Imagine a new contract nurse arriving for their first shift. They aren't just handed the keys to the entire hospital. They're vetted, given access only to the systems needed for their specific job, and monitored to ensure they're doing that job correctly. Once the contract is over, their access is immediately revoked.
Should we treat artificial intelligence any differently?
According to Fran Rosch, the CEO of digital identity firm Imprivata, the answer is a firm no. He argues that AI agents in clinical settings should be treated with the same caution as a new, unvetted contract nurse. This means they need to be carefully vetted, continuously monitored, and—crucially—cut off as soon as their specific task is complete.
This approach frames AI not as a permanent, all-knowing presence, but as a temporary tool brought in to perform a specific function. Just as you wouldn't want a temporary staffer to have indefinite access to patient records, an AI agent's access should be strictly defined and time-limited.
Why This Matters for Digital Health
At Medicup, we see this as a foundational principle for building trust in digital health. The rise of telehealth and AI-powered tools brings incredible potential, but it also brings valid concerns for patients and providers about security and oversight. The 'contract nurse' model offers a clear, responsible path forward.
When a provider on our platform uses an AI tool to help summarize a patient visit or analyze data, that tool is performing a discrete task. It needs secure, role-based access for that function and that function alone. This ensures that AI acts as a powerful assistant, augmenting the clinician's ability to provide care without introducing unnecessary risk.
For patients using telehealth, this framework provides assurance. It means the platforms they trust are built with robust security protocols, where every user—human or AI—is properly managed. By treating AI with the same scrutiny as a human team member, we can harness its power while upholding the highest standards of patient safety and data privacy.
Source: [MedCity News](https://medcitynews.com/2026/09/imprivata-ai-agents/)

