The Coalition for Health AI convened a Health AI Cybersecurity Work Group on August 12: nearly 100 health system, payer, and industry members, guided by a leadership council of 14. Duke Health, Johns Hopkins, Boston Children's Hospital, Centene, Rubrik, Censinet, and Health-ISAC hold council seats. The group meets every two weeks and owes three deliverables by the end of 2026: a defensive playbook, an offensive playbook, and a frontier AI cyber risk assessment tool. CHAI chief executive Brian Anderson called preparing for cyber vulnerabilities critical and urgent.
MedTech Dive ties the group's formation to frontier models released this spring that can identify vulnerabilities and convert them into working exploits on their own. John Flores, CISO at the University of Texas Medical Branch, said advances in AI fundamentally change the threat level. Hospitals addressed 6 percent of identified cyber risks in the first quarter of 2026, down from 23 percent a year earlier, per Fortified Health Security. Device makers should read the risk assessment tool in draft, because hospital procurement teams will score against it within a year.