Just announced!
∙
Download The Physicians Guide to AI, a new book from Offcall and MD+.Download here.
  • Products
      • Salary
      • Referrals
  • Learn
  • About
Offcall Footer Background
ProductsSalaryReferrals
ResourcesLearnAboutContactFix Referrals ManifestoPrivacy PolicyTerms and Conditions
Apps
apple

Download on the

App Store
google

GET IT ON

Google Play
In the browser
Follow us
Sign up for Offcall's newsletter
Copyright © 2026 Offcall All Rights Reserved
Articles

Shadow AI in Healthcare: The 17% Problem and How to Fix It

Offcall Team
Offcall Team
  1. Learn
  2. Articles
  3. Shadow AI in Healthcare: The 17% Problem and How to Fix It

Every health system has an AI policy. Many of them are being quietly ignored. In a December 2025 Wolters Kluwer Health survey of 518 providers and administrators, 17% admitted to using unapproved AI tools in their clinical workflow. More than 40% said they knew a colleague doing the same. And when researchers asked those providers why, 45% gave the same answer: the sanctioned tools are too slow.

That is shadow AI in healthcare. It is not a story about rule-breaking clinicians. It is a story about workflow friction, and it was one of the sharper threads running through Offcall's recent AI Morbidity and Mortality webinar with Dr. Graham Walker, Dr. Michael Hobbs, and Dr. Kai Romero of Evidently. The overview article from that session touched on the compliance question briefly. The problem deserves its own treatment, because it is quietly becoming one of the most consequential governance issues in medicine.

Sign up for our newsletter

On/Offcall is the weekly dose of information and inspiration that every physician needs.

The 17% Number That Should Worry Every Health System

The headline statistics are striking on their own:

  • 17% of providers and administrators admitted using unapproved AI tools
  • 45% of those providers said the reason was a faster workflow
  • 40%+ of staff know a colleague who does it

These numbers are self-reported, which means the real figures are almost certainly higher. People do not volunteer policy violations in surveys at a rate greater than the actual violation rate.

Why "faster workflow" is the real root cause, not negligence

The temptation when a compliance officer sees these numbers is to assume the problem is clinician discipline. The data says otherwise. Nearly half of the providers using shadow AI identified speed as the driver, which means the sanctioned alternative existed, they knew about it, and they chose a different tool because the approved one got in the way of patient care.

That is a design problem, not a character problem. A clinician staring down a 40-patient day who has to choose between a slow approved tool and a fast consumer tool is going to make the predictable choice some percentage of the time. The question for every health system is whether that percentage is 2% or 25%, and whether the leaders know which it is.

Why Shadow AI Is a Design Problem, Not a Discipline Problem

Dr. Kai Romero made a comparison in the webinar that reframes how to think about this. She described working with LLMs as not dissimilar from working with an early trainee:

"It's not dissimilar in my mind from working with like an early trainee where they really want to make you happy. There's a lot on the line, like they want to do as best as they possibly can and they don't know where the pitfalls are." — Dr. Kai Romero

The same framing applies to the clinicians reaching for consumer AI tools. They are not trying to breach HIPAA. They are trying to finish their notes before their kid's bedtime. The tool that lets them do that wins, every time, unless the approved alternative is genuinely competitive on speed and ergonomics.

The intern analogy and what it means for governance

An intern who takes shortcuts because the approved workflow is broken is a signal about the workflow, not the intern. The right response is to fix the workflow. The same logic applies to shadow AI. If 45% of your clinicians using unapproved tools are doing it for speed, the sanctioned tool is the problem.

What changes when agents enter the picture

The old shadow AI risk was straightforward: a clinician pastes identifiable patient information into ChatGPT. The data leaks at the moment of the paste. Agents change the surface area entirely. A clinician who connects their email, their calendar, or their EHR to an agentic AI tool is no longer leaking what they paste. They are leaking what they connect. As the webinar slide put it bluntly:

"With chatbots, PHI leaks when you paste it. With agents, it leaks when you connect it." — AI M&M slide deck

That shift matters because connections persist. A single approval grants ongoing access. The chance to catch the leak at the moment of the action disappears.

