Most physicians know the basic cybersecurity risks: ransomware, phishing emails, stolen passwords and hackers trying to gain access to patient information.
Artificial intelligence is adding a new risk.
Recent incidents involving AI agents have shown that these systems can do more than answer questions. Some can interact with websites and computer systems, search for information and take actions on their own.
That creates an important question for every medical practice:
Could AI find a weakness in your computer systems before you do?
What Happened to Australian Medicare?
In June 2026, an OpenAI artificial intelligence agent gained unauthorized access to a Services Australia website containing Medicare statistical information.
The AI was reportedly conducting legitimate research. When it couldn't obtain the information through the normal process, it found another way to access the system.
It is important to be clear about what happened. This was not reported as a breach of individual Australians' Medicare medical records. The affected system contained Medicare statistics, and Australian officials said there was no evidence that individual patient information was accessed.
What makes the incident important is that the AI reportedly wasn't told to hack the system. It was given a task, encountered an obstacle and found another way to accomplish it.
OpenAI has reported other incidents involving experimental AI agents that were able to get around security controls and gain unauthorized access to computer systems.
For physicians, the message is not that AI is suddenly hacking medical practices everywhere.
The message is that AI may make existing cybersecurity weaknesses easier to find and exploit.
What Does This Have to Do With My Practice?
Think about how many computer systems you use every day:
EHR • Practice-management system • Patient portal • E-prescribing • Laboratory systems • Imaging • Email • Scheduling • Billing • Clearinghouse • Cloud storage
Any one of these systems could contain patient information or provide a pathway to it.
Then think about the things that are easy to overlook: an old computer, outdated software, a former employee's account that was never disabled, a weak password or a backup system that has never actually been tested.
These are the vulnerabilities we need to find before someone—or something—else does.
Your Patient Information Is Probably in the Cloud
This is especially important because many of the computer systems used by medical practices aren't located in the office anymore.
Your EHR may be cloud based. So may your billing system, scheduling software, patient portal, email, backup system and other applications.
This is commonly called Software as a Service, or SaaS.
Cloud software has many advantages and may be more secure than maintaining a server in your office.
But putting your patient information in the cloud does not eliminate cybersecurity risk.
It simply means that some of the risk has moved somewhere else.
For example, a hacker or AI agent might look for a weakness in your cloud vendor's website, login process, software or connections to other systems.
There is also a big difference between attacking the computer in your office and attacking a cloud vendor.
Your computer contains information about your patients.
A large cloud vendor may contain information from hundreds or thousands of medical practices.
That can make cloud healthcare systems attractive targets.
“My Vendor Handles Security” Isn't Enough
Your cloud vendor certainly has responsibility for protecting its systems.
But your medical practice still has responsibilities under HIPAA.
You should know which companies have your patient information and what protections they have in place.
You don't need to understand how their servers work.
You do need answers to some basic questions:
Do they have our patient information?
Do we have a Business Associate Agreement?
Is multifactor authentication available?
How will they notify us if there is a breach?
What happens if their system goes down?
How do we get our information back?
And now there is another question:
Does the vendor use AI with our patient information?
A company you have used for years may add an AI feature to its software. That could change how your patient information is accessed, processed or shared.
Don't Give AI More Access Than It Needs
Medical practices are beginning to use AI for documentation, transcription, scheduling, patient communication, coding and other functions.
These tools can save physicians a tremendous amount of time.
But they should have only the access they need.
If an AI application needs appointment information, it shouldn't automatically have access to the entire medical record.
If it only needs to read information, it may not need permission to change or delete it.
Think about AI the same way you think about employees:
Give it access to what it needs to do its job—and nothing more.
Cybersecurity Is a Patient-Care Issue
Cybersecurity isn't just an IT problem or a HIPAA problem.
It can become a patient-care problem.
Imagine arriving at your office tomorrow morning and discovering that your EHR is unavailable.
Can you see your patients' medication lists?
Can you retrieve yesterday's laboratory results?
Can you send prescriptions?
Do you know which patients are scheduled?
Can you contact them?
Your computers could be working perfectly, but if your cloud EHR is down because the vendor was attacked, your practice may still be unable to function.
That is why physicians need to pay attention to cybersecurity.
5 Questions to Ask Your IT Company This Week
You don't need to become a cybersecurity expert. Ask your IT company these five questions:
☐ 1. Do we use multifactor authentication everywhere we should?
Include your EHR, email, billing system, cloud applications and administrator accounts.
☐ 2. Do we have any old computers, software or network equipment that need to be replaced or updated?
Ask specifically whether anything is no longer receiving security updates.
☐ 3. If ransomware attacked us tonight, could you restore our systems tomorrow?
Don't just ask whether you have backups.
Ask:
“When was the last time you actually restored our data from the backup?”
☐ 4. How would you know if somebody was trying to get into our systems?
Ask who monitors suspicious activity and who gets notified when something unusual happens.
☐ 5. What AI programs have access to our patient information?
Include AI used for documentation, transcription, scheduling, billing, coding and patient communication.
Then ask one final question:
“What is the cybersecurity weakness in my practice that concerns you the most?”
Follow it with:
“What are we doing about it?”
How TLD Systems Helps
One of the challenges for a medical practice is that nobody may be looking at the entire picture.
Your IT company manages your computers and network.
Your EHR company manages your medical records.
Another company may handle your billing.
Someone else provides your email, backups, scheduling or patient communication.
And increasingly, some of those companies are using AI.
Who is looking at all of these systems from the perspective of protecting your patient information and maintaining HIPAA compliance?
That is where TLD Systems helps.
We start with a HIPAA Security Risk Analysis.
The first question is simple:
Where is your patient information?
We look at the computers in your office, but we also look at your EHR, cloud applications, software vendors and other companies that create, receive, maintain or transmit patient information.
Then we look at how that information is protected.
Are appropriate security measures in place?
Is your data encrypted?
Are your backups adequate?
Are your computers protected?
Are there old systems that should be replaced?
Are employees receiving appropriate training?
Are your vendors properly addressed in your HIPAA compliance program?
Are new AI applications creating risks that weren't there before?
Finding the Problem Is Only the Beginning
A Security Risk Analysis isn't useful if it simply produces another report that gets put in a drawer.
When we identify a problem, TLD Systems helps the practice develop a Risk Mitigation Plan.
Some problems may need to be addressed by your IT company. Others may involve employee training, office procedures, vendors or changes to how information is handled.
The goal isn't to make cybersecurity complicated.
The goal is to identify the most important risks and develop a reasonable plan to address them.
No One Can Guarantee You Won't Be Attacked
No IT company, cybersecurity company or HIPAA compliance program can guarantee that your practice will never experience a cyberattack.
The goal is to make an attack less likely and to make sure you are prepared if something does happen.
That means:
Know where your patient information is.
Know who has access to it.
Know which cloud companies have it.
Know which AI applications can access it.
Make sure your backups work.
Make sure your staff knows what to do.
And most importantly:
Find your vulnerabilities before someone—or something—else does.
TLD Systems helps medical practices identify those vulnerabilities and develop practical plans to address them.
Don't wait for a ransomware attack, data breach—or an AI agent—to find your vulnerabilities before you do.
This article is based on publicly reported information available as of September 28, 2026. Investigations involving the Australian Medicare incident and other autonomous AI-agent activity remain ongoing, and additional facts may emerge.

Read Comments