The Cybersecurity Working Group (CWG) of the Health Sector Coordinating Council (HSCC) in the US published a guide to help healthcare organisations (HCOs) establish cyber governance frameworks for secure AI implementation. The Health Industry AI Cyber Governance Framework Implementation Guide addresses unique cybersecurity and privacy challenges as the sector adopts Artificial Intelligence across clinical and operational use cases, targeting the identification and mitigation of AI-specific cyber-risks, including data poisoning, model drift and adversarial attacks, while ensuring compliance with the healthcare sector’s complex regulatory environment. It addresses the full spectrum of AI technologies deployed in healthcare, from traditional Machine Learning/reactive/non-agentic models to Generative AI, and Agentic AI systems capable of autonomous action.
The guide focuses on the cybersecurity dimensions of AI governance: protecting AI systems from adversarial threats, ensuring data integrity and privacy, securing the AI supply chain and maintaining operational resilience. Topics such as clinical safety, ethics and patient engagement are addressed to the extent that they intersect with cybersecurity risk. Organisations should maintain a broader AI governance program that addresses the full spectrum of AI risks beyond cybersecurity in the ever-changing ecosystem.
It also complements other HSCC AI-specific publications and should be considered as part of a larger volume of work developed to guide the health industry in its safe and secure adoption of AI. Specifically, this document will significantly reference the Health Industry Third-Party AI Risk and Supply Chain Transparency Guide published April 15, 2026 and should be used in conjunction with this publication.
Standardising terminology
Alongside today’s release of the guide, the HSCC Cybersecurity Working Group’s AI Task Group references its AI Cyber Glossary – a living reference document establishing consistent, governance-ready definitions for artificial intelligence terminology across the health sector.
The glossary was developed in direct response to a critical gap in managing healthcare AI and AI cybersecurity: the absence of shared, sector-specific language that clinical, operational, compliance and technical stakeholders can use with confidence. As AI adoption accelerates across healthcare organisations of every size, inconsistent terminology creates real risk – in procurement decisions, vendor contracts, regulatory submissions, policy development and patient safety oversight. As a living document the glossary is designed to serve as the terminological foundation for all current and future HSCC AI Task Group guidance materials.

