Generative AI, Cybersecurity Among Top Risks for Healthcare Provider Organizations in 2025

Overseeing the use of generative artificial intelligence, enhancing cybersecurity and ensuring compliance with a host of federal healthcare regulations headline the Top Risks health systems face in 2025, according to an annual study by Kodiak Solutions.

Kodiak Solutions develops its annual Top Risks list based on discussions with leaders of many of the largest U.S. hospitals and health systems, and risk assessments or audits at hundreds of hospitals, health systems, medical practices and other provider organizations.

“Our annual Top Risks report illustrates the wide range of risks that are keeping leaders of hospitals and health systems awake at night,” said Dan Yunker, senior vice president, risk and compliance, at Kodiak Solutions. “The ripple effects these risks can cause across a provider organization underscore the need for vigilance to keep problems from becoming entrenched in processes and systems.”

Generative AI leads financial/operational risks

Generative AI, machine learning and other forms of AI offer great promise to health systems to enhance efficiency, offer greater convenience to patients and reduce burdens on clinicians. The growing use of AI comes with many significant potential risks that must be avoided or mitigated. Internal auditors should consider audits in several areas to gauge their preparedness, including:

  • Quality and integrity of existing data sets
  • Cross-functional process development and oversight
  • Testing, governance, policies and legal frameworks for the use and fairness of generative AI
  • Resource training and support of AI-driven processes for adoption of safe and responsible use to ensure patient safety and security
  • Kodiak’s risk management experts also identified revenue cycle and workforce challenges as other financial/operational challenges that deserve heightened oversight.

Cybersecurity threats continue to rise

Hospitals, health systems and medical providers face rising cybersecurity risks directly to their own information systems and, increasingly, from their exposure to attacks made on their vendors. The Change Healthcare data breach, and resulting shutdown of payments for many healthcare providers, illustrated the significant financial losses that provider organizations can sustain during a third-party cyberattack.

Other information technology top risks identified by Kodiak Solutions also are related to cyberattacks. Business continuity capabilities are needed to aid in recovery from cybersecurity incidents. System access management and biomed device security are both aspects of preventing attacks.

Compliance risks in No Surprises Act, price transparency, 340B

Kodiak’s audits and discussions with leaders over the past year highlighted the growing, fast-changing compliance risks with the No Surprises Act, the 340B drug discount program and price transparency regulations. Failing to maintain compliance in any of these areas can lead to significant monetary penalties. In the case of the 340B program, poor compliance can lead to repaying discounts to drug makers and even expulsion from the program.

“Robust internal auditing serves as the last line of defense before small issues grow into large problems that can threaten the health of the enterprise,” Yunker said. “Internal auditing also provides the road map for enhancing training, policies and processes to ensure greater compliance going forward.”

Featured

  • TSA Intercepts 6,678 Firearms at Airport Security Checkpoints in 2024

    During 2024, the Transportation Security Administration (TSA) intercepted a total of 6,678 firearms at airport security checkpoints, preventing them from getting into the secure areas of the airport and onboard aircraft. Approximately 94% of these firearms were loaded. This total is a minor decrease from the 6,737 firearms stopped in 2023. Throughout 2024, TSA managed its “Prepare, Pack, Declare” public awareness campaign to explain the steps for safely traveling with a firearm. Read Now

  • 2024 Gun Violence Report: Fewer Overall Incidents, but School Deaths and Injuries Are on the Rise

    Omnilert, provider of gun detection technology, today released its compilation of Gun Violence Statistics for 2024 summarizing gun violence tragedies and their adverse effects on Americans and the economy. While research showed a decrease in overall deaths and injuries, the rising number of school shootings and fatalities and high number of mass shootings underscored the need to keep more people safe in schools as well as places of worship, healthcare, government, retail and commerce, finance and banking, hospitality and other public places. Read Now

  • Survey: Only 7 Percent of Business Leaders Using AI in Physical Security

    A new survey from Pro-Vigil looks at video surveillance trends, how AI is impacting physical security, and more. Read Now

  • MetLife Stadium Uses Custom Surveillance Solution from Axis Communications

    Axis Communications, provider of video surveillance and network devices, today announced the implementation of a custom surveillance solution developed in collaboration with the MetLife Stadium security team. This new, tailored solution will help the venue augment its security capabilities, providing high-quality video at unprecedented distances and allowing the security team to identify details from anywhere in the venue. Read Now

Featured Cybersecurity

Webinars

New Products

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols. 3

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis. 3

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure. 3