Skip to main content

Search site

Find podcasts, news, articles, webinars, and contributors in one search.

All articles

Summary

"Do They Know What AI Tools Their Clinicians Are Using?": Sebastian Estades on Why Browser Visibility Comes First

Health systems generally have strong visibility into their networks. Sebastian Estades, Senior Account Executive for Enterprise Platforms and Devices at Google, argued in a recent Google Chrome Friday conversation with Drex DeFord that the browser remains a significant blind spot, especially when it comes to AI.

Asked what question health system leaders should be asking their teams but probably aren't, Estades didn't hesitate: "Do they know what AI tools clinicians and doctors are using? How much shadow AI is out there? Some customers are asking the question, but maybe just don't have a reliable way to understand that and understand how many content transfers are happening to those sites."

Estades brings a healthcare-specific lens to that question. Introducing himself, he said: "I've been with Google just over two and a half years now. Originally came in focused on healthcare, and I have a long history of working with healthcare clients throughout my 15 years of software sales. So, extensive background dealing with Epic, Cerner, Allscripts, so on and so forth. I have a passion for healthcare, as that's what I studied in undergrad."

Why the Browser Has Become the Blind Spot

Asked where health systems face the most critical challenges around browser security, Estades named AI usage first: "A big security gap right now and a challenge that is driving most of our conversations today is around AI usage. Typically, there are blind spots there for organizations as far as user context and what's happening in the browser DOM. Most tools today rely on things having to get to the network before you see things that maybe shouldn't be happening, like copying and pasting of patient information."

He pointed to remote and unmanaged devices as another gap: "The last piece would be around the unmanaged device access. So remote access for these individuals. Depending on the organization, they allow it, they may not allow it at all, or they allow it through a virtualization technology or exposing their entire infrastructure via VPN." He framed the day-to-day version of that risk directly: "How do doctors and clinicians access specific patient files from an unmanaged device while they're home pajama charting?"

Getting Visibility Without Disrupting Anyone

Estades said organizations typically begin by deploying a browser token through existing management tools such as Intune. Once enrolled, browsers begin reporting copy-and-paste activity, uploads, downloads, and AI tool usage "with zero user impact." He noted that the change doesn't require abandoning existing policy structures right away: "You're still relying on GPO for all your policies initially until you migrate over. But just by enrolling them, there's no user impact."

That same enroll-first approach extends to keeping browsers current. With Chrome now on a two-week release cycle, Estades said some organizations "have challenges around just keeping up with managing those updates with their ADMX files and GPO policies," which is why some move to a cloud console to manage updates centrally, using the same platform that provides visibility into browser activity.

Throughout the conversation, Estades consistently returned to visibility before enforcement: "That's how we start with all customers. Even if they've already decided they're going to do secure browse and they already know what the use cases are, usually the first step is let's just enroll all your browsers, pull reporting, understand what's going on, and then see if our assumptions were correct."

The ROI Argument, According to Estades

On the business case CIOs bring to CFOs, Estades described tool consolidation: "There is a tool consolidation piece with a secure browser offering. We're taking elements of a SASE solution, some native DLP solutions, and baking them into the browser. While not every customer will be able to eliminate everything, they may be able to draw down on the cost of those tools. Maybe less licensing, maybe a different license tier."

He also described a VDI angle for systems leaning on virtual desktop infrastructure: "Secure browser presents a different way to securely deliver these critical applications in a way that doesn't have the backend infrastructure cost that you see with virtualization." That's the logic, he said, behind Google's partnerships with Citrix and Omnissa: "Who both have our solution as part of their stack as a way to help customers save costs on the infrastructure, where it makes sense to."

Estades argued that while cost savings help justify the investment, organizations first need visibility into what's actually happening in the browser before they can build a policy or a budget around it.

Visibility First

Near the end of the conversation, Drex offered the line that captured the whole discussion: "You can't protect it if you can't see it, if you don't know what's happening, right? That's really the bottom line." Estades' reply was simple: "Exactly."

If health systems don't know where clinicians are actually using AI, they can't govern it.

Thank You to Our Article Partner

Google Chrome

Found this useful? Share it with your network

Explore more on this topic

Related articles, news, and podcast episodes