MEC Veradigm 8.26
Blog|Articles|August 5, 2026

In a world of expanding healthcare management risks, ERM Is not optional

Fact checked by: Todd Shryock
Listen
0:00 / 0:00

Key Takeaways

  • Surveyed clinicians and leaders anticipate escalating enterprise threats, including ransomware, tightening compliance enforcement, nuclear verdicts, and operational failures linked to staffing shortages and burnout.
  • Incremental ERM implementation prevents risk-register bloat, prioritizing actionable, high-value information before adding layered metrics and sophistication as governance maturity increases.
SHOW MORE

Enterprise risk management is no longer optional for health systems — and smaller practices can build a program too, one step at a time.

There's no question the unfolding healthcare environment is fraught with intensifying risks, making the U.S. healthcare system increasingly unstable.

In fact, in a new survey of practicing physicians, nurses and healthcare leaders, 70% agreed the risk environment has worsened in the last two years, and 72% expect it to intensify further in the next 24 months.

The size, scope and impact of these risks mean provider organizations of all sizes must adopt a comprehensive and holistic perspective to manage them effectively, shifting away from the more typical, fragmented approach that centers on insurance and hazards. This is where enterprise risk management (ERM) comes in.

Putting an ERM strategy in place can be a complex process that demands real investment, which is likely why it's far more common in large organizations, with some 98% of large hospitals and health systems using ERM in some form. Among smaller medical groups and practices, budget constraints and competing priorities make it less common. That doesn't mean smaller organizations should sit on the sidelines. ERM can be built incrementally, at a scale that fits.

Whatever the organization's size, the goal is the same: build a proactive — not reactive — foundation for enterprise-wide risk management. Here's what's important to know.

Build incrementally

While ERM can seem overwhelming, it doesn't have to be. Successful implementation is built over time, starting with the most essential risk information, then layering in data, metrics and sophistication as the program matures.

A common pitfall when getting an ERM program off the ground is overloading the enterprise-wide risk register. Too many components, multiple layers of categories, measurements and metrics, can quickly turn a vital process into a form-filling exercise.

A practical, realistic focus helps you improve protection, ensure compliance, and support strategic goals, without adding unnecessary complexity to an already complicated risk landscape.

Done right, a proactive ERM strategy aligns an organization with its strategic goals, enabling smarter risk-taking, sharper decision-making, and better resource allocation. It also builds resilience and steadies financial performance against volatility, equipping the organization with a structured, manageable framework for handling future uncertainty.

Understand the risk picture

The enterprise-level threats facing medical organizations are vast, interconnected, and hard to overstate.

Cybersecurity lapses and ransomware attacks are almost inescapable in today's tech-driven world and growing more frequent. Regulatory scrutiny is tightening, too, with massive penalties for non-compliance. Nuclear verdicts of $10 million or more are increasingly common, covering not just clinical risks but systemic and staffing failures as well. And operational risk is rising as staffing shortages and burnout open the door to further exposures.

Test the waters by focusing initially on one risk domain, like patient safety or billing, and assign clear ownership of the program from the outset.

A range of tools can help. Digital registries, for instance, are invaluable for tracking hazards, near-misses, and mitigation efforts, while structured resources, such as a National Institutes of Health analysis on key risks and mitigation strategies, can help teams understand relevant ERM standards.

Build a solid ERM framework

ERM strategies draw on an organization's own data and internal systems to break down silos and build a shared view of potential threats. Guidance from your broker or risk advisor with deep healthcare experience is invaluable here. Practices that develop a comprehensive ERM program are also viewed positively by insurers, often resulting in broader coverage, more competitive terms, and a lower total cost of risk.

Five important guidelines to consider:

  1. Define your ERM objectives and identify key stakeholders early. Input from every business function: resident/patient care, diagnostic services, human resources, and information technology is essential to reflect the organization's full range of perspectives.
  2. Leverage the tools and resources you already have. Valuable data and existing risk protocols are likely already at hand; most organizations just need help organizing, analyzing, and putting that information to work.
  3. Plan for consequences. Running various scenarios will provide the muscle memory needed to drive a quick and effective response to crises: How will your people respond to a disruption? What happens to your supply chain? Which critical systems need to stay online?
  4. Conduct regular enterprise-level assessments. Your risk advisor will be invaluable in continuously evaluating business risks, helping you identify potential exposures before they become problems.
  5. Enlist advisors who understand the full risk picture. Specialists with deep healthcare expertise across financial, legal/compliance, IT and cybersecurity risk are invaluable for their insight into specific threats and their ability to tailor solutions to your organization's unique risk profile.

Today's increasingly complex risk environment makes it essential for organizations to shift from a reactive to a proactive posture, one where the ERM program is embedded into daily operations and reinforced by continuity planning and forward-looking risk strategies. The result is a more resilient organization, ready for whatever comes next.

Chrystie Howard, ARM, CRM, CIC, is Vice President and Enterprise Risk Management Leader for leading global insurance brokerage Hub International's Complex Risk Practice. In this role, she designs and leads the strategic risk platform dedicated to assessing business risks and threats to business objectives, while optimizing mitigation and financing strategies. Chrystie brings a streamlined and targeted approach to ERM that delivers practical and realistic output.