
-
When expertise becomes scarce
Competency remains the most acute risk at both sector and individual business level, compounded by ongoing practitioner recruitment and credentialling challenges cited as a top business risk by a further 29% of leaders in our survey.
One reason why competency is such an issue is the difficulty businesses have keeping track of a digital healthcare workforce, many of whom are independent or third-party contractors. Strikingly, three quarters (75%) of executives are troubled by lack of training or employee turnover, which makes it hard for businesses to ensure that the right people are always doing the right things.
-
“A lot of our clients are treating vulnerable populations. So, it’s important clients know their staff and their history. It’s one thing vetting people on entry, but businesses need to keep up the scrutiny as team members change. Staff might report well when they come in the door, but then something happens.”
Evan SmithThe industry is also grappling with a severe talent shortage. Few people combine the clinical, technical, commercial and regulatory skills now required. Many seasoned professionals are simply retiring, burning out, or unwilling to shoulder the rising cost of ongoing training. The sector’s image is not helping either, dampening interest among younger talent and shrinking the pipeline even further. In the meantime, pressure mounts on a scaled-back workforce to keep up with innovation and shifting demand.
“Workforce shortages and recruitment challenges can lead to increased claims, especially when clinical oversight is lacking. This in turn raises concerns about the evolving standard of care as companies adopt greater use of AI and technology, making clear policies, procedures, human guardrails and oversight even more important than ever.”
Carolyn Conners
When cyber becomes clinical
Cyber risk is a systemic threat, hardwired into every digital operating model. In virtual care, it spans everything from real-time data interception via pixels and chatbots, through unauthorised disclosure of health data through marketing tools, to ransomware targeting high-value patient records, weak remote-access controls and vulnerabilities across cloud and third-party systems.
In this high-stakes environment, a single misconfiguration or marketing misstep can trigger major financial, regulatory, and reputational fallout. No wonder almost a third (32%) of executives globally cite data theft, ransomware and system failure as top risks in our survey.
-
The threat becomes physical
Although incidents remain mercifully rare, cyber attacks have already caused actual bodily harm in healthcare. Ransomware attacks on hospitals have delayed treatments, shut down electronic health records, and forced clinicians into unsafe manual workarounds1. Remote-monitoring platforms and connected medical devices have been disrupted by cyber incidents, interrupting insulin delivery, cardiac monitoring, and telehealth-based triage2.
Even when attacks don’t directly manipulate devices, the operational paralysis they create can lead to missed diagnoses, medication errors, and delayed emergency responses.
-
As virtual care becomes more dependent on cloud platforms, APIs, and continuous connectivity, the risk of cyber events translating into physical harm is no longer theoretical. It’s an escalating reality.

Source: Beazley’s 2026 Digital Health & Wellness survey
-
Vigilance essential
Looking ahead, resilient organisations will need to prioritise removing high-risk tracking tools from patient interfaces, enforcing strict vendor and API controls, and securing remote-access pathways with strong identity management.
Continuous monitoring for ransomware and phishing threats, rigorous encryption and audit logging for all sensitive medical data, will also be essential, backed up by close oversight of marketing technologies to prevent unlawful data sharing.
-
“The most resilient organisations treat privacy and security as a single discipline, run regular risk assessments, and ensure every digital workflow, from intake bots to telehealth platforms, is designed to minimise data interception, disclosure, and third-party leakage.”
Evan Smith
