is extending a privileged access security gateway that it already runs for its highest-risk human users, like administrators and outside vendors, to also govern agents.

This approach considers the fact that most providers are stretched thin financially and reluctant to take on new vendor relationships and implementation projects, Rosch added. 

He pointed to a health system visit earlier that day as a typical example: the leadership wanted to extend the tools they already have before buying something new. 

presented by

About a dozen health systems are currently working with Imprivata as design partners, testing the approach before it becomes something hospitals have the budget to adopt more broadly. 

Rosch was candid that the market is still early. The model is well-established for human users but not widely deployed yet for agents.

Still, Rosch said Imprivata isn’t alone in pursuing this model, and he expects this approach to agentic AI security to look fairly standard industry-wide once health systems start budgeting for it. 

But for now, he sees Imprivata’s job as getting ahead of a problem most hospitals haven’t had to solve yet.

Photo: akinbostanci, Getty Images