Building healthtech resilience in 2026

When disruption is the norm, staying focused on innovation isn’t easy. Get support to strengthen your healthtech business while managing risk and preparing for what’s ahead.

How we help you

With AI evolving at breakneck speed and regulations constantly shifting, you need help adapting to change and staying ahead of the curve. Wipfli finds opportunities hidden in uncertainty so you can overcome the obstacles that distract you from what matters most: innovating to strengthen healthcare.

Pivot quickly, turn data into action and secure sensitive data.

Maintain a competitive edge in an increasingly crowded market.

Adapt to change and spend more time on your business, not your back office .

Mitigate compliance and regulatory risks.

Meet uncertainty with grit

With deep experience in both healthcare and technology, Wipfli is there at every inflection point of your business — from protecting patient health information to navigating private equity funding to keeping your back office running.

Explore our services

Insights and resources

  • A middle aged woman working on digital tablet.

    ARTICLE

    Revenue leakage in healthcare: How to find and prevent it

    Healthcare organizations continue to face mounting financial pressure. Labor costs remain elevated, reimbursement uncertainty persists and leaders are expected to invest in technology, workforce, compliance and patient or resident experience — often with limited resources. In response, many organizations focus on growth initiatives. But before looking outside the org for growth, healthcare leaders should prioritize identifying and preventing revenue leakage that is damaging their bottom line. Whether revenue leakage stems from denied claims, underpayments, documentation gaps, billing inefficiencies, reimbursement opportunities, occupancy challenges or operational breakdowns, the result is the same: Financial performance suffers. For organizations operating on narrow margins, small inefficiencies can create significant financial impact over time. What is revenue leakage in healthcare? Revenue leakage occurs when an organization fails to collect all the money it is owed for services provided. These losses can occur at any point in the revenue cycle, from patient registration and eligibility verification to clinical documentation, billing, collections and payer reimbursement. Revenue leakage often results from multiple small breakdowns across departments and processes. A registration error, missed charge, coding issue, delayed claim submission or overlooked payer underpayment may seem minor on its own. Collectively, however, these issues can significantly reduce margins, delay cash flow and limit a healthcare provider’s ability to invest in patient care, technology and workforce needs. Revenue leakage goes beyond claim denials While claims denials are a significant form of revenue leakage, there are other causes of lost revenue, including: Underpayments Inaccurate coding Incomplete charge capture Staffing shortages that prevent services from being delivered Inefficient workflows Where does revenue leakage occur in healthcare? Many leaders assume financial performance challenges stem from a single issue. In reality, revenue leakage often occurs through a series of small breakdowns across clinical, operational and financial functions. Mistakes that can lead to revenue leakage include: Patient registration, eligibility and authorization Errors in patient registration and insurance information can lead to claim denials, delayed payments and lower reimbursement levels, creating avoidable revenue leakage throughout the revenue cycle. Clinical documentation, coding and charge capture Incomplete clinical documentation, coding inaccuracies and missed charges can prevent organizations from collecting all the money they are owed for services performed. Even small documentation and charge capture mistakes can result in underpayments, claim denials or missed reimbursement opportunities. These errors can contribute to significant revenue leakage over time while increasing compliance and audit risks. Claims and denials Claims that are denied or paid below expected reimbursement levels often require significant time and resources to investigate, appeal and resolve, reducing overall revenue and increasing administrative burden. Payer reimbursement and underpayments Organizations may fail to capture all available reimbursement due to overlooked payer requirements, incomplete charge capture, unclaimed supplemental payments or a lack of processes to identify and pursue eligible revenue opportunities. Billing, accounts receivable and collections Inefficient workflows, staffing constraints or process bottlenecks can slow claim submission and collections efforts, extending the revenue cycle and negatively impacting cash flow. Operational inefficiencies Poor workforce planning, underutilized staff or scheduling inefficiencies can increase labor costs while limiting productivity and operational performance. In senior living and post-acute care settings, delays in admissions, prolonged vacancy periods or barriers in the move-in process can reduce occupancy rates and result in lost revenue opportunities. Lack of visibility into operational performance When data is fragmented across departments or systems, leaders may struggle to identify emerging issues, track key performance indicators or understand the root causes of declining financial performance. Individually, these issues may appear manageable. Collectively, they can represent meaningful lost revenue and reduced financial flexibility. How can you identify leakage in healthcare? Revenue leakage occurs across multiple departments, not just financial. Because of that, organizations must conduct a comprehensive assessment of operational, clinical and revenue-cycle performance to identify where revenue is being lost. Healthcare organizations should evaluate: Claim denial trends: Analyze denial rates, denial reasons and appeal outcomes to identify recurring issues and process gaps. Registration and eligibility accuracy: Review patient registration errors, insurance verification processes and authorization compliance to uncover front-end breakdowns that lead to reimbursement challenges. Clinical documentation quality: Assess documentation completeness and accuracy to determine whether services are being fully supported for coding and reimbursement purposes. Coding and charge capture performance: Look for coding inconsistencies and mistakes and missed charges that may be reducing reimbursement. Payer reimbursement patterns: Compare expected and actual reimbursement amounts to identify underpayments or missed payment