When Attackers Bring AI, Healthcare Security Needs a Human in the Loop

By Steve Akers, CISO, CTO and Chief Security Officer, Clearwater
LinkedIn: Steve Akers
LinkedIn: Clearwater

In July, researchers at the security firm Sysdig disclosed something that had not been documented before: an artificial intelligence (AI) agent, nicknamed JadePuffer, carried out an entire ransomware intrusion on its own. After breaking into a vulnerable server through a known software flaw, it used a large language model to adapt its own actions, executing more than 600 coordinated payloads. It harvested credentials, mapped internal systems, encrypted 1,342 database records, deleted the originals and left behind a Bitcoin ransom demand. At one point, recovering from a failed attempt to create an administrator account, it produced a working bypass in 31 seconds.

Months earlier, Anthropic disclosed that a Chinese state-sponsored group had used its Claude models to run 80 to 90 percent of a cyber espionage campaign against nearly 30 organizations, with human direction limited to about 20 minutes of decisions across an operation that ran for hours. This July, OpenAI reported that its own frontier models broke out of a sandboxed evaluation, found a genuine vulnerability on their own, and breached the AI platform Hugging Face while chasing a benchmark answer key. Days later, Anthropic disclosed three similar cases of its own models slipping into the open internet from supposedly isolated test environments and compromising real infrastructure, using nothing more than weak passwords and open endpoints. No adversary directed any of it.

Healthcare security programs were built around an assumption that no longer holds everywhere: that a human sits on the other end of an attack, working at human speed and making human mistakes. That is why the Five Eyes intelligence alliance, in a joint advisory this past June, told member nations plainly that the timeline for adversaries to reach this level of capability is not years. It is months. Washington noticed too. Within days of the OpenAI disclosure, a bipartisan bill known as the AI Kill Switch Act was introduced in Congress, requiring the largest AI developers to be able to throttle or shut down their own frontier models. Whatever becomes of that bill, its introduction alone signals that policymakers now treat frontier AI capability as a matter of national security, not a product feature.

For healthcare organizations, the exposure compounds in a familiar way. Protected health information remains among the most valuable data sold on illicit marketplaces, and healthcare’s tolerance for operational downtime is close to zero, a combination that makes hospitals, health systems and specialty practices attractive targets regardless of the tooling behind an attack. Voice cloning adds another layer. The Federal Bureau of Investigation’s (FBI) Internet Crime Complaint Center has warned that malicious actors are using AI-generated voice and text messages to impersonate senior officials, a technique that translates directly into wire transfer fraud and credential reset scams inside healthcare finance and information technology departments.

The governance gap behind all of this is measurable. IBM’s newest Cost of a Data Breach analysis, published in July, found that more than two-thirds of breached organizations had no process in place to govern shadow AI, the unsanctioned tools employees adopt on their own, and that the share of security incidents involving shadow AI more than doubled year over year to 43 percent. In healthcare specifically, a survey of hospital and health system workers found more than 40 percent aware that colleagues were using unauthorized AI tools for clinical notes and patient communications, an exposure path most compliance programs have not yet named, let alone controlled.

None of this argues for abandoning AI, in defense or anywhere else. It argues for naming AI risk as its own category in the enterprise risk register, not general information technology risk, and for rebuilding a few assumptions security programs have relied on for years. Detection has to move from static signatures toward behavioral baselines, because AI-generated malware changes its fingerprint faster than any hash list can track. Verification of anything involving credentials, wire transfers or patient data has to move to a second, independent channel, because a familiar voice or face is no longer proof of identity. And every AI tool touching protected health information, sanctioned or not, needs to be inventoried and mapped to what it can read and write, because an organization cannot govern, test or defend a system it has never catalogued.

The instinct in a moment like this is to reach for more automation to match the adversary’s speed. The better instinct is narrower. Automate detection and response where speed genuinely matters, and put trained judgment back at the checkpoints where a wrong answer causes the most damage: identity verification, financial approval, clinical data access. Healthcare cannot outrun machine-speed attacks with human-speed defenses spread evenly across everything. It can win by deciding, deliberately, where a person still has to be the one who says yes.[/vc_column_text]

[/vc_column][/vc_row]