Hospitals face an AI cyber defense gap

Advertisement

Hospitals already know they are targets for cyberattacks. The emerging problem is whether they can afford to defend themselves as hackers begin adopting AI.

James “Scott” Gee, deputy national adviser for cybersecurity and risk at the AHA, told Becker’s that artificial intelligence is rapidly changing the pace and sophistication of cyber threats confronting hospitals, particularly as attackers use the technology to improve phishing, social engineering and exploitation of newly discovered vulnerabilities.

“The threat is very real,” Mr. Gee said. “This is a huge issue coming, and it’s coming at us incredibly fast.”

His comments come after OpenAI, Microsoft and more than 100 technology and cybersecurity companies issued a public call Aug. 27 for governments, industry and AI developers to strengthen cyber defenses before AI-enabled attacks become substantially more capable.

The letter specifically identified hospitals among the critical infrastructure organizations at risk and called for under-resourced essential services to receive greater access to defensive AI technology and hands-on cybersecurity support.

Mr. Gee said the urgency is reflected in a recent warning from Five Eyes intelligence partners, which he said cautioned that AI models could overwhelm existing cyber defenses “in months, not years.” He said the unusual decision to have agency leaders themselves sign the alert underscored its significance.

Attackers are already putting those capabilities to work.

Mr. Gee pointed to increasingly sophisticated phishing emails, which AI can produce without the spelling and grammatical mistakes that once helped employees identify suspicious messages. Healthcare organizations are also hearing reports of AI-generated voices being used in phone-based social engineering attacks, including attempts to impersonate people contacting information technology (IT) help desks.

AI is also compressing the time between the disclosure of a software vulnerability and an attacker being able to exploit it, he said. Mr. Gee cited reports of ransomware operators developing attacks against newly published vulnerabilities within 24 hours — work that once could have taken weeks or months.

“Adversaries are absolutely using it to enhance their operations,” he said.

Hospitals can use the same technology defensively. AI-enabled security tools can help identify malicious activity faster than human security operations teams and potentially ease some of the workload facing already stretched cybersecurity staffs.

But access to those capabilities will not be even across healthcare.

“The problem is, we cannot afford the tools to properly defend ourselves against an adversary that is armed with AI,” Mr. Gee said. “It’s not something that I think hospitals can solve themselves.”

That challenge could be particularly acute for smaller hospitals with underfunded or understaffed cybersecurity programs. As attackers become faster, Mr. Gee said those organizations could become vulnerable faster as well.

The same concern extends beyond hospitals to technology companies and other third parties whose systems have become critical to healthcare operations. Cybercriminals increasingly target vendors knowing an attack against one company can disrupt numerous hospitals and health systems simultaneously.

“Until everyone is defending themselves at AI speed, we’re going to have these problems,” Mr. Gee said.

For CIOs and chief information security officers, Mr. Gee said one of the most immediate priorities should be establishing enterprise-wide governance around AI.

That starts with knowing where AI is already operating inside the organization. Hospitals should maintain an inventory of AI tools, establish guidelines governing appropriate use and create an intake process for new AI technologies that examines security, implementation and what organizational data each tool can access, he said.

“AI is already in environments; it is everywhere, whether you know it or not,” Mr. Gee said.

Health systems should also understand where information entered into AI systems is stored to avoid inadvertently exposing protected health information, he said. And because AI applications are still software, hospitals will need processes to patch and update them as vulnerabilities emerge.

Mr. Gee said technology companies could help close the resource gap by making advanced cybersecurity tools more affordable and accessible to hospitals. He pointed to Microsoft’s efforts to provide cybersecurity assistance to rural healthcare organizations as one model that could be expanded across the industry.

Government also has a role beyond helping organizations defend themselves, he said. Federal authorities can disrupt cybercriminal infrastructure, make arrests and impose greater costs on the groups attacking healthcare.

Ultimately, Mr. Gee said keeping pace with AI-enabled attackers will require a shared defense rather than expecting individual hospitals to solve the problem independently.

“That sort of collective effort, that sort of collective defense, is what we’re going to need to really succeed in this environment,” he said.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Advertisement

Next Up in Cybersecurity

Advertisement