Skip to main content
Welcome to Deloitte

If we have selected the wrong experience for you, please change it above.

2026 Midyear Deloitte Global Health Care Outlook

Using AI to defend AI: the latest in health care cybersecurity

By Sara Siegel, Deloitte Global Health and Human Services Sector Leader, and Ed Moore, Partner, Deloitte Spain

It has been seven months since Deloitte Global released its 2026 Global Health Care Outlook, and in those months, AI technology has continued to evolve rapidly. While this can offer more opportunities for health systems to streamline processes and improve efficiencies, it also expands the attack surface for cyber incidents.

That’s why recent AI tools that dramatically enhance the ability to secure technological systems may be capturing the attention of health care executives. These models are tuned for offensive security research. And despite the fact that these technologies can be used by threat actors to target organizations, they can also represent a step-change in how organizations protect themselves from cyberattacks. Indeed, though still nascent, these security research tools have already demonstrated that even the most sophisticated security systems can have vulnerabilities.

With about half of health system executives surveyed last fall citing cybersecurity as a top concern in 2026—dedicating close to 14% of their tech budgets—these tools could be a boon to a sector with limited resources and high exposure. Yet as the landscape continually changes with new AI models as well as their governance, the question is how should health system executives incorporate these tools into their cybersecurity strategies?

The inherent risks to health care systems
In 2026, the health care sector continues to be a prime target for cyberattacks.1 These systems hold highly valuable information about the people they serve, which can then be used for identity theft, insurance fraud, and other crimes. Medical record information can be sold on the dark web for as much as $1,000, versus $1 to $3 for email account login credentials.2 Add to that the 24/7 nature of hospitals that often limits downtime for maintenance and lower cybersecurity budgets, and health systems become an even more vulnerable target.

Now, as health systems around the world embrace AI to streamline processes and improve efficiencies as well as help enable AI-driven diagnostics and decision-making support, vulnerabilities have increased.3 Leaders often don’t fully understand the heightened security risks AI can bring, which can include nonconventional threats such as model manipulation, adversarial inputs, and data poisoning.4 Some key areas of vulnerability include:

  • Access controls: Among the surveyed health care organizations that experienced breaches in AI, 97% said they lacked proper AI access controls.5
  • Medical devices: These devices often embed AI that can open an invisible back door for cybercriminals if insecurely connected to the internet.
  • Third-party vendors: Health systems could be at risk if their third-party vendors do not prioritize cybersecurity.6
  • Staff use: Clinical staff may be increasingly relying on AI tools to write clinical notes and summarize patient data. These tools can have hidden risks,7 particularly if speed is prioritized over security.

The role of defensive AI
Health care organizations shouldn’t put off the benefits that AI can offer both in terms of improving systems and, now, in securing them. But the world of AI tools is moving fast, with their application still very much evolving—and health care executives should keep in mind that even the best and most sophisticated AI tools cannot offset foundational weaknesses. Below are some key considerations executives should pay attention to as they assess cybersecurity and the recent advent of defensive AI tools:

  • Cyber hygiene: Up-to-date patching, secure configurations, and reducing the external attack surface are still some of the best ways to block most attacks.
  • Asset and exposure visibility: Knowing what’s owned, where it runs, and how it is exposed remains foundational. AI cannot compensate for blind spots in, for example, cloud and third-party environments.
  • Identity and segmentation fundamentals: Strong identity and access management, restricted permissions, and network segmentation still help protect against breaches. Poorly governed administrative access and flat networks are more likely to be vulnerable.
  • Incident response and crisis management: Well-rehearsed playbooks, clear decision rights, and tested communications can be a key part of preventing and responding to cyberattacks.
  • Culture and governance gaps: Organizations with limited board engagement and less effective remediation timelines may be structurally exposed—which may persist despite investments in AI-assisted defense.

As defensive AI tools become more broadly available, health care organizations should consider starting to use current AI models to detect vulnerabilities now, mapping such risks as end-of-life assets and externally exposed systems. However, the goal should not be to place AI at the center of a security operating model, but rather to use AI pragmatically to find and remove easily exploitable weaknesses.

Health care security teams should also measure actual remediation latency. If these new AI capabilities are indeed deployed, vulnerability discovery may outpace remediation. The challenge, then, is no longer identifying vulnerabilities but deciding which ones matter and acting quickly.

Taking the lead
One of the best ways to address the risks of AI continues to be for leadership to make cybersecurity part of its decision-making processes. Regardless of new defense tools, cybersecurity should not be an afterthought. Leadership should treat cyber risk as a core strategic issue, with cybersecurity teams involved right from the start—not tagged on once an attack breaches the system.

Even with the potential for AI to improve health care efficiency and outcomes, the institutions that tend to fall behind are not those with the fewest AI pilots or the lowest AI adoption. They are generally those health care organizations with slow patch cycles, weak identity and access control, unsegmented networks, limited third-party visibility, unsupported or legacy technology, and inadequately tested recovery plans. In other words, those that are most likely vulnerable to cyberattacks.

Latest news from @DeloitteHealth

Endnotes:
1ORDR, Healthcare Cybersecurity Statistics 2026 Report , accessed July 23, 2026.
2Aranza Trevino, “Why Do Hackers Want Medical Records?” Keeper, January 11, 2024.
3Internet Crime Report 2025, Federal Bureau of Investigation, p. 14.
4Farhad Abtahi, et al., “Data Poisoning Vulnerabilities Across Health Care Artificial Intelligence Architectures: Analytical Security Framework and Defense Strategies,” Journal of Medical Internet Research, January 23, 2026.
5IBM, Cost of a Data Breach Report 2025, accessed July 23, 2026.
6Jimmy Joseph, Steph Meehan, “A cyber TPRM program could help make hospitals more resilient,” Deloitte & Touche LLP, October 22, 2024.
7Science & Tech Spotlight: AI for Medical Notes and Coding, U.S. Government Accountability Office, July 16, 2026.

This publication contains general information only and Deloitte is not, by means of this publication, rendering accounting, business, financial, investment, legal, tax, or other professional advice or services. This publication is not a substitute for such professional advice or services, nor should it be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified professional advisor.

Deloitte shall not be responsible for any loss sustained by any person who relies on this publication.

Return to the Health Forward home page to discover more insights from our leaders. 

Subscribe to the Health Forward blog via email