Over the past decade, the US healthcare landscape has witnessed the emergence of alternative payment models designed to realign incentives, improve patient access, and stabilize practice finances. Chief among these innovative models are concierge medicine, Direct Primary Care (DPC), and the pay-first approach.
Although each model operates differently, they share a common goal: reducing administrative burden, enhancing patient engagement, and ensuring predictable revenue streams. Understanding their nuances, benefits, and implementation challenges can help practices decide which path best fits their mission and patient population.
Concierge Medicine, sometimes called “boutique” or “retainer” medicine, typically involves patients paying an annual fee, often several thousand dollars, in exchange for enhanced access to their physician. This can include same-day or next-day appointments, longer visit times, 24/7 phone or text access, and comprehensive annual physicals. For physicians, the concierge model offers a reliable source of revenue detached from traditional insurance reimbursement.
This steady income can reduce reliance on high patient volumes, allowing doctors to maintain smaller patient panels and dedicate more time to individualized care. Patients, in turn, enjoy a white-glove experience: fewer waits, more personal attention, and simplified navigation of preventive care.
Despite its advantages, concierge medicine remains accessible primarily to higher-income patients who can afford the retainer fee. Practices evaluating this model must consider patient demographics and local competition. Physicians must be transparent about which services the retainer covers and which remain subject to traditional insurance billing.
Clear contract terms help prevent confusion when patients seek specialists or hospital care outside the concierge arrangement. Additionally, regulatory and legal frameworks governing retainer practices vary by state, so clinics should seek guidance to ensure compliance with fee-splitting and insurance regulations.
Direct Primary Care (DPC) represents a middle ground between concierge medicine and traditional fee-for-service. In DPC, patients pay a flat monthly or annual subscription—typically ranging from $50 to $100 per person—that covers an agreed-upon suite of primary care services. These may include preventive exams, chronic disease management, basic labs, and unlimited office visits. By removing insurance billing for primary care services, DPC practices eliminate much of the administrative overhead associated with coding, claims submission, and payer denials. The model enables physicians to focus on delivering comprehensive care, often with same-day appointments and enhanced access through telehealth or direct messaging.
Unlike concierge medicine, Direct Primary Care is designed to be affordable for a broader patient base, including those with high-deductible insurance plans or no coverage at all. Patients appreciate the predictability of subscription fees, which can replace unpredictable copays and coinsurance charges. For physicians, DPC creates predictable revenue streams while maintaining the flexibility to bill insurance for services outside the primary care scope, such as specialist referrals, imaging, or hospitalizations. Practices considering DPC should carefully size their patient panels to balance access with financial sustainability, as too many subscribers can strain provider capacity and erode the very benefits that make the model attractive.
The Pay-First Model addresses financial sustainability through a different mechanism: point-of-service collections. At its core, pay-first asks patients to pay their copays, deductibles, or estimated out-of-pocket responsibility when they check in, or even in advance via secure online portals. After insurance adjudication, any remaining balance is automatically charged to a credit card on file. By collecting anticipated patient dues upfront, practices can drastically reduce accounts receivable and bad debt write-offs. Staff spend less time on billing follow up and more on patient engagement, while revenue cycles accelerate and cash flow becomes more predictable.
From the patient perspective, pay-first delivers transparency and convenience. When patients understand their financial responsibility before the visit, surprise bills become a thing of the past. Many practices augment this clarity with automated estimates generated from integrated eligibility and benefits platforms, which check coverage in real time. To succeed with pay-first, practices must communicate clearly across multiple channels—phone, text, email, and web—and offer flexible payment options, including online portals, health savings account payments, or payment plans. Training staff to navigate conversations about costs empathetically is crucial to maintaining trust and minimizing friction.
Although these models each offer compelling advantages, practices must carefully align choice of model with their patient population, specialty, and operational capacity. Smaller primary care clinics in underserved areas may find DPC especially well-suited to populations with high-deductible insurance, as the predictable subscription fee encourages regular preventive visits. Specialty practices with stable, affluent patient bases might lean toward concierge medicine, offering a differentiated, service-rich experience. Multi-specialty groups or larger health systems can pilot pay-first for routine outpatient visits, leveraging their administrative infrastructure and digital engagement tools to reduce billing complexity and improve patient satisfaction.
