Data management risk levels in the healthcare industry have been at or near “crisis level” for some time. Today, we are seeing a variety of data-related variables converge, creating a perfect storm of risk that, if not properly recognized and considered by internal audit functions serving the healthcare sector, can have vast repercussions, including denied claims, duplicate testing, medication errors, regulatory compliance errors, and failed AI initiatives.
A Risk Gathering Speed
Basic data lifecycle management can seem straightforward: data is taken in, stored, classified, shared, archived, and ultimately disposed of. In practice, however, industry realities can cause significant issues at one or more of these stages.
One such risk is decentralized data, says Jason Stepnoski, Senior Director of Internal Audit at insurance provider VSP Vision.
“Finance is going to own the finance data, sales is going to own sales data, and in healthcare, of course, you’re going to have medical records, which will likely be managed by software and IT people,” says Stepnoski. “All these different parties are going to think of their data in different ways and treat it in different ways, and without strict enterprise data governance oversight this obviously is going to result in each party handling the data differently and it may result in it not getting the proper management or disposition of that date.
Compounding this risk is also the issue of time. “It’s not just data governance that is usually decentralized,” says Stepnoski. “Dealing with data that’s 20 or 30 years old, it can be like a game of telephone in that it’s now gone through a couple of system and database migrations. Over time, as events occur and things change, that data can just wither away as fields and records don’t quite align with what the previous system had so it gets migrated into what is perceived as the best fit— and that is assuming the tools and resources are still available to access it properly, which is not a given if knowledge transfer controls are lacking.”
Improper controls and governance around legacy data management can have immense consequences — and in healthcare, they can be lethal.
“Healthcare data conversations are always going to have that added piece of patient data. In some context outside of the industry, I imagine some office folks would say a minor data issue would say ‘It’s not life or death,’” says Stepnoski. “Well, here, if critical patient data is mangled or deleted, it very might well be.”
The health and safety element, however, is only one part of this broad risk. It overlaps with other risk conversations, including:
- AI Investment Risk. The AI race continues to gain steam across all business sectors, and healthcare is no exception. In a 2026 report from Silicon Valley Bank, AI alone made up 46% of all healthcare investment in 2025, totaling over $18 billion. Industry reports and studies also indicate major data management gaps in many current healthcare systems. One recent study from the American Journal of Managed Care found that 40% of provider director inaccuracies remain in data systems for over 540 days — six times longer than what U.S. federal mandates allow. In another data study published in JAMA Open Network, four out of five provider directory entries in the five largest private health plans were inaccurate. With poor and outdated data to feed into AI tools, much or even all of the tools’ potential is wasted.
- New Regulation Concerns. Beyond complex federal data privacy standards already in place (such as HIPAA in the U.S.), regulations around data management in the healthcare sector continue to tighten. Examples include the Centers for Medicare & Medicaid Services' Interoperability and Prior Authorization Final Rule, which requires payers to adopt standardized Application Programming Interfaces by 2027; and the Office of the National Coordinator for Health IT's HTI-1 Final Rule, which establishes first-of-its-kind transparency requirements for healthcare AI algorithms and revises information blocking regulations.
- Skyrocketing Costs. Bad data, simply, is bad for the bottom line and is responsible for a massive part of the typical healthcare institution’s annual losses. According to a 2024 study published in the National Library of Medicine, poor data quality costs healthcare organizations an average of $20 million annually, most of which results from misallocation of resources, prolonged patient stays, increased overtime pay, and even increased events of misdiagnoses — all of which are largely preventable.
Where Internal Audit Fits
The state of healthcare data management is not the only risk that is concerning. Internal audit’s capacity to assess data management in this sector also deserves notice. According to data compiled in the 2026 North American Pulse of Internal Audit, 33% of healthcare internal audit leaders surveyed reported budget cuts in their functions — a 27% increase from the year before. Additionally, staff cuts among healthcare internal audit functions increased to 28%, up from 7% in 2024. As healthcare risks expand, internal audit functions and resources appear to be shrinking.
This reality does not exempt internal auditors from their duties. To the contrary, internal audit must be more efficient, deliberate, and accurate in its assessment responsibilities. Cherry Bekaert, in collaboration with The IIA, as part of a webinar on this subject, provided a helpful list of the key elements any effective internal audit of data governance needs to consider:
- Policies, Standards, and Procedures. Developing and updating policies, standards, and procedures to support new capabilities and requirements for classifying and protecting data.
- Change Management. Communicating new processes and technology capabilities to employees, and ensuring a seamless transition for people, processes, and technology.
- Sustainment: Identifying teams and developing processes to maintain ongoing operations of new technology capabilities.
- Metrics and Reporting. Developing key risk and performance indicators to measure the effectiveness of people, process, and technology.
- Governance. Establishing management and operational groups to make decisions and resolve risks and issues.
- Training and Awareness. Training employees on data classification policies and solutions, and developing awareness campaigns to promote the importance of classifying their files and documents.
Key to providing assurance against this risk is understanding that data management and governance is worthy of its own explicit part of internal audit’s coverage plan, Stepnoski explains. When resources are limited, it can be tempting to make it an element of other related audits. To build stakeholder understanding and establish buy-in, however, that might not be enough.
“Where we as internal auditors can be a real catalyst for change is just pointing out this big risk,” Stepnoski explains. “What internal audit puts its focus on is what ultimately will be put on the board’s radar. For better or worse, at least now there is a spotlight on it, which hopefully will unlock resources for stakeholders or perhaps even a steering committee to address the issue, which then can be later monitored by internal audit.”
Legacy Data Can Leave a Risk
Legacy data, while easily overlooked, is critical to a healthcare organization’s overall data infrastructure. In the age of AI, legacy data is more critical to an organization’s future than ever. Internal audit functions that help build dedicated, standards-aligned coverage of data management and governance principles will be well positioned to give their boards something increasingly rare in this environment: real assurance that the data driving clinical and financial decisions can be trusted.