Optum data assets and the trust question for competing health systems
Photo by David Clode on Unsplash
insight

Optum data assets and the trust question for competing health systems

By Jason Alan Snyder·September 3, 2026

Optum controls claims, pharmacy, clinical, and behavioral data on more than 150 million lives. Health systems that send data into Optum's platforms are training the analytics tools of a company that competes with them for patients, contracts, and market share. The trust question is not hypothetical. It is structural.

Optum processes claims, clinical, pharmacy, and lab data on more than 150 million Americans. That number alone would make it one of the largest health data holders in the country. But Optum is not a neutral data custodian. It is a subsidiary of UnitedHealth Group, which also operates UnitedHealthcare (the largest commercial health insurer in the U.S.), a growing network of physician practices employing or affiliating with more than 90,000 physicians, and ambulatory surgery centers that compete directly with hospital systems for procedural volume.

When a health system shares data with Optum's analytics, revenue cycle, or population health platforms, it is handing operational intelligence to an entity that may use aggregate learnings to compete against it. That is the Optum data trust question, and most health systems have not answered it.

The scale of UnitedHealth data assets

UnitedHealth Group data asset coverage by segment
UnitedHealth Group data asset coverage by segment

UnitedHealth Group reported $371.6 billion in revenue in 2023. Optum alone accounted for $227.3 billion of that, making it larger by revenue than all but a handful of companies in any industry. Optum's data assets span four major categories.

First, claims data. UnitedHealthcare covers approximately 51 million members across commercial, Medicare Advantage, and Medicaid plans. Every claim generates structured billing data: diagnosis codes, procedure codes, provider identifiers, dates of service, and allowed amounts.

Second, clinical data. Through Optum Health's physician practices and urgent care centers, the company captures EHR data at the point of care. The 2023 acquisition activity accelerated this. Optum now operates or affiliates with physician groups across more than 30 states.

Third, pharmacy data. OptumRx processes more than 1.4 billion adjusted prescriptions annually, giving UnitedHealth Group real-time visibility into medication adherence, therapeutic switching, and specialty drug utilization.

Fourth, analytics and benchmarking data. Optum Insight provides revenue cycle management, coding, and analytics services to hundreds of health systems and hospitals. These engagements generate operational data that flows through Optum's infrastructure, including cost-per-case metrics, length-of-stay patterns, denial rates, and staffing models.

Why competing health systems should be concerned

The concern is not that Optum violates HIPAA. The concern is that HIPAA compliance does not address competitive intelligence risk. HIPAA governs the privacy and security of protected health information. It does not prohibit a covered entity from using de-identified or aggregated data to build products, train models, or inform competitive strategy.

When a hospital system contracts with Optum Insight for revenue cycle services, Optum gains access to that system's charge capture patterns, payer mix, denial rates, and operational bottlenecks. Even if individual patient records remain protected, the aggregate patterns become intelligence. Optum can use that intelligence to build better analytics products, optimize its own clinical operations, and identify market opportunities where UnitedHealthcare or Optum Health can expand.

This is not speculation. UnitedHealth Group has publicly stated that data integration across its segments is a strategic priority. The company's investor presentations describe the flow of insights between UnitedHealthcare and Optum as a competitive advantage. When the same parent company that processes your claims data also employs physicians who compete with your medical staff for patients, the trust question becomes a business risk question.

The data asymmetry problem

Health systems face a structural asymmetry. They need analytics, revenue cycle tools, and population health platforms. Optum offers some of the most widely deployed versions of these products. But by using them, health systems contribute to a data pool that benefits their competitor.

Consider a regional health system with 400 beds and a 30% Medicare Advantage population covered by UnitedHealthcare. That system contracts with Optum Insight for coding optimization. Optum now sees the system's coding accuracy, case mix index trends, and documentation gaps. Simultaneously, UnitedHealthcare is negotiating reimbursement rates with that same system. The insurer and the analytics vendor share a parent company.

The health system has no visibility into how its operational data flows within UnitedHealth Group's corporate structure. It cannot audit the firewall between Optum Insight and UnitedHealthcare's contracting teams. It has to take Optum's word for it. That is a trust deficit, not a trust relationship.

What the Change Healthcare breach revealed

The February 2024 Change Healthcare cyberattack exposed a related dimension of this problem. Change Healthcare, acquired by UnitedHealth Group in 2022 for $13 billion, processes approximately 15 billion healthcare transactions annually. The breach affected an estimated 100 million individuals and disrupted claims processing across the entire U.S. healthcare system for weeks.

The breach was a security failure, but it also revealed a concentration risk. When a single corporate entity controls the claims clearinghouse, the analytics platform, the pharmacy benefit manager, and the insurance plan, a failure at any point cascades everywhere. Health systems that had diversified their payer mix still found their operations frozen because Change Healthcare was the infrastructure layer underneath multiple payers.

This concentration of health data infrastructure in one corporate entity is the trust question made physical. The data is not just at risk of misuse. It is at risk of systemic failure.

Key statistics

  • UnitedHealth Group's Optum segment generated $227.3 billion in revenue in 2023, larger than many national economies
  • OptumRx processes more than 1.4 billion adjusted prescriptions per year, giving UnitedHealth Group real-time medication utilization intelligence
  • The Change Healthcare breach affected an estimated 100 million individuals and disrupted 15 billion annual healthcare transactions
  • UnitedHealth Group employs or affiliates with more than 90,000 physicians through Optum Health, making it the largest employer of physicians in the United States
  • Health systems using Optum Insight for revenue cycle management contribute operational data covering charge capture, denial rates, and payer mix to an entity whose parent company competes for the same patients and contracts
  • The consent problem hidden inside vendor contracts

    Most health system contracts with Optum include data use provisions that permit aggregation, de-identification, and secondary use for product improvement. These provisions are standard in health IT vendor agreements. They are also the mechanism by which competitive intelligence extraction becomes legally permissible.

    Patients consent to their health system using their data for treatment, payment, and operations under HIPAA's TPO framework. They do not typically consent to their data being aggregated by a vendor that is also their insurer's corporate sibling. The consent architecture here has a gap. The patient sees a hospital. The data flows to a conglomerate.

    Health systems that want to close this gap need to audit their vendor contracts for secondary use provisions. They need to understand exactly what data leaves their walls, in what form, and under what restrictions. And they need to establish data trust requirements that go beyond HIPAA compliance. HIPAA is a floor. It is not a trust framework.

    How other vertically integrated entities compare

    Optum is not the only vertically integrated health data entity raising trust questions. CVS Health owns Aetna (insurance), Caremark (PBM), MinuteClinic (care delivery), and Signify Health (home-based care). Amazon operates Amazon Clinic, One Medical, and PillPack while running AWS, the cloud infrastructure underneath many health systems' data. These entities all create similar data trust tensions.

    But UnitedHealth Group's scale makes the Optum question the most consequential. No other entity combines the largest insurer, the largest PBM, the largest physician employer, the largest claims clearinghouse, and one of the largest health IT analytics platforms under a single corporate parent. The data convergence is unmatched.

    Health systems competing against Optum Health for ambulatory volume, against UnitedHealthcare for favorable contract terms, and against OptumRx for pharmacy margin cannot simultaneously trust Optum Insight as a neutral analytics partner. The math does not work.

    What health systems should do about it

    The answer is not to stop using analytics platforms. The answer is to stop trusting analytics platforms that cannot prove neutrality.

    Health systems need three things. First, data trust scoring that operates independently of the vendor relationship. Every data record entering or leaving a health system should carry a trust score that measures provenance, consent, recency, and quality. This score should be computed by the health system or a neutral third party, not by the vendor that benefits from the data flow.

    Second, contractual restrictions on secondary use that are auditable. Vague language about "de-identified aggregate use" is insufficient. Health systems should demand specificity about what data is retained, how long it is retained, what models it trains, and whether any derivative products compete with the health system's services.

    Third, alternative infrastructure that separates analytics from competitive entanglement. This means investing in data platforms that score, govern, and make data queryable without requiring it to leave the health system's control. Zero-copy architectures, where data is scored and queried in place without being transferred to a vendor's environment, eliminate the competitive intelligence extraction risk entirely.

    The trust scoring gap in health data competition

    Data trust scoring dimensions and weights
    Data trust scoring dimensions and weights

    The fundamental problem is that health data flows today without a trust layer. Data moves from EHRs to clearinghouses to analytics platforms to AI models without any standardized measurement of whether that data was properly consented, recently validated, correctly coded, or appropriately governed.

    Optum benefits from this gap. The absence of trust scoring means health systems cannot quantify the risk of their data relationships. They cannot compare the competitive intelligence exposure of one vendor against another. They cannot tell their boards, with specificity, what data they are giving away and what it is worth.

    A trust scoring framework changes this calculation. When every record carries a score from 0 to 100 across dimensions like provenance, consent, recency, and concordance, health systems can make data-sharing decisions based on measured risk rather than vendor promises. They can set floors. They can refuse to share data that falls below certain trust thresholds. They can audit their data relationships with the same rigor they apply to financial audits.

    Why 2025 is the inflection point

    Several forces are converging. CMS is expanding its data quality requirements through programs like ACCESS, which ties $420 per beneficiary payments to data completeness and recency standards. The ONC information blocking rules continue to expand the surface area of required data sharing, making the question of who receives that data more urgent. And the FTC has signaled increasing scrutiny of health data brokers and vertically integrated entities that aggregate patient data across corporate subsidiaries.

    Health systems that wait for regulation to solve this problem will find themselves already locked into data relationships that are difficult to unwind. The time to establish data trust infrastructure is before the next contract renewal with Optum, not after.

    The competitive intelligence question nobody is asking

    Here is the question that should be on every health system CEO's agenda: if Optum can see our operational data, our coding patterns, our denial rates, and our patient volumes, and Optum's parent company is simultaneously negotiating reimbursement rates with us and recruiting our physicians, what is the actual cost of that data relationship?

    No health system would share its financial models with a competitor. But many health systems share their operational data with Optum every day. The only difference is that the data sharing happens through a vendor contract rather than a spreadsheet. The competitive exposure is the same.

    Data trust is not an abstract concept. It is a measurable property of every data relationship a health system maintains. The health systems that measure it will outperform the ones that do not.

    SuperTruth scores incoming EHR data at the point of ingestion, before it reaches a model. If your system is deploying clinical AI and needs to answer an auditor's questions about data provenance, consent governance, or competitive exposure, contact Louis Simeonidis at louis@supertruth.ai or (215) 918-4140.

    Further reading:

  • DTI™ Engine
  • Health systems solution
  • What the Change Healthcare breach taught us about health data infrastructure trust
  • CVS Health and Aetna data integration: what vertical integration means for data trust
  • UnitedHealth Group AI denial rate controversy: what data trust had to do with it
  • The consent layering problem: when downstream data use exceeds original consent
  • Jason Alan Snyder

    Jason Alan Snyder

    Co-founder of SuperTruth and Artists & Robots, and an inventor on the Data Trust Index patents. Twenty-plus years building technology inside Interpublic Group. He writes here nearly every day on data trust, provenance, and what AI should be allowed to act on, and publishes essays on his Substack.

    About SuperTruth · LinkedIn · Substack · jasonalansnyder.com

    See it in practice

    EHR data scored before any AI model sees it.

    DTI integrates with Epic, Cerner, and all major EHR systems.

    See our health systems solution
    Share