Regardless of model, technology plays a pivotal role in ensuring success. Practices should invest in integrated EHR platforms that streamline scheduling, billing, and documentation for virtual and in-person visits alike. Automated patient portals and mobile apps facilitate pre-visit questionnaires, consent forms, and payment processing. Telehealth capabilities extend reach beyond the conference room, offering virtual check ins and chronic disease monitoring that complement subscription- or retainer-based care. Data analytics tools can track key performance indicators such as patient acquisition costs, no-show rates, revenue per visit, and patient satisfaction, which enables continuous optimization.
Looking ahead, the adoption of concierge medicine, Direct Primary Care, and pay-first models reflects a broader shift toward value-based, patient-centric care. These approaches challenge the status quo of volume-driven reimbursements, incentivizing proactive, relationship-driven engagement over transactional encounters. As policymakers and payers increasingly recognize the importance of preventive care and population health, hybrid models may emerge, blending subscription fees with performance-based incentives for quality metrics. Practices that remain agile, invest in digital infrastructure, and prioritize transparent communication will be best positioned to thrive in this evolving landscape.
Ultimately, the future of U.S. healthcare depends on aligning financial incentives with patient outcomes and experience. Emerging payment models, whether through concierge retainers, DPC subscriptions, or pay-first collections, offer practical pathways to reduce administrative overhead, improve access, and build sustainable practices. By thoughtfully selecting and tailoring these models to fit their unique context, healthcare providers can create resilient, patient-focused practices that stand the test of time.
This Integrated Cloud Email Security (ICES) application is a cloud-based email security solution that supplements the native security of cloud email providers (such as Microsoft 365) using advanced detection techniques to identify malicious emails and suspicious activity.
ICES empowers organizations to identify and address email security vulnerabilities to better defend against today’s threats, such as Business Email Compromise, AI-crafted Phishes, Deepfake media, and more. For partners, this solution provides a valuable addition to their offerings, enhancing their ability to deliver comprehensive security solutions to customers.
Integrated Email Security Solution
The VIPRE Integrated Email Security Solution offers organizations a powerful, all-in-one defense system against today’s most persistent email-based threats. Combining advanced AI-powered detection, comprehensive protection of internal emails, real-time threat intelligence, automated policy enforcement, and seamless Microsoft 365 integration, this comprehensive solution helps businesses protect sensitive communications, block malicious content, and ensure compliance with regulatory requirements.
“We are proud to deliver a fully integrated email security solution that empowers organizations to stay protected against the ever-evolving email threat landscape, without sacrificing simplicity,” said Oliver Paterson, director, product management, at VIPRE Security Group. “In a time when email remains the number one attack vector, this solution ensures our customers have the layered, adaptive protection needed to outpace evolving threats.”
The VIPRE Integrated Email Security Solution is available as a standalone service or as part of VIPRE’s broader suite of cybersecurity offerings. Its flexible deployment and integration capabilities support organizations in building a unified, layered security strategy tailored to their evolving business needs.
By Matthew Bernier, product management director and VP of PayerSync, Rectangle Health.
Healthcare providers are at a defining point, grappling with financial strain, often stemming from outdated and inefficient revenue cycle management (RCM) strategies.
These strategies, often riddled with manual inefficiencies and slow to adapt, are no longer sufficient to navigate the relentless tide of evolving payer regulations, skyrocketing denial rates, and the growing financial burden on patients.
RCM is widely recognized as an essential framework supporting the financial health and operational effectiveness of medical practices. Despite significant advancements in healthcare technology, many reimbursement processes remain outdated, cumbersome, and fragmented. This escalating pressure isn’t just a minor inconvenience; it’s actively eroding reimbursements, stifling cash flow, and ultimately compromising a provider’s ability to deliver essential patient care.
