Nearly every health plan in the US is now using artificial intelligence. What most have not built yet is the governance infrastructure to manage it safely. The 2026 Healthcare AI Readiness Index, published by Cotiviti and MedCity News, documents that gap through a summer 2026 survey of 70 payer and provider executives.
Among payer respondents, 97 percent said their organizations are piloting or actively using AI. A further 37 percent described it as a core aspect of their business. Providers are earlier in the process, with more than 70 percent still in the early stages.
The governance deficit cuts across both groups. Fewer than 40 percent of payer or provider organizations have detailed policies governing employee use of generative AI tools, and 60 percent of payers report employees are using "shadow AI" tools not authorized or integrated with their IT systems, such as general-purpose generative AI platforms accessed without IT approval or HIPAA-compliant configuration.
The shadow AI figure is the sharpest illustration of the problem. Health plans process claims, manage prior authorizations, and handle member data through AI-assisted workflows while a majority also acknowledge staff are using AI tools outside formal oversight. The HIPAA implications of unauthorized AI handling protected health information are not theoretical. They sit directly in the liability framework governing every employer-sponsored health plan.
The cybersecurity data reinforces that picture. Just 42 percent of payers said they are "very prepared" to respond to AI-assisted cyberattacks. Among providers, the figure was 32 percent. More than half of payers said they are "extremely concerned" about AI vendors introducing cybersecurity or compliance vulnerabilities into their systems.
That concern connects to a pattern in federal breach data. Business associates, meaning the vendors processing claims and managing utilization on behalf of health plans, were involved in 43 percent of all large healthcare data breaches in the first half of 2026. AI tools deployed by those same vendors expand the attack surface without necessarily expanding security controls.
Seventy-two percent of payer respondents said AI is used for vulnerability management at their organizations. Only 32 percent said they use it for incident response, the function most relevant when a breach is underway.
Regulatory issues, cited by 69 percent of payers, and data security concerns, cited by 59 percent, are the primary barriers to adoption. Neither has slowed deployment. More than 90 percent of both payer and provider respondents expect their AI and cybersecurity investments to increase over the next year.
Benefits advisers placing or renewing group health plans are evaluating the same organizations the survey describes. A health plan deploying AI across claims and prior authorization workflows, while 60 percent of its employees may be using ungoverned tools, presents a different risk profile than one with detailed policies and tested incident response procedures. That difference does not appear in premium pricing.
The report's finding on clinical functions adds another layer. Seventy-two percent of payer respondents said clinical recommendations should always require human review, regardless of AI capability. Sixty percent said the same of appeals. Those are functions where AI-driven decisions at health insurers have drawn growing regulatory scrutiny and where errors carry direct consequences for plan members. Whether a carrier's AI governance policies actually apply those human review standards to specific workflows is a question that goes beyond price at renewal.
The National Association of Insurance Commissioners (NAIC) has been pressing health insurers on AI governance for several years, and its AI Systems Evaluation Tool is targeting national rollout later in 2026. Nearly a third of health insurers surveyed by the NAIC do not regularly test their AI models for bias or discrimination. The Cotiviti and MedCity News findings land in that regulatory environment, adding the self-reported preparedness data that the NAIC survey does not capture.
The index draws on responses from 70 executives, with 43 percent from payer or health plan organizations and 57 percent from providers, and its findings should be read as directional rather than statistically representative of the broader market.