- Why digital enrollment infrastructure is under unprecedented pressure
- Why are attackers targeting the open enrollment window?
- Open enrollment readiness from edge to core: 6 pillars of protection Traffic and performance DDoS and app protection Bot visibility API security Microsegmentation and HIPAA Application security posture management
- Traffic and performance
- DDoS and app protection
- Bot visibility
- API security
- Microsegmentation and HIPAA
- Application security posture management
- How can payers prepare before open enrollment begins?
- Why does open enrollment readiness need to be year-round?
- Learn more
Key takeaways
Open enrollment compresses peak member traffic and heightened attacker activity into the same narrow window, putting added pressure on payer infrastructure and security teams.
Readiness requires protection from edge to core, including traffic management, distributed denial-of-service (DDoS) and bot defense, API security, microsegmentation, and application security posture management.
The work should begin well before enrollment opens so teams have time to assess, implement, test, and close gaps before traffic and attack volume increase.
Most retail purchases come with a return policy. If the sweater doesn't fit, you send it back. But health plan selections work differently. Once a member chooses a plan during open enrollment, they generally keep that plan for the year unless they qualify for a Special Enrollment Period or get coverage another way.
That permanence is exactly what makes the open enrollment experience so consequential, and exactly why the digital infrastructure behind it deserves more scrutiny than it usually gets. For a few intense weeks every autumn, a payer's website becomes one of its most important member touchpoints. It also becomes an especially attractive target for attackers.
Why digital enrollment infrastructure is under unprecedented pressure
The numbers tell the story. During the 2025 Marketplace open enrollment period, 24.3 million consumers selected or were automatically re-enrolled in health coverage, a 13% increase from the previous year. Digital enrollment is also increasingly central to workplace benefits: 60% of employers offered self-service online benefits enrollment in 2025, while 83% of employees said being able to manage benefits online was very or extremely important.
When all that enrollment activity is compressed into the same narrow window, payers must scale from a few hundred concurrent users to hundreds of thousands. As a result, a site that performs flawlessly in July can buckle under the load it sees when the enrollment window opens in November. And, as payers add AI-powered plan comparison and member support experiences, open enrollment can also put new pressure on the distributed cloud infrastructure and AI inference workloads behind them.
Why are attackers targeting the open enrollment window?
Attackers understand the calendar as well as payers do. At the beginning of Q4 2023, our researchers observed a spike in API attack traffic and an overall increase in activity during that period, a pattern that likely reflects attackers targeting open enrollment to disrupt operations when the cost of downtime is highest.
So while a DDoS attack in May is an inconvenience, the same attack during the enrollment window can stop members from selecting plans, disrupt claims operations, and inflict lasting brand damage at the worst possible moment.
That seasonal pressure sits within an already elevated healthcare threat environment. The Healthcare and Public Health sector reported 460 ransomware and 182 data breach complaints in 2025, the highest counts shown across the 16 critical infrastructure sectors.
Payers are particularly attractive targets because they hold both financial and clinical data. Healthcare records can fetch between US$250 and US$1,000 on the underground market, compared with an average of US$100 for credit cards. That value increases the incentive for credential stuffing, account takeover, and data theft during the exact period when login volume is at its peak.
The threat doesn’t stop at the perimeter, either. Once an attacker gets inside, whether through a phishing email, a compromised vendor credential, or an unpatched endpoint, flat internal networks let ransomware move laterally toward enrollment systems, claims databases, and protected health information stores.
At the same time, the payer attack surface is expanding outward. As payers implement additional APIs required under the 2024 CMS Interoperability and Prior Authorization Final Rule, they create more connections across member, provider, and partner systems. That makes continuous API visibility especially important, because shadow APIs can leave security teams with gaps they can’t protect.
Open enrollment readiness from edge to core: 6 pillars of protection
Protecting the enrollment experience requires defending two distinct fronts at once. Threats arriving from the internet need to be stopped at the perimeter, and those that have already breached the perimeter need to be contained before they reach member data.
Figure 1 shows that effective readiness covers both types of threats, and it can be organized around six pillars of protection, including:
- Traffic and performance
Traffic and performance
- DDoS and app protection
DDoS and app protection
- Bot visibility
Bot visibility
- API security
API security
- Microsegmentation and HIPAA
Microsegmentation and HIPAA
- Application security posture management
Application security posture management
Traffic and performance
Performance isn’t a cosmetic concern during open enrollment. Instead, it directly shapes whether a member completes the process or abandons it in frustration. And when hundreds of thousands of members arrive in the same compressed window, every trip back to a central origin server adds latency. Under peak load, those round trips are what cause timeouts and slowdowns.
Caching eligible static assets such as plan documents, benefit summaries, and provider directories at the edge, close to members, offloads origin infrastructure and absorbs the surge before it ever reaches core systems. As a result, enrollment pages stay fast and responsive even when traffic climbs to many times its normal volume.
That same distributed approach also matters as payers add generative AI assistants and interactive plan-matching tools to member experiences. Running latency-sensitive inference close to users with Akamai Cloud for AI can help keep those experiences responsive during enrollment surges while reducing reliance on centralized infrastructure.