New research from American Express and PYMNTS revealed that 67% of healthcare payer executives reported that their firms’ reliance on manual payment systems is hampering their operational efficiency. Additionally, nearly 74% said that these outdated systems are increasing their exposure to regulatory fines and compliance penalties. Healthcare providers are already feeling the sting, meaning streamlining these processes is vital for redirecting valuable resources toward patient care and clinical services.
The Pitfalls of Outdated Reimbursement Methods
Many inefficiencies originate from continued reliance on traditional payment systems, notably paper checks and standard ACH transfers. While foundational in their own right, these payment methods were not designed to accommodate healthcare’s specialized requirements, such as the secure, compliant transmission of detailed patient remittance information. Providers frequently find themselves manually reconciling Explanation of Payments (EOPs) with deposits, a process prone to delays, errors, and unnecessary complexity.
Although ACH transfers represent a digital improvement over paper checks, standard ACH formats typically cannot include the comprehensive remittance details essential for precise and timely payment reconciliation. Additionally, financial institutions lack the infrastructure and incentives to manage HIPAA-sensitive information securely, adding administrative burdens and complexity for healthcare organizations.
Mounting Financial Pressures on Providers
The financial impact on providers due to outdated reimbursement methods is evident. According to a 2024 survey by Experian Health, 73% of healthcare administrators reported an increase in claim denials, rising from 42% just two years prior.
Several factors contribute to this decline:
Increased claim denials: Providers are seeing higher initial claim denial rates, especially from commercial health plans and Medicare Advantage plans.
Higher patient financial responsibility: The rise in high-deductible health plans and cost-sharing arrangements has placed more financial burden on patients, complicating the collection process.
Bad debt write-offs: Insured patients are increasingly accounting for significant amounts of bad debt, creating additional financial strain on healthcare providers.
Ongoing healthcare staffing shortages only amplify these challenges. Healthcare leaders report severe impacts from staff shortages, with 81% citing delays in care, longer wait times, and reduced access to essential services as significant issues. Providers, already stretched thin, are forced to divert limited resources to manage overdue payments, exacerbating administrative strain and creating uncertainty around cash flows and financial projections.
The Power of Next Generation Payment Rails
Addressing the persistent challenges of healthcare payments, next-generation digital payment rails offer providers a transformative path forward. Unlike standard ACH transfers, these advanced digital rails embed detailed remittance data directly within transactions, providing immediate, automated reconciliation. This integration reduces the time providers spend matching payments to claims, dramatically decreasing accounts receivable (A/R) days.
Providers already leveraging these innovative payment rails have experienced reimbursement processing times shrink from weeks to days. These streamlined systems automatically post reimbursements directly into practice management systems (PMSs) or electronic medical records (EMRs), eliminating manual data entry and reducing costly errors.
Next generation payment solutions meet patients’ evolving expectations. Modern online digital payment portals provide patients with transparent billing, cost estimates, flexible payment options, and insurance information. This is particularly important as nearly seven in 10 Gen Z patients report having payment issues with their latest healthcare service, highlighting a strong preference for convenient, contactless, and online payment methods. For providers, these solutions streamline billing through stored patient payment methods, deliver instant notifications, and offer consistent reporting across all payers, significantly enhancing financial visibility and control.
Digital Reimbursement: Accelerating Cash Flow and Accuracy
To overcome revenue cycle challenges effectively, providers should embrace automation and digitization within their reimbursement workflows. Modern, healthcare-specific digital reimbursement solutions securely integrate detailed, HIPAA-compliant patient data directly into financial transactions. This integration reduces manual reconciliation, enhancing accuracy and accelerating the reimbursement cycle.
Digitally automated reimbursement solutions consolidate various payment forms into a unified system, offering providers real-time transaction visibility and simplified reconciliation. By automating routine administrative tasks, healthcare staff can dedicate more time to high-value activities focused on patient care and practice growth, resulting in improved patient experiences and outcomes.
Additionally, automated reimbursement solutions provide immediate insights into payment statuses, equipping providers with accurate revenue forecasting, efficient budgeting, and proactive financial management.
The Path to Financial Strength
As reimbursement complexity grows, adopting automated and digitally integrated payment systems designed explicitly for healthcare becomes essential. Providers who modernize their reimbursement processes today will position themselves to handle industry challenges more effectively, securing their financial health, enhancing operational efficiency, and ensuring superior patient care for years to come.
