
How AI Can Reshape Access To Specialty Medications
In 1969, a psychologist named Philip Zimbardo conducted a now-famous experiment. He parked two identical cars in two neighborhoods: one in the Bronx, a high-crime area, and the other in Palo Alto, a quiet, affluent community.
The car in the Bronx was quickly vandalized, stripped within hours. The Palo Alto car sat untouched. But then Zimbardo broke one of its windows. Within days, the once-pristine car was equally wrecked.
Zimbardo's "broken window theory" suggested that environments left unchecked can lead to systemic dysfunction. I see healthcare facing its own version of this phenomenon. Prior authorizations, which I see as an outdated and fragmented process, have become the "broken window" of specialty medications—neglected, frustrating and quietly draining resources.
But unlike in the 1960s, we now have tools that can help. I believe AI offers a path to not just patch the system but to reimagine it entirely.
Prior authorizations for specialty medications are often managed manually—often involving faxes and phone calls. Providers report spending 12 to 15 hours a week on these tasks, which can result in delayed treatment, lost revenue and burned-out staff.
For a patient waiting on chemotherapy or a biologic for Crohn's disease, that delay isn't just inconvenient—it can be life-altering.
AI isn't just a buzzword in this space; it's a practical tool that's already making an impact. Here's what I witness it enabling within the healthcare space:
• Real-time eligibility checks by analyzing patient insurance details the moment a prescription is entered.
• Predictive denial prevention, flagging incomplete or noncompliant requests before they're submitted.
• Natural language processing to extract clinical data from electronic health record notes, lab results and attachments without manual entry.
• Automated submission and tracking across payer portals, with proactive alerts on missing information.
In my direct experience, I've seen AI reduce approval times from 10 to 14 days to as little as two to three days. That's not theory—that's from real clinics we've partnered with.
But AI doesn't work in isolation. To be successful, providers should:
1. Start with high-friction areas (e.g., oncology, rheumatology and rare disease) where prior authorization is frequent and urgent.
2. Involve clinical staff early to identify workflow pain points.
3. Choose AI tools that integrate directly into your electronic health records and don't force a new UI.
4. Review audit logs regularly and tune your AI models to local payer patterns.
AI in healthcare raises valid questions: Will it follow HIPAA? Can we trust it to make clinical inferences? The answer is yes, but only with oversight.
The best AI tools are transparent, explainable and built with guardrails. Vendors should offer encryption, role-based access control and Systems and Organization Controls 2 (SOC 2) compliance. And just as important: Staff need training not just on how to use the tools, but on how to challenge and verify their decisions.
Building off the need for your staff to challenge AI decisions, AI isn't here to replace people; it's here to take the weight off their shoulders. It's the assistant that never sleeps, never gets overwhelmed and doesn't forget payer rules.
In the context of healthcare, I see it as a force multiplier enhancing the role of pharmacists, providers and care coordinators.
When we introduced AI at a multisite provider group, the most surprising feedback wasn't just about time saved; it was how morale improved. Nurses and coordinators said they finally felt like they could focus on patients again.
The future of prior authorizations won't be about eliminating them; it will be about making them invisible. The AI systems will know what's needed before we do. They'll draft documentation, catch gaps and smooth the back-and-forth.
But it only happens if we adopt early and thoughtfully. Prior authorizations have been a source of friction for too long. AI gives us the power to fix the "broken windows"—not with duct tape but with real structural change. The next step is ours to take.
Forbes Business Council is the foremost growth and networking organization for business owners and leaders. Do I qualify?

