Article

Security is a standard every healthcare partner should prove

Reveleer blog articles about MA
September 28, 2026

Written by: Jay Ackerman, Chief Executive Officer & President, Reveleer

Written by:

Epic's announcement last week that it is shifting its development focus to cybersecurity made me think about our own responsibility.1 Reveleer handles over 1.2 billion pages of clinical records a year for health plans, and every one of them belongs to a patient.

Protecting those records is a job we share with every health plan and provider we serve. At Reveleer, that job starts with the first line of code. Every company that touches member and patient data should be able to prove how it protects that data, and that includes mine.

Cybersecurity work never ends

Security is a continuous cycle in which vendors harden their systems, attackers find new exploits, and the work starts again. Every organization that handles patient data lives inside that cycle, and the cycle keeps getting faster. Attackers use the same AI tools that health plans and providers are adopting, and a defense that worked last year has to be tested again this year. The organizations that stay ahead plan for that work before anyone asks for it, and they can show their customers the results.

‍

Security pressure across healthcare

Federal breach data, FBI complaint data, and HITRUST certification outcomes

772

Large breaches reported to the US Department of Health and Human Services (HHS) Office for Civil Rights (OCR) in 2025, the highest annual count on record2

#1

Healthcare's rank among 16 critical infrastructure sectors in FBI cyber complaints in 20253

192.7M

Individuals affected by the Change Healthcare ransomware attack, the largest breach ever reported to OCR4

99.62%

HITRUST-certified environments that reported no security breach in 20255

Sources: HIPAA Journal analysis of HHS OCR data; FBI Internet Crime Complaint Center; HHS Office for Civil Rights; HITRUST

‍

We built security into Reveleer from day one

Behind every chart we retrieve is a member, and protecting that record is part of caring for that person. At Reveleer, we built security into our architecture from day one, and our engineers plan security work into every release before we schedule a single feature. We made that choice because health plans and providers trust us with their members' most sensitive information, and they should be able to check our work. Value-based care depends on clinical data that health plans, providers, and patients can trust, and security is a requirement of how we build every part of the Reveleer Platform.

Today Reveleer serves over 55 health plans, and we operate with Health Insurance Portability and Accountability Act (HIPAA) compliance on a HITRUST-certified foundation. Reveleer keeps an audit trail of chart access and movement and applies role-based permissions to protected health information.

We pursued independent certification because our customers deserve evidence they can verify, and our word alone should never be enough. HITRUST reports that 99.62% of HITRUST-certified environments did not report a security breach in 2025.5

One weak link can reach every patient

Healthcare organizations reported a record 772 large breaches to the HHS Office for Civil Rights (OCR) in 2025.2 Attackers look for the weakest connection among health plans, providers, and their technology partners. Every plan and provider should expect its technology partners to build security into each stage of development.

The FBI Internet Crime Complaint Center ranked healthcare and public health as the most targeted of 16 critical infrastructure sectors in 2025.3 The largest breach ever reported to OCR, the 2024 Change Healthcare ransomware attack, affected about 192.7 million individuals and began at a clearinghouse that connects health plans and providers.4 One vendor's weakness became a problem for thousands of its customers, and I think about that every time we plan a release.

Our own research points the same direction. In the 2025 State of Technology in Value-Based Care report, which Reveleer produced with Mathematica and The Harris Poll, 34% of payers and 24% of providers reported a major cybersecurity incident in the prior year, and only 47% of payers said they felt very prepared.6 The report named HITRUST certification as one of the most valuable indicators of a vendor's security practices, and it noted that business associates are increasingly the source of mass-impact breaches. In our 2026 report, data security displaced data quality as the top data investment priority for payers. The same survey found that 68% of payers rely on outside artificial intelligence (AI) vendors, and 93% of organizations agreed that vendors had overpromised on their ability to support value-based care performance.7

‍

Security is the first thing we build and the one thing we will never cut. Health plans and providers trust us with their members and patients, and we earn that trust in every release."
- Jay Ackerman, CEO and President, Reveleer

‍

Five questions to ask any healthcare technology partner, including us

If I led a health plan or a provider organization, these are the five questions I would ask every company that handles my members' and patients' data, starting with Reveleer. A technology partner that built security into its architecture should be able to produce the evidence on request. We can. The same questions apply inside your own organization, because member and patient data moves among all of us.

