Sponsored

Why data is healthcare AI’s new attack surface — 4 takeaways

Advertisement

Healthcare organizations are deploying AI faster than they can build the controls to secure it. Most security tools were designed to monitor users, servers and networks, not the data AI systems ingest, transform and transmit.

In a featured session sponsored by HP at Becker’s 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health on Sept. 14, Jonathan Gohstand, director of technical product marketing at HP Inc., explained why AI moves the security challenge to the data layer.

Here are four takeaways from the session.

1. The data itself can become the attack

Mr. Gohstand described an AI scribe that had cleared standard compliance reviews but remained vulnerable through an off-the-shelf document library used to create PDFs. An attacker exploited a flaw in that library by supplying malicious input, ultimately gaining full access to the EHR.

“The hacker didn’t have to hack anyone. All they did was submit data,” he said. “The data is the hack.”

The example also illustrated the limits of relying on compliance reviews as proof of security. Although the vendor was presented as SOC 2- and HIPAA-compliant, a vulnerability in one underlying component still exposed the broader system. Mr. Gohstand urged health systems to treat vendor audits as a starting point rather than sufficient assurance.

2. Data leakage

In a survey presented by HP, healthcare security and IT leaders ranked attackers weaponizing AI and a lack of visibility into employees’ AI use as their two greatest overall risks. When respondents selected five specific concerns from a longer list, however, 57% identified employees accidentally sharing confidential data through AI. A compromised AI system leaking sensitive information ranked close behind.

Respondents also named integrated data leakage prevention as the most important attribute in an AI security product. The findings expose a mismatch: Many traditional security controls can monitor identities, devices and networks but were not designed to determine whether a clinical note, image or other sensitive input should move through an AI model or connected agent.

3. What the HIPAA Security Rule is missing

The proposed update would eliminate the distinction between required and addressable controls while adding requirements around encryption at rest, multifactor authentication, asset inventories, vulnerability scanning and annual audits. However, the proposal does not specifically address AI, Mr. Gohstand said. Organizations would therefore have to apply existing controls to a fundamentally different architecture.

That will be more complicated than applying them to traditional systems. Agents can exchange information with other agents, act faster than manual security processes and produce different responses to the same request, making data flows harder to trace and conventional penetration testing less conclusive.

Encryption at rest illustrates another tension. Mr. Gohstand said it could complicate efforts to inspect data for potential leakage, particularly when security tools require access to encryption keys. He recommended that organizations begin planning for compensating controls.

4. External frameworks are crucial

Mr. Gohstand pointed to Google’s Secure AI Framework and Anthropic’s Zero Trust for Agents guidance as credible references for connecting risks such as data poisoning and sensitive data disclosure with specific safeguards.

The organizational value can be as important as the technical guidance, he said. An established framework gives security leaders an external standard to cite when a business unit wants to bypass controls.

Mr. Gohstand recommended risk-rating each AI application and applying protections according to that risk. This gives organizations a more defensible approach than attempting to impose every available control equally across every use case.

Smaller open-weight models running on dedicated, on-premises hardware may fit many healthcare use cases. This approach can cap token costs while placing firm boundaries around the systems and data a model can access.

He closed with five recommendations: assign dedicated personnel to AI security; use AI to automate control validation; adopt an external framework and apply it consistently; strengthen data protections through tighter access, granular API controls and data-poisoning safeguards; and stop treating a vendor’s audit report as sufficient assurance.

“You have to put people on it who live and breathe it every day,” he said. “It’s just way too dynamic.”

Advertisement

Next Up in Strategy

Advertisement