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


Time Business News
8 hours ago
- Time Business News
Navigating the IOP Landscape: A Step-by-Step Startup Guide
Launching an Intensive Outpatient Program in behavioral health is an opportunity to combine strong clinical impact with a scalable business model. It begins with understanding your community's needs, defining your target population, and shaping a program that fills an actual gap in care. This requires market research, competitor analysis, and conversations with referral sources to design group schedules, specialty tracks, and service hours that truly fit the lives of those you aim to serve. Creating an intensive outpatient program begins with identifying the specific needs of your target population and developing a service model that delivers measurable results. Careful planning ensures the program offers flexible scheduling while maintaining clinical rigor. Securing qualified staff, establishing evidence-based treatment protocols, and complying with local and federal regulations are vital steps. Knowing how to start an IOP program means also addressing insurance credentialing, community outreach, and outcome tracking to demonstrate value. When designed thoughtfully, such programs provide the structure and support clients need to recover while continuing their daily responsibilities, fostering long-term healing and stability. Once your concept is clear, choosing a compliant, accessible location is essential. Your site should be zoned appropriately for healthcare, designed to ensure privacy, and equipped with multiple group spaces, a private intake area, and technology-ready rooms for telehealth. From the start, align your licensing and accreditation plan with state requirements—such as DHCS Licensing for Behavioral Health in California—and aim for CARF or Joint Commission accreditation to strengthen both credibility and payer relationships. Your clinical program should follow evidence-based practices and offer a structured mix of group therapy, individual sessions, family involvement, and psychiatric care. Clearly define admission criteria, safety protocols, and step-up or step-down care pathways. A strong staffing plan is crucial, with leadership, licensed clinicians, case managers, and prescribers all in place, and payer credentialing for each provider completed early to avoid delays. Supporting this team with an EHR designed for behavioral health, HIPAA-compliant telehealth tools, and robust documentation workflows will set the tone for smooth operations. Financial planning is equally important, with a realistic budget that covers startup expenses, operating reserves, and the inevitable collections lag in insurance-based care. Develop a payer mix strategy that blends commercial insurance, Medicaid where viable, and cash pay options, while maintaining rigorous denial management practices. Ethical marketing—built on strong referral networks, local SEO, and a responsive intake process—will help admissions grow steadily without overreliance on advertising. From referral to discharge, every step in the client journey should be mapped and intentional. Intake processes, treatment planning, progress tracking, and alumni engagement must be consistent and streamlined. Measurement-based care using tools like the PHQ-9 or GAD-7 not only improves clinical quality but also supports payer negotiations and continuous quality improvement. Alongside this, strict adherence to HIPAA, 42 CFR Part 2, and risk management protocols ensures client trust and protects your business from compliance issues. Establishing a behavioral health program begins with a clear framework for quality, safety, and accountability. From securing the right facility to hiring qualified staff, every step must align with industry regulations. A crucial part of this process is understanding and obtaining DHCS licensing for behavioral health, which ensures that your services meet state standards for treatment delivery and patient protection. This involves preparing documentation, passing inspections, and adhering to ongoing reporting requirements. Compliance not only protects your organization legally but also strengthens trust with clients and payers, setting the stage for long-term sustainability in the behavioral health field. Launching an IOP successfully means starting small, testing workflows, collecting feedback, and refining before scaling. Once operations are stable, you can expand to additional tracks, services, or locations, supported by standardized policies, clinical curricula, and data-driven decision-making. For those exploring how to start an addiction treatment center through a broader network, a well-run IOP can become both a powerful standalone business and a strategic building block for future growth. TIME BUSINESS NEWS


Forbes
19 hours ago
- Forbes
20 Hidden Cybersecurity Weaknesses In The Healthcare Industry
Few industries face a digital environment as complex and high-stakes as healthcare, where a single breach can endanger both patients and providers. While HIPAA compliance and patient privacy dominate most cybersecurity discussions, many other critical threats remain overlooked—hidden in workflows, medical devices and third-party partnerships. These gaps can be exploited quietly, sometimes for months, before they're detected. Below, members of Forbes Technology Council reveal the most underreported cybersecurity challenges in healthcare. They explain why addressing these risks is essential to safeguarding patient care, maintaining compliance and preserving trust in the healthcare system. 