Research · curated 27 Sep 2026

Prompt Injection in Healthcare AI: Hiding an Attack in a Scan

Coverage timeline

14 Sep 2026cyberlab.co.uk

Single-source research — first reported, latest, and curated coincide.

Why it matters

Indirect prompt injection hidden in medical scan pixels shows that attacker instructions can enter a clinician-facing diagnostic AI through trusted data channels, potentially corrupting clinical decisions without any direct access to the system.

CyberLab's penetration testing team demonstrated an indirect prompt injection against an NHS-style clinical imaging AI platform by embedding innocuous-looking 'technical note' text directly into the pixels of a medical scan (DICOM image). When a clinician later uploaded the tampered scan and asked routine natural-language questions, the multimodal model ingested the hidden text and let it shape its clinical reasoning, with effects worsening over the conversation.