Virtual credit card (VCC) payments from insurance companies are on the rise and are often costing practices more than they realize. We sat down with Eric Cohen, CEO of Merchant Advocate, to unpack what providers should know about VCCs, the fees they often don’t see, and how to fight back without switching processors.
Q: What exactly are virtual credit cards, and why are they becoming more common in healthcare reimbursement?
Virtual credit cards are randomly generated, single-use credit card numbers typically issued by an insurance payer or payment aggregator for provider reimbursement. They’re often pitched as a secure and efficient alternative to paper checks or electronic funds transfers (EFTs). For insurance companies, VCCs streamline the payment process, allowing them to earn cashback rewards on the transaction. This makes VCCs attractive for payers, but the convenience comes at a cost to providers.
Q: What kind of costs are we talking about?
Most healthcare providers are unaware that virtual credit card payments can carry processing fees anywhere from 2% to 5%. On average, we see providers paying between an additional 3% to 4% per transaction with VCCs. Over time, those fees add up significantly, especially for high-volume practices.
Q: Isn’t that just the cost of doing business in a digital age?
Not necessarily. That’s a common misconception. The truth is that providers often have a choice, but they don’t realize it. In many states, insurance companies are legally required to offer alternatives to VCCs, including ACH EFT payments, which carry much lower fees, typically just a few cents per transaction. Many insurers still default to VCCs unless the provider explicitly requests something else.
Q: So, if a provider wants to avoid these fees, what should they do first?
Step one is understanding your rights. Several states, including Colorado, have passed legislation that prohibits insurance companies from making VCCs the only reimbursement method. Check with the American Medical Association or your state medical board to find out what the law says in your jurisdiction.
Reviewing your contracts is also crucial. Many providers sign agreements with insurers without realizing that payment terms are included or negotiable. If you’re not sure what your agreement allows, that’s a red flag that warrants a closer review.
Q: What other steps can providers take to reduce or avoid these hidden fees?
Audit your current payments. Understand how you’re getting paid, by whom, and how often. Separate VCCs from EFTs and patient payments. Many practices don’t even realize how much of their reimbursement is tied to VCCs until they do a line-item audit.
Request alternative payment methods. If your state allows it, formally request ACH EFTs from payers instead of accepting VCCs by default. Keep written documentation of those requests and any responses from the payer. If they deny your request without cause, you can file a complaint against the health plan with the Centers for Medicare & Medicaid Services.
Partner with experts. Outside experts can help providers navigate the complexities of payment systems and identify areas where fees can be reduced. These professionals can assist with contract analysis, clarify fee structures, and suggest more cost-effective payment arrangements, all without requiring a change in processors.
Q: Can you share an example of what fee reduction might look like in practice?
Every medical practice is different, but we often find that providers are unaware of how much they’re losing to virtual card fees until they take a closer look. By analyzing how reimbursements come in and working through the details of payer contracts, many practices can shift toward lower-cost payment methods, such as ACH, and significantly reduce overall processing costs. These improvements often don’t require changing processors or overhauling operations, just more transparency and better oversight.
Q: Why isn’t this issue more widely known in the healthcare industry?
I think it’s a combination of opacity and inertia. The payment space is complex and constantly evolving. Most administrators are focused on delivering quality care and managing day-to-day operations, not the nuances of interchange fees. VCCs are also marketed as the default, making them easy to accept and hard to question unless you know what to look for.
Q: Any final advice for healthcare administrators who want to get ahead of this?
Stay informed and proactive. Treat your payment methods like any other vendor or operational expense; you wouldn’t accept a 3% surcharge on your rent or utilities without questioning it. The same scrutiny should apply here. A few small changes could make a big difference to your bottom line.
Health Level Seven International (HL7), a leading global healthcare standards development organization, is pleased to announce the official launch of its HL7 Business Process Modeling (BPM) Community of Practice. Now open for membership, the community is dedicated to advancing interoperability, process consistency, and process automation through the use of formal modeling techniques promoting better modeling, sharing, and execution of clinical and administrative workflows across the healthcare ecosystem.
