Showing 1 - 10 of 0 results
Page 1 of 1 | Results 1 - 10 of 0
Main image for news
Insight

Cyber Risk in Managed Care: Why Operational Resilience Matters in 2026

By Tara Albin, Alliant Cyber, & Kenny White, Alliant Healthcare

For years, cyber risk in managed care centered on HIPAA compliance and protecting patient health information. While those concerns remain critical, the threat landscape has shifted significantly, and so have the stakes.

Today's cyber incidents extend beyond data security to become business disruption events. Claims processing delays, provider payment failures, pharmacy outages and reputational damage are all documented consequences of attacks that now target managed care organizations (MCOs) with increasing frequency and sophistication. As MCOs continue to expand their technology ecosystems, the ability to withstand and recover from disruptions has become just as important as preventing them.

Why Managed Care Organizations Remain a Prime Target

MCOs sit at the center of a highly interconnected healthcare ecosystem. They manage sensitive member data, facilitate significant financial transactions, and rely on complex technology platforms to support critical operations.

Healthcare consistently ranks as one of the most targeted industries for cyber attacks. According to the American Hospital Association, healthcare recorded more reported cyber threats than any other sector in 2024, with 238 ransomware incidents and 206 data breach incidents. The average cost of a healthcare data breach reached $9.8 million in 2024, more than double the cross-industry average, according to IBM and ScienceSoft research.

For MCO leadership, the question is no longer whether cyber threats exist. It is whether the organization is prepared to respond when an incident occurs.

Four Risk Areas Shaping the Conversation

Privacy remains at the core of cyber risk in managed care. MCOs maintain large repositories of protected health information, financial records, pharmacy data and behavioral health information, all of which are subject to federal and state regulation.

The challenge extends beyond preventing data exposures. Organizations must also manage how patient data is collected, stored, shared and used across a growing ecosystem of vendors, partners and technology platforms. The expanded use of AI and advanced analytics adds new complexity around data governance, consent and appropriate use of sensitive information. As privacy regulations continue to evolve and enforcement activity increases, balancing innovation with member trust is an ongoing operational priority.

AI is transforming healthcare administration, supporting clinical decision-making, automating claims workflows and improving operational efficiency. It also introduces new risks that many organizations are still working to address.

According to the Health Sector Coordinating Council's Cybersecurity Working Group, healthcare's accelerating AI adoption has expanded dependence on third-party tools and introduced complex cybersecurity challenges that traditional risk management models cannot fully address. These include data poisoning, model drift, adversarial attacks and limited visibility into AI vendor supply chains.

At the same time, threat actors are using AI to build more sophisticated phishing and social engineering attacks. A 2025 report from KnowBe4 found that 82 percent of phishing emails now use AI-generated content. Healthcare, which is the most susceptible industry to phishing at 41.9 percent of organizations affected, faces compounding exposure.

Many of the most significant cyber threats facing MCOs originate outside their own networks. MCOs depend on vendors, cloud providers, pharmacy benefit managers and outsourced service providers to deliver core functions. A cyber event affecting a critical vendor can disrupt multiple organizations simultaneously.

The February 2024 ransomware attack on Change Healthcare illustrated the systemic risk at scale. A single event at a claims processing subsidiary affected the majority of U.S. hospitals and physician practices, causing weeks of billing and payment disruption and resulting in reported losses of $2.9 billion to UnitedHealth Group. According to research published in JAMA Network Open, ransomware affected 69 percent of all patient records compromised in 2024.

Vendor risk management has evolved from a procurement and compliance function into a strategic business priority. Organizations that lack visibility into third-party security postures face significant exposure, regardless of how strong their internal controls may be.

Ransomware remains one of healthcare's most persistent cyber threats. While ransom demands in healthcare dropped significantly in 2025 according to Sophos research, the frequency of attacks continued to climb. Ransomware attacks targeting healthcare businesses, including the vendors and service providers MCOs rely on, increased 51 percent in 2025 compared to 2024.

Today's attacks frequently involve data exfiltration alongside encryption. Sophos found that the percentage of healthcare providers whose data was extorted without encryption tripled since 2023, reaching the highest rate reported across all sectors. For MCOs, the operational impact extends well beyond data loss, creating interruptions in claims processing, provider reimbursement and member services.

Organizations focused exclusively on prevention may find themselves underprepared when an incident occurs. Recovery planning, business continuity capabilities and tested incident response protocols have become core elements of a mature cyber program.

Healthcare Cybersecurity Risk Is a Governance Issue

Cyber risk is increasingly viewed as an enterprise governance issue, not solely an IT responsibility. Regulators, boards and stakeholders expect healthcare organizations to demonstrate effective oversight, third-party risk management, incident response preparedness and operational resilience. Leadership teams must understand cyber risk in business terms and align cybersecurity strategies with broader enterprise risk objectives.

