Cybersecurity of Large Language Models Across the Deployment Life Cycle in Health Systems.

Journal: JMIR medical informatics
Published Date:

Abstract

In this Viewpoint, we highlight the principal cybersecurity measures that should be implemented to facilitate safe and effective integration of large language models (LLMs) into health care and propose a conceptual, life cycle-based framework synthesizing evidence from security and clinical informatics literature. While LLMs offer significant potential for applications in clinical documentation, triage, and medical education, their deployment creates novel vulnerabilities that can compromise patient safety and data confidentiality. We argue that these vulnerabilities must be addressed across the entire deployment life cycle, with distinct threats arising before and after a model enters clinical use. Predeployment risks include data and model poisoning, where an LLM's training data or core parameters are maliciously corrupted to embed biases or backdoors. After deployment, LLMs are susceptible to inference attacks, such as prompt injection and adversarial inputs, which can be used to manipulate model behavior and extract sensitive information. Standard performance benchmarks are often insufficient to detect these sophisticated attacks. Therefore, we argue that a proactive, multilayered security framework combining technical safeguards, rigorous governance, and human-in-the-loop oversight is essential for the safe and trustworthy adoption of LLMs in clinical practice.

Authors

Keywords

No keywords available for this article.