A discharge summary pasted for rewording. A clinic call transcribed by a bot on someone's phone. Shadow AI in healthcare is not hypothetical, it is Tuesday. The question compliance owns: which tools, which workflows, and what do the vendors' terms actually say.
Three recurring paths, each innocent at the point of action, each producing the same compliance question.
Clinical notes, referral letters and patient emails pasted into chatbots for drafting help. Names, conditions and dates travel together, which is what makes it PHI rather than prose.
Meeting bots and dictation apps hear entire consultations. Intake breadth makes this the highest-exposure path: it captures what nobody would knowingly paste.
AI features arriving inside scheduling, billing and communication SaaS the organization already uses. The vendor was assessed; the feature came later, on its own subdomain.
The common denominator: no BAA, no risk analysis, no entry in any vendor register, because nobody upstream knew the flow existed. Discovery is the control that unlocks every other control.
The report's flags map to a healthcare triage order. This is the pass a privacy officer makes on page two.
The audit itself is triage-friendly: it reads hostnames, identities and timestamps, never note content. Uploads are discarded after the run; reports are deletable before the 90-day expiry.
A multi-site outpatient group, FortiGate at each site, FSSO on staff segments. Sample data; the shape repeats across healthcare audits.
Note what did not happen: no individual clinician was disciplined for the discovery itself. Shadow AI in clinical settings is nearly always workflow pressure, and the durable fix is a sanctioned outlet plus measurement.
Generic-safe mapping to the documents healthcare compliance teams already maintain.
An observed inventory of AI flows, dated per period, is exactly the kind of "reasonably anticipated" evidence risk analyses are built from.
Tools in real use without agreements surface with user counts attached, which is the prioritization the BAA backlog needs.
When a concern arises, a targeted window export answers which tools and which identities in an afternoon, before panic sets the narrative.
The report's real findings, anonymized, make workforce training concrete: these tools, these categories, this is why the sanctioned list exists.
Cyber-liability forms now ask about AI usage controls. "Quarterly log-based audit, reports on file" is a one-line answer with attachments.
Quarter-over-quarter deltas, fewer unsanctioned tools, rising sanctioned share, document a functioning program rather than a one-off cleanup.
Three pages of sample data: flags, verdicts, per-identity rows and the control evidence statement your file wants. No signup to read it.
That determination belongs to your privacy officer and counsel per flow. What the audit settles is the factual layer: which tools, which identities, what the vendor terms said on a given date.
Vendors touching PHI in a covered workflow generally enter that conversation, and shadow tools by definition never had it. The report's user counts prioritize which vendors to approach first.
Transcription and dictation, because intake is total: whole consultations rather than selected pastes. Triage those rows first.
The audit reads hostnames, identities and timestamps; URL paths are dropped at parse, uploads are discarded after the run, and reports are deletable early. That description is written for your review packet.
Quarterly as the floor, monthly where tool churn is high. Insurer questionnaires and risk-analysis refreshes both consume the same reports.
Off-network use is outside log evidence and inside policy and training. State the scope; the on-network findings usually supply the urgency for both.
Thirty days of logs, one upload, and your privacy officer works from facts. The free preview shows the totals today.
Run the free audit