Coalition for Health AI (CHAI) launched the Health AI Cybersecurity Work Group on Aug. 12, tapping cybersecurity leaders from eight health systems to build the sector’s first peer-developed playbooks on frontier AI model cyber risk.
A leadership council steers the nearly 100-member work group, including chief information security officers from eight health systems:
- Randy Arvay, chief technology officer and CISO, Duke Health, based in Durham, N.C.
- James Case, CISO, Baptist Health, based in Jacksonville, Fla.
- John Flores, CISO, University of Texas Medical Branch, based in Galveston
- Kevin Hamel, CISO, Hartford (Conn.) HealthCare
- Bruce James, CISO, Boston Children’s Hospital
- Shawn Kelly, CISO, UCI Health, based in Orange, Calif.
- Isaiah Nathaniel, SVP and CISO, Delaware Valley Community Health, based in Philadelphia
- Janet Rathod, CISO, Johns Hopkins Health System, based in Baltimore
The effort follows the June 9, public release of Anthropic’s Mythos-class frontier models, which CHAI says sped up cyberattacks and patient data theft while giving defenders new tools for vulnerability management and response.
The work group will produce a defensive playbook, an offensive playbook and a frontier AI cyber risk assessment tool.