BPM Community of Practice builds upon three open standards-based languages – referenced together as “BPM+”, and include:
BPMN (Business Process Model and Notation): For prescriptive workflows
CMMN (Case Management Model and Notation): For reactive activities
DMN (Decision Model and Notation): For complex decision-making rules
The use of these standards, in concert, allows inherent ambiguities in natural-language guidelines to be clarified, providing precise, automatable guidance to improve care quality and consistency. Organizations use BPM+ to model and streamline processes, ensuring accurate and scalable healthcare delivery, process consistency, comparability, and repeatability.
“HL7’s focus is on bringing together communities to advance all aspects of interoperability, and that includes workflow and care processes,” said Ken Rubin, Community Coordinator of the HL7 BPM Community of Practice. “This launch marks an important step in providing the healthcare industry with tools, models, and frameworks to manage care processes more effectively, consistently, and collaboratively.”
The BPM Community of Practice builds on years of foundational work in clinical business process modeling and is now positioned to contribute meaningfully to FHIR-based implementation efforts. Members will collaborate to support real-world needs like shared care planning, cross-organizational process execution, human and system interaction modeling, and automation through service orchestration and decision support.
“Welcoming the BPM Community of Practice into our organization was a natural fit. We are excited about the possibilities it brings to leverage and build upon FHIR to enable and support shared care, consistency, and reliability in healthcare practices,” said Dr. Charles Jaffe, CEO of HL7 International. “Moving forward, our industry needs solutions that can effectively manage interactions between humans, systems, and AI to support process portability and seamless care.”
The BPM Community of Practice offers an open environment where stakeholders from healthcare, health IT, academia, and government can collaborate to shape how workflows are represented and executed within the FHIR ecosystem. It provides a platform for those working in this space to collaborate, learn from one another, collect and document best practices, and engage with peer experts.
“The HL7 BPM Community of Practice is a game-changer for aligning complex healthcare workflows with the precision and scalability of FHIR,” said Dr. Thomas Chon, CEO of Tetra Fields LLC. “By uniting leading modeling standards, this community empowers collaborative, interoperable solutions that improve care coordination and execution across the healthcare system.”
By Scott E. Rupp, editor, Electronic Health Reporter.
In 2025, AI in healthcare is no longer a distant ambition—it’s an operational force. But as we stare down the next five years, what matters isn’t what AI could do. It’s what it will do, based on current trajectory, real-world deployment, and policy infrastructure.
Let’s cut past the marketing fluff. Below is a grounded look at how AI is reshaping healthcare now—and how it will evolve by 2030—through the lens of diagnostics, documentation, monitoring, drug development, operations, and governance. This isn’t speculation. It’s what the tech, the economics, and the outcomes are already showing us.
AI in Diagnostics: From Hype to Clinical Utility
Recent developments in diagnostic AI underscore a leap beyond narrow models. Microsoft’s Multimodal AI Diagnostic Orchestrator (MAI-DxO), for example, has shown 85.5% accuracy in diagnosing complex conditions—significantly outperforming unaided physicians in a controlled study. It isn’t replacing clinicians, but rather augmenting them by synthesizing imaging, lab values, and clinical notes into actionable differentials.
What’s next? Between now and 2030, expect diagnostic support tools to become embedded into EHR workflows. AI won’t just suggest differential diagnoses—it will flag overlooked symptoms, propose appropriate next steps, and track care adherence. Clinicians who adopt this technology will find themselves practicing “assisted medicine,” with reduced cognitive load and more consistent care across patient populations.
Clinical Documentation: The Administrative Front Line
Physician burnout continues to correlate with time spent in EHRs—often charting late into the night. AI scribes and ambient listening tools like Suki, Abridge, and Nuance DAX are making measurable inroads. One recent study found documentation time dropped by over 60% after implementing voice AI, with corresponding improvements in patient satisfaction and physician experience.
