Generative AI, Cybersecurity Among Top Risks for Healthcare Provider Organizations in 2025

Overseeing the use of generative artificial intelligence, enhancing cybersecurity and ensuring compliance with a host of federal healthcare regulations headline the Top Risks health systems face in 2025, according to an annual study by Kodiak Solutions.

Kodiak Solutions develops its annual Top Risks list based on discussions with leaders of many of the largest U.S. hospitals and health systems, and risk assessments or audits at hundreds of hospitals, health systems, medical practices and other provider organizations.

“Our annual Top Risks report illustrates the wide range of risks that are keeping leaders of hospitals and health systems awake at night,” said Dan Yunker, senior vice president, risk and compliance, at Kodiak Solutions. “The ripple effects these risks can cause across a provider organization underscore the need for vigilance to keep problems from becoming entrenched in processes and systems.”

Generative AI leads financial/operational risks

Generative AI, machine learning and other forms of AI offer great promise to health systems to enhance efficiency, offer greater convenience to patients and reduce burdens on clinicians. The growing use of AI comes with many significant potential risks that must be avoided or mitigated. Internal auditors should consider audits in several areas to gauge their preparedness, including:

  • Quality and integrity of existing data sets
  • Cross-functional process development and oversight
  • Testing, governance, policies and legal frameworks for the use and fairness of generative AI
  • Resource training and support of AI-driven processes for adoption of safe and responsible use to ensure patient safety and security
  • Kodiak’s risk management experts also identified revenue cycle and workforce challenges as other financial/operational challenges that deserve heightened oversight.

Cybersecurity threats continue to rise

Hospitals, health systems and medical providers face rising cybersecurity risks directly to their own information systems and, increasingly, from their exposure to attacks made on their vendors. The Change Healthcare data breach, and resulting shutdown of payments for many healthcare providers, illustrated the significant financial losses that provider organizations can sustain during a third-party cyberattack.

Other information technology top risks identified by Kodiak Solutions also are related to cyberattacks. Business continuity capabilities are needed to aid in recovery from cybersecurity incidents. System access management and biomed device security are both aspects of preventing attacks.

Compliance risks in No Surprises Act, price transparency, 340B

Kodiak’s audits and discussions with leaders over the past year highlighted the growing, fast-changing compliance risks with the No Surprises Act, the 340B drug discount program and price transparency regulations. Failing to maintain compliance in any of these areas can lead to significant monetary penalties. In the case of the 340B program, poor compliance can lead to repaying discounts to drug makers and even expulsion from the program.

“Robust internal auditing serves as the last line of defense before small issues grow into large problems that can threaten the health of the enterprise,” Yunker said. “Internal auditing also provides the road map for enhancing training, policies and processes to ensure greater compliance going forward.”

Featured

  • 2025 Gun Violence Statistics Show Signs of Progress

    Omnilert, a national leader in AI-powered safety and emergency communications, has released its 2025 Gun Violence Statistics, along with a new interactive infographic examining national and school-related gun violence trends. In 2025, the U.S. recorded 38,762 gun-violence deaths, highlighting the continued importance of prevention, early detection, and coordinated response. Read Now

  • Big Brand Tire & Service Rolls Out Interface Virtual Perimeter Guard

    Interface Systems, a managed service provider delivering remote video monitoring, commercial security systems, business intelligence, and network services for multi-location enterprises, today announced that Big Brand Tire & Service, one of the nation’s fastest-growing independent tire and automotive service providers, has eliminated costly overnight break-ins and significantly reduced trespassing and vandalism at a high-risk location. The company achieved these results by deploying Interface Virtual Perimeter Guard, an AI-powered perimeter security solution designed to deter incidents before they occur. Read Now

  • The Evolution of ID Card Printing: Customer Challenges and Solutions

    The landscape of ID card printing is evolving to meet changing customer needs, transitioning from slow, manual processes to smart, on-demand printing solutions that address increasingly complex enrollment workflows. Read Now

  • TSA Awards Rohde & Schwarz Contract for Advanced Airport Screening Ahead of Soccer World Cup 2026

    Rohde & Schwarz, a provider of AI-based millimeter wave screening technology, announced today it has won a multi-million dollar award from TSA to supply its QPS201 AIT security scanners to passenger security screening checkpoints at selected Soccer World Cup 2026 host city airports. Read Now

  • Brivo, Eagle Eye Networks Merge

    Dean Drako, Chairman of Brivo, the leading global provider of cloud-native access control and smart space technologies, and Founder of Eagle Eye Networks, the global leader in cloud AI video surveillance, today announced the two companies will merge, creating the world’s largest AI cloud-native physical security company. The merged company will operate under the Brivo name and deliver a truly unified cloud-native security platform. Read Now

New Products

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction.

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure.

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.