1. Aging, Interconnected Devices And Software The biggest weakness is the interoperability between vastly disparate medical devices and software and the stacks and ages between them. The industry relies on connected tech ranging from cutting edge to 20 years old. This forces advanced systems to communicate with less secure ones, inevitably negotiating security down to the lowest common denominator and leaving the ecosystem vulnerable at its weakest link. - Gunter Ollmann, Cobalt 2. Vendors' Email Systems We invest heavily in internal security, but the real risk often sits in a vendor's inbox. Email is still the top attack vector, and third-party partners with weak defenses put us all at risk. It's time we hold our ecosystem to higher standards—asking tough questions about authentication, phishing readiness and account takeover protection. - Eyal Benishti, IRONSCALES Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify? 3. Third-Party Software And Devices Many hospitals and health systems rely on dozens (sometimes hundreds) of third-party tools: electronic health record plug-ins, diagnostic systems, billing platforms and Internet-of-Things-connected medical devices. These vendors often require access to sensitive patient data or internal networks; however, they may not be held to the same security and compliance standards as the healthcare organization itself. - Jonathan Stewart, ZenSource 4. Phishing Attacks One overlooked challenge is the sheer volume of phishing attacks targeting healthcare organizations. Hackers target valuable patient data and exploit outdated systems, vast supply chains and limited security training to dupe employees into clicking links or interacting with business email compromise attacks. This can lead to ransomware, and healthcare firms are more likely to pay to keep critical services running. - Mike Britton, Abnormal AI 5. Outdated Legacy Systems Outdated legacy systems are a major overlooked weakness. Long depreciation cycles mean critical connected medical devices and software often can't be updated, forcing reliance on vulnerable old policies. This widespread issue creates significant network attack surfaces. Better control, visibility and microsegmentation are vital to restrict access and mitigate damage until patching is possible. - Erez Tadmor, Tufin 6. Lack Of Frontline Cybersecurity Training Frontline staff often lack adequate cybersecurity training, making them susceptible to social engineering attacks. For instance, a smooth-talking patient might distract a clinician, who then forgets to lock their workstation before leaving the room. This could expose sensitive data, including personally identifiable information and other patients' health records, which poses serious risks to privacy and healthcare system security. - Sunny Banerjee, First Citizens Bank 7. Missing Data Lineage In AI-Driven Systems In today's AI-driven healthcare offerings, one big gap no one talks about is data lineage. We obsess over encryption and access controls but rarely ask, 'Where did the data come from, how was it changed, and who touched it?' Without clear tracking, silent corruption and model poisoning slip through, quietly eroding diagnostic accuracy, AI performance and patient trust over time. - Kiran Elengickal, Siemba 8. On-Premises Servers One overlooked cybersecurity risk in healthcare is the reliance on on-premises servers. Many practices still store sensitive patient data locally, without regular updates, backups or monitoring. This creates serious vulnerabilities. Cloud-based platforms with well-managed open APIs provide centralized security and safer, scalable integrations. - Eric Giesecke, Planet DDS 9. Manual Certificate Management One overlooked challenge in healthcare cybersecurity is manual certificate management. Expired or misconfigured digital certificates can take down EHR systems, delay care and put patient safety at risk. Automated certificate lifecycle management is critical to maintaining secure, uninterrupted operations. - Jason Sabin, DigiCert Inc. 10. Data Silos And BMAs One overlooked weakness or challenge is data silos and business-managed applications. BMAs fly under the radar when it comes to security guidelines and are always at risk of exposure. BMAs also tend to be at risk of compliance failures at various levels. The risk is higher with financial analytics or operational analytics, which involve highly sensitive and critical data. - Sanath Chilakala, NTT Data 11. Outdated Medical Devices One significant cybersecurity risk in healthcare is outdated medical devices. Many work with expensive legacy software and struggle each cycle to patch it, making them easy pickings for internet bad actors. With limited encryption and little chance of being swapped out, they continue to be plugged into sensitive networks, endangering patients and the integrity of client records. - Sreekanth Narayan, LTIMindtree 12. Shadow IT And BYOD Practices Shadow IT and bring-your-own-device practices in healthcare, such as staff using personal devices or apps for convenience, expand the attack surface beyond what most systems monitor. These informal workflows bypass standard protections, leaving patient data and core systems exposed without anyone noticing. - Mark Mahle, NetActuate, Inc. 13. Insecure Data Sharing During Clinical Trials An overlooked cybersecurity risk in healthcare is insecure data sharing during clinical trials. With multiple stakeholders and fragmented oversight, sensitive patient data often flows across systems without unified governance. The sector must adopt secure-by-design interoperability frameworks that protect trust as much as innovation. - Rishi Kumar, MatchingFit 14. Unsecured Data Exhaust From Medical IoT Devices A critical but under-discussed vulnerability in healthcare is the data exhaust from medical IoT devices like infusion pumps and smart monitors. These devices stream telemetry constantly, often unsecured, creating a quiet but massive attack surface. Deploying edge-based zero-trust agents directly on these devices could validate every outbound data packet in real time. - Nicola Sfondrini, PWC 15. Legacy Devices With Hardcoded Credentials Legacy medical devices with hardcoded credentials or outdated firmware are a massive blind spot. They often sit on flat networks and are invisible to IT teams. During EHR breaches, a compromised infusion pump or MRI interface could quietly offer persistent access, turning patient care tools into attack surfaces. Cybersecurity must evolve to treat these devices like endpoints, not exceptions. - Raghu Para, Ford Motor Company 16. Continued Use Of Fax Machines The real threat in healthcare cybersecurity? Fax machines. Hospitals still send patient data through outdated, insecure systems because 'that's how it's done.' It's not hackers we should fear most; it's complacency. Security won't come from patching the past. It'll come from rethinking it entirely. - Oleg Sadikov, DeviQA 17. Lack Of Standardized Secure Communication Protocols Shared secure communication between different companies is a