This is one of the lowest-risk, highest-yield applications of AI in healthcare, and adoption is accelerating. By 2027, we should expect clinical documentation to be mostly machine-generated and human-edited in ambulatory care and some inpatient settings. Expect significant expansion into coding, utilization review, and real-time note summarization. In revenue cycle management, this will radically improve claims accuracy and reduce denials.
AI in Remote Monitoring: Early Intervention, Not Just Passive Data
The convergence of wearables, ambient sensors, and AI analytics is quietly becoming one of the most effective tools for managing chronic conditions. What’s changing now is contextualization: AI doesn’t just measure—it interprets and flags risk. Systems are already showing promise in detecting atrial fibrillation, early-onset heart failure, and even cognitive decline through pattern recognition in voice and movement.
Expect AI to play a growing role in longitudinal care between visits. More than 35% of U.S. health systems are expected to integrate AI-driven monitoring solutions by 2026. Hospital-at-home models will increasingly rely on these tools to support early discharge, flag adverse trends, and prevent readmissions—helping address the financial strain from value-based care models.
AI in Drug Discovery and Trial Design: Time-to-Therapy Will Shrink
AI is accelerating drug discovery by optimizing target identification, simulating molecular interactions, and streamlining trial recruitment. Insilico Medicine, Recursion, and Exscientia are examples of companies slashing preclinical timelines by up to 50% using AI.
By 2030, expect AI to redesign how clinical trials are run—from adaptive designs that learn during execution, to digital twins that simulate patient responses to reduce trial size. Large language models will also aid protocol writing, patient matching, and compliance documentation. The result? Fewer failed trials, faster paths to market, and dramatically lower costs.
Back-Office Automation: The Real Cost Frontier
Administrative complexity remains one of the largest sources of waste in the U.S. healthcare system. AI is already reducing this burden through automations in prior authorizations, denial management, supply chain logistics, and call center operations.
By 2030, back-office automation powered by AI will be table stakes. Health systems will deploy intelligent agents for high-volume tasks like eligibility checks, appointment reminders, claims scrubbing, and patient financial counseling. This will reshape the workforce, reallocating humans to oversight and exception handling, rather than repetitive processing.
Estimates from McKinsey and others suggest that automation could drive over $150 billion in annual savings across the U.S. healthcare system, without touching a single clinical procedure.
Regulatory Momentum and Ethical Infrastructure
As of mid-2025, over 340 AI-enabled tools are FDA-cleared, mostly in radiology and cardiology. The regulatory environment is slowly catching up to the pace of innovation, with a push toward lifecycle oversight, real-world performance data, and post-market surveillance.
The next challenge is equity and transparency. Recent studies highlight significant performance discrepancies across demographic groups. To avoid algorithmic bias becoming clinical harm, AI developers and health systems must prioritize diverse training data, model interpretability, and explainable outputs.
We’re also likely to see a move toward mandatory algorithm audits and AI “nutrition labels”—initiatives that clarify how models were trained, tested, and validated for real-world use.
What Health IT Professionals Should Do Now
As stewards of digital infrastructure, health IT leaders are at the center of this transformation. But the task isn’t just implementation; it’s orchestration. Here’s where to focus:
Pilot with a purpose: Start small, measure well. Focus on low-risk, high-reward areas like documentation or revenue cycle automation.
Govern with clarity: Stand up AI review boards and build governance frameworks now—before use cases scale.
Invest in interoperability: AI is only as good as the data it receives. Ensuring clean, accessible, and standardized data remains the most strategic move any IT team can make.
Push for explainability: If a vendor can’t explain how their AI reaches conclusions, don’t implement it. Full stop.
Final Thought: Beyond the Buzzwords
AI in healthcare is real, impactful, and increasingly essential. But this isn’t about science fiction. It’s about systems — designed, tested, and governed by people — serving other people.
By 2030, the systems that win will be those that operationalize AI in ways that are trusted, useful, and invisible to the patient. We don’t need to marvel at AI. We need to make it mundane, baked into the background, improving care every day, without fanfare.
From the dawn of the Internet to the advent of electronic health records, the healthcare industry historically has been slow to embrace new technologies and the improvements they can bring. One reason is the perceived risks associated with these technologies. Another is the perceived costs of implementing them.
