Coalition for Health AI launches cybersecurity work group to address AI threats

Coalition for Health AI launched a cyber work group with nearly 100 leaders to create AI threat playbooks. Resources for hospitals, payers and tech firms arrive by end of 2026.

Categorized in: AI News Healthcare
Published on: Aug 14, 2026
Coalition for Health AI launches cybersecurity work group to address AI threats

The Coalition for Health AI has launched a Health AI Cybersecurity Work Group that will meet biweekly to build playbooks and develop a frontier AI cyber risk assessment tool for health systems, payers and health tech companies. The group, which includes nearly 100 industry leaders, aims to release the resources by the end of 2026 to help healthcare organizations respond to emerging AI threats and deploy frontier models for defense.

The announcement follows the release of Anthropic's Mythos-class frontier models, including the public Fable variant released June 9. CHAI said Mythos-class capabilities could compress attack timelines, industrialize the exfiltration of protected health information, and ramp up ransomware attacks. The same capabilities offer defense teams unprecedented help with vulnerability management and incident response.

Individual hospitals and health plans cannot keep pace with these threats alone, according to Errol Weiss, chief security officer of Health-ISAC and a member of the work group's leadership council.

"Health sector cybersecurity is a team sport," Weiss said. "What makes CHAI's Health AI Cybersecurity Work Group so important is that it brings together health systems, technology companies and industry organizations to develop practical guidance we can all use to reduce risk before incidents occur."

This initiative builds on CHAI's efforts to develop governance frameworks and tools for trustworthy AI adoption. Last month, CHAI announced an initiative to engage public health agencies on generative AI to improve data usability. In May, CHAI released AI governance playbooks aligned with the Joint Commission's Responsible Use of AI in Healthcare certification.

Industry response

Ed Gaudet, CEO and founder of security firm Censinet, said the speed of change means most organizations cannot respond alone, and third parties multiply the exposure. "Frontier-latest AI models are changing the speed, scale and sophistication of cyber threats faster than most healthcare organizations can respond, and third parties can multiply that exposure," he said in a statement.

Weiss recently participated in Operation Critical Signs, a national tabletop exercise testing the healthcare sector's response to major cyber disruptions, with more than 500 participants. He said the exercise showed that organizations are eager to collaborate and compare approaches, and the new CHAI initiative is about turning that cooperation into practical best practices.

Isaiah Nathan, senior vice president and chief information security officer at Delaware Valley Community Health and a work group leadership council member, said the stakes are highest for less-resourced organizations. "As AI rapidly transforms our industry, it also brings new speed, common ground," he said. "On the ground in a health system, it suggests a new playbook is needed."

AI in Healthcare - The work group includes community hospital systems, academic medical centers, health plans, and technology and cybersecurity companies. The goal is to produce guidance and tools that organizations of any size can actually adopt, according to CHAI.

Cyber defense roles

CHAI's playbooks align with the Joint Commission's Responsible Use of AI in Healthcare voluntary AI safety certification. The playbooks cover organizational AI policy, organizational structure, and organizational resources.

Healthcare organizations evaluating AI for Cybersecurity Analysts - and whether the same AI that increases risk can also be an effective defense.

"As a provider-led community committed to responsible AI in health, we play a critical role in keeping patients, staff, data and operations safe from emerging threats through information sharing, playbooks, resources and tools that enable meaningful action," said CHAI CEO Brian Anderson. "We are convening cyber experts across healthcare, including community hospitals, academic medical centers and our technology and cybersecurity ecosystem, because preparing for cyber vulnerabilities is critical and urgent."

Anderson said preparing for cyber vulnerabilities is urgent across health systems of all sizes.

Why this matters for healthcare professionals

The realistic time between AI threat emergence and exploitation is shrinking, just as collaboration is becoming the cornerstone of sector-wide defense. For healthcare IT and security professionals who work with hospitals, payers, or vendors, the group lets you adopt a developed playbook to prep your staff, vendor risk reviews, and incident response protocols earlier than the next major event. The focus is on practical actions, not theory: follow developed best practices, compare your AI defense environments, and allocate effort to the same technologies that help attackers - applied to defense.


Get Daily AI News

Your membership also unlocks:

700+ AI Courses
700+ Certifications
Personalized AI Learning Plan
6500+ AI Tools (no Ads)
Daily AI News by job industry (no Ads)