The Four Questions to Ask Before Any Clinical AI Tool Touches a Patient

The webinar surfaced a simple pre-flight checklist that any clinician can run through before putting PHI anywhere near an AI tool. These are not legal advice. They are the questions that would have prevented most of the shadow AI incidents that have made the news in the last 18 months.

1. Is there a BAA?

A business associate agreement governs how the vendor handles your data. Critically, the BAA sits with the account, not the model. A ChatGPT Enterprise seat may have one. A personal ChatGPT Plus subscription does not. The model behind both is the same. The compliance posture is not. The account matters more than the model.

2. Is it really de-identified?

De-identification is harder than it sounds in pediatrics and rare disease work. A birth date, a school, and a rare diagnosis can collectively identify a single child. Stripping the name is not sufficient. The question to ask is whether the combination of fields you are entering could narrow the universe of possible patients to a small enough group to re-identify.

3. What can it reach?

If the tool is connected to your email or your calendar, it can read all of it. If it is an agent with EHR access, it can touch everything that account can touch. The question is not what you intend to show the tool. The question is what the tool can see once you grant it access.

4. Is there a sanctioned tool?

If there is one, use it. If it is too slow, tell the people who run it. Dr. Graham Walker made this point directly during the session:

"Don't put real data into any of these models." — Dr. Graham Walker

Clinicians who silently route around the approved tool guarantee that the next version of that approved tool will not be any better, because nobody with budget authority knows there is a problem.

A Practical De-Risking Playbook

For individual clinicians and for the people responsible for AI governance, the response to shadow AI should look less like enforcement and more like product management.

  • Build sanctioned tools people actually want to use. If the approved scribe takes three extra clicks per note compared to the consumer alternative, those clicks are the problem. Fix them.
  • Give clinicians a legitimate sandbox for synthetic cases. Dr. Hobbs built his entire 140-answer benchmark on synthetic pediatric cases. The webinar explicitly encouraged clinicians to generate their own test cases with AI, edit them for realism, and run them through whatever tool they are evaluating. That is a safe way to kick the tires. It should be the default path, not a workaround.
  • Report, don't punish, when shadow use surfaces. The 17% number only moves if the clinicians using unapproved tools feel safe telling you why. The ones who get fired for admitting it will teach their colleagues to lie.
  • Separate the compliance question from the clinical reasoning question. A detail that is permissible to discuss conceptually with an AI tool is not the same as a chart that is permissible to paste.

The Bottom Line on Shadow AI

The 17% is a leading indicator, not a trailing one. The number will rise as AI tools get better, faster, and more deeply embedded in the apps clinicians already use. Health systems that treat shadow AI as a workflow problem will reduce it. Health systems that treat it as a discipline problem will drive it underground and lose the ability to see what is actually happening on the ground.

The clinicians doing this are not villains. They are telling you something about your sanctioned tools. The question is whether you are listening.

Resources and Links

  • Kai Romero, MD on LinkedIn
  • Michael Hobbs, MD on LinkedIn
  • Graham Walker, MD on LinkedIn
  • Evidently on LinkedIn
  • The Physicians Guide to AI (free, from Offcall and MD+)
  • The Poland water-monitoring clams: Dr. Walker swore they were real, and they became the session's unofficial mascot for choosing the right tool for the job
Medical background
downloadDownload to join the waitlist

Medicine med icon is complex enough.
Referrals referral icon shouldn't be.

Send and receive referrals, build wealth, and grow your physician community with Offcall.

apple

Download on the

App Store
google

GET IT ON

Google Play
Offcall Team
Written by Offcall Team

Offcall Team is the official Offcall account.

Comments

(0)

Join the conversation

See what your colleagues are saying and add your opinion.

Trending


17 Sep 2026Cut Out the Middleman, Keep the Patients: Dr. Chloe Kindred on Building a Direct Primary Care Practice From Zero
0
117
0
10 Sep 2026These Physicians Explain Why They'd Never Go Back to Being Employed
0
83
0
24 Sep 2026How Dr. Keith Matheny Turned His Practice's Biggest Headaches Into Businesses, While Still Seeing Patients
0
70
0