How can healthcare providers make AI pay off?
Most organisations are still breaking even on technology spending.
Healthcare providers are rapidly adopting artificial intelligence (AI), but weak data, cybersecurity risks, and regulatory requirements continue to limit returns, according to KPMG's Global Tech Report 2026: Healthcare.
The study, released in May and based on a survey of 128 healthcare technology leaders worldwide, found that 40% of organisations spend $50m to $100m a year on technology, mainly on electronic health records, cloud platforms, and enterprise systems.
AI adoption has more than doubled. KPMG found that 66% of healthcare organisations are deploying AI applications, up from 32% a year earlier. Another 76% expect to expand AI over the next 12 months, whilst 86% are integrating it into clinical or operational work.
Despite higher spending, returns remain uneven.
Fifty-seven percent of organisations said their technology investments were only breaking even, whilst 30% reported returns above their original investment.
KPMG found that cybersecurity, poor quality data, and regulatory compliance remain the biggest barriers to wider tech adoption.
Weak governance and limited in-house expertise were cited by 42% of respondents as their biggest challenge.
Separate reports released by PricewaterhouseCoopers in May and the Healthcare Information and Management Systems Society in April identified similar obstacles.
Both found providers are focusing on cybersecurity, data quality, and information sharing as they expand digital services.
KPMG also reported growing interest in remote patient monitoring, robotic surgery, digital twins, predictive analytics, and patient support networks.
Nearly one-third of organisations plan to hire more local technology professionals to reduce reliance on offshore workers.
Questions to ponder:
- How can healthcare providers improve returns on AI investments?
- Should organisations fix data quality before expanding AI?
- How can providers balance faster AI adoption with cybersecurity and regulatory requirements?
EXPERT OPINION
Realizing the value of AI in healthcare requires more than technology investment. It requires clarity of purpose, organizational readiness, and a commitment to continuous measurement. Healthcare providers that achieve meaningful returns typically begin with well-defined, high-volume use cases where outcomes can be clearly tracked, such as administrative efficiency, clinical decision support, and patient flow optimization.
Across APAC, the opportunity is significant, but successful adoption depends on thoughtful implementation. Aligning AI initiatives with existing workflows, investing in staff capabilities, and establishing clear success metrics from the outset are key to distinguishing sustainable programmes from short-lived pilots. Ultimately, the success of AI depends less on the tools themselves and more on an organization's ability to learn, adapt, and scale responsibly.
To maximize returns on AI investments, organizations need a clear understanding of the problems they are trying to solve, meaningful involvement from clinicians and other relevant stakeholders, and reliable ways to measure improvements in outcomes, efficiency, and patient care. High-quality data must be viewed as a fundamental requirement, not a separate or secondary initiative, since inaccurate or incomplete data can amplify errors and undermine decision-making. Equally important is the need to build cybersecurity, privacy protection, and regulatory compliance into AI projects from the outset. Treating these considerations as core design principles, rather than addressing them later, helps ensure that AI solutions are both effective and trustworthy. Organizations that are achieving benefits are those that apply AI to address clearly defined clinical and operational challenges, rather than adopting the technology simply because it is available.
How can healthcare providers improve returns on AI investments?
Healthcare providers can improve returns by focusing less on the technology itself and more on the specific operational or clinical problem being solved. The strongest use cases have a clearly defined baseline, measurable outcomes and an implementation pathway that fits existing workflows.
For example, in Indonesia, some providers are using AI-assisted billing and coding to reduce the time required to prepare and manage claims submitted to BPJS. This can help lower administrative effort, reduce coding errors and potentially accelerate reimbursement, providing a practical and measurable source of value.
Providers should also account for the full cost of implementation, including integration, governance, training and ongoing monitoring. AI pilots may demonstrate technical potential, but returns are realised only when solutions are adopted consistently, scaled and supported by the appropriate operating-model changes.
Should organisations fix data quality before expanding AI?
Its generally the case that large organisations have messy, sprawling, sometimes inaccurate data. That’s despite significant investment over many years in trying to improve their data – sometimes with a view to monetising that even.
The AI models now in widespread use are quite good at picking up this kind of messy data, so from a technological perspective I think there is the option to move on AI before perfecting data. The constraints I see, however, are mostly around security management (e.g., what data pools should a particular AI tool and its users have unfettered access across) and the predictability or resilience of the outputs being generated (e.g., where the source data is messy and potentially ambiguous or inaccurate).
