Dive Brief:
- The Coalition for Health AI has convened a work group of nearly 100 health system, payer and industry leaders to address cyber risks associated with frontier artificial intelligence models, the nonprofit standards organization announced Wednesday.
- The group will meet biweekly with the goal of creating and publishing health AI cybersecurity guidance by the end of 2026. Deliverables include an AI cyber risk assessment tool and playbooks covering both defensive and offensive security strategies.
- Anthropic’s release of its advanced Mythos and Fable AI models this spring “fundamentally changed” the cyber threat landscape for healthcare, and was a catalyst to stand up the work group, CHAI said.
Dive Insight:
CHAI, which regularly produces frameworks for the responsible use of health AI, said it convened the new work group with the goal of helping healthcare organizations respond to an advanced form of AI that has the potential to completely change how organizations protect their critical systems from cyberattacks.
Frontier models, such as Anthropic’s Claude Mythos and its publicly available iteration, Fable, represent the most powerful AI systems available today — they can think through complicated tasks, handle massive amounts of information and work independently without constant human guidance. In the case of Mythos, it also can autonomously root out cybersecurity vulnerabilities and turn them into working exploits.
For healthcare organizations, these advanced models pose a serious opportunity — and a serious concern. When publicly available, they can be leveraged both by defenders and by hackers.
"Health systems have always faced cybersecurity challenges, but today's advancements in AI fundamentally change our threat level,”John Flores, chief information security officer at the University of Texas Medical Branch, said in a statement.
Flores is one of 14 leadership council members for CHAI’s new work group who will spearhead the group’s efforts. He is joined by representatives from other health systems, like Baptist Health and Duke Health, as well as health tech and cybersecurity company executives and professionals from cyber threat information sharing and standards organizations.
Healthcare organizations have faced a high volume of cyberattacks and data breaches in recent years. Cyberattacks can lead to patient care disruptions, including ambulance diversions, cancelled appointments and surgeries, and electronic health record systems taken offline.
Hospitals addressed just 6% of identified cyber risks in the first quarter of 2026, a steep decline from the 23% of risks addressed in the first quarter of 2025, according to cybersecurity company Fortified Health Security. The volume of cybersecurity vulnerabilities being discovered now exceeds healthcare organizations' capacity to fix them.
Although advancements in AI have the potential to help healthcare organizations detect and respond to threats faster, it also allows threat actors to increase the speed, volume and effectiveness of their attacks.
“We need to ensure that all parts of healthcare, including systems of all sizes, are equipped to handle the downsides that come along with technological advances,” Isaiah Nathaniel, senior vice president and chief information security officer at Delaware Valley Community Health and a leadership council member, said in a statement.