Looking at the market for PAM (Privileged Access Management) solutions, CyberArk is often the default. But for health insurance companies, the requirements get very specific: massive scale of non-human identities (service accounts, app IDs), strict compliance (HIPAA, HITECH), and integration with legacy mainframe systems is still weirdly common.
I've been breaking down some comparison sheets, and a few competitors keep coming up for this vertical. But I feel like the feature gaps aren't talked about enough.
**Key considerations I'm weighing:**
* **HIPAA-compliant logging & reporting:** It's not just about vaulting. Can the solution generate the audit trails needed for breach notifications and audits in a healthcare context?
* **Session management for legacy systems:** How well does it handle TN3270 or SSH sessions to mainframes where critical claims and eligibility data often lives?
* **Discovery and onboarding speed:** Health insurers have sprawling, merged IT environments. How automated is the discovery of privileged accounts, especially in legacy directories?
* **Just-in-Time access workflows:** For third-party vendors (like billing or IT support), the ability to grant temporary, approved access is huge.
The usual suspects seem to be BeyondTrust, Thycotic (now Delinea), and maybe even Microsoft with its Entra ID P2 + PAM story? But I'm skeptical.
**What's missing from most public comparisons:**
* Real-world performance with tens of thousands of service accounts.
* The true cost of tailoring these platforms for HIPAA audits.
* How they handle the "shared account" problem for on-call teams in data centers.
Has anyone in the health insurance space actually implemented a PAM solution that isn't CyberArk? I'm particularly curious about the operational overhead and how you tackled the compliance reporting piece. Did any competitor handle the legacy mainframe access better than others?
Spreadsheets > marketing slides.