Netwrix Finds Healthcare Identity Security Gaps
Netwrix healthcare findings show 79% of organizations do not fully govern non-human identities, while 31% reported unauthorized access.

Netwrix has released healthcare findings from its 2026 Data and Identity Security Report, reporting that 79% of healthcare organizations do not fully govern non-human identities. The survey found that 31% of healthcare organizations had unauthorized identities access sensitive data in the past year, compared with 24% in other industries. Among healthcare organizations that experienced an incident, 33% placed the cost above $250,000, versus 21% in other industries. The research also found that 86% of healthcare respondents lacked full confidence that their Active Directory environments were free of privilege escalation risks.
AI Adds Identity Risks
Netwrix’s healthcare findings show that 75% of respondents believe AI and automation have increased identity-related risk to sensitive data over the past two years. Seventy percent said their data access governance is behind the speed of AI adoption.
“In healthcare, nobody is starting from a clean slate. These environments are built on decades of legacy systems, typically underpinned by Active Directory and all the permissions that have accumulated in it. Instead of inheriting the access you meant to give it, an AI agent inherits what's already there.”
Access Visibility Remains Limited
Seventy-seven percent of healthcare organizations surveyed said they cannot immediately determine who has access to a particular piece of sensitive data. Sixty-one percent said identifying access would take hours and multiple tools, while 48% identified a compromised identity as the most common starting point for unauthorized access to sensitive data.
Healthcare ranked lowest among 16 industries for confidence in Active Directory security. Just 14% of respondents were fully confident that their Active Directory environment was free of privilege escalation risks, compared with 26% across all industries.
Active Directory Assessment Tool
Netwrix offers Netwrix PingCastle, a tool that assesses Active Directory environments for security risks and provides remediation guidance. The company says accounts with limited permissions can still have routes to more sensitive resources through delegation and group membership, while permissions no longer needed can obscure those paths.
“Before adding more AI agents and other non-human identities, healthcare organizations need to understand the access that's already there. An account can appear to be pretty limited and still have a route to something much more sensitive. Proactively discovering privilege escalation paths and cleaning up permissions give you a much clearer view of what you're handing to a new identity.”
Survey Scope And Access
The report is based on a global survey of 2,317 security professionals conducted in early 2026. It benchmarked 1,889 organizations across more than 60 industries and 12 security dimensions. The healthcare findings draw on responses from 145 healthcare respondents, primarily in the United States.
From an announcement by Netwrix.


