Why legacy privacy programs are misaligned for today’s healthcare payers
Traditional privacy programs were built to manage privacy risks through manual controls, point solutions and after-the-fact reviews and were better suited to more linear data environments. This model assumed relatively stable data environments, clear system boundaries and the ability to assess risk periodically without materially affecting the day-to-day operations of the enterprise.
That assumption no longer holds. As healthcare payers expand the use of AI and automation, sensitive data now proliferates and flows continuously across internal systems, cloud platforms, vendors and other third parties. Visibility into how data is accessed, combined and used becomes fragmented, limiting effective oversight and leaving already capacity-constrained privacy teams more reactive than proactive at a time when data-driven decisions are increasing in speed and scale.
Improper handling of sensitive data can create regulatory and legal exposure, particularly in healthcare, where protected health information underpins core business operations and care coordination. Recent survey data underscores the business impact of cyber incidents for healthcare payers, with 72% of healthcare organizations reporting a moderate-to-severe financial impact from cyber incidents and 60% seeing operational disruptions.1 Reactive controls and retrospective reviews leave organizations responding to problems after exposure rather than managing risk as data and decisions move in real time.
As a result, legacy privacy models are increasingly misaligned with how healthcare payers operate today. Models designed to review and remediate risk struggle to keep pace with automated, AI-enabled workflows and complex data ecosystems, exposing organizations to compounding regulatory, cybersecurity and reputational risk.
Why technology alone is insufficient to govern privacy and AI
As privacy pressures increase, many healthcare payers have turned to technology as the primary response. New tools and platforms promise efficiency, scale and consistency at a time when organizations face expanding data use, greater AI adoption and constrained resources. But technology alone does not resolve the more fundamental challenge: how privacy-related decisions are governed, owned and executed across the enterprise.
In practice, responsibility for privacy, data use and AI-enabled decision-making is often fragmented across legal, technology, compliance and business functions, with key decisions frequently made in silos and outside the purview of the chief privacy officer (CPO) and their team. While technology can support individual activities, it does not reconcile competing priorities or establish clear authority over risk trade-offs. Often, the lure of technical efficiency outpaces that of thoughtful redesign that incorporates the privacy team’s perspective. As a result, similar privacy risks may be assessed differently across teams, and decisions about data use are often made without a shared governance framework or a consistent escalation path.
When technology is implemented without corresponding changes to operating models, decision rights and accountability, it reinforces existing silos rather than addressing them. Tools may surface issues faster or enable greater throughput, but they do not address underlying process or governance issues such as determining who has the authority to approve high-risk use cases, when activity should pause or how emerging risks are managed as data- and AI-enabled workflows evolve exponentially.
Embedding privacy within the enterprise operating model
Addressing today’s privacy and cybersecurity risks requires a strategic shift. As AI-enabled and data-driven decision-making becomes embedded in core payer operations, privacy teams can no longer function as a downstream checkpoint or advisory role that operates in isolation from business and technology functions. Instead, they must operate as an integral component of the enterprise operating model, shaping decisions as data and technology are designed, deployed and used.
This shift begins with how privacy work is positioned within the organization. Rather than operating through periodic review, privacy leadership (particularly the CPO and the privacy team) must be positioned in the executive-level governance apparatus overseeing AI- and data-driven initiatives. This elevated role includes having defined authority to set policy, procedures, guardrails; influence design decisions; and escalate or halt high-risk use cases when privacy, cybersecurity or trust thresholds are exceeded.
When embedded within an operating model that defines decision rights, accountability, oversight and traceability, technology can enable greater visibility and more auditable outcomes. Without that foundation, it remains disconnected from the decisions it is meant to inform.
The objective of this shift is not to slow innovation. Rather, it is to enable AI and automation to scale within clearly defined privacy, data-use and cybersecurity boundaries.
Evolving privacy governance for healthcare payers
Facing growing pressure to manage AI-driven data use, cybersecurity exposure and regulatory scrutiny, some healthcare payers are beginning to rethink how the privacy team operates within the organization. These organizations are embedding privacy directly into AI governance, data governance and cybersecurity.
Instead of concentrating responsibility within a single function, some payers are formalizing shared ownership through defined roles embedded within business and operational teams, supported by centralized standards and oversight. This structure allows privacy expectations to be applied consistently while remaining close to the data, systems and decisions where risk is introduced.
Greater visibility across the data ecosystem is another defining feature of this shift. As privacy and cybersecurity risks extend beyond organizational and jurisdictional boundaries, many payers are placing greater emphasis on understanding how sensitive data is accessed, shared and used across vendors, platforms and third-party environments. This broader line of sight supports earlier detection of emerging issues and more coordinated responses as risk thresholds are approached or exceeded.
Taken together, these patterns signal a shift toward managing privacy and cyber risk as part of everyday business activity.
Key actions for healthcare payer leaders
For healthcare payers, redesigning privacy operations begins with a clear assessment of where governance, accountability and execution no longer align with how data and AI are actually used across the organization. The following actions can help organizations close this gap and achieve greater alignment.