Healthcare networks are messy. Years of clinical systems, medical devices, applications, vendors and infrastructure create connections that made sense individually but collectively create far more reach than most organizations would design intentionally.
Now add AI agents.
An agent can arrive with credentials and access across multiple systems, sometimes without going through the mature intake processes we built for people, vendors or medical devices. A capability gets enabled inside an existing platform, or someone stands one up with an API key and a legitimate business need.
The technology is moving faster than most governance models. We can spend months debating who owns an agent, who approves it and who turns it off. The agent’s access doesn’t wait for that debate to finish.
So I’d start with reach.
The control isn’t new. Identity-based microsegmentation limits what an identity can reach. The principle is the same whether that identity belongs to a nurse, a workload, an ultrasound machine we can’t patch or an AI agent. Least privilege doesn’t stop being relevant because the identity is autonomous.
That enforcement point matters. Some of the hardest healthcare assets to protect are also the ones where installing another endpoint control isn’t practical. And a process with local administrative rights may be able to disable software running beside it. It cannot disable a segmentation policy enforced by the network it is using.
The fair objection is money. Healthcare doesn’t have an unlimited technology budget, and every security investment competes with clinical, operational and infrastructure priorities. The answer cannot be to create an entirely separate security architecture every time a new technology appears.
The better answer is to make the controls we already need extensible to the next identity and the next use case.
St. Luke’s University Health Network is a useful example of what that looks like at healthcare scale. Its environment included 15 hospitals, 85,000 production devices and 23,000 active users. After years of trying to solve segmentation through VLANs and firewalls, alternatives included re-IPing older devices, building another network or undertaking a lengthy consultant-led deployment.
Daniel Dopsovic, a senior enterprise information security architect at St. Luke’s, described the problem plainly: “We had been at this for ten years. We weren’t going to spend another ten.” Converting roughly 500 PACS workstations the old way had already taken well past six months. That approach simply did not scale.
Instead, St. Luke’s deployed Elisity on the network infrastructure it already owned. There was no endpoint agent to install, no new hardware and no re-IPing. Elisity classified devices by what they were rather than where they happened to sit on the network, and the team could observe what a policy would block before enforcing it. After about a month of preparation, the major segmentation buckets were in place in roughly 46 days, without network downtime.
The use case was not theoretical. Dopsovic described the old environment this way: “One bad day on one device could take the rest of us down with it.” The goal was to reduce that blast radius so a compromised identity or device could reach only the small set of systems it legitimately needed.
That also meant the organization could move faster on clinical technology. Surgical robots came online December 29 after the physician group and surgical staff had been waiting two years for them. Security didn’t have to become another reason to delay the clinical use case.
That same architecture places a boundary around an AI agent.
But that boundary matters only for what the agent can reach. Segmentation decides which paths exist. It doesn’t decide what happens on a path you’ve authorized. If an agent is legitimately allowed to reach the EHR and then behaves incorrectly inside the application, that’s not a segmentation failure. That’s where application controls, monitoring, detection and AI governance have to take over.
That’s the larger lesson for AI security. We shouldn’t have to invent an entirely new security architecture every time the identity changes.
The organization that already knows how to constrain the nurse, the workload, the vendor and the unpatchable medical device has much less left to build for the AI agent.
The technology is new. The principle isn’t: give every identity only the reach it actually needs.
Sponsored by Elisity. Elisity helps health systems see and control what agents, devices and users can reach through identity-based microsegmentation.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.