2026Unreviewed
Prompt Injection Attacks Against Clinical LLM Agents Accessing Electronic Health Records: A Survey, Threat Model, Benchmark Specification, and Layered Defense Synthesis
Divya Pandey, Shivani Manchanda, Gangesh Pathak, Nishant Sonkar
Abstract
Clinical large language model (LLM) agents are entering production hospital deployments, where they read longitudinal electronic health records (EHRs), retrieve evidence from clinical knowledge bases, and assist with summarization, dosing, triage, and guideline-based decisions. The same architectural patterns that make these agents useful-instruction-following on retrieved text, tool use over patient data, and multi-turn conversation-also expose them to prompt injection attacks across heterogene
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
OWASP Top 10 for Agentic Applications
- ASI02Tool Misuse & Exploitation
MITRE ATLAS
- AML.T0051LLM Prompt Injection
- AML.T0053AI Agent Tool Invocation
Suggested from the entry's categories.
Cite
@misc{pandey2026prompt,
title = {{Prompt Injection Attacks Against Clinical LLM Agents Accessing Electronic Health Records: A Survey, Threat Model, Benchmark Specification, and Layered Defense Synthesis}},
author = {Divya Pandey and Shivani Manchanda and Gangesh Pathak and Nishant Sonkar},
year = {2026},
doi = {10.2139/ssrn.6828838},
url = {https://doi.org/10.2139/ssrn.6828838}
}