The Coalition for Health AI has launched a cybersecurity work group to develop defensive playbooks for healthcare organizations facing AI-powered attacks that can unfold in seconds. Dr. Brian Anderson, CEO of the Coalition for Health AI, said frontier AI models can identify network vulnerabilities and compress cyberattacks that previously took days or weeks into minutes or even milliseconds, forcing healthcare security teams to plan for automated responses.
"With these kinds of frontier models now, what we are hearing from cybersecurity efforts, what our CISOs at health systems are hearing, is that there is a significant amount of time compression in these kinds of attacks, where it previously might have taken days or weeks, it's now seconds, or minutes, or even milliseconds," said Anderson, a physician and former MITRE digital health lead.
The workgroup, which already has nearly 100 members, will publish an initial public version of guidance in December. Documents will include a defensive playbook, an offensive playbook, risk-assessment tools for frontier AI, and reference implementations with technical steps for security leaders. Some highly technical material may require vetting before access, Anderson said.
Why that's a problem
When an attack's lifecycle is reduced to milliseconds, a human being standing by to respond simply can't keep up. Anderson described the need for "AI operating in a semi-autonomous, defensive posture" to handle these attacks.
"So, when we think about that time compression, the need to have a level of automation... is a very real consideration that we need to begin planning for and developing strategies and operational playbooks for," he said.
In the healthcare context, a fast-moving attack is not just a data breach. It can take down clinical applications and force hospitals offline. The workgroup is also focused on protected health information leakage, ransomware, and clinical downtime, which are specific risk categories that come when AI and agentic tools fetch external data.
Who is building the playbooks
The workgroup's leadership council includes CISOs and security experts from health systems and payers, as well as representatives from industry groups like the Health Information Sharing and Analysis Center. The council will oversee development to make sure the resources for hospitals and clinics keep pace with emerging threats.
"We don't intend to leave this and move on to the next thing," Anderson said, describing the guidance as ongoing work that includes a constant tempo of updates.
That's a notable design choice in a space where one-off risk frameworks are common. The playbuilds will also prioritize rural and safety providers, who often have smaller IT teams and fewer security tools, and would benefit from shared operational playbooks.
The coalition is building on existing frameworks rather than starting flat-footed. This is important because many healthcare systems already have NIST frameworks or internal security policies and need guidance for how to integrate AI-defense within their existing controls. The niche here is in providing guidance that applies those general standards to specific health sector vulnerabilities.
training professionals who specialize in the hands-on defensive skills healthcare teams need, collectively known as AI for Cybersecurity Analysts, will have roles to play in building and maintaining these automation and response functions.
Playbook implications for health teams
Even if your security team isn't in the coalition's working group, the group's December release will affect your plans. Here is why it matters for your day-to-day:
- You're being asked to prepare for machine-speed attacks that have longer incident-response windows, so static controls like annual security audits cannot account for the new reality.
- Your leadership should throw its support behind building an automation or AI-assisted response capability at your security operations center before the first attack.
- There will be a place for AI models in healthcare security - the operational staff to man these models, curve and verification, and politics - so watch for gaps in team skills and lean on AI for Healthcare training as your organization changes direction.
Smaller providers, especially in rural areas, stand to gain from real, standardized playbooks. Without them, a one-person security team is becoming the default first line of defense against a technology-enabled attacker that can still hit "run" in milliseconds.
Your membership also unlocks: