The Stakes

Threats to the healthcare landscape are rising at breakneck speed. Censinet’s analysis found that February 2026 alone saw 63 healthcare breaches compromising over 8.1 million people’s data, a 436% month-over-month spike.

This data point alone should serve as a call-to-action for all market access professionals, and indeed, all professionals working in pharmaceuticals.

In pharma, privacy and security are a duty, not a checkbox. We see this every day as an enormous volume of sensitive data flows across systems, ensuring that medications reach the right patient at the right time: patient data, insurance information, pharmacy claims, payment data. These data points are critical for patients in need and essential for understanding the true impact that our programs have across gross-to-net (GTN), copay assistance, patient support, and several adjacent systems.

With so many crucial data points flowing in real time, a security gap doesn’t just put data at risk, it puts a patient’s very access to their medication in jeopardy.

When we stepped into the roles of CISO and Chief Privacy Officer, we understood what was at stake, and RIS Rx’s mission inspired us to put our security and privacy expertise to work for the patients who need it most. As our co-founders Gerard and Stephen frequently say: “Affordability isn’t just a financial issue. It’s a clinical one.” We see data protection the same way: “Data privacy isn’t just a security issue. It’s a clinical one.”

The Five Safeguards

If you’re evaluating any market access vendor – including us – ensure these five safeguards are in your next RFP and ask for evidence:

1. Governance and workforce security

Vendors should have a dedicated leader for security and a dedicated leader for privacy. Folding security into the responsibilities of a talented COO or other executive leader is not enough. Security and privacy require experienced subject matter experts. That’s why RIS Rx has a dedicated CISO and CPO partnering to deliver the most secure and compliant solutions possible for our customers.

Beyond people, vendors need water-tight governance processes that are developed, refined, and routinely enforced. Our shortlist includes formal risk assessments, security/privacy/HIPAA training for all personnel, and compliance monitoring via an automated platform. RIS Rx checks every one of these boxes and goes further with in-person training sessions and executive briefings during company town halls.

2. Infrastructure and physical safeguards

We view infrastructure and physical safeguards the same way the best professional sports coaches view fundamentals: they function like clockwork for any high-performing team. For RIS Rx, non-negotiables include AWS-hosted production in SOC 2 / ISO 27001 certified facilities, full-disk encryption on all workstations, and secure media disposal.

Unencrypted assets and unsecure media are behind some of the world’s biggest historical data breaches – often due to a single employee’s misfortune or error – so execution on the fundamentals is paramount. Beyond being tight on these fundamentals, RIS Rx undergoes an annual SOC 2 Type II assessment (the report is available to customers and prospects under NDA).

3. Technical safeguards

To stop incidents before they start, certain safeguards are table stakes: encryption in transit and at rest, MFA and least-privilege access with quarterly reviews, 24×7 managed detection and response, annual independent penetration testing, and secure SDLC.

At RIS Rx, we execute and monitor these controls continuously.

4. Third-party and subprocessor management

Collaboration is essential to any market access partnership, but it can’t come at the expense of patient data protection. That’s why RIS Rx conducts rigorous due diligence before any third party gains access to customer or patient data.

Contracts with strict data privacy, confidentiality, and security obligations aren’t just a formality, they are what ensure third parties uphold the same rigor and diligence we apply internally. This is precisely where many vendors fall short and where scrutiny needs to be the heaviest.

5. Incident response and business continuity

A key maxim to live by when talking about security: “It’s not a matter of if, but when.” Documented, tested incident response plans, escalation, customer notification procedures, daily automated backups, annually tested BCP/DR, and multi-availability-zone architecture are pivotal when that unexpected attack hits, when that power outage occurs, or when that bad actor shows up unannounced.

You can count on RIS Rx. Our incident response plan is designed with built-in redundancy, so a disruption to any one system or site won’t affect the service you depend on.

Go Deeper with our Whitepaper

Our Security and Data Privacy Whitepaper goes deeper on each pillar: data categories and minimization, encryption standards, access governance, and more.

To request the full whitepaper, please reach out to us directly – Matthew Webster and Careen Martin – we’ll be glad to provide a copy and answer any questions you may have. We also have detailed audit evidence. Our SOC 2 Type II report and penetration test summary are available under NDA.

Let’s connect soon. We can show you exactly how RIS Rx protects data at every step, from claim to payment.

Get GTN Insights by Email
Matthew Webster
Matthew Webster
Chief Information Security Officer

Matthew serves as Chief Information Security Officer for RIS Rx, bringing more than 30 years of experience in cybersecurity and risk management. He has held CISO leadership roles across healthcare, financial services, and technology organizations, building security programs that meet regulatory demands while managing real operational risk. Matthew holds a degree in Mathematics from The Ohio State University. Read More

Careen Martin
Careen Martin
Chief Compliance & Privacy Officer

Careen Martin serves as Chief Privacy Officer at RIS Rx, bringing more than 20 years of experience helping healthcare, life sciences, and technology organizations navigate complex privacy, data protection, AI governance, and regulatory compliance challenges. She previously served as Chief Privacy Officer at Allina Health and Innovations for Aging, led Medtronic's Privacy Third-Party Risk Assessment team, and advised Seagen (Pfizer) as Senior Privacy Counsel. Careen partners with executive leadership to enable innovation through practical, risk-based governance that protects data, strengthens trust, and supports business growth in highly regulated healthcare environments. Read More