The work group will develop playbooks and risk assessment tools to help healthcare organizations defend against advanced model risks.
The Coalition for Health AI (CHAI) announced the formation of a new Health AI Cybersecurity Work Group to help healthcare organizations, payers, and technology companies respond to emerging threats from advanced artificial intelligence (AI) models.
The group, which includes leaders from more than eight health systems, intends to develop the industry’s first set of practical playbooks focused on cyber risk and readiness. These resources are expected to be released by the end of 2026.
Addressing New Cybersecurity Risks
The initiative comes in response to the release of advanced frontier models, such as the Mythos-class models released in June 2026. CHAI says these models have changed the cybersecurity landscape by compressing attack timelines, automating the exfiltration of protected health information, and increasing the scale of ransomware attacks.
“Health systems have always faced cybersecurity challenges, but today’s advancements in AI fundamentally change our threat level. With these unprecedented capabilities, it’s key that industry leaders work together to develop a real toolkit for hospitals, health systems and beyond,” says John Flores, chief information security officer at the University of Texas Medical Branch, in a release.
The work group consists of nearly 100 members who will collaborate through bi-weekly sessions. Their goal is to produce a defensive playbook, an offensive playbook, and a cyber risk assessment tool specifically for healthcare environments.
Supporting Diverse Healthcare Systems
The effort aims to provide guidance that is applicable to a wide range of organizations, including community hospitals and academic medical centers.
“As AI rapidly transforms our industry, it also brings new speed, scale, and sophistication to cyberthreats. On the ground in a health system—particularly in underserved and lower-resourced communities—it suggests a new playbook is needed,” says Isaiah Nathaniel, senior vice president and chief information officer at Delaware Valley Community Health, in a release.
The leadership council for the group includes experts from organizations such as Duke Health, Centene, Baptist Health, Boston Children’s Hospital, and Johns Hopkins Health System.
“We are convening cyber experts across healthcare, from community hospitals to academic medical centers as well as members of our technology and cybersecurity ecosystem, because preparing for cyber vulnerabilities is critical and urgent,” says Brian Anderson, CEO of CHAI, in a release.
The project is part of the CHAI’s broader mission to establish consensus-driven frameworks and governance tools to support the use of AI in the medical sector.
ID 218184585 © Phuttaphat Tipsana | Dreamstime.com