Skip to main content
Advertisement
Home

Main navigation

  • Digital Issue Archive
  • Service Directory
  • Awards
  • Advertise
  • Subscribe now

Secondary

  • Travel Insurance
  • Policies & Partnerships
  • Travel Risk Management
  • Travel Trends
  • Hospitals & Healthcare
  • Industry Moves
  • Reviews

Cybersecurity in healthcare and insurance: building trust in a high-risk digital ecosystem

Travel Insurance
3 Aug 2026 | Chloe Fox
Featured in ITIJ 307 | August 2026
Share
Collage with a doctor and a laptop and cybersecurity icons

Chloe Fox speaks to experts about how healthcare’s growing digital connectivity is transforming cybersecurity through zero trust, legacy risks, AI, and telemedicine

As healthcare providers, insurers, and assistance companies rely more heavily on digital infrastructure, cybersecurity is no longer just an IT concern. Large volumes of sensitive data – from medical records and payment details to travel itineraries and personal identifiers – are constantly exchanged between insurers, hospitals, third-party administrators (TPAs), telemedicine providers, and travellers. This interconnectedness improves efficiency and claims handling, but it also expands the attack surface for cybercriminals, with ransomware attacks on hospitals and pressure on insurers to demonstrate resilience and secure data handling.

Elena Glukhman, Business Development Manager at AP Companies Global Solutions, also emphasised the importance of structurally embedded cybersecurity: “At AP Companies, cybersecurity has evolved from being primarily an IT function into a core operational and governance priority,” she said. “As a global TPA and medical assistance provider handling sensitive medical and insurance data across multiple jurisdictions, we recognise that traditional perimeter-based security models are no longer sufficient.

“Our approach today is increasingly aligned with zero trust principles – meaning that no user, device, or connection is automatically trusted, even within internal environments,” she explained. “Access to systems and medical information is granted based on strict identity verification, role-based permissions, and the principle of least privilege.”

She added that segmentation helps limit the impact of potential breaches: “Operational environments, claims systems, financial systems, and medical data repositories are separated and controlled to minimise lateral movement in the event of a security incident.”

According to Dominic Steptoe, Global Chief Product Officer at BOXX Insurance, a layered approach to security is becoming essential: “Zero trust and data segmentation within an organisation’s network is a key component of ensuring secure data storage,” he explained. “BOXX has adopted a layered approach to secure data storage that centres on zero trust and data segmentation.”

In a world of hybrid working, remote access, cloud infrastructure, and cross-border data flows, traditional boundaries no longer hold

The shift away from perimeter-based security models is accelerating as cloud adoption, hybrid working, and cross-border data flows reshape the sector. 

Mark Kirkby, Professional Services Director at Intersys, said the shift had become unavoidable: “In a world of hybrid working, remote access, cloud infrastructure, and cross-border data flows, traditional boundaries no longer hold,” he said.

Kirkby said this development was being driven by the need to secure increasingly mobile and sensitive information across distributed environments.

“Our approach is firmly identity- and data-centric. Zero trust is foundational: every user, device and workload must continuously prove it can be trusted, regardless of location,” he explained. “Alongside this, data classification and segmentation have become critical, particularly in healthcare and insurance, where highly sensitive personal and clinical data is constantly in motion.”

Bruce McIndoe, Founder of Travel Risk Academy, argued that the implications extend beyond infrastructure alone: “Secure data storage is no longer just an IT architecture issue,” he said. “In healthcare and insurance, it is central to operational resilience.”

Thierry Montrieux, Mentor at Travel Risk Academy, highlighted that this complexity was compounded by regulatory fragmentation and user behaviour in cross-border environments: “Cross-border compliance is another key challenge. Organisations must navigate varying data protection, residency, and healthcare regulations, often aligning with international standards while adapting to local legal requirements.”

He added that the human layer remained central to reducing exposure: “There is also an increasing emphasis on traveller awareness, encouraging users to avoid unsecured networks, maintain updated devices, and use trusted platforms when accessing healthcare services abroad.”

The growing burden of legacy systems

Although many organisations are investing in modern security frameworks, legacy infrastructure remains one of the sector’s most persistent vulnerabilities. Outdated hardware, software, and physical facilities that no longer meet current technological or operational standards continue to expose organisations to risk.

“The biggest cybersecurity challenge posed by legacy systems is that they are no longer patched or maintained, and there can be significant vulnerabilities within them,” Steptoe warned. “And unfortunately, artificial intelligence (AI) and cybercrime organisations can use these vulnerabilities as entry points to cause breaches and systems damage.”

These risks are becoming more visible as organisations are pushed to modernise: “AI-based projects, notably [Anthropic-led cybersecurity initiative] Project Glasswing, are bringing these vulnerabilities to the forefront and showcasing that organisations need to prioritise modernising their infrastructure,” Steptoe explained.

