Cybersecurity, Generative AI Among Top Risks for Healthcare Organizations in 2025

Ensuring compliance with a number of federal healthcare regulations was also identified as a concern by this recent study.

By HFT Staff


Overseeing the use of generative artificial intelligence, enhancing cybersecurity and ensuring compliance with a host of federal healthcare regulations headline the Top Risks health systems face in 2025, according to an annual study by Kodiak Solutions. 

Kodiak Solutions develops its annual Top Risks list based on discussions with leaders of many of the largest U.S. hospitals and health systems, and risk assessments or audits at hundreds of hospitals, health systems, medical practices and other provider organizations. 

“Our annual Top Risks report illustrates the wide range of risks that are keeping leaders of hospitals and health systems awake at night,” says Dan Yunker, senior vice president, risk and compliance, at Kodiak Solutions. “The ripple effects these risks can cause across a provider organization underscore the need for vigilance to keep problems from becoming entrenched in processes and systems.” 

Generative AI leads financial/operational risks 

Generative AI, machine learning and other forms of AI offer great promise to health systems to enhance efficiency, offer greater convenience to patients and reduce burdens on clinicians. The growing use of AI comes with many significant potential risks that must be avoided or mitigated. Internal auditors should consider audits in several areas to gauge their preparedness, including: 

  • Quality and integrity of existing data sets 
  • Cross-functional process development and oversight 
  • Testing, governance, policies and legal frameworks for the use and fairness of generative AI 
  • Resource training and support of AI-driven processes for adoption of safe and responsible use to ensure patient safety and security 

Kodiak’s risk management experts also identified revenue cycle and workforce challenges as other financial/operational challenges that deserve heightened oversight. 

Cybersecurity threats continue to rise 

Hospitals, health systems and medical providers face rising cybersecurity risks directly to their own information systems and, increasingly, from their exposure to attacks made on their vendors. The Change Healthcare data breach, and resulting shutdown of payments for many healthcare providers, illustrated the significant financial losses that provider organizations can sustain during a third-party cyberattack. 

Other information technology top risks identified by Kodiak Solutions also are related to cyberattacks. Business continuity capabilities are needed to aid in recovery from cybersecurity incidents. System access management and biomed device security are both aspects of preventing attacks. 

Compliance risks in No Surprises Act, price transparency, 340B 

Kodiak’s audits and discussions with leaders over the past year highlighted the growing, fast-changing compliance risks with the No Surprises Act, the 340B drug discount program and price transparency regulations. Failing to maintain compliance in any of these areas can lead to significant monetary penalties. In the case of the 340B program, poor compliance can lead to repaying discounts to drug makers and even expulsion from the program. 

“Robust internal auditing serves as the last line of defense before small issues grow into large problems that can threaten the health of the enterprise,” Yunker said. “Internal auditing also provides the road map for enhancing training, policies and processes to ensure greater compliance going forward.” 



December 17, 2024


Topic Area: Information Technology


Recent Posts

The Most Read Healthcare Facilities Today Articles of 2024

Healthcare Facilities Today continues to be a resource for the facilities industry.


Cybersecurity, Generative AI Among Top Risks for Healthcare Organizations in 2025

Ensuring compliance with a number of federal healthcare regulations was also identified as a concern by this recent study.


Facility Condition Assessments and the Bottom Line

Assessments can give managers critical tools they need to transform facilities from cost centers into revenue centers.


NYC Health + Hospitals/Queens Completes Energy Efficiency Upgrade

These upgrades will generate more than $400,000 in annual energy savings.


Saint Vincent Hospital Upgrades Its Security Systems

Case study: The facility upgraded its security systems to comply with the new patient health and safety law, Laura’s Law.


 
 


FREE Newsletter Signup Form

News & Updates | Webcast Alerts
Building Technologies | & More!

 
 
 


All fields are required. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

 
 
 
 

Healthcare Facilities Today membership includes free email newsletters from our facility-industry brands.

Facebook   Twitter   LinkedIn   Posts

Copyright © 2023 TradePress. All rights reserved.