Nearly every health plan in the US uses artificial intelligence, but most have not built the governance infrastructure to manage it safely. A new survey of 70 payer and provider executives reveals that 60% of health plans have employees using unauthorized AI tools, while fewer than half feel prepared to handle AI-assisted cyberattacks.
The 2026 Healthcare AI Readiness Index, published by Cotiviti and MedCity News, documents a widening gap between AI adoption and oversight. Among payer respondents, 97% said their organizations are piloting or actively using AI, with 37% calling it a core aspect of their business. Providers are earlier in the process, with more than 70% still in early stages.
The shadow AI problem
The governance deficit cuts across both groups. Fewer than 40% of payer or provider organizations have detailed policies governing employee use of generative AI tools. The sharpest illustration: 60% of payers report employees are using "shadow" AI tools not authorized or integrated with their IT systems. These include general-purpose generative AI platforms accessed without IT approval or HIPAA-compliant configuration.
This is not a peripheral risk. Health plans process claims, manage prior authorizations, and handle member data through AI-assisted workflows while a majority acknowledge staff are using AI tools outside formal oversight. The HIPAA implications of unauthorized AI handling protected health information sit directly in the liability framework governing every employer-sponsored health plan. For professionals seeking structured training on these risks, AI for Insurance Courses address the governance and compliance challenges specific to payer organizations.
Cybersecurity preparedness lags adoption
Just 42% of payers said they are "very prepared" to respond to AI-assisted cyberattacks. Among providers, the figure dropped to 32%. More than half of payers said they are "extremely concerned" about AI vendors introducing cybersecurity or compliance vulnerabilities into their systems.
That concern connects to a documented pattern. Business associates - the vendors processing claims and managing utilization on behalf of health plans - were involved in 43% of all large healthcare data breaches in the first half of 2026. AI tools deployed by those same vendors expand the attack surface without necessarily expanding security controls. While 72% of payer respondents said AI is used for vulnerability management, only 32% said they use it for incident response, the function most relevant when a breach is underway.
Regulatory issues, cited by 69% of payers, and data security concerns, cited by 59%, are the primary barriers to adoption. Neither has slowed deployment. More than 90% of both payer and provider respondents expect their AI and cybersecurity investments to increase over the next year.
Clinical decisions and human review
The report's findings on clinical functions add another layer of risk. Seventy-two percent of payer respondents said clinical recommendations should always require human review, regardless of AI capability. Sixty percent said the same of appeals. These are functions where AI-driven decisions at health insurers have drawn growing regulatory scrutiny and where errors carry direct consequences for plan members.
The National Association of Insurance Commissioners has been pressing health insurers on AI governance for several years, and its AI Systems Evaluation Tool is targeting national rollout later in 2026. Nearly a third of health insurers surveyed by the NAIC do not regularly test their AI models for bias or discrimination. The Cotiviti and MedCity News findings land in that regulatory environment, adding self-reported preparedness data that the NAIC survey does not capture. Organizations working across both payer and provider settings can find relevant training through AI for Healthcare Courses, which cover governance frameworks applicable to clinical and administrative AI use.
Why this matters for insurance professionals
Benefits advisers placing or renewing group health plans are evaluating the same organizations the survey describes. A health plan deploying AI across claims and prior authorization workflows, while 60% of its employees may be using ungoverned tools, presents a different risk profile than one with detailed policies and tested incident response procedures. That difference does not appear in premium pricing. Whether a carrier's AI governance policies actually apply human review standards to specific workflows is a question that goes beyond price at renewal - and one that advisers should be asking directly.
Your membership also unlocks: