Frisco, Texas – September 30, 2026 -- Thirty-one percent of healthcare organizations experienced unauthorized identities accessing sensitive data in the past year, compared with 24% across other industries, according to new healthcare findings from Netwrix's 2026 Data and Identity Security Report. Among healthcare organizations that suffered an incident, 33% reported costs exceeding $250,000, versus 21% in other sectors.
Healthcare ranks last among 16 industries on Active Directory confidence
Only 14% of healthcare organizations said they are fully confident their Active Directory environments are free of privilege escalation risks, compared with 26% across all industries surveyed. Eighty-six percent lack full confidence in their AD security, the lowest ranking among the 16 industries with sufficient survey representation for comparison.
"In healthcare, nobody is starting from a clean slate," said Jeff Warren, Chief Product Officer at Netwrix. He noted that legacy systems underpinned by Active Directory carry decades of accumulated permissions, meaning an AI agent inherits existing access rather than access specifically granted to it.
Non-human identities are outpacing governance controls
Seventy-nine percent of healthcare organizations said their non-human identities are not fully governed. Seventy-five percent said AI and automation have increased identity-related risk to sensitive data over the past two years, and 70% said their data access governance has fallen behind the pace of AI adoption.
Most organizations cannot quickly identify who holds sensitive data access
Seventy-seven percent of healthcare organizations cannot immediately determine who has access to a specific piece of sensitive data. Sixty-one percent said resolving that question would take hours and require multiple tools. Forty-eight percent identified a compromised identity as the most common entry point for unauthorized access to sensitive data.
Darryl Baker, Senior Staff Security Researcher at Netwrix, said accounts with seemingly limited permissions in Active Directory can still provide routes to more sensitive resources through delegation and group membership relationships. He said organizations need to discover privilege escalation paths and clean up unused permissions before deploying additional AI agents or non-human identities.
Survey covered 145 healthcare respondents among 1,889 benchmarked organizations
The report is based on a global survey of 2,317 security professionals conducted in early 2026, benchmarking 1,889 organizations across more than 60 industries and 12 security dimensions. Healthcare findings draw on 145 respondents, primarily in the United States, with comparisons made against 16 industries that had sufficient representation for industry-level analysis.