The rise of cloud computing and artificial intelligence presents healthcare providers — traditional ones like hospitals and health systems, along with medical device providers and other entities that meet the “provider” definition — presents the industry with a similar tech conundrum. As new players join more conventional providers in reshaping the patient care ecosystem, opportunities abound for them to leverage the cloud, AI and other tools to reinvent healthcare business processes, services and the patient experience.
But with those upside opportunities come potential new risks and costs, including compliance challenges with HIPAA, a law that doesn’t readily reconcile with technologies like AI or cloud computing, which weren’t around when it was promulgated, nor with the growing diversity of entities now defined as patient care providers.
For this growing class of providers, the applications for AI and other intelligent technologies are indeed promising, for things like predicting certain elevated risks for patients, diagnosing issues and recommending treatments. Generative AI (genAI) copilots driven by large language models could support decision-making about diagnoses and treatments. GenAI also shows great promise for improving clinician and clinical productivity. As versatile as it is, AI also can help companies manage their compliance responsibilities — and the data required to meet them — across multiple jurisdictions.
What’s more, AI shows potential for connecting patient health with marketing, where, for example, based on an analysis of patient data, AI-powered capabilities serve shopping list recommendations to patients for vitamins, supplements, over-the-counter medications, etc., when they’re in-store or shopping online. This intelligent health-based marketing looks like a highly promising frontier for companies that can get it right.
Risk and reward
AI’s huge potential clearly isn’t lost on healthcare companies. In a 2024 survey of 100 upper-level U.S. healthcare execs conducted by McKinsey, 72% of respondents said their organizations are either already using genAI tools or are testing them. Another 17% said they were planning to pursue genAI proof of concepts. And now their AI investments have begun to pay off. About 60% of those who have implemented gen AI solutions are either already seeing a positive ROI or expect to.
This growing embrace of AI and cloud computing introduces a whole new set of issues, risks and responsibilities that healthcare providers — and their regulators — must contemplate. Ensuring patient privacy and data security in compliance with HIPAA is perhaps the most pressing of those issues. Because HIPAA became law in 1996, well before Amazon, Google, the cloud and AI entered the tech mainstream, and well before medical device companies, insurers and the Walmarts of the world were providing some form of care directly to patients, its provisions aren’t equipped to discern how compliance responsibilities and liability should be shared among the various parties that now touch patient data, including covered entities and their business associates. As the definition of “provider” changes, companies in many more industries now may touch patient data in some way.
The increasing use of AI by patient care providers brings new categories of associated entities into the compliance mix. That includes the hyperscalers that host the cloud-based AI capabilities and large language models providers are using, the software/tech companies that build and sell these systems, and the system integrators that are helping providers implement them. Who’s liable for a data breach? Who owns the risk associated with protecting patient information in this broader care ecosystem? It is a true legal quagmire with few clear answers.
The perception of AI as an untested technology (at least in a healthcare context) is also part of the risk equation. How to address potential bias and hallucination risk in large language models, for example? The cost of implementing cloud-based AI and other tech infrastructure, and internal resistance to embracing these new technologies, also factor into that equation.
Maximizing tech’s potential
A 2023 article in the Harvard Business Review contends that implementing cloud-based AI capabilities in a way that’s compliant will require extensive cooperation among stakeholders across the healthcare landscape. “Payers, health systems, and providers need to come to a common understanding about when it is appropriate to use an AI application, how it should be used, and how potential side effects will be identified and mitigated.”
That’s a necessary and worthwhile undertaking, the article’s author concludes. “It would be sadly ironic if the U.S. health sector lagged in reaping the benefits of this transformative new technology.”
The challenge here is a huge one: establishing widely accepted practices, standards and guardrails around cloud computing and AI so regulation can catch up to and keep pace with technology and the ethical and security issues it raises, as well as with the shifting patient care ecosystem.
The most viable vehicle for doing so, at least here in the U.S., could be to establish some kind of broad stakeholder consortium, perhaps led by the U.S. government (the FDA and/or HHS, for example), and including medical colleges/boards, along with covered entities and their business associates under HIPAA. The goal: develop consensus about how the responsibilities and liabilities associated with HIPAA will be divided and executed in the AI era.
