Learn the 5 questions to ask technology partners about healthcare cybersecurity standards and compliance.



Epic's announcement last week that it is shifting its development focus to cybersecurity made me think about our own responsibility.1 Reveleer handles over 1.2 billion pages of clinical records a year for health plans, and every one of them belongs to a patient.
Protecting those records is a job we share with every health plan and provider we serve. At Reveleer, that job starts with the first line of code. Every company that touches member and patient data should be able to prove how it protects that data, and that includes mine.
Security is a continuous cycle in which vendors harden their systems, attackers find new exploits, and the work starts again. Every organization that handles patient data lives inside that cycle, and the cycle keeps getting faster. Attackers use the same AI tools that health plans and providers are adopting, and a defense that worked last year has to be tested again this year. The organizations that stay ahead plan for that work before anyone asks for it, and they can show their customers the results.
Behind every chart we retrieve is a member, and protecting that record is part of caring for that person. At Reveleer, we built security into our architecture from day one, and our engineers plan security work into every release before we schedule a single feature. We made that choice because health plans and providers trust us with their members' most sensitive information, and they should be able to check our work. Value-based care depends on clinical data that health plans, providers, and patients can trust, and security is a requirement of how we build every part of the Reveleer Platform.
Today Reveleer serves over 55 health plans, and we operate with Health Insurance Portability and Accountability Act (HIPAA) compliance on a HITRUST-certified foundation. Reveleer keeps an audit trail of chart access and movement and applies role-based permissions to protected health information.
We pursued independent certification because our customers deserve evidence they can verify, and our word alone should never be enough. HITRUST reports that 99.62% of HITRUST-certified environments did not report a security breach in 2025.5
Healthcare organizations reported a record 772 large breaches to the HHS Office for Civil Rights (OCR) in 2025.2 Attackers look for the weakest connection among health plans, providers, and their technology partners. Every plan and provider should expect its technology partners to build security into each stage of development.
The FBI Internet Crime Complaint Center ranked healthcare and public health as the most targeted of 16 critical infrastructure sectors in 2025.3 The largest breach ever reported to OCR, the 2024 Change Healthcare ransomware attack, affected about 192.7 million individuals and began at a clearinghouse that connects health plans and providers.4 One vendor's weakness became a problem for thousands of its customers, and I think about that every time we plan a release.
Our own research points the same direction. In the 2025 State of Technology in Value-Based Care report, which Reveleer produced with Mathematica and The Harris Poll, 34% of payers and 24% of providers reported a major cybersecurity incident in the prior year, and only 47% of payers said they felt very prepared.6 The report named HITRUST certification as one of the most valuable indicators of a vendor's security practices, and it noted that business associates are increasingly the source of mass-impact breaches. In our 2026 report, data security displaced data quality as the top data investment priority for payers. The same survey found that 68% of payers rely on outside artificial intelligence (AI) vendors, and 93% of organizations agreed that vendors had overpromised on their ability to support value-based care performance.7
Security is the first thing we build and the one thing we will never cut. Health plans and providers trust us with their members and patients, and we earn that trust in every release."
- Jay Ackerman, CEO and President, Reveleer
If I led a health plan or a provider organization, these are the five questions I would ask every company that handles my members' and patients' data, starting with Reveleer. A technology partner that built security into its architecture should be able to produce the evidence on request. We can. The same questions apply inside your own organization, because member and patient data moves among all of us.
No single organization can protect patient data alone. Health plans, providers, and technology partners exchange member records every day, and a weakness at any point in that exchange puts every patient in it at risk.
Judge every technology partner by what it delivers today. Promises can stand in for delivery for years, and customers absorb the cost. A capability working in production can be tested, audited, and written into a contract. A roadmap date cannot.
Federal baselines are shifting as well. In its HTI-5 proposed rule, the HHS Assistant Secretary for Technology Policy and Office of the National Coordinator for Health IT (ASTP/ONC) proposed removing all privacy and security certification criteria from the ONC Health IT Certification Program.9 If ASTP/ONC finalizes the proposal, health plans and providers will depend more on their own reviews to confirm how each technology partner protects member data. We welcome that scrutiny.
Paul Burke, our Chief Product Officer, has written about a related risk for health plans that route point-of-care programs through a single electronic health record (EHR) platform, along with the questions he would ask every technology partner. We agree on the core point. Health plans and providers need partners that plan for disruption before it arrives.
