Health · AI
Guide

Your AI agents can access your patient records. Can you prove they should?

Most healthcare organisations deploying agentic AI have inherited a critical identity gap: permissions no human deliberately approved, because the identity architecture was built for people, not machines.

HealthAIIdentityAgentic AIPrivacy
Inside the guide
  1. 01Why the identity architecture behind clinical systems was built for people, not machines
  2. 02Where identity drops out of the request chain
  3. 03What the Privacy Act's automated decision-making rules require, and what they do not
  4. 04Why Australia's health identifiers can trace a patient but not the agent that queried them
  5. 05What a correctly architected agent-identity gateway looks like
  6. 06Six actions to take before your next AI deployment goes live

Full guide delivered to your inbox

What the guide covers

Why the identity gap exists, and why closing it can't wait

Agentic AI is already scheduling appointments, summarising clinical notes, triaging referrals, and querying patient records across Australian healthcare. Each of those actions touches sensitive data, and in most deployments, the clinical system receiving the request has no reliable way to know who authorised it, which agent made it, or whether the access sat within the scope of the original privacy impact assessment. This article explains why that identity gap exists, why neither national policy nor the vendor market has closed it yet, and what a correctly architected agent-identity gateway looks like in practice, before the Privacy Act's automated decision-making disclosure rules land in December 2026.

What's inside

Includes the full architecture breakdown of where identity is lost in agentic healthcare workflows, an explanation of the Privacy Act's incoming automated decision-making disclosure rules, and a six-step checklist for closing the identity gap before your next AI deployment goes live.

Get the full guide
Delivered to your inbox. Name and email only.

No noise. Unsubscribe anytime. Your details are used only to deliver this guide and occasional Lumaris insights on the same topic.

95%
Of health care and social assistance incidents ASD's ACSC responded to in FY2024-25 saw the attacker succeed, versus 52% across all sectors.
Source: ASD Annual Cyber Threat Report 2024-25.
109:1
Machine identities for every human identity in the average enterprise, up from 82:1 a year earlier.
Source: Palo Alto Networks, 2026.
10 Dec 2026
When the Privacy Act's automated decision-making disclosure rules (APP 1.7-1.9) commence for Australian organisations.
Source: Office of the Australian Information Commissioner (OAIC), 2026.

Martin Barnier

Principal Consultant · Lumaris Consulting

Martin is a strategy, architecture, and technology leader with over a decade of experience helping public and private sector clients securely evolve their digital services. Martin consults at the intersection of AI, cyber security, and enterprise transformation; advising clients on risk, designing architectures, and leading delivery across complex regulated environments.

View LinkedIn profile
Before you download

Questions about this guide

It is written for CISOs, CIOs, and heads of AI at Australian healthcare organisations that are deploying or evaluating agentic AI systems. It assumes the reader understands what AI agents are but has not yet addressed the identity governance gap they create.

The Privacy Act's automated decision-making disclosure rules (APP 1.7-1.9) commence on 10 December 2026. Organisations that cannot trace which AI agent accessed which record, under whose authorisation, will not be able to meet the disclosure obligation credibly.

Yes. The identity gap is the same regardless of whether the AI agent was built in-house or supplied by a vendor, because the clinical system still cannot answer who authorised the access without a correctly architected identity gateway in place.

Map every AI agent's access to identifiable patient data and name an accountable owner for each one. Without that inventory, none of the other remediation steps, including scoped credentials and policy-as-code enforcement, can be sequenced or prioritised.

Let us talk

If the guide surfaces something you want to work through, that is a good place to start.

Most conversations begin simply. Someone wants to know whether we are the right fit for what they are navigating. That is a perfectly good starting point.