Free rein on data and the occasional glitch are OK in some AI use situations, much less so in many high intensity healthcare settings where the ability to QA every AI generated artifact might be uncomfortably thin. Every provider needs to find their own balance and route to a ‘workable’ data structure and quality.
How can providers balance faster AI adoption with cybersecurity and regulatory requirements?
I don’t think there is much that can be done to ‘balance’ healthcare data processing and use with AI when considering cybersecurity: Its quite simple that patient and clinician (and institutional) trust has to be maintained in order to move forward with a change agenda … if there is a security issue then that trust takes a major step backwards, and so does the change agenda.
Healthcare data is already a major target for bad actors, and most Boards and regulators will rightly refuse a significant escalation in risk profile just to secure the clinic-economic returns that have been demonstrated to date by AI implementations. As a result, a lot of AI implementation has been ‘trapped’ in sandboxes and pilots where the risks can be contained to a better degree while exploring the potential.
The good news is that the major AI developers know this issue well and seem to be evolving rapidly to accommodate the need for healthcare and other high sensitivity sectors, and the third party security toolbox is also improving to provide more predictable guardrails to operate within, so hopefully there won’t be an either / or choice in the near future.
Healthcare boards across Asia-Pacific have stopped asking whether AI belongs in hospitals. After two years of pilots, the question is narrower and more commercial: where will it pay for itself first, and how quickly? The mood has moved from curiosity to accountability, and executives want measurable evidence, not optimism. If a system cuts labor, lifts throughput, or reduces revenue leakage, it earns its place as infrastructure. If it does not, it stays on the books as a cost.
Clinical use is where most of the attention goes, and diagnostic imaging has the clearest momentum. Algorithms are increasingly used to interpret scans, prioritize urgent cases, and flag abnormalities that support earlier diagnosis. Hospitals and imaging providers across the region are deploying them to help radiologists work faster and report more consistently. Consumer health apps are expanding alongside, tracking everything from heart-rhythm irregularities to sleep disorders and metabolic risk. Used under clinical supervision, they can extend continuity of care and ease demand on a stretched workforce.
The clinical story carries real caveats. Unsupervized use invites harm when symptoms overlap and require expert interpretation, and performance varies with how a system was trained and whether it was validated for the population using it. Trust is the softer barrier. Limited public awareness, stigma around certain conditions, and confusion about what AI can and cannot do can push patients either to over-rely on automated advice or to reject sound tools outright. Governance, patient education, and safeguards that keep AI an aid rather than a substitute for clinical judgement will decide how far the technology travels.
For all that clinical promise, the most reliable returns sit outside the operating theater. Documentation, scheduling, coding, prior authorization, and patient communication are the workflows where AI strips out repetitive effort and eases pressure on overstretched staff, and where the financial impact is immediate and easy to measure. Revenue cycle management is the clearest proving ground of the lot, sitting where operations meet finance, so better coding, fewer denials, and faster claims turnaround convert quickly into visible savings. The key lesson from AI deployments to date is that success depends less on the choice of AI model and more on how effectively AI is integrated into real workflows and local payment systems rather than left as a standalone pilot.
As hospitals and clinics adopt administrative AI for patient data handling, questions about governance, privacy, and security are rising just as quickly. AI governance must be treated as a core responsibility, not a side issue. That includes vetting vendors, limiting unnecessary access to protected health information, and setting rules for how AI tools are used across recordkeeping, billing, and other workflows.
Medical records contain some of the most sensitive information a person can share, and those systems must be protected with strict access controls and clear oversight of how data is collected and used. Without those safeguards, a breach can harm both patients and healthcare organizations, exposing private details while also eroding trust and inviting legal and financial fallout. Most of all, AI in healthcare should be helpful to both patients and healthcare professionals instead of another layer of disparity between social classes.
The goal for providers is straightforward. Rather than chase every clinical promise at once, the stronger play is to start where the economics are proven - back-office automation, revenue cycle management, and workflow-heavy services while maintaining governance protocols and ensuring accessibility across all patient classes. Demonstrate the value there, and the broader clinical case becomes far easier to justify.