CHAI launches work group to write healthcare cybersecurity playbooks for frontier AI threats
The Coalition for Health AI (CHAI) launched a new work group that is developing playbooks and tools to help providers, payers and tech companies in the healthcare sector address the new cybersecurity threats that come with frontier AI models. Frontier models like Claude Mythos bring not only more powerful capabilities in coding and other types of knowledge work but also the potential for greater cyber threats.
Anthropic’s Project Glasswing and OpenAI’s Project Daybreak are collaborative initiatives aimed at developing cyber defense capabilities that keep up with evolving cyber threats. These projects generated excitement among healthcare CISOs, but they wanted something more, according to CHAI CEO Brian Anderson, MD. “This chorus of voices really began advocating for a health sector-specific effort that took into account all of the unique ways that the health sector confronts cybersecurity,” he said.
The CHAI work group came together to be that industry-specific effort. It has nearly 100 participants from across the healthcare ecosystem led by a leadership council with members from academic medical centers, community hospitals, industry groups and technology companies.
Developing a new set of playbooks
Healthcare CISOs and other security leaders share many of the same worries that their counterparts in other industries have. Randy Arvay, PhD, CTO and CISO of Duke Health and a member of the work group’s leadership council, counts generative AI-enhanced attacks, identity security and third-party risk among his top concerns.
But healthcare cybersecurity has the additional demands that come with protecting highly targeted protected health information (PHI) and avoiding clinical downtime that could cost lives. AI makes defending against the attacks that compromise PHI and disrupt operations increasingly difficult.
“I know everyone thinks AI is an enabler, and it is, but it has enabled the wrong side of the attack surface. That’s where we’re trying to catch up,” Arvay told DHI.
The CHAI work group is meeting every other week to develop a collection of deliverables that will be released by the end of the year, Anderson shared. One of these resources will be an operational playbook for health system and payer CISOs. How can they integrate AI tools into their cybersecurity strategy?
Another playbook will focus on defensive strategy. Where should healthcare security leaders focus their efforts as bad actors seek to turn new AI models’ capabilities against their organizations?
“An example might be the use of an agent in a semi-autonomous or autonomous manner to respond at the millisecond level to the kinds of penetration and exploits that these new Mythos class models are capable of,” Anderson said.
The group also plans to create policy briefs and playbooks to help CISOs identify and mitigate risk in their organizations.
Members will be draw on their expertise as leaders of large health systems, community hospitals and cybersecurity companies to develop these resources. For example, Arvay and his team at Duke Health are going to help with the technical components of the offensive and defensive playbooks.
Work group members with major health systems and cybersecurity companies may get early access to frontier models, enabling them to offer valuable insight into the development of offensive and defensive capabilities. Other members will be able to draw on their experience of participating in Project Glasswing and Project Daybreak, according to Anderson.
Elevating cybersecurity across the healthcare ecosystem
An attack on one entity can have cascading effects throughout the industry’s supply chain. But not all organizations have access to the same level of resources to defend against cyberattacks, a reality the CHAI work group recognizes.
“We do not want to have this content only speak to the cybersecurity experts at leading academic medical centers or very well-resourced urban health systems and hospitals,” Anderson said. “If we did that, this would be a failure.”
The group is working to engage CISOs at regional community health centers and rural hospitals. The goal is not to release playbooks that recommend huge cost expenditures, according to Arvay. Rather, the group wants to offer a series of actionable best practices with technical depth.
While the work group is focused on the near-term goal of developing and releasing these resources, the cyber threats AI poses are ongoing. Anderson hopes to see stakeholders across the health care sector adopt best practices like these.
“CISOs don’t operate in a vacuum,” he said. “I would imagine a future where the products that are being developed and made available to the CISOs are going to be based off of these best practices.”