opportunities. Accounts receivable aging: Monitor aging receivables, collection timelines and outstanding balances that may indicate process inefficiencies. Operational and workforce metrics: Evaluate productivity, staffing utilization, scheduling patterns and workflow bottlenecks that may be contributing to financial inefficiencies. Occupancy and admissions performance: For senior living and post-acute organizations, review occupancy trends, move-in timelines and admission conversion rates to identify lost revenue opportunities. Key performance indicators (KPIs): Track metrics such as clean claim rates, days in accounts receivable, denial rates, net collection rates, case mix index and reimbursement per service line. Data visibility and reporting capabilities: Determine whether leadership has timely access to accurate, actionable information that supports informed decision-making. How can healthcare organizations prevent revenue leakage? The highest-performing healthcare organizations do more than recover lost revenue. They create systems that consistently protect revenue across operations. By focusing on these three high-impact areas, healthcare leaders can often uncover meaningful financial improvements while also strengthening long-term operational performance. 1. Strengthen the front-end processes that influence financial performance Financial outcomes are often determined long before payment is received. For hospitals and Federally Qualified Health Centers (FQHCs), this may include patient access, eligibility verification, documentation and coding processes. For senior living organizations, it may involve occupancy management, admissions workflows and resident billing practices. Regardless of the setting, breakdowns early in the process can create downstream financial challenges that are difficult and costly to correct later. To strengthen front-end processes, organizations should start by mapping key workflows from initial patient or resident contact through reimbursement. This can help identify bottlenecks, handoff issues and areas where errors commonly occur. Leaders should also establish standardized procedures for registration, insurance verification, authorizations, documentation and coding to improve consistency across departments. Regular staff training is equally important. Front-line employees often have a direct impact on revenue capture, yet they may not fully understand how documentation errors, missing information or workflow delays affect reimbursement. Ongoing education can help reduce mistakes and strengthen accountability. Organizations should also monitor performance metrics such as registration accuracy, clean claim rates, coding accuracy, authorization compliance and admission-to-service timelines. Tracking these indicators allows leaders to identify problems early and address issues before they result in denials or delayed payments. Organizations that establish clear processes, accountability and performance monitoring are better positioned to reduce downstream revenue loss. 2. Improve operational visibility and consistency Improved visibility and consistency allow organizations to identify issues earlier and make more informed decisions. However, many organizations struggle to identify where financial performance is being impacted because data is fragmented across departments. Leaders can improve operational visibility by: Breaking down departmental data silos: Finance, clinical, operational and administrative teams should have access to consistent data and clearly defined metrics that align with organizational goals. Developing dashboards: Gain real-time or near-real-time insight into key performance indicators with dashboards. Rather than reviewing financial results after issues occur, leaders can monitor trends such as denial rates, labor costs, occupancy levels, accounts receivable that are beyond the due date and productivity measures as they happen. Maintaining consistency: Establishing routine performance reviews, department scorecards and leadership reporting helps ensure issues are identified and addressed promptly. Cross-functional meetings that bring together operational and financial leaders can also improve collaboration and deepen understanding of how day-to-day decisions affect overall financial performance. Leaders should also focus on understanding how operational decisions influence financial outcomes. Workforce utilization, clinical productivity, documentation quality, reimbursement performance, occupancy trends and patient service utilization all contribute to overall margin performance. 3. Identify and recover missed revenue opportunities The back end of the financial process often reveals opportunities for improvement. Denials, underpayments, aging receivables, reimbursement variances, collection challenges or billing delays frequently point to broader process issues that can be corrected. Organizations should conduct regular reviews of denial trends, payer performance and reimbursement outcomes to identify patterns that may be limiting revenue collection. Rather than addressing individual denials one at a time, leaders should analyze root causes to determine whether recurring issues stem from documentation gaps, coding errors, authorization problems or workflow inefficiencies. In addition, finance and revenue cycle teams should periodically evaluate accounts receivable, payer contracts and collection processes to identify underpayments or reimbursement opportunities that may have been overlooked. For senior living organizations, this may also include reviewing occupancy trends, move-in conversion rates and resident billing processes to identify opportunities to improve financial performance. Technology and analytics tools can also play an important role by helping organizations identify anomalies, monitor trends and prioritize areas requiring attention. However, the greatest value often comes from combining data analysis with cross-departmental collaboration to address issues in underlying processes. Organizations that regularly review financial performance data and investigate root causes of revenue leakage are often able to recover revenue while strengthening future performance. How Wipfli can help Wipfli has a team of professionals dedicated to helping healthcare organizations achieve their financial goals. We can help your organization identify where it is leaking revenue and develop processes to prevent it. Start a conversation . Capitalize on revenue capture opportunities Learn more Webinar: Find hidden revenue without adding services or staff AI in healthcare finance: Practicality over hype, strategy over speculation 2026 healthcare industry outlook: Get ready for seismic disruption

  • Stock photograph depicting a professional team meeting in an office environment.

    ARTICLE

    A SOC 2 report can be a launching pad for FedRAMP certification

    Healthtech companies, SaaS organizations and other technology businesses that hold a current SOC 2 Type II report have a potential new market to tap into. Revisions to FedRAMP have created an easier path for selling cloud service offerings (CSOs) to federal agencies. Continue reading to learn more about the FedRAMP program and the new, lower-resistance road to certification available to companies with a SOC 2 report. What is FedRAMP? The Federal Risk and Authorization Management Program is the federal government’s standardized approach for assessing, authorizing and monitoring cloud service offerings used by federal agencies. Cloud service providers (CSPs), including SaaS companies with cloud-based software, that want to sell their products and services to federal agencies via the FedRAMP marketplace need some level of FedRAMP certification (formerly known as authorization) before their CSO can be listed. FedRAMP uses the NIST SP 800-53 security controls and includes parameters and guidance that go above the NIST baseline to address the unique elements of cloud computing. How is FedRAMP changing? To streamline certification, increase automation and reduce compliance friction, FedRAMP is transitioning from the legacy Rev. 5 model to FedRAMP 20x . As part of the transition, FedRAMP is also shifting away from the low, moderate and high impact-level terminology and moving to a class-based certification structure. The certification classes are: Class A is a new entry-level certification designed to help eligible providers enter the FedRAMP marketplace. Class B generally aligns with lower-risk use cases and limited or departmental adoption. Class C is intended for broader agency use cases, including more sensitive or mission-critical workloads. Class D is expected to support the highest-risk or most sensitive use cases. A SOC 2 report can serve as a foundation for FedRAMP Class A FedRAMP 20x allows companies to use a qualifying SOC 2 Type II report as proof of the security maturity needed for Class A certification. Class A does not have the agency sponsorship requirement. In the past, many SaaS providers and healthtech organizations struggled to find an agency willing to sponsor them, creating a major roadblock to getting their products listed on the marketplace. The SOC 2 option creates an easier path to certification. Businesses need to understand that Class A certification is not a permanent solution. It gives your business a two-year window to begin assessing your security framework against Class B, C or D standards. Class A is only authorized for low-risk deployments. The value of FedRAMP Class A certification Think of FedRAMP Class A as a way to test the federal market before making the full investment required for higher FedRAMP certification levels. If you are unsure whether there is federal demand for your products, Class A offers a chance to assess interest levels. It will also give your business time to determine which product or security improvements may be needed to support federal agency needs. Easing into FedRAMP via Class A certification will allow your business to: Test demand for your cloud offering within the federal market. Increase visibility by appearing in the FedRAMP marketplace. Validate how well your CSOs fit the federal market before making larger compliance investments. Build a roadmap toward higher certification levels based on actual customer interest. What federal opportunities exist for healthtech companies? For healthtech companies, being able to sell their CSOs to federal agencies opens the potential to land significant contracts. A notable example is the Department of Veterans Affairs (VA). Selling patient monitoring tools, telehealth platforms, medical imaging archiving systems or other cloud-based products to the largest integrated healthcare system in the U.S. could be very lucrative. But handling VA data requires FedRAMP certification. Instead of delaying market entry to pursue a more rigorous FedRAMP certification, your organization can use Class A to begin engaging the federal marketplace faster. Use your two-year window to prepare for a Class B, C or D certification. Other federal agencies that are potential customers for FedRAMP-certified healthtech companies include HHS and CMS. What are the SOC 2 requirements to secure