Back to news
Cybersecurity Alert
June 5, 2026 by EmailMeNow IT Consulting

Cybersecurity Audit of Major U.S. Healthcare Payers in 2026

Independent audits of the largest U.S. health insurers and managed-care organizations — UnitedHealthcare, Elevance, Cigna, Humana, and more — reveal a wide range of cybersecurity results. Weak email authentication is a direct path to member phishing and benefits fraud.

HealthcareHealth InsuranceHIPAAEmail Security
Digital audit dashboard with a United States map showing cybersecurity scores of healthcare payers

An independent cybersecurity review across the largest healthcare payers in the United States — national health insurers, Blue Cross plans, and managed-care organizations including UnitedHealthcare, Elevance Health, and Cigna — reveals a surprisingly wide range of results. These organizations handle sensitive customer and financial data at national scale, yet several show the same email-authentication gaps found at much smaller regional institutions.

Using data from audit.emailmenow.com, we evaluated each payer’s primary domain across email, website, and network security — including SPF, DKIM, DMARC, MTA-STS/TLS, and security headers.

In this national audit, scores ranged from 78% to 44%6 of 18 (33%) scored below 60%.

Cybersecurity Scores of Healthcare Payers

Overall compliance scores from audit.emailmenow.com. Re-run any domain at the link to verify.

RankHealthcare PayerDomainOverall ScorePerformance Level
1Cignacigna.com78%Strong
2Molina Healthcaremolinahealthcare.com71%Strong
2Health Care Service Corphcsc.com71%Strong
4Elevance Healthelevancehealth.com70%Strong
4Humanahumana.com70%Strong
4Centenecentene.com70%Strong
7Oscar Healthhioscar.com68%Good
8UnitedHealth Groupunitedhealthgroup.com65%Good
9Highmarkhighmark.com64%Above Average
10Aetnaaetna.com62%Above Average
11UnitedHealthcareuhc.com61%Above Average
12Independence Blue Crossibx.com60%Above Average
13Florida Bluefloridablue.com54%Below Average
13Blue Cross Blue Shield MAbcbsma.com54%Below Average
13Clover Healthcloverhealth.com54%Below Average
13Point32Healthpoint32health.org54%Below Average
13GuideWellguidewell.com54%Below Average
18Kaiser Permanentekp.org44%Weak

What the Results Reveal

  • Scores range from 78% (Cigna) down to 44% (Kaiser Permanente) — 6 payers reach a strong (70%+) posture, led by Cigna at 78%.
  • Several Blue Cross affiliates and regional plans cluster near 54%, while Molina (71%), HCSC (71%), and Centene (70%) lead the managed-care segment.
  • Kaiser Permanente (44%) — one of the largest integrated payers — trails nearly every standalone insurer on basic email authentication.
  • Without an enforced DMARC policy, criminals can spoof a payer’s own domain to phish members about benefits, EOBs, or premium payments.

Why This Matters for Healthcare Payers

Health insurers and managed-care organizations are bound by HIPAA security rules, HHS oversight, and state insurance department requirements. Email authentication (SPF, DKIM, and an enforced DMARC policy) is the single highest-impact control against member phishing, benefits fraud, and business email compromise targeting enrollment and claims data.

Check any payer’s posture at audit.emailmenow.com/?industry=healthcare-systems.

See also — state audits

Recommendations

  • Enforce DMARC (p=reject), strict SPF (-all), and DKIM signing.
  • Add MTA-STS and website security headers.
  • Adopt verified call-back procedures for any change to payment or wiring instructions, and train customer-facing staff.

Protect your organization. Run a free Instant Cybersecurity Audit at audit.emailmenow.com/?industry=healthcare-systems.

Contact EmailMeNow IT Consulting for help with HIPAA-aligned email security hardening.


Source & methodology: Overall compliance scores from the free scan at audit.emailmenow.com — each domain checked for email authentication (SPF, DKIM, DMARC), transport security (MTA-STS/TLS), website security headers, and network security. Re-run any domain at the link to verify.