Ask this A strong answer A red flag
1. What role does security play at each stage of your software development cycle, from design through release? Security requirements, code review, and testing at every stage, with documentation the team can share on request Security reviews scheduled after development is complete, or only after an incident
2. What is your continuity plan if a critical vulnerability requires an immediate change in operations? A documented, tested plan that keeps critical customer services available while the fix is deployed No documented plan, or a plan the team has never tested
3. How will you notify us if a security incident affects our member or patient data? A defined notification timeline in the business associate agreement and a named contact for incident response No contractual notification timeline, or notice only after an internal investigation closes
4. What evidence stands behind the outputs your platform produces? Every output traces to a source record with a complete audit trail Outputs that cannot be explained, reproduced, or defended in a Centers for Medicare & Medicaid Services (CMS) audit7,8
5. How do you apply Cybersecurity and Infrastructure Security Agency (CISA) Secure by Design principles to new products? Security settings on by default, a published vulnerability disclosure policy, and documented secure development standards Security features sold as add-ons or enabled only on request

‍

Security is a responsibility we share

No single organization can protect patient data alone. Health plans, providers, and technology partners exchange member records every day, and a weakness at any point in that exchange puts every patient in it at risk.

Judge every technology partner by what it delivers today. Promises can stand in for delivery for years, and customers absorb the cost. A capability working in production can be tested, audited, and written into a contract. A roadmap date cannot.

Federal baselines are shifting as well. In its HTI-5 proposed rule, the HHS Assistant Secretary for Technology Policy and Office of the National Coordinator for Health IT (ASTP/ONC) proposed removing all privacy and security certification criteria from the ONC Health IT Certification Program.9 If ASTP/ONC finalizes the proposal, health plans and providers will depend more on their own reviews to confirm how each technology partner protects member data. We welcome that scrutiny.

Paul Burke, our Chief Product Officer, has written about a related risk for health plans that route point-of-care programs through a single electronic health record (EHR) platform, along with the questions he would ask every technology partner. We agree on the core point. Health plans and providers need partners that plan for disruption before it arrives.

How Reveleer does its part

We meet our share of that responsibility in four ways.

  • Security in every release. Our engineers reserve security capacity in each release before any feature is scheduled. When a new finding arrives, the fix goes into that reserved capacity, and scheduled work for customers continues.
  • Controlled access with a full audit trail. Role-based permissions limit who can see protected health information, and every chart access and movement is logged. The same log shows the chain of custody when CMS asks for evidence in a Risk Adjustment Data Validation (RADV) audit.
  • Fewer handoffs of member records. With Reveleer Clinical Data Repository (CDR), health plans retrieve each record once and reuse it across risk adjustment, quality, and audit work. Fewer copies moving between systems means fewer places to defend and more consistent data for accurate risk adjustment.
  • Independent validation. We maintain HITRUST certification and share our certification letter on request, which gives health plans and providers evidence they can verify before they share clinical data with us.
    ‍

Security is a standard we owe one another, our customers, and every patient. Reveleer intends to meet that standard in every release and to show our work. Ask us for the evidence. Then ask every other technology partner you work with for the same. Talk to a Reveleer expert to review our security controls and the evidence behind them.

Key takeaways

  • Security work never ends, and the strongest technology partners build it into every stage of software development.
  • Reveleer built security into its architecture from day one and plans security work into every release, operating with HIPAA compliance on a HITRUST-certified foundation.
  • Healthcare led all critical infrastructure sectors in FBI cyber complaints in 2025, and OCR logged a record 772 large breaches.
  • Health plans and providers should weigh capabilities in production today above roadmap dates, and ask every technology partner for evidence of its security practices.

‍

Healthcare technology partner security FAQs

How does Reveleer respond when it finds a new security vulnerability?

Our engineers reserve security capacity in every release before any feature is scheduled. When a new finding arrives, the fix goes into that reserved capacity, and scheduled work for customers continues.

How does Reveleer reach clinicians at the point of care?

Reveleer delivers prospective risk insights to clinicians through several channels, including a provider portal and workflow overlays, which gives health plans and providers multiple routes to the point of care. Paul Burke, Chief Product Officer at Reveleer, explains the point-of-care implications in his recent article.

How does Reveleer protect member and patient data during chart retrieval, coding, and abstraction?