However, modernisation is rarely simple in healthcare and insurance environments that run continuously and depend on complex international systems. Therefore, insurers are increasingly favouring gradual approaches.

“Legacy systems remain one of the most persistent sources of cyber risk, especially in insurance, where core platforms often underpin critical operations but lack compatibility with modern security frameworks,” said Kirkby.

He warned that full replacement could itself create disruption: “A more effective approach is phased modernisation,” he explained. “In the short term, organisations can reduce exposure through compensating controls such as network segmentation, privileged access management, and enhanced monitoring.

“This allows insurers to strengthen their security posture incrementally while maintaining business continuity, an essential balance in a 24/7, customer-facing industry,” Kirkby added.

McIndoe noted that legacy risk was often underestimated because of how embedded older systems were: “Legacy systems create risk because they often support critical workflows, are costly to replace and retrain the workforce, but were not designed for today’s threat environment,” he said.

He stressed the urgency in healthcare, where system failures can directly affect patient care: “I would think that addressing legacy systems is particularly important in healthcare, where ransomware, data breaches, and availability attacks remain persistent concerns.

The cyber risk is not only the connection; it is the ecosystem behind the connection

“The immediate answer to addressing this is replacement. However, doing this is costly and difficult,” McIndoe explained. “Many healthcare and insurance organisations must modernise while continuing to operate.”

Advertisement

Glukhman highlighted added complexity in international ecosystems due to uneven digital maturity across partners. “In international medical assistance, this challenge is amplified because we interact not only with our own systems, but also with medical providers, insurers, and payment providers operating at very different levels of digital maturity,” she said.

As a result, many organisations opt for gradual migration strategies. “Rather than attempting large-scale ‘rip and replace’ projects, we focus on isolating legacy components, strengthening access controls around 
them, introducing secure middleware layers, and progressively migrating critical functions toward more modern architectures,” Glukhman explained.

She also emphasised the importance of human factors alongside technical change: “At the same time, at AP Companies we place significant emphasis on staff awareness and operational discipline because human behaviour remains one of the largest cybersecurity risk factors regardless of technology stack,” she added.

Telemedicine expands the attack surface

The rapid growth of telemedicine is adding new complexity for healthcare and travel insurers, enabling travellers to access medical advice from airports, hotels, cruise ships, and other temporary locations. However, these conveniences also introduce new cyber risks tied to public Wi-Fi, unmanaged devices, and cross-border data transfers.

Steptoe warned that organisations should assume unfamiliar networks are unsafe: “When accessing sensitive data while travelling, especially across borders, best practice is to assume any unfamiliar network is insecure and act accordingly,” he said.

That requires strong protective measures: “Use a trusted, encrypted connection always – preferably a corporate VPN or secure cellular data instead of public Wi-Fi – and ensure all access is protected with strong, phishing-resistant multi-factor authentication,” Steptoe advised.

Kirkby said telemedicine was reshaping how secure access is designed, with a focus on default distrust of networks. He told ITIJ that layered protections were now standard. “We enforce secure access through conditional access policies, strong authentication, device posture checks, and end-to-end encryption,” he explained. 

Keep on reading

Collage of a doctor using an iPad

Digital doctoring: the importance of cybersecurity in healthcare

Oliver Cuenca explores the issues caused by poor cybersecurity and what healthcare providers can do to address them
1 Dec 2025

“This ensures that even when a traveller connects from a hotel, airport or remote location, sensitive medical data remains protected.”

McIndoe highlighted that telemedicine expands risk beyond connectivity into governance and third-party exposure. “The traveller may be in an airport, hotel, cruise ship, conflict-adjacent location, or foreign jurisdiction using an unmanaged device over an untrusted network,” he said. “This creates a complex risk profile.”

McIndoe added that data governance was now central: “There is also a cross-border governance issue. Healthcare and insurance organisations need to understand where data is stored, where it is accessed, which laws apply, and which third parties are involved in the care or claims process. The cyber risk is not only the connection; it is the ecosystem behind the connection.”

AI adoption raises new governance questions

AI is now embedded across healthcare, insurance, and assistance operations, supporting claims handling, fraud detection, triage, and customer support.

Steptoe told ITIJ that structured oversight was essential: “At BOXX, we take a structured approach to embedding AI safely into operations,” he said. “We equip employees with clear policies, approved tools, and targeted training on AI-specific risks so they can confidently integrate AI into their workflows without introducing unnecessary exposure.”

He added that reducing ‘shadow AI’ – the use of unauthorised AI tools, software, or large language models (LLMs) by employees within an organisation – was a priority: “By making it easier to ask than to bypass controls, we reduce shadow AI and ensure new capabilities are deployed with appropriate oversight.”