We meet our share of that responsibility in four ways.
Security is a standard we owe one another, our customers, and every patient. Reveleer intends to meet that standard in every release and to show our work. Ask us for the evidence. Then ask every other technology partner you work with for the same. Talk to a Reveleer expert to review our security controls and the evidence behind them.
Our engineers reserve security capacity in every release before any feature is scheduled. When a new finding arrives, the fix goes into that reserved capacity, and scheduled work for customers continues.
Reveleer delivers prospective risk insights to clinicians through several channels, including a provider portal and workflow overlays, which gives health plans and providers multiple routes to the point of care. Paul Burke, Chief Product Officer at Reveleer, explains the point-of-care implications in his recent article.
Reveleer keeps an audit trail of chart access and movement and applies role-based permissions to protected health information. Further, with Reveleer Clinical Data Repository (CDR), health plans retrieve each record once and reuse it across risk adjustment, quality, and audit work, which reduces the number of times member records move between systems.
The audit trails and access controls that protect member data also document how each chart was retrieved, reviewed, and used. When the Centers for Medicare & Medicaid Services (CMS) or an auditor asks for evidence behind a submitted diagnosis, health plans and the providers who support their audits can show the source record and its chain of custody from the same system.
Health plans and providers should expect every technology partner that handles protected health information to comply with the HIPAA Security Rule and to show independent validation, such as HITRUST certification. Federal guidance adds two useful benchmarks. The HHS 405(d) Health Industry Cybersecurity Practices (HICP) describe recognized security practices for the health sector,10 and CISA Secure by Design principles ask software makers to take ownership of customer security outcomes.11
Health plans and providers can request our current HITRUST certification letter, business associate agreement terms, and the evidence listed in the five questions above. The Reveleer security page outlines our controls, and a Reveleer expert can walk through each one.
1Joyce Famakinwa, “Epic Systems Pauses Product Development to Focus on Cybersecurity,” Modern Healthcare, September 22, 2026, https://www.modernhealthcare.com/health-tech/mh-epic-systems-pause-product-development-ai/.
2“Largest Healthcare Data Breaches of 2025,” HIPAA Journal, accessed September 22, 2026, https://www.hipaajournal.com/largest-healthcare-data-breaches-of-2025/; US Department of Health and Human Services, Office for Civil Rights, “Breach Portal,” accessed September 22, 2026, https://ocrportal.hhs.gov/ocr/breach/breach_frontpage.jsf?faces-redirect=true.
3Federal Bureau of Investigation, Internet Crime Complaint Center, 2025 IC3 Annual Report (Washington, DC: FBI, 2026), https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf.
4US Department of Health and Human Services, Office for Civil Rights, “Change Healthcare Cybersecurity Incident Frequently Asked Questions,” accessed September 22, 2026, https://www.hhs.gov/hipaa/for-professionals/special-topics/change-healthcare-cybersecurity-incident-frequently-asked-questions/index.html.
5HITRUST, 2026 HITRUST Trust Report (Frisco, TX: HITRUST, April 7, 2026), https://hitrustalliance.net/trust-report.
6Reveleer, Mathematica, and The Harris Poll, 2025 State of Technology in Value-Based Care (Glendale, CA: Reveleer, August 2025), 25–27, https://www.reveleer.com/reports/state-of-tech-in-vbc-2025.
7Reveleer, Mathematica, and The Harris Poll, 2026 State of Technology in Value-Based Care (Glendale, CA: Reveleer, July 2026), 5–9, https://www.reveleer.com/reports/state-of-technology-in-value-based-care.
8Paul Burke, “Why ‘Black Box’ AI Isn’t Enough for Providers,” Reveleer, accessed September 23, 2026, https://www.reveleer.com/resource/why-black-box-ai-isnt-enough-for-providers.
9Assistant Secretary for Technology Policy/Office of the National Coordinator for Health Information Technology, “HTI-5 Proposed Rule Overview,” February 19, 2026, https://healthit.gov/wp-content/uploads/2026/02/2026-02-19_HTI-5_Proposed_Rule_Overview_Presentation_508.pdf.
10US Department of Health and Human Services, 405(d) Program, Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients, 2023 ed. (Washington, DC: HHS, 2023), https://405d.hhs.gov/cornerstone/hicp.
11Cybersecurity and Infrastructure Security Agency, “Secure by Design,” accessed September 22, 2026, https://www.cisa.gov/securebydesign.