All systems that receive, process, transmit or store PHI, including AI tools, are subject to HIPAA Privacy and Security Rules. Unregulated third-party or “shadow AI” adoption puts up multiple roadblocks as hospital IT teams work to protect their organizations from external liabilities. A 2026 Cyberhaven AI report found that nearly 40% of employee interactions with generative AI across industries such as healthcare involved sharing sensitive data. IT teams should conduct regular audits of all AI tools across the organization to discover unauthorized platform connections before data exposure occurs. Combine this with tiered controls to block high-risk consumer AI tools while also giving employees a transparent evaluation pathway to formally request access to AI-enabled software.