Kirkby highlighted visibility and governance as key issues: “The biggest challenge is visibility: understanding what data is being used, how models are accessed, and where vulnerabilities may emerge,” he explained. He added that controls should be built in early: “Retrofitting controls after deployment is where organisations expose themselves to the greatest risk.”

The biggest challenge is visibility: understanding what data is being used, how models are accessed, and where vulnerabilities may emerge

McIndoe argued AI should be treated as core infrastructure: “That means it needs governance, access controls, testing, monitoring, and clear rules about what data can be used, retained, shared, or acted upon.”

Advertisement

Keep on reading

Nordic Insurance Software

The future of travel

Elliott Draga, Chief Commercial Officer at Nordic Insurance Software (NIS), speaks to ITIJ about digital marketplaces, and why the customer journey is so important

Sponsored by Nordic Insurance Software

2 Jul 2024
|
Editorial Team

He warned of risks around misuse and automation: “In healthcare and insurance, these risks can affect privacy, claims handling, clinical support, regulatory compliance, and customer trust,” he explained.

Montrieux framed the issue more broadly, pointing to the underlying technical risk categories emerging across the sector: “Key concerns being addressed across the market include data leakage, model manipulation, bias, and unintended system behaviour.”

He added a governance imperative: “The prevailing view is that AI should enhance resilience and operational effectiveness, but only within a structured and well-governed security framework.”

Glukhman stressed the importance of human oversight and caution with third-party tools: “At AP Companies, we view AI as a tool that should augment professional judgement rather than replace it,” she said. “We are especially careful regarding third-party AI tools, data-sharing practices, and the potential for sensitive information leakage into external models,” she added.

Overall, she said the key challenge was responsible adoption at scale: “Ultimately, the challenge for the industry is not whether to adopt AI – because that is already happening – but how to adopt it in a way that strengthens operational resilience rather than weakening it,” she added.

Cyber insurance drives higher standards

Steptoe pointed out that cyber insurance was helping raise baseline security expectations: “The rise of cyber insurance is helping set clear minimum-security standards across ecosystems, with more forward-thinking cyber insurers shifting the focus toward prevention rather than just recovery,” he said.

He also noted the improvement of risk management across supply chains: “Cyber insurance also has a role to play in helping to build trust by raising the overall security baseline across partners and supply chains, ensuring risks are better managed and shared.”

Kirkby noted that insurers were already shaping behaviour through underwriting requirements: “Cyber insurance is actively shaping how organisations are managing risk,” he explained. “Insurers are increasingly requiring clear evidence of controls, resilience, and incident readiness, which is driving improved cyber hygiene across the ecosystem.”

He added that cyber maturity was becoming commercially important: “The ability to demonstrate strong cyber maturity is an absolute differentiator… for building trust with partners and customers,” he said.

McIndoe said insurance strengthens resilience when it reinforces good practice. “Cyber insurance helps strengthen the cybersecurity posture… because it forces organisations to quantify exposure, examine controls, and think more seriously about business interruption, ransomware, data loss, third-party dependency, and recovery,” he said. However, he warned it was not a replacement for preparedness: “Insurance provides economic protection, not organisation or people protection.”

Montrieux reinforced this distinction between financial mitigation and operational resilience: “There is a growing understanding that insurance is not a substitute for resilience. The emphasis is shifting toward prevention, early detection, and coordinated response.”

Overall, organisations are converging on layered security and resilience models combining zero trust, segmentation, monitoring, and governance as digital ecosystems expand and threats become more complex. 

ITIJ 307 August Cover

August 2026
 Issue

This month we examine an issue important to many of us – the complexities of insuring business travellers. Employee travel exposes organisations to risks including medical emergencies, travel disruption, geopolitical instability and cyber threats. Adequate insurance coverage is more than a financial safeguard; it is a vital part of meeting an organisation’s duty of care obligations and responsibilities.

Read full issue
Travel Insurance
3 Aug 2026
Share

Chloe Fox

Chloe Fox is an Editorial Assistant for Voyageur Group, joining in 2024. She writes for ITIJ and AirMed&Rescue, covering a range of topics including international travel and health insurance, medical assistance provision, and air medical transportation. Chloe holds a BA (Hons) in English and an MA in English Literature from the University of Bristol.

Keep on reading

No results

There are no results available matching your search term.

Why subscribe to ITIJ?

In-depth analysis

In-depth analysis

Unique insights and expert opinions on the latest industry developments

A wider perspective

A wider perspective

Get the global view on the topics that are trending in your region

Breaking news

Breaking news

ITIJ.com has all the latest news relevant to travel insurance and IPMI professionals

Subscribe now
ITIJ IH&H

Footer menu

  • About Us
  • Subscribe
  • Advertise
  • Contact
  • Privacy Policy
  • Terms
  • Voyageur
International Travel & Health Insurance Conferences

Social

  • LinkedIn link
  • Twitter link

© Voyageur Publishing & Events 2026

Close