FedRAMP Class A? A SOC 2 Type II report can support the Class A path, but you will still need to meet other FedRAMP-specific requirements. A provider cannot simply submit any SOC 2 report and assume it will be accepted. To use SOC 2 for Class A , companies should be prepared to provide: A complete SOC 2 Type II report that was completed in the last 12 months Any bridge or gap letters Verified audit engagement documentation An estimated schedule for the next SOC 2 report Supplemental compliance evidence (if applicable) Your SOC 2 scope does need to include cloud security. There are other FedRAMP Class A requirements, including relevant Key Security Indicators , which address areas such as vulnerability detection, incident communication, network traffic restrictions, service configuration and more. What are the steps to getting FedRAMP Class A certification? The path to Class A is relatively short compared to higher FedRAMP certification classes. However, it still requires planning, evidence collection and implementation of FedRAMP-specific requirements. Companies should consider the following steps: Confirm eligibility: Verify that your organization holds a current SOC 2 Type II report. Validate the scope of your SOC 2 report: Make sure the SOC 2 report covers the cloud service offering you want to submit for FedRAMP Class A. If the scope is too narrow, outdated or misaligned with the product being submitted, you may need to remediate gaps or complete additional assessment work. Assemble your evidence package: Gather the complete SOC 2 Type II report, any bridge or gap letters, verified audit engagement documentation, the estimated schedule for your next SOC 2 report and any supplemental evidence that helps show how your controls align with FedRAMP expectations. Implement the required FedRAMP controls: Implement the necessary policies, procedures and controls to meet the mandatory FedRAMP 20x rules and key security indicators required for Class A. Prepare machine-readable certification materials: FedRAMP 20x emphasizes more structured, machine-readable evidence. Companies should expect to modernize how they manage compliance documentation and move away from manual, screenshot-heavy evidence models. Submit through program certification: Apply through the FedRAMP program certification path. How can businesses move to a higher FedRAMP certification? If your business decides FedRAMP certification is a long-term strategy, it will need to advance to one of the more rigorous certification levels. Here are some steps your business can take to prepare for Class B, C or D certification: Adopt a broader control baseline: Higher classes require more rigorous security controls and more extensive evidence. The organization will need to mature its control environment beyond what was necessary for Class A. Prepare for more detailed assessment expectations: Companies moving to Class B, C or D should be ready for a more comprehensive review of their cloud security controls. Strengthen automation and evidence collection: FedRAMP 20x places more emphasis on machine-readable evidence and automation. Providers may need to modernize their governance, risk and compliance processes so evidence is continuously available and easier to validate. Build ongoing certification processes: FedRAMP required companies to demonstrate that controls continue to operate effectively over time, not just at a single point in time during an assessment. Align the certification level to the target market: Class B may be appropriate for more limited or departmental use cases, while Class C and D may be needed for broader, more sensitive or mission-critical federal deployments. Companies should align their target class to the agencies and use cases they want to pursue. Plan early: The two-year Class A window can move quickly. Providers should use the time to validate federal demand, prioritize gaps and develop a realistic roadmap for reaching the next certification class. CSPs that pursue Class B or C have a choice between the agency sponsorship route or the new program certification route without a sponsor. All Class D certifications require a sponsor. Read more Which AI risk framework is right for your organization? Tech companies experience thousands of attempted cyberattacks each day. Are your defenses ready for 2026? SOC audit timing: When to schedule your SOC 1 or SOC 2 exam

  • Image showing two individuals reviewing and pointing at content on a computer screen.

