The Coalition for Health AI has convened a work group of nearly 100 health system, payer, and industry leaders to address cyber risks associated with frontier artificial intelligence models.
CHAI plans to create playbooks to help organizations work with powerful frontier AI models.
Addressing Cyber Risks
The group will meet biweekly with the goal of creating and publishing health AI cybersecurity guidance by the end of 2026.
Deliverables include an AI cyber risk assessment tool and playbooks covering both defensive and offensive security strategies.
Anthropic’s release of its advanced Mythos and Fable AI models this spring “fundamentally changed” the cyber threat setting for healthcare, and was a catalyst to stand up the work group, CHAI said.
Frontier AI Models
Frontier models, such as Anthropic’s Claude Mythos and its publicly available iteration, Fable, represent the most powerful AI systems available today — they can think through complicated tasks, handle massive amounts of information, and work independently without constant human guidance.
Related: AMS sale to H B Fuller approved
In the case of Mythos, it also can autonomously root out cybersecurity vulnerabilities and turn them into working exploits.
For healthcare organizations, these advanced models pose a serious opportunity — and a serious concern.
When publicly available, they can be leveraged both by defenders and by hackers.
Health systems have always faced cybersecurity challenges, but today’s advancements in AI “fundamentally change our threat level,” John Flores, chief information security officer at the University of Texas Medical Branch, said in a statement.
Leadership and Efforts
Flores is one of 14 leadership council members for CHAI’s new work group who will spearhead the group’s efforts.
He is joined by representatives from other health systems, like Baptist Health and Duke Health, as well as health tech and cybersecurity company executives and professionals from cyber threat information sharing and standards organizations.
Related: User Account Blocked by Social Media Platform
Healthcare organizations have faced a high volume of cyberattacks and data breaches in recent years.
Cyberattacks can lead to patient care disruptions, including ambulance diversions, cancelled appointments and surgeries, and electronic health record systems taken offline.
Hospitals addressed just 6% of identified cyber risks in the first quarter of 2026, a steep decline from the 23% of risks addressed in the first quarter of 2025, according to cybersecurity company Fortified Health Security.
Although advancements in AI have the potential to help healthcare organizations detect and respond to threats faster, they also allow threat actors to increase the speed, volume, and effectiveness of their attacks.
Isaiah Nathaniel, senior vice president and chief information security officer at Delaware Valley Community Health and a leadership council member, said healthcare organizations need to ensure that all parts of healthcare, including systems of all sizes, are equipped to handle the downsides that come along with technological advances.
