5 min readSanitized AI Team

Shadow AI in Clinical Workflows: The Blind Spot EMR Security Misses

Shadow AIData PrivacyCompliancePIIHealthtech

A nurse practitioner finishes a complex visit, opens a new browser tab, and pastes the encounter note into ChatGPT to draft a clean referral letter. The note includes the patient's name, date of birth, a diagnosis, and a medication list. The referral comes back polished in seconds. The EMR sitting in the tab next door — with its role-based access, audit logs, and encryption at rest — recorded none of it. The protected health information just left the organization's control, and there is no way to pull it back.

This is the gap in clinical data security that most health organizations haven't measured. Enormous effort goes into securing the electronic medical record: access reviews, break-glass logging, integrations vetted for PHIPA and Bill C-27 alignment. All of that governs data inside the system of record. None of it governs the prompt box a clinician reaches for the moment the EMR doesn't do what they need fast enough.

Why EMR security can't see the prompt box

EMR security is built around a boundary: the system of record and its sanctioned integrations. Everything flowing through that boundary is logged, permissioned, and defensible. The assumption underneath it is that PHI moves between known systems along known paths.

Generative AI breaks that assumption. The clinician copies text out of the EMR — a legitimate, invisible act — and pastes it somewhere the EMR has no relationship with. From the record's perspective, nothing happened. No integration fired, no export was logged, no policy triggered. The data simply appeared in a public tool through the most ordinary interface in computing: copy and paste.

This is why so much AI usage goes unseen. LayerX's 2025 research found organizations have zero visibility into roughly 89% of AI usage, and that 82% of the data pasted into AI comes from unmanaged, personal accounts. In a clinical setting that means the referral letter, the discharge summary, the insurance appeal — all drafted in a personal ChatGPT tab that no health IT dashboard will ever surface. Netskope's 2025 data puts a number on the exposure: the average organization logs around 223 sensitive-data policy violations a month through GenAI apps, and 54% of those involve regulated data.

The workflows where PHI actually leaks

The risk isn't abstract, and it isn't malicious. It's the natural result of overworked people using the fastest available tool. Consider where it shows up:

A scheduling clerk pastes a batch of patient names and phone numbers into an AI tool to reformat them into a call list. A researcher drops a de-identification-in-progress dataset into a chatbot to spot outliers — before the identifiers are actually stripped. A physician summarizes a lengthy chart into plain language for a family, pasting the full history to get a readable paragraph back. An admin uploads a spreadsheet of billing records — SINs, dates of birth, diagnosis codes — to have AI find the anomalies.

Every one of these is someone doing their job well, under pressure, with the best tool at hand. Cyberhaven's 2025 analysis found that roughly 40% of AI interactions involve sensitive data, and that the sensitive share of corporate data going to AI has climbed to about 35% — up from around 11% two years earlier. Healthcare sits at the sharp end of that trend: high data sensitivity, heavy regulation, and clinicians who already live in browser-based SaaS all day.

The stakes are not theoretical either. IBM's 2025 Cost of a Data Breach Report puts healthcare at the highest average breach cost of any sector — $7.42M — and found that breaches involving high levels of shadow AI cost about $670K more on average. The same report notes that 97% of organizations with an AI-related breach lacked proper AI access controls.

Why the answer isn't another ban

The instinctive response is to block the tools. It doesn't work, and health leaders have watched it fail before. When Samsung banned ChatGPT in 2023 after engineers pasted source code into it, the ban came only after the data was already gone — and the lesson generalizes: bans push usage onto personal devices and personal accounts, where visibility drops to zero. Gartner found that 88% of employees with enterprise AI access also use personal AI tools for work.

A clinician who can't use AI on a work login will use it on their phone during a break. The data still leaves; you just stopped being able to see it. And a ban punishes the productivity gains that make AI worth having, so people quietly route around it and stop telling you what they use.

Governance beats prohibition. The controls that actually reduce PHI exposure work at the level of the data, not the tool: catch the sensitive content in the prompt before it's submitted, and — crucially — explain to the person in the moment what was flagged and why. Redacting the identifiers while letting a realistic placeholder version through means the AI still returns a usable referral letter, so nobody has a reason to route around the control. Each flagged prompt becomes a small piece of training, and over time the workforce gets measurably better at safe AI use. Leaders get a view of where AI risk concentrates — a record of the policy event, never the patient data itself.

This is the principle Sanitized AI is built on: sensitive data should be caught before a prompt ever reaches a public AI tool, because once PHI is submitted, there is nothing left to control.

The question to ask this quarter

Your EMR audit tells you who read a chart. It tells you nothing about whether that chart was pasted into a public AI tool an hour later. Those are two different security surfaces, and most health organizations have only instrumented one of them.

The practical step this quarter is to find out what's actually happening in the browser tab next to the EMR — not by surveying staff, who under-report, but by looking at whether PHI can leave through the prompt box at all. If you can't answer that, your clinical data governance has a blind spot exactly where your busiest people are working. If you'd like to see how catching PHI before it leaves works in practice, request a demo.

See how Sanitized AI stops sensitive data from leaving the prompt box.