    ARTICLE

    Tech companies experience thousands of attempted cyberattacks each day. Are your defenses ready for 2026?

    For tech companies of any size, cybersecurity threats are part of doing business. The typical company’s network will often experience thousands of attempted cyberattacks per day, and as vendor relationships proliferate, the average attack surface only continues to grow. But are your defenses prepared to handle this onslaught and prevent a data breach? Keep reading to find out. For tech companies, data breach risks are only growing Tech companies have always been targets, but AI has made it easier than ever for even inexperienced cybercriminals to attempt an attack. Flawed AI-written code has also created new holes to be exploited. And tech companies are sharing more data with their vendors, which means you can suffer the consequences of a data breach even if your own systems remain secure. Key risks include: AI-powered attacks: Data privacy breaches and identity threat-based attacks are way up because of AI. For example, AI tools make it easier to pull off a phishing scam with polymorphic emails so attackers can steal credentials needed to access your systems, at which point they can steal valuable data or attempt a ransomware attack. AI makes it simple enough that even children are trying their hand at hacking. Poorly written AI code: Tech companies are increasingly turning to AI coding tools like Claude Code to quickly write new code. However, this code is often implemented without human due diligence or testing, raising the risk that security holes will go undetected until exploited during an attack. Vendor proliferation: Companies that use multiple SaaS products or AI tools face additional exposure. If one of your vendors gets successfully breached, all the data you shared with that vendor is at risk of compromise, so each additional vendor you use raises your risk level. To make this even more complicated, consider that your vendors could have shared your data with third-party vendors of their own. Practice attacks on smaller companies: If your business is under a certain size, you might think you’re not worth attacking. But cybercriminals increasingly see small and mid-sized businesses as practice: A way to try out new attack methods and hone their skills before moving on to target a big fish. Complex cybercriminal relationships: Just as you have vendor relationships, many bad actors do as well. For example, a hacker may attack your business simply as a demonstration to impress a potential client or carry out a successful breach of your systems not to steal any of your data themselves, but so they can sell that access to another party. What kind of damage could a major data breach do to your business? The most damaging cyberattacks involve gaining insider access to your core systems. Attackers sometimes collaborate with a willing insider, like an employee looking to make some extra cash, but will more often get in by tricking a team member into sharing their access credentials through phishing or other social engineering scams. Once inside, attackers often take their time to look around. By some estimates, the typical cybercriminal may remain in your systems for an average of 220 days after first breaking in. That’s a lot of time to find valuables to steal. Insider attacks often cost the company 10-15% more (on the low end) than an external bad actor. Plus, the length of time that an investigation takes usually increases because insiders can cover their tracks more effectively. Look out for both financial and reputational damages A successful cybersecurity breach can quickly lead to damages like: Sensitive internal and customer data stolen and sold on the black market Ransom payments starting at $60K Higher cybersecurity insurance premiums, think 2-3X Regulatory blowback, which can include fines, starting at $500K Reputational damage, with customers moving to your competition The cost of resecuring your systems after an attack, which can undo five years of network investment Ransomware attacks can add additional costs When they do strike, hackers may simply steal your data and then vanish. However, once access is gained, a ransomware attack is always an option. Average ransomware costs for firms range from: $60,000 for small businesses $500,000 for midsize companies $1.5 million for larger firms If these ransom amounts sound lower than you might expect, consider that if the ransoms were too big, nobody would pay. But if they’re tolerable from a cash flow perspective, the firms are likely to pay and try to recover later. This lets bad actors take advantage of laziness. A risk-based cybersecurity strategy helps protect your business from harm Many tech companies think about cybersecurity strictly in terms of compliance. If you’re a fintech company, for example, you might be tempted to assess your specific regulatory requirements, implement frameworks like PCI and HITRUST to satisfy regulators and then move on. That would be a mistake. Treating cybersecurity as just a compliance exercise still leaves you exposed to potential