AI Cybersecurity in Hospitals — Dual-Use Threat and Governance Responses
CONCEPTContent
Overview
As hospitals increasingly deploy AI to improve patient care, the same AI capabilities are being weaponized by malicious actors — including hackers and nation-states — to launch faster, more sophisticated cyberattacks against healthcare infrastructure. This dual-use dynamic is emerging as one of the most acute governance challenges in healthcare AI.
The Dual-Use Threat
Karen Habercoss, Chief Information Security and Privacy Officer at the University of Chicago Medicine, has articulated the core problem: AI tools that enhance clinical workflows and patient outcomes also lower the barrier for attackers to execute complex, targeted intrusions. Nation-state actors and criminal groups are using AI to accelerate phishing, automate vulnerability scanning, generate convincing social engineering content, and conduct multi-vector attacks at scale.
Governance Response
University of Chicago Medicine is building a governance structure specifically designed to manage dual-use AI risk. This includes policies that account for both the clinical benefits of AI adoption and the expanded attack surface that AI integration creates. The governance framework addresses questions of vendor security assessment, AI system access controls, and incident response protocols tailored to AI-assisted threats.
Systemic Implications
The dual-use problem complicates standard AI procurement and governance frameworks, which typically focus on clinical safety, bias, and accuracy rather than adversarial exploitation. Health systems must now treat their AI adoption decisions as cybersecurity decisions as well, requiring closer coordination between clinical informatics, IT security, and executive leadership.