The Coalition for Health AI is building a security playbook for AI in healthcare before regulators write one.
CHAI announced a Health AI Cybersecurity Work Group on Aug. 12, as Healthcare IT News reported. The group brings together nearly 100 organizations spanning health systems, payers, tech vendors, and industry bodies, and will meet biweekly.
A leadership council guides the work, including Health-ISAC CSO Errol Weiss, Censinet CEO Ed Gaudet, and Delaware Valley Community Health CISO Isaiah Nathaniel. The council draws from at least eight health systems.
Deliverables are targeted for release by the end of 2026 and include defensive and offensive playbooks, plus a “frontier AI cyber-risk assessment tool.” CHAI frames the effort as a response to a new class of frontier models it says heightens PHI-exfiltration and ransomware risk. This threat assessment comes from CHAI’s press release and lacks independent technical verification.
Healthcare, one of the most regulated and breach-prone sectors, is moving toward its own AI risk benchmarks rather than waiting on federal rulemaking. Expect the resulting playbooks and assessment tool to become de facto audit references for vendor and system reviews.



Leave a Reply