Omada
Threat Modeling for AI in Digital Healthcare
Pages
31
Time to read
46 mins
Publication
Language
English
Pages
31
Time to read
46 mins
Publication
Language
English
This white paper presents the PROMISE TO MAP threat model, developed by Omada Health, to address the complexities introduced by artificial intelligence (AI) systems, particularly large language models (LLMs), in digital healthcare. It builds upon the previously established INCLUDES NO DIRT model, which guided security and engineering teams in evaluating risks associated with various systems. The new model aims to incorporate AI-specific threats while retaining the foundational risks identified in the original framework. The authors emphasize the importance of defining a common language between risk assessment and engineering teams to facilitate effective threat modeling. The document outlines key components of the threat model, including definitions of system, trust boundary, vulnerability, threat, attack vector, risk, probability, impact, control, and action items. Additionally, it provides a simplified questionnaire worksheet to assist teams in assessing AI systems, encouraging practitioners to adapt the model to their unique needs.