risk. While the healthcare industry has a standard for HIPAA compliance, there is no standard for communication. Some data is still exchanged in physical form. The weakness occurs when data moves from one system to another and is left unencrypted. The best solution is to establish a communication standard that uses changing keys and algorithms. - WaiJe Coler, InfoTracer 18. Weak Endpoint Security For Mobile Devices One significant but frequently overlooked challenge in healthcare cybersecurity is the lack of robust endpoint security for mobile devices used by healthcare professionals. These devices often access sensitive patient data remotely, yet many organizations fail to implement adequate security measures such as encryption and remote wipe capabilities. This increases exposure to data breaches. - Roman Vinogradov, Improvado 19. Unsecured DevOps Pipelines One risk that's often ignored is unsecured DevOps pipelines in healthcare tech stacks. Rapid CI/CD deployment cycles (without quality control and cyber reviews) can bypass critical security gates, introducing unvetted code into patient data environments. Secure DevSecOps integration shouldn't be optional; it's a vital aspect of developing secure code and essential to protecting data integrity and maintaining clinical trust. - Dan Sorensen 20. Lack Of Comprehensive DSPM Practices When you combine the healthcare industry's irregular cloud adoption tendencies, disparate network of legacy devices and lack of consistent cybersecurity training, you create the perfect opportunity for malware and ransomware attacks. By integrating comprehensive data security posture management, teams can continue to grow their digital capabilities without sacrificing patient privacy. - Thyaga Vasudevan, Skyhigh Security


Time Business News
2 days ago
- Time Business News
Everything Simplified: How to Start a Rehab Center
Launching a rehab center is both a business opportunity and a powerful way to make a difference in people's lives. For entrepreneurs, the challenge often lies in balancing the mission of recovery with the operational demands of running a healthcare facility. By following a clear, structured plan, you can navigate the complexities of licensing, funding, staffing, and facility setup without becoming overwhelmed. This guide simplifies the process, helping you move from vision to reality with confidence and clarity. Opening a treatment facility demands more than compassion—it requires strategic financial planning. Operators must balance quality care with efficient resource management to thrive in a competitive healthcare market. Factors such as occupancy rates, payer mix, and specialized services significantly influence revenue potential. Many entrepreneurs wonder, are rehab centers profitable, and the answer often depends on the alignment of operational costs with steady patient inflow. Strong referral networks, accreditation, and evidence-based programs can enhance both reputation and returns. Ultimately, when managed effectively, a rehab facility can achieve financial stability while fulfilling its mission of helping individuals reclaim their lives. Before anything else, articulate a mission that reflects your values and the specific needs of your target community. Will your center specialize in inpatient residential care, outpatient therapy, detox programs, or a combination of these? Your chosen care model will shape everything—from facility design and staffing requirements to marketing and compliance needs—so it must be well thought out from the start. Rehab facilities operate in a heavily regulated sector, making licensing one of the first major hurdles. Depending on your state, you may need approval from agencies such as the Department of Health Care Services (DHCS) and compliance with national standards like HIPAA for patient privacy. The process often involves documentation, facility inspections, and verification of staff credentials. Addressing compliance early helps avoid costly delays later. Starting a rehab center requires substantial investment, often covering property costs, medical equipment, salaries, and marketing. A comprehensive financial plan should outline startup expenses, ongoing operating costs, and revenue projections. Explore multiple funding sources—such as bank loans, private investors, or grants—and create a contingency budget for unexpected costs. Solid financial preparation ensures your center's long-term stability. Your physical space is more than a building—it's part of the healing process. Focus on creating an environment that feels safe, welcoming, and therapeutic. Comfortable private rooms, accessible common areas, and serene outdoor spaces can greatly influence patient engagement and recovery outcomes. Ensure that your design also meets safety codes and accessibility standards. The people you hire will determine your center's reputation and effectiveness. Recruit licensed therapists, nurses, physicians, and support staff who are both qualified and compassionate. Provide ongoing training in clinical excellence, regulatory compliance, and patient care best practices to maintain high-quality service and staff morale. Establishing a behavioral health program requires a strong focus on legal, ethical, and operational compliance. Providers must design services that meet community needs while aligning with state and federal regulations. An essential step is navigating DHCS Licensing for behavioral health, which ensures your facility adheres to standards for safety, staff qualifications, and clinical practices. This process often involves inspections, policy reviews, and ongoing reporting to maintain good standing. By achieving and upholding licensure, organizations not only protect their clients but also build credibility, enabling them to partner with insurers, expand services, and deliver high-quality, sustainable mental health care. Starting a rehab center doesn't have to be overwhelming if you focus on the core pillars of mission, compliance, finance, environment, and team. By breaking the process into manageable stages, you can create a facility that not only operates efficiently but also delivers meaningful, life-changing results. With the right approach, your rehab center can become a trusted resource for recovery while thriving as a sustainable business. TIME BUSINESS NEWS