Skip to content
Search
paper2026Unreviewed

Prompt Injection Attacks Against Clinical LLM Agents Accessing Electronic Health Records: A Survey, Threat Model, Benchmark Specification, and Layered Defense Synthesis

Divya Pandey, Shivani Manchanda, Gangesh Pathak, Nishant Sonkar

Abstract

Clinical large language model (LLM) agents are entering production hospital deployments, where they read longitudinal electronic health records (EHRs), retrieve evidence from clinical knowledge bases, and assist with summarization, dosing, triage, and guideline-based decisions. The same architectural patterns that make these agents useful-instruction-following on retrieved text, tool use over patient data, and multi-turn conversation-also expose them to prompt injection attacks across heterogene

Categories

Framework mappings

OWASP Top 10 for Agentic Applications
  • ASI02Tool Misuse & Exploitation
MITRE ATLAS
  • AML.T0051LLM Prompt Injection
  • AML.T0053AI Agent Tool Invocation

Suggested from the entry's categories.

Cite

@misc{pandey2026prompt,
  title = {{Prompt Injection Attacks Against Clinical LLM Agents Accessing Electronic Health Records: A Survey, Threat Model, Benchmark Specification, and Layered Defense Synthesis}},
  author = {Divya Pandey and Shivani Manchanda and Gangesh Pathak and Nishant Sonkar},
  year = {2026},
  doi = {10.2139/ssrn.6828838},
  url = {https://doi.org/10.2139/ssrn.6828838}
}