A broader embrace of the cloud and AI within the patient care ecosystem increases the universe of covered entities and business associates that likely will be touching or at least have some role, direct or indirect, in the handling of patient data. That in turn necessitates formation of business networks, within which data can flow unimpeded, transparently and securely between relevant entities in the patient care ecosystem.
So, for instance, in the case of cell and gene therapies, a business network would enable the various stakeholders handling a patient’s treatment, from drawing a blood sample to producing, delivering and administering the actual therapy, to securely connect to share and analyze information in a timely and compliant way to yield the best possible patient outcome. Each member of the value chain thus must have the security and data-management capabilities in place to viably participate in such a network. This same concept would also apply to clinical networks.
As daunting as some of this may sound, technology like AI will not stand still. So neither should members of the patient care value chain in laying the necessary groundwork — standards, networks, etc. — to take full advantage of intelligent technologies in a way that’s compliant, profitable and most importantly, beneficial for patients.
By Chris Cronin, partner, HALOCK Security Labs and chair of the DoCRA Council
We strongly recommend an annual penetration test if your company is on the internet. Also known as a pen test, this is where you simulate a cyber attack to discover and exploit weaknesses in your network, app, wifi, or system.
Note, however, you have external threats, but you have what are thought of as internal ones too. Internal penetration testing is just as much required.
This type of testing will simulate the type of attack you could get from an unscrupulous insider, like an unhappy employee or contractor who would misuse their privilege.
Why Conduct Pen Testing?
It is also recommended that you hire a third party with expertise in the latest penetration test techniques. Think of it as hiring an ethical hacker to break into your digital infrastructure before the bad guys do. Some of the benefits of conducting a pen test include:
Although a pen test by itself is invaluable, it shouldn’t be looked at as a one-time event. Regular pen testing is needed to keep pace with evolving threats, uncover new vulnerabilities introduced by system changes, validate the effectiveness of security controls, and ensure ongoing compliance with industry standards
A New Incentive for Pen Testing
If your organization is responsible for HIPAA compliance, you may have another incentive to begin regular pen testing. That is because on December 24, the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) issued a Notice of Proposed Rulemaking (NPRM) to modify HIPAA. Some of the details include the following:
Tests must be performed by qualified professionals with appropriate cybersecurity expertise.
Pen tests must simulate real-world cyberattacks to identify exploitable weaknesses in systems that create, receive, maintain, or transmit electronic protected health information (ePHI).
The frequency of penetration testing may be increased if a risk analysis determines it is necessary. The proposed rule would also require technical controls such as regular patching and vulnerability management, with penetration testing serving as a key validation method.
New Requirements for Incident Response Plans
Every digital organization today must have a well-crafted incident response plan (IRP) to guide their response and recovery efforts for an attack today. The new proposal for HIPAA also includes guidance for responding to security incidents. Some of the proposed requirements include:
Establish written security incident response plans and procedures documenting how workforce members are to report suspected or known security incidents and how the regulated entity will respond to suspected or known security incidents.
Establish written procedures to restore the loss of certain relevant electronic information systems and data within 72 hours.
Implement written procedures for testing and revising written security incident response plans.
Current HIPAA Obligation
As of right now, current HIPAA requirements do not require pen testing. While HIPAA does require organizations to have incident response plans in place, the existing rules allow considerable flexibility that allows each organization to tailor its incident response approach based on its unique risks, size, and resources.
Under the proposal, organizations would be required to adopt a formalized, fully documented incident response plan that clearly defines roles and responsibilities, outlines escalation procedures, and mandates thorough post-incident reviews. This shift aims to standardize incident response practices and ensure a consistent, proactive approach.
When Will the New Requirements Take Effect?
The updated HIPAA Security Rule was introduced in January 2025 and the public comment period closed on March 7, 2025. The Department of Health & Human Services (HHS) is now processing and evaluating the submitted comments and will subsequently issue the Final Rule in the Federal Register.
The proposed changes include additional requirements as well such as bi-annual vulnerability scan and multi-factor authentication (MFA) requirements.