DDoS and app protection
DDoS and application-layer attacks are designed to do one thing: overwhelm a target until legitimate users can no longer reach it. During open enrollment, that target is the payer’s member portal.
Malicious traffic should be identified and blocked at the edge, before it ever reaches payer infrastructure, so that attack volume is absorbed across a distributed network rather than concentrated against a single origin. This keeps enrollment portals available and responsive — even during active attacks timed to the enrollment window, when the cost of even a brief outage is at its highest.
Bot visibility
During open enrollment, automated bots test stolen credentials against member login pages at scale in an attempt to take over accounts, harvest protected health information, or simply overwhelm authentication systems. The challenge is that this malicious traffic often looks legitimate, arriving in volumes and patterns designed to blend in with the real surge of members logging in to compare and select plans. Distinguishing the two in real time and blocking the bots without adding friction for genuine members is foundational to a secure enrollment experience.
AI agents are adding another layer to that automated traffic, making it increasingly important for payers to understand which bots and agents are accessing their sites and how that traffic should be handled.
API security
APIs are the connective tissue of the modern payer environment, linking member portals, eligibility systems, claims platforms, and the growing web of third-party and interoperability partners. That same connectivity makes them a favored target because a single exposed or poorly governed API can offer direct access to member data.
Every API across that ecosystem should therefore be discovered, monitored for anomalous behavior, and protected at the edge. This includes the undocumented and shadow APIs that interoperability-driven sprawl tends to leave behind, often without security teams knowing they exist. Continuous discovery matters as much as protection here. An organization can’t secure what it hasn’t found, and the payer API estate changes faster than most inventories can keep up.
Microsegmentation and HIPAA
This is where the inside-out story begins, and where regulatory pressure is mounting. A proposed update to the Health Insurance Portability and Accountability Act (HIPAA) Security Rule would require healthcare organizations to use technical controls to segment key systems, making it harder for attackers to move freely across the network.
That’s exactly what microsegmentation is designed to do. It isolates enrollment systems, claims databases, and protected health information from the rest of the network, blocks the lateral movement that ransomware depends on, and generates the audit evidence that compliance reviewers will increasingly expect.
The proposed HIPAA update specifically cites risk reduction as part of its rationale for requiring segmentation controls. And while the new rule hasn’t yet been finalized, the federal government’s 2026 Unified Agenda lists it as a long-term action, with final action scheduled for July 2027. That gives organizations time to assess their current segmentation strategy and close gaps before a final rule arrives with a compliance clock attached.
Application security posture management
Payer enrollment platforms rarely live in a single application. They span member portals, eligibility APIs, provider directories, and third-party integrations, often across multiple environments and development teams. That makes it difficult for security teams to maintain a clear view of which applications are exposed, how they’re protected, and where gaps remain.
Application security posture management brings that information together so teams can identify vulnerabilities and protection gaps, prioritize the risks that matter most, and address them before open enrollment puts those systems under greater pressure.Akamai and Apiiro together deliver application security posture management that combines application and API visibility with runtime protection to help security teams understand their exposure and focus remediation where it’s needed most.
During enrollment, that visibility becomes especially important. A vulnerability or protection gap in one part of the enrollment experience can expose member data across the entire platform. Continuous, risk-prioritized visibility into the application portfolio closes that visibility gap before attackers find it.
How can payers prepare before open enrollment begins?
The common thread across all six areas is timing. Each of these controls takes time to assess, implement, and validate — and none of that work can wait until the enrollment window is already open. The most prepared payers treat the third quarter, from July through September, as readiness season. During that period, DDoS and web application firewall configurations get reviewed, API inventory and shadow API discovery happens, credential stuffing defenses are tuned, segmentation is assessed against the coming HIPAA requirements, and application risk gets baselined.
And by the time the enrollment window opens, typically on or close to November 1, the work should be done and tested (Figure 2). The enrollment window itself can then remain focused on execution and monitoring.
Why does open enrollment readiness need to be year-round?
Open enrollment concentrates a payer's highest member traffic, the highest level of attacker interest, and a tightening set of compliance obligations into the same few weeks. Treating that convergence as a year-round readiness discipline, rather than as a seasonal fire drill, can help payers navigate the period smoothly and avoid making headlines for the wrong reasons.
Members only get one decision window per year. The infrastructure behind that decision should be ready to support it, every time.
Learn more
Akamai partners with health insurance payers to secure and accelerate the digital experiences their members depend on, from the edge to the core. To learn more about open enrollment readiness, connect with your Akamai account team for a readiness assessment.
About the Author(s)
Sokchhan Oum
Sokchhan “Sok” Oum is a Senior Solutions Engineer at Akamai, where he works with health insurance payers to secure and accelerate the digital experiences that their members rely on. His work spans AI visibility and security, bot management, and application protection, with a particular focus on how AI is reshaping both attacker behavior and member acquisition in healthcare.
Bridget Campbell
Bridget Campbell is a Major Account Executive at Akamai, partnering with Blue Cross Blue Shield plans nationwide on the decisions that shape how their members experience healthcare digitally. She started her career as an industry strategist, and that foundation still drives how she works. Bridget is outcome-driven, relentlessly curious, and the kind of person who doesn't just track where the industry is heading, but helps her customers get there first.




