June 2026

When the Attackers Bring AI: 2026 Healthcare Threats in Plain View 

Executive Summary 

Artificial intelligence is changing healthcare, but it is also changing the tactics, speed, and sophistication of cyberattacks. Threat actors are using AI to create more convincing phishing campaigns, automate reconnaissance, improve social engineering, and identify vulnerabilities faster than ever before. At the same time, healthcare organizations are deploying AI-enabled technologies that introduce new security considerations, including prompt injection, data exposure, and AI application security. 

In the third session of Clearwater’s 2026 Healthcare AI Executive Summer Series, moderator Dave Bailey, Vice President of Consulting Solutions & Strategy at Clearwater, is joined by Steve Akers, Corporate CISO, Justin Sun, Director of Clearwater’s Security Operations Center (SOC), and Philip Burnham, Consultant and Penetration Tester. Together, they examine how AI is reshaping today’s healthcare threat landscape and discuss what organizations are seeing in real-world environments. 

Rather than focusing on hypothetical scenarios, the conversation centers on practical observations from security operations, penetration testing, and healthcare incident response. The panel explains that while AI is making cyberattacks more effective, the organizations best positioned to defend against AI-enabled threats are those with mature cybersecurity fundamentals, strong governance, and continuous visibility into their environment. 

Why This Conversation Matters 

AI has become one of the most talked-about topics in cybersecurity, but separating fact from hype is becoming increasingly difficult. 

Healthcare leaders hear about AI-generated phishing, deepfakes, autonomous malware, prompt injection, and emerging AI vulnerabilities almost daily. While many of these threats are real, organizations must understand where AI is genuinely changing the threat landscape and where traditional cybersecurity practices remain just as effective as ever. 

Throughout the discussion, the panel emphasizes that AI is not replacing conventional attack techniques. Instead, it is making existing attacks faster, more scalable, and more convincing. 

Healthcare organizations should prepare for these changes without losing sight of the cybersecurity fundamentals that continue to provide the strongest defense. 

Dave Bailey: “AI isn’t replacing traditional attacks. It’s making them more effective.” 

Key Insights from the Discussion 

AI Is Accelerating Familiar Attack Techniques 

One of the first topics explored is how AI is changing the attack lifecycle. 

Instead of inventing entirely new forms of cyberattacks, threat actors are using AI to improve activities they have performed for years. AI allows attackers to generate realistic phishing emails, research potential victims, create malicious code more efficiently, and automate portions of their reconnaissance. 

The result is greater speed, higher volumes of attacks, and communications that are increasingly difficult for employees to distinguish from legitimate messages. 

For healthcare organizations, this means long-standing cyber risks remain highly relevant, but defenders should expect those risks to become more sophisticated as AI capabilities continue to mature. 

Social Engineering Is Becoming More Convincing 

The panel spends considerable time discussing how AI is enhancing social engineering. 

Attackers can now generate professional emails with minimal effort, mimic writing styles, translate content naturally, and even create convincing voice recordings using publicly available information. 

These capabilities reduce many of the indicators employees have traditionally relied upon to identify phishing attempts. 

The speakers emphasize that security awareness training remains one of the most important defensive investments healthcare organizations can make. 

Technology alone cannot eliminate social engineering risk. 

Employees must understand how AI is changing the way attackers communicate and know how to verify suspicious requests before taking action. 

Healthcare Security Operations Are Seeing AI in Practice 

Justin Sun shares observations from Clearwater’s Security Operations Center, explaining that AI is no longer simply an emerging trend. 

Security analysts are seeing evidence that attackers are incorporating AI throughout multiple stages of the attack lifecycle, particularly during reconnaissance, phishing, and content generation. 

While AI itself is not always the root cause of security incidents, it increasingly serves as a force multiplier that helps attackers operate more efficiently. 

The discussion reinforces the importance of continuous monitoring, rapid investigation, and mature incident response capabilities as AI-enabled attacks become more common. 

Organizations that maintain strong visibility into their environments remain well positioned to detect suspicious activity regardless of how attacks are generated. 

AI Applications Introduce New Security Risks 

The conversation also explores risks introduced by AI itself. 

As healthcare organizations deploy large language models, AI assistants, and AI-enabled applications, security teams must begin evaluating new attack techniques such as prompt injection, unauthorized data exposure, and manipulation of AI system behavior. 

Prompt injection receives particular attention as an emerging application security concern. 

Rather than exploiting traditional software vulnerabilities, attackers may attempt to manipulate AI systems through carefully crafted prompts designed to influence responses or bypass intended safeguards. 

The panel encourages organizations to include AI-enabled technologies within existing application security, vulnerability management, and governance programs. 

AI should not be evaluated separately from other enterprise technologies. 

Penetration Testing Is Evolving Alongside AI 

Philip Burnham discusses how offensive security testing continues to evolve. 

Traditional penetration testing remains essential, but assessments increasingly include AI-enabled applications, third-party AI integrations, and systems that process sensitive information using machine learning or large language models. 

Organizations should understand: 

Expanding security testing to include AI helps organizations identify weaknesses before attackers can exploit them. 

Cybersecurity Fundamentals Still Matter 

Although AI introduces new considerations, one of the strongest messages throughout the discussion is reassuring. 

The cybersecurity fundamentals that have protected healthcare organizations for years remain the foundation of effective defense. 

Identity and access management, multi-factor authentication, vulnerability management, network segmentation, security awareness training, logging, monitoring, and incident response all remain essential. 

The panel cautions against chasing every new AI headline while neglecting these proven security practices. 

Organizations with mature cybersecurity programs are generally better prepared to defend against AI-enabled attacks because they already maintain strong visibility, governance, and response capabilities. 

Preparing for What’s Next 

As AI continues evolving, healthcare organizations should expect both attackers and defenders to adopt new capabilities. 

The panel encourages organizations to begin inventorying AI-enabled technologies across the enterprise, incorporate AI into risk assessments, educate employees about emerging threats, and ensure governance processes evolve alongside technology. 

Success will depend on balancing innovation with disciplined cybersecurity practices. 

Organizations do not need entirely new security programs to address AI. 

They need to understand how AI changes existing risks and continuously adapt their defenses accordingly. 

Practical Recommendations for Healthcare Leaders 

The discussion offers several practical recommendations for healthcare security teams: 

These steps help organizations improve resilience while preparing for a rapidly changing threat landscape. 

Notable Quotes 

Dave Bailey: “AI isn’t replacing traditional attacks. It’s making them more effective.” 

Justin Sun: Security teams are already seeing AI incorporated into real-world attack activity. 

Steve Akers: Strong cybersecurity fundamentals remain the foundation of effective defense, regardless of how attackers use AI. 

Questions This Discussion Answers 

About This Webinar 

This webinar is the third session of Clearwater’s 2026 Healthcare AI Executive Summer Series. Dave Bailey moderates a discussion with Steve Akers, Justin Sun, and Philip Burnham on how artificial intelligence is reshaping today’s healthcare cyber threat landscape. Combining perspectives from executive cybersecurity leadership, security operations, and penetration testing, the panel explores how attackers are leveraging AI, how healthcare organizations can prepare, and why mature cybersecurity programs remain the strongest defense against emerging threats. The discussion provides practical guidance for healthcare executives, CISOs, SOC teams, and security professionals responsible for protecting organizations in an increasingly AI-driven threat environment.