Accepted for/Published in: JMIR Medical Informatics
Date Submitted: May 18, 2026
Date Accepted: Sep 23, 2026
Warning: This is an author submission that is not peer-reviewed or edited. Preprints - unless they show as "accepted" - should not be relied on to guide clinical practice or health-related behavior and should not be reported in news media as established information.
Cyber-secure AI: protecting large language models across their deployment in health systems
ABSTRACT
In this article, we highlight the principal cybersecurity measures that should be implemented to facilitate safe and effective integration of large language models (LLMs) into healthcare. While LLMs offer significant potential for applications in clinical documentation, triage, and medical education, their deployment creates novel vulnerabilities that can compromise patient safety and data confidentiality. We argue that these vulnerabilities must be addressed across the entire AI deployment lifecycle, with distinct threats arising before and after a model enters clinical use. Pre-deployment risks include data and model poisoning, where an LLM’s training data or core parameters are maliciously corrupted to embed biases or backdoors. Post-deployment, LLMs are susceptible to inference attacks such as prompt injection and adversarial inputs, which can be used to manipulate model behaviour and extract sensitive information. Standard performance benchmarks are often insufficient to detect these sophisticated attacks. Therefore, we argue that a proactive, multi-layered security framework combining technical safeguards, rigorous governance and human-in-the-loop oversight, is essential for the safe and trustworthy adoption of LLMs in clinical practice.
Citation
Request queued. Please wait while the file is being generated. It may take some time.
Copyright
© The authors. All rights reserved. This is a privileged document currently under peer-review/community review (or an accepted/rejected manuscript). Authors have provided JMIR Publications with an exclusive license to publish this preprint on it's website for review and ahead-of-print citation purposes only. While the final peer-reviewed paper may be licensed under a cc-by license on publication, at this stage authors and publisher expressively prohibit redistribution of this draft paper other than for review purposes.