Healthcare remained a prime target for cybercriminals in 2025, with a staggering 22% of reported ransomware attacks aimed at the sector, according to a prominent industry study. Alarmingly, 93% of healthcare institutions experienced at least one cyber incident over the last year. By the end of 2025, more than 642 significant breaches were documented, impacting approximately 57 million people.
The repercussions for healthcare extend beyond typical cybersecurity and data concerns. Above all, healthcare environments focus on patient safety. Thus, failures in AI security can lead to failures in patient care delivery, rather than merely privacy violations.
As cyber threats evolve in frequency and severity, generative AI (GenAI) is transforming both the security landscape and operational protocols within healthcare. This advanced technology simplifies and accelerates the execution of intricate cyberattacks, including tactics like “vibe coding.” Additionally, GenAI can unintentionally lead well-intentioned employees to disclose sensitive information to unauthorized systems. In a healthcare context, the primary concern is often not a deliberate attack but rather the excessive use of AI with protected health information (PHI), clinical data, credentials, or internal processes.
Given the rapid increase in risk, healthcare organizations must shift their approach from solely preventing breaches to embracing a mindset of resilience, ensuring safe operations and recovery capabilities.
Understanding Today’s Threats and the Impact of GenAI
The rate of innovation in GenAI is extraordinary, with new advancements emerging nearly every day, particularly influenced by AI agents. These tools are often affordable or even open-source, enabling the development of increasingly sophisticated cyberattack strategies that enhance phishing, impersonation, malware creation, reconnaissance, and social engineering.
Human error remains the primary vulnerability, and it is further exacerbated by AI-generated content and workflows that make malicious actions more believable and easier to implement.
In the healthcare sector, GenAI-related risks present multifaceted challenges. Key concerns include data leakage (exposure of PHI), prompt injection, model manipulation, and integration vulnerabilities across clinical and operational infrastructures. The introduction of copilots and agents increases the attack surface, and there is a risk of identity and authorization drift when integrating AI tools with electronic health records (EHRs), collaborative platforms, knowledge repositories, and ticketing systems.
Moreover, organizations face risks from third-party and supply chain sources, including foundation model providers, AI plugins, and model gateways. Insecure retrieval pathways and retrieval-augmented generation (RAG) connectors can compromise sensitive data. Other potential risks include the unpredictability of AI-generated outputs, like misinformation or “hallucinations,” as well as uncertainties surrounding the models used, the data utilized for training, and the logging of outputs.
To effectively navigate the integration of GenAI, organizations should prioritize the following actions:
1. Comprehensive inventory of AI systems, models, agents, data sources, and connectors. 2. Risk assessment categorized by use case, sensitivity of data, and level of autonomy. 3. Requirement for human oversight in high-risk applications. 4. Documentation of prompts, outputs, tool usage, data access, and administrative modifications. 5. Due diligence regarding vendors supplying models and AI-driven software.
A Shift in Focus for Healthcare CISOs: From Security to Resilience
For Chief Information Security Officers (CISOs) in healthcare, AI security now intertwines with operational resilience. Rather than asking, “Are we using AI?”, the focus has shifted to identifying where AI influences decisions, summarizes data, initiates actions, or interacts with regulated information—and ensuring these processes are governed and manageable during a cyber event.
Healthcare boards are now asking critical questions such as:
“How quickly can we recover?”
“What strategies exist to maintain essential operations if vital clinical, administrative, identity, or AI-driven processes are compromised?”
These inquiries signal a profound reevaluation of cybersecurity in healthcare. With ransomware and significant cyber disruptions linked increasingly to delays in patient care and adverse outcomes, the stakes are high. Research has indicated that hospital patients experience a 34–38% increase in risk when a cyberattack occurs, while other studies show a rise in in-hospital mortality rates during ransomware incidents.
CISOs must frame AI risk in terms that resonate with business imperatives: patient safety, operational downtime, trustworthiness, legal liabilities, and recovery capabilities. They also need to clarify the usage of AI, ownership, control mechanisms, and operational protocols during cyber incidents.
Understanding Compliance as an Enabler of Resilience
In addressing AI-related risks, healthcare organizations must navigate updated regulatory frameworks, including significant adjustments to the HIPAA Security Rule proposed in December 2024. Additionally, other essential regulations gaining prominence include guidance from HHS on implementing security measures, HITRUST standards, PCI DSS for payment systems, and FDA stipulations for AI/ML medical devices and their cybersecurity.
Such regulatory changes underscore a greater urgency for swift incident reporting, reflected in initiatives like CIRCIA, which proposes that entities disclose cyber incidents within 72 hours and ransom payments within 24 hours.
Healthcare organizations must clearly delineate between what is proposed, enforced, and contractually or legally mandated by states, payers, or partners. For instance, the proposed HIPAA Security Rule would necessitate documented procedures for restoring relevant systems and data within a 72-hour timeframe.
This regulatory evolution emphasizes that the speed of recovery and prioritization of restoration are becoming essential governance obligations, rather than mere internal aspirations. However, it remains crucial to recognize that compliance is a snapshot in time that can swiftly change, highlighting the importance of fostering continuous resilience.
Implementing compliance frameworks can help organizations:
- Justify investments in resilience initiatives. - Drive system testing. - Develop repeatable resilience strategies.
While compliance alone cannot guarantee the security of Generative AI, CISOs should leverage compliance efforts to instill rigor around AI inventory management, risk evaluation, data handling, human oversight, logging practices, vendor assessments, and recovery testing.
Ultimately, organizations that emerge as leaders in GenAI will be those that implement robust governance, establish clear boundaries, pursue ongoing oversight, and confirm their recovery capabilities. The CISO's primary mission is to ensure that AI integration occurs safely and effectively, protecting patient care even when challenges arise.
About Chris Bevil
Chris Bevil, an experienced expert in cybersecurity and compliance who has previously served as a CISO, currently holds the position of principal in global cyber resilience and AI at Commvault. His extensive background as a cybersecurity and compliance consultant has equipped him to assist organizations in incident response, disaster recovery, and business continuity planning, enabling them to craft solid cyber recovery strategies that effectively counter potential threats. Chris translates intricate cybersecurity issues into straightforward, relatable insights, merging in-depth expertise with an engaging storytelling approach to connect with audiences and empower them in addressing today’s most pressing challenges.




