Cybersecurity in healthcare and insurance: building trust in a high-risk digital ecosystem Chloe Fox speaks to experts about how healthcare’s growing digital connectivity is transforming cybersecurity through zero trust, legacy risks, AI, and telemedicine As healthcare providers, insurers, and assistance companies rely more heavily on digital infrastructure, cybersecurity is no longer just an IT concern. Large volumes of sensitive data – from medical records and payment details to travel itineraries and personal identifiers – are constantly exchanged between insurers, hospitals, third-party administrators (TPAs), telemedicine providers, and travellers. This interconnectedness improves efficiency and claims handling, but it also expands the attack surface for cybercriminals, with ransomware attacks on hospitals and pressure on insurers to demonstrate resilience and secure data handling. Elena Glukhman, Business Development Manager at AP Companies Global Solutions, also emphasised the importance of structurally embedded cybersecurity: “At AP Companies, cybersecurity has evolved from being primarily an IT function into a core operational and governance priority,” she said. “As a global TPA and medical assistance provider handling sensitive medical and insurance data across multiple jurisdictions, we recognise that traditional perimeter-based security models are no longer sufficient. “Our approach today is increasingly aligned with zero trust principles – meaning that no user, device, or connection is automatically trusted, even within internal environments,” she explained. “Access to systems and medical information is granted based on strict identity verification, role-based permissions, and the principle of least privilege.” She added that segmentation helps limit the impact of potential breaches: “Operational environments, claims systems, financial systems, and medical data repositories are separated and controlled to minimise lateral movement in the event of a security incident.” According to Dominic Steptoe, Global Chief Product Officer at BOXX Insurance, a layered approach to security is becoming essential: “Zero trust and data segmentation within an organisation’s network is a