harm, especially because compliance standards typically don’t account for newer or evolving threats. However, adopting a risk-based cybersecurity strategy can help significantly reduce your potential pain. Under a risk-based approach, you’d go beyond simple compliance to map out the specific threats you face and prioritize them based on likelihood and degree of harm. This can allow you to implement additional defenses to reduce your potential repercussions should you suffer an attack. How should you implement a risk-based cybersecurity approach? Tech CIOs or CISOs often benefit from guiding their businesses to adopt a cybersecurity posture built on defense-in-depth. This is a risk-based strategy that deploys multiple layers of protective measures so your systems won’t be compromised by a single point of failure. Using a defense-in-depth approach, an attacker can often be stopped even if they’ve already broken through one or more of your defensive layers. Defense-in-depth also factors in the likelihood of a particular attack, prioritizing defenses based on risk rather than attempting the impossible task of being strong everywhere at all times. Here are key action steps to implement a risk-based cybersecurity approach that incorporates defense-in-depth: 1. Work with a cybersecurity advisor Unless you have a large internal cybersecurity team (10+ people), you’ll typically benefit from working with a third-party cybersecurity advisor who does this every day. An advisor can help you implement a risk-based approach and apply concepts like defense-in-depth to your specific business. 2. Understand your points of failure Map out your points of failure, like breached firewalls, team members clicking on a phishing link or third-party vendors. This will help you figure out where to add additional controls, policies and team training exercises. Your people are probably your weakest link, so you’ll need to account for that as you move forward. 3. Don’t add unnecessary tech Don’t add new tech to your business just because it’s new. Every additional vendor you work with expands your attack surface, so as you integrate more AI and other advances into your existing systems and processes, do so deliberately and with a careful eye on cybersecurity. 4. Limit network access for everyone Higher-than-necessary credentials represent a distinct security threat. Make sure that your team only has the minimum level of network access they need to do their jobs, including your C-suite, who are the most vulnerable to phishing or spear-phishing attacks. 5. Use AI network monitoring to speed up breach detection AI tools can help you implement more effective network monitoring, so you can detect an unusual login or other signs of a breach more quickly. This can help you avoid long-term exposure even if your systems are successfully compromised. 6. Do careful vendor due diligence Talk to your third-party vendors about their own cybersecurity efforts, including whether they take a risk-based or compliance-based approach. To fully understand your vendor risks, you’ll also want to ask about whether any of their own third-party vendors could have access to your data. 7. Implement governance policies and trainings Your whole team needs to be responsible for cybersecurity. Establish clear governance policies, including for how you use AI , to prevent team members from exposing your data to unauthorized tools. Offer regular training on threats like phishing scams and hold tabletop exercises to practice how your business would respond to an active cyberattack. 8. Set up MFA All of your core systems should use multifactor authentication (MFA) to add an additional layer of protection against unauthorized access. Ideally, this should be done with an authenticator app rather than through a code sent via email or text message, as the latter is easier to compromise. 9. Back up your data To mitigate a worst-case scenario like a ransomware attack (or a strike by a nation-state actor hell-bent on causing chaos ), regularly back up your data. This will prevent a total loss in the event that an attacker decides to wipe your systems and allow you to resume normal operations more quickly in the aftermath of an attack. Think of cybersecurity as a journey, not a single event Finally, you’ll do a better job protecting your data and your business if you think of cybersecurity as an ongoing process. You don’t have to implement a bunch of new defensive layers all at once. In fact, small but consistent monthly actions to improve your security will often deliver more impact than one big splashy annual upgrade. Bear that in mind as you move forward. Read more The right cybersecurity framework boosts a business’s value Nation-state actors represent a growing cybersecurity threat AI governance framework: Start with intent

Perspective changes everything.

Receive timely industry developments, regulatory changes and other news impacting your success.

Reach out to our team

Growing through uncertainty means balancing security, compliance and innovation. Access healthtech-focused guidance that helps you move forward with confidence.