Reveleer keeps an audit trail of chart access and movement and applies role-based permissions to protected health information. Further, with Reveleer Clinical Data Repository (CDR), health plans retrieve each record once and reuse it across risk adjustment, quality, and audit work, which reduces the number of times member records move between systems.

How do Reveleer security controls support CMS audits, including Risk Adjustment Data Validation (RADV)?

The audit trails and access controls that protect member data also document how each chart was retrieved, reviewed, and used. When the Centers for Medicare & Medicaid Services (CMS) or an auditor asks for evidence behind a submitted diagnosis, health plans and the providers who support their audits can show the source record and its chain of custody from the same system.

Which security frameworks should health plans and providers expect a technology partner to follow?

Health plans and providers should expect every technology partner that handles protected health information to comply with the HIPAA Security Rule and to show independent validation, such as HITRUST certification. Federal guidance adds two useful benchmarks. The HHS 405(d) Health Industry Cybersecurity Practices (HICP) describe recognized security practices for the health sector,10 and CISA Secure by Design principles ask software makers to take ownership of customer security outcomes.11

How can health plans and providers verify Reveleer's security practices?

Health plans and providers can request our current HITRUST certification letter, business associate agreement terms, and the evidence listed in the five questions above. The Reveleer security page outlines our controls, and a Reveleer expert can walk through each one.

‍

Sources

1Joyce Famakinwa, “Epic Systems Pauses Product Development to Focus on Cybersecurity,” Modern Healthcare, September 22, 2026, https://www.modernhealthcare.com/health-tech/mh-epic-systems-pause-product-development-ai/.

2“Largest Healthcare Data Breaches of 2025,” HIPAA Journal, accessed September 22, 2026, https://www.hipaajournal.com/largest-healthcare-data-breaches-of-2025/; US Department of Health and Human Services, Office for Civil Rights, “Breach Portal,” accessed September 22, 2026, https://ocrportal.hhs.gov/ocr/breach/breach_frontpage.jsf?faces-redirect=true.

3Federal Bureau of Investigation, Internet Crime Complaint Center, 2025 IC3 Annual Report (Washington, DC: FBI, 2026), https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf.

4US Department of Health and Human Services, Office for Civil Rights, “Change Healthcare Cybersecurity Incident Frequently Asked Questions,” accessed September 22, 2026, https://www.hhs.gov/hipaa/for-professionals/special-topics/change-healthcare-cybersecurity-incident-frequently-asked-questions/index.html.

5HITRUST, 2026 HITRUST Trust Report (Frisco, TX: HITRUST, April 7, 2026), https://hitrustalliance.net/trust-report.

6Reveleer, Mathematica, and The Harris Poll, 2025 State of Technology in Value-Based Care (Glendale, CA: Reveleer, August 2025), 25–27, https://www.reveleer.com/reports/state-of-tech-in-vbc-2025.

7Reveleer, Mathematica, and The Harris Poll, 2026 State of Technology in Value-Based Care (Glendale, CA: Reveleer, July 2026), 5–9, https://www.reveleer.com/reports/state-of-technology-in-value-based-care.

8Paul Burke, “Why ‘Black Box’ AI Isn’t Enough for Providers,” Reveleer, accessed September 23, 2026, https://www.reveleer.com/resource/why-black-box-ai-isnt-enough-for-providers.

9Assistant Secretary for Technology Policy/Office of the National Coordinator for Health Information Technology, “HTI-5 Proposed Rule Overview,” February 19, 2026, https://healthit.gov/wp-content/uploads/2026/02/2026-02-19_HTI-5_Proposed_Rule_Overview_Presentation_508.pdf.

10US Department of Health and Human Services, 405(d) Program, Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients, 2023 ed. (Washington, DC: HHS, 2023), https://405d.hhs.gov/cornerstone/hicp.

11Cybersecurity and Infrastructure Security Agency, “Secure by Design,” accessed September 22, 2026, https://www.cisa.gov/securebydesign.

About the Author

Jay Ackerman, Chief Executive Officer & President, Reveleer

With over 30 years of experience in leadership roles, Jay has established Reveleer as a leader in Healthcare SaaS solutions, enabling our customers to take control of critical value-based care programs. Prior to joining Reveleer, Jay served in notable roles such as Chief Revenue Officer at Guidance Software. He is also proud of his contributions to ServiceSource and WNS, where he served in a variety of leadership roles supporting innovation and outsized growth as these companies grew to be market leaders and went public.
Author Spotlight