
Share
A new survey of 70 payer and provider executives finds AI ambitions outpacing security readiness, with shadow AI tools and AI-assisted cyberattacks emerging as under-addressed operational threats heading into 2027.
Healthcare organizations are moving fast on AI. Their security postures are not keeping pace. That is the core tension surfaced in a new report from MedCity News and Cotiviti, drawn from interviews with 70 healthcare executives at payer and provider organizations surveyed over the summer of 2026.
The findings will be unpacked in a webinar on September 30, running from 1pm to 2pm ET, built around the 2026 Healthcare AI Readiness Index. The session promises a level of candor that survey data alone rarely delivers, since it draws on direct executive commentary rather than aggregated percentages.
For investors and operators tracking healthcare's AI buildout, this matters. Readiness gaps have a way of turning into balance sheet events, whether through breach costs, regulatory penalties, or stalled deployments that never reach the ROI executives promised their boards.
The report's scope is narrower than the typical AI hype survey, and that is a strength. Rather than asking executives whether they believe in AI, it asks what is actually blocking adoption, how success gets measured, and who is minding the security perimeter.
Four themes anchor the discussion. First: the primary barriers to AI adoption, which the webinar organizers position as distinct from the usual budget-and-talent complaints. Second: the metrics organizations use to define AI success, and how those metrics diverge between payers and providers. That divergence is worth sitting with. A payer optimizing for claims-processing accuracy and a provider optimizing for clinical documentation speed are not playing the same game, even when both call it "AI success."
Third, and arguably the most consequential theme: policies governing employee AI use, and how organizations are responding to shadow AI, the unsanctioned tools employees adopt on their own initiative. Shadow AI is not a hypothetical risk. It is a known failure mode in every enterprise software category that preceded this one, and healthcare's data sensitivity makes the stakes higher than most.
Fourth: preparation for AI-assisted cyberattacks, paired specifically with multi-factor authentication readiness. That pairing is notable. It suggests executives are not just worried about AI as an attack vector in the abstract, but are being asked concretely whether their authentication infrastructure can hold up against AI-enhanced social engineering and credential-stuffing techniques that are already more sophisticated than the defenses many organizations built five years ago.
Healthcare has long been a target-rich environment for cybercriminals. Patient data commands a premium on illicit markets, and provider networks often run on legacy infrastructure that was never designed with modern threat models in mind. Layer AI adoption on top of that, and the attack surface expands in ways that are hard to fully audit.
Shadow AI compounds the problem. When employees route sensitive data through consumer-grade AI tools that IT never approved, the organization loses visibility into where that data goes. Governance policies help, but only if they are enforced and understood at the point of use, not just written into a compliance manual.

The metrics divergence between payers and providers deserves attention too. If payer organizations are measuring AI success primarily through cost containment and processing efficiency, while providers lean toward clinical outcomes and workflow time savings, that split has implications for how vendors price and position their products. It also complicates any effort to benchmark AI performance across the industry, since apples-to-apples comparisons become harder when the underlying success criteria differ by business model.
The most immediate risk is the gap between adoption speed and security maturity. Deploying AI tools faster than an organization can govern them is a familiar pattern in enterprise technology history, and healthcare has less margin for error than most sectors given HIPAA exposure and patient safety stakes.
A second risk sits in the authentication layer specifically. Multi-factor authentication has become table stakes in most industries, yet the webinar's framing implies it remains a live question in healthcare, whether existing MFA implementations are robust enough to withstand AI-assisted attacks. If that question is still open among executives responsible for enterprise security, it signals the industry's defensive posture has not fully absorbed how much attacker capability has evolved.
Regulatory uncertainty adds a third layer. AI governance frameworks in healthcare are still being written in real time at the federal and state level. Organizations building internal policy now risk having to retrofit compliance later, an expensive proposition once systems and workflows are already in production.
None of this argues against AI adoption. It argues for sequencing. Organizations that build governance and authentication infrastructure alongside their AI rollouts, rather than after a breach forces the issue, will likely see better cost outcomes over a three-to-five-year horizon.
The report's provider-payer metric split also points to a market opportunity for vendors that can serve both success definitions simultaneously. A platform that can demonstrably reduce claims processing costs for a payer while also improving clinical documentation speed for a provider has a wider addressable market than a tool built for just one side of that divide.
For executives evaluating vendor partnerships, the shadow AI findings suggest a practical filter: does the vendor's product reduce the temptation for employees to seek workarounds, or does it add friction that pushes usage underground? That single question may do more to predict long-term security outcomes than any compliance checklist.
Sixty-eight percent of the surveyed executives, drawn from a sample of 70 across payer and provider organizations, are grappling with the same core question: how to move fast on AI without creating security debt that outlasts the productivity gains. The September 30 webinar will offer more granular breakdowns of the index's findings, but the shape of the problem is already clear. AI readiness in healthcare is no longer primarily a technology question. It is a governance and security question wearing a technology label, and the organizations that treat it that way will be the ones still standing when the next wave of AI-assisted threats arrives.
Tags
Original Sources
Healthcare Executives Weigh In: AI Readiness and the Growing Risk of Cybersecurity Threats - MedCity News
↗ https://medcitynews.com/2026/09/healthcare-executives-weigh-in-ai-readiness-and-the-growing-risk-of-cybersecurity-threats
About the author
Marcus began tracking AI's market implications in 2016, noticing AI-related patent filings accelerating ahead of earnings upgrades before most of the sell-side had caught on. A former fixed-income quantitative analyst, he spent two decades building models that priced risk across emerging markets before pivoting to cover the economic impact of AI full-time. His writing translates opaque technical developments into clear risk/reward terms — and he's rarely diplomatic about the gap between AI valuations and underlying fundamentals. He believes most market participants still underestimate AI's long-run deflationary effect on knowledge work.
More from The Analyst →This Week's Edition
11 September 2026
33 articles
Related Articles

AI Enters the Exam Room: Federal Investment in Heart Failure Tools Meets Rural Health Skepticism
Health & Science · 5 min

What Health Equity Advocates Could Learn From Drug Sales Reps
Health & Science · 6 min

Hugging Face Attack Signals Wider Risks in the AI Infrastructure Everyone Relies On
Security & Risk · 5 min
Related Articles

AI Enters the Exam Room: Federal Investment in Heart Failure Tools Meets Rural Health Skepticism
Health & Science · 5 min

What Health Equity Advocates Could Learn From Drug Sales Reps
Health & Science · 6 min

Hugging Face Attack Signals Wider Risks in the AI Infrastructure Everyone Relies On
Security & Risk · 5 min
More Stories
© 2026 Cedar & Bloom. All rights reserved.