Operational Resilience as the New Standard

The future of cybersecurity in managed care will not be defined solely by an organization's ability to prevent attacks. It will be defined by its ability to continue operating when disruptions occur.

Privacy protection, AI governance, vendor risk management and ransomware preparedness each present distinct challenges. But they share a common implication: Cyber risk has become a business resilience issue. Organizations that understand their critical dependencies, regularly test response capabilities and integrate cyber risk into enterprise decision-making will be better positioned to navigate an increasingly complex threat environment.

For managed care organizations, cybersecurity is no longer just about protecting information. It is about maintaining trust, ensuring continuity of service and preserving the ability to support members, providers and partners when it matters most.

Frequently Asked Questions

Managed care organizations face cyber risk across four primary areas: patient privacy and data protection, AI adoption, third-party and vendor dependencies, and ransomware. Of these, third-party risk has drawn significant attention following the 2024 Change Healthcare attack, which demonstrated how a single vendor incident can disrupt operations across hundreds of healthcare organizations simultaneously. Ransomware frequency also continues to rise, with attacks on healthcare businesses and their vendors increasing 51 percent in 2025.

Ransomware in managed care creates cascading operational disruptions that extend well beyond compromised data. Attacks routinely interrupt claims processing, delay provider reimbursements, take pharmacy systems offline and create gaps in member services. Modern ransomware attacks increasingly involve data exfiltration alongside encryption, meaning organizations face both operational and regulatory exposure. According to Sophos, the rate of data extortion without encryption in healthcare tripled between 2023 and 2025, reaching the highest level of any sector.

Third-party cyber risk refers to the exposure an organization inherits through its vendors, partners and service providers. For health plans and MCOs, this includes pharmacy benefit managers, claims processors, cloud platforms and outsourced administrative functions. A cyber incident at any of these providers can compromise member data, disrupt operations or trigger regulatory obligations, regardless of the health plan's own security controls. Effective vendor risk management requires visibility into third-party security postures, contractual protections, and contingency plans for critical dependencies.

AI governance in managed care requires organizations to go beyond evaluating clinical or operational performance. Cybersecurity considerations should be embedded into AI procurement, deployment and ongoing oversight. The Health Sector Coordinating Council's Cybersecurity Working Group recommends that healthcare organizations assess AI tools for risks including data poisoning, model drift, adversarial attacks and supply chain vulnerabilities. Organizations should also establish policies governing how AI systems access, process and store patient data, and ensure those policies are reviewed as regulatory guidance continues to evolve.

Operational resilience means an organization's ability to maintain or rapidly restore critical functions during and after a cyber incident. For managed care organizations, this includes continuity of claims processing, provider communications, pharmacy operations and member services. A resilience-focused cybersecurity program goes beyond perimeter defense to include incident response planning, business continuity capabilities, regular tabletop exercises and defined recovery time objectives for core systems. As cyber incidents become more frequent and operationally disruptive, resilience has become a core component of enterprise risk strategy.

Partner with Alliant to Strengthen Cyber Resilience in Managed Care

Alliant's managed care specialists work with health plans, MCOs and healthcare organizations to assess cyber risk, structure coverage and build resilience strategies that align with how these organizations actually operate. From vendor risk management to incident response planning, Alliant brings specialized knowledge of the managed care market to every engagement.

To learn more about cyber risk solutions for managed care organizations, visit Alliant Managed Care.

For more information about how Alliant Cyber provides holistic cyber risk management services, including Cyber Insurance Brokerage and Cyber Consulting, visit Alliant Cyber.

Sources

American Hospital Association, Health Care Had Most Reported Cyberthreats in 2024 (May 2025); IBM/ScienceSoft, Healthcare Data Breach Cost Analysis (2024); JAMA Network Open, Ransomware Attacks and Data Breaches in US Health Care Systems (2025); Sophos, State of Ransomware in Healthcare 2025; Comparitech, Healthcare Ransomware Roundup 2025; Health Sector Coordinating Council Cybersecurity Working Group, Health Industry AI Cybersecurity Governance Framework Implementation Guide (2026); KnowBe4, 2025 Phishing by Industry Benchmarking Report; Cobalt, Healthcare Data Breach Statistics (2026).

This document is provided for general informational purposes only and does not constitute legal, tax, accounting, insurance, brokerage, risk management, or other professional advice. You should consult your own legal counsel or other qualified professional advisors regarding your specific circumstances, and receipt of this document does not create any client, advisory, fiduciary, brokerage, or other professional relationship with Alliant Insurance Services, Inc. This document is provided “as is” without warranty of any kind, and Alliant Insurance Services, Inc. disclaims any liability for any loss or damage arising out of or relating to reliance on this document.