DistilINFO
Recent Posts
HomeProviderHospitals Face a Growing AI Cyber Gap

Hospitals Face a Growing AI Cyber Gap

Cyber

Hospitals already know they are targets for cyberattacks. The emerging problem is whether they can afford to defend themselves as hackers begin adopting AI, according to AHA’s James “Scott” Gee, who describes a widening hospitals AI cyber defense gap that he says is arriving faster than the industry can respond.

Why AI Is Reshaping the Threat Landscape Behind This Hospitals AI Cyber Defense Gap

Gee, deputy national adviser for cybersecurity and risk at the AHA, told Becker’s that artificial intelligence is rapidly changing the pace and sophistication of cyber threats confronting hospitals, particularly as attackers use the technology to improve phishing, social engineering, and exploitation of newly discovered vulnerabilities. He described the threat as coming at the industry incredibly fast.

A Coordinated Industry Warning

Gee’s comments follow a public call issued Aug. 27 by OpenAI, Microsoft, and more than 100 technology and cybersecurity companies urging governments, industry, and AI developers to strengthen cyber defenses before AI-enabled attacks become substantially more capable. The letter specifically identified hospitals among the critical infrastructure organizations at risk and called for under-resourced essential services to receive greater access to defensive AI technology.

How Fast This Hospitals AI Cyber Defense Gap Is Widening

Gee pointed to a recent Five Eyes intelligence warning cautioning that AI models could overwhelm existing cyber defenses within months rather than years, noting that having agency leaders themselves sign the alert underscored its significance.

Concrete Examples of AI-Enhanced Attacks Already Underway

Attackers are already using AI to produce phishing emails without the spelling and grammatical errors that once helped employees spot suspicious messages, and healthcare organizations are hearing reports of AI-generated voices used in phone-based social engineering, including attempts to impersonate callers to IT help desks. Gee also cited reports of ransomware operators developing attacks against newly published vulnerabilities within 24 hours, work that once could have taken weeks or months.

Why Hospitals Can’t Close This AI Cyber Defense Gap Alone

Hospitals can use AI defensively too, with AI-enabled security tools helping identify malicious activity faster than human security teams and easing the burden on stretched cybersecurity staff. But Gee said access to these capabilities won’t be even across the industry, noting hospitals cannot afford the tools needed to properly defend against an AI-armed adversary and that this isn’t a problem hospitals can solve themselves.

Why Smaller Hospitals and Vendors Face Outsized Risk

Gee said this challenge could be particularly acute for smaller hospitals with underfunded or understaffed cybersecurity programs, and the same concern extends to technology vendors whose systems have become critical to healthcare operations, since an attack against one vendor can disrupt numerous hospitals and health systems simultaneously.

What Gee Recommends Hospitals Do Now Within This AI Cyber Defense Gap

For CIOs and CISOs, Gee said one of the most immediate priorities should be establishing enterprise-wide AI governance, starting with an inventory of AI tools already in use, guidelines for appropriate use, and an intake process for new AI technologies examining security, implementation, and data access.

Additional Practical Steps Gee Outlined

Health systems should also understand where information entered into AI systems is stored to avoid inadvertently exposing protected health information, and since AI applications remain software, hospitals need processes to patch and update them as vulnerabilities emerge over time.

The Role Gee Says Technology Companies and Government Must Play

Gee said technology companies could help close the resource gap by making advanced cybersecurity tools more affordable and accessible to hospitals, pointing to Microsoft’s cybersecurity assistance for rural healthcare organizations as a model that could be expanded industrywide. He said government also has a role beyond helping organizations defend themselves, since federal authorities can disrupt cybercriminal infrastructure, make arrests, and impose greater costs on groups attacking healthcare.

Why Collective Defense Is the Only Path Forward

Gee said keeping pace with AI-enabled attackers will require a shared defense rather than expecting individual hospitals to solve the problem independently, framing collective effort as essential to succeeding in this environment.

What This Hospitals AI Cyber Defense Gap Means Going Forward

With more than 100 technology and cybersecurity companies now publicly warning that AI-enabled attacks could overwhelm existing defenses within months, hospitals and health systems should treat AI governance, including tool inventories and patching processes, as an immediate operational priority rather than a longer-term initiative. Given Gee’s specific warning that smaller, underfunded hospitals face disproportionate risk, health system leaders and policymakers may need to prioritize how affordable defensive AI tools and technical support reach these more vulnerable organizations first.

What to Watch Going Forward

As the Five Eyes intelligence warning and the OpenAI-Microsoft coalition’s call to action continue drawing attention, industry observers will likely watch whether technology vendors expand affordable cybersecurity assistance programs like Microsoft’s rural healthcare initiative, and whether federal authorities intensify efforts to disrupt cybercriminal infrastructure targeting healthcare specifically. Given the compressed timeline Gee described between vulnerability disclosure and exploitation, closing this hospitals AI cyber defense gap will likely require sustained, coordinated action across hospitals, vendors, and government rather than any single organization’s unilateral effort.

For more healthcare industry updates, insights and news, visit DistilINFOClick here to subscribe to stay informed.

No comments

Sorry, the comment form is closed at this time.