By: Naveena Davay Arunkumar, Lead Data Analyst, IT Asset Management
For a long time, our organization believed it had a reasonably good handle on its IT assets. The dashboards said so. The audits didn’t flag anything alarming enough to change anyone’s mind. And yet, when we actually measured how much of our environment we could truly see, the number was closer to 70 percent. That means roughly three out of every ten assets in a healthcare payer environment, systems that could be touching member data, weren’t reliably showing up anywhere central at all.
Over the next 18 months, we brought that number to 95 percent. This is the story of what that gap actually was, why it had gone unnoticed for so long, and what it took to close it.
A Number That Sounds Fine Until You Sit With It
Seventy percent discovery coverage doesn’t sound like a crisis. In a lot of industries, it might not be. But in health insurance, an undiscovered asset isn’t just an inventory gap. It’s a system that might be storing, processing, or transmitting protected health information without anyone in security or compliance knowing it exists. It’s a server nobody’s patching. It’s a database quietly holding member records that never made it into a risk assessment because nobody knew to assess it.
What made this hard to see at first was that nothing was actively failing. The systems we did know about were reasonably well managed. The problem lived entirely in what wasn’t showing up: assets spun up outside normal provisioning, old systems that survived a merger or reorg without anyone updating the records, cloud resources created by a team that had never been looped into the central asset process. None of it looked like an emergency. All of it was risk sitting quietly in the dark.
Why the Gap Existed in the First Place
Part of it was tooling. We were running asset discovery and configuration management across multiple systems: Flexera for license and hardware visibility, ServiceNow as the system of record, and neither was set up to reconcile against the other automatically. Each tool had its own version of the truth, and the two didn’t always agree. When they disagreed, the honest answer was usually that nobody had gone back to figure out which one was right, so the gap just persisted.
Part of it was organizational. Asset management had grown up as a compliance function, something you did to pass an audit, rather than a living, continuously updated picture of the environment. That mindset works fine until the environment starts changing faster than the audit cycle does, which in most healthcare organizations now it does.
What Actually Closed the Gap
The first real shift was treating reconciliation as an ongoing discipline instead of a periodic cleanup project. We built a process where Flexera and ServiceNow data got compared regularly, not just before an audit, and discrepancies got flagged and resolved as part of normal operations instead of piling up until someone had to do a massive manual sweep.
The second was bringing Snowflake and dbt into the picture as the layer where all of this data actually got modeled and validated consistently. Instead of asset data living in silos that occasionally got compared by hand, we built a single, queryable source of truth that made it obvious when something didn’t add up, and made it possible to trust the number we were reporting instead of just hoping it was close.
The third, and probably the most important, was going after the assets that don’t announce themselves: things provisioned outside normal channels, systems left behind after a reorganization, cloud resources nobody remembered to register. That’s not a tooling problem so much as a persistence problem. Someone has to keep asking where the gaps are likely to be, because the gaps don’t show up on their own.
Why This Matters Beyond the Number
It’s tempting to talk about this as a data quality win, and it is one. But in a health insurance environment, closing a discovery gap is also a patient data protection story. Every asset that moves from unknown to known is one more system that can actually be assessed for risk, patched on schedule, and included in incident response planning instead of being a blind spot someone discovers the hard way.
Audit risk drops for the same reason. It’s much harder to defend an environment when a meaningful share of it isn’t even inventoried. Getting from 70 to 95 percent didn’t just make our reporting more accurate. It meant fewer places where a real problem could sit undetected for months.
What I’d Tell Other Data and Governance Leaders
If your organization is confident in its asset visibility, ask how that confidence was earned. A dashboard showing high coverage is only as good as the reconciliation behind it. If two systems can disagree with each other and nobody’s actively resolving that disagreement, the real number is probably lower than what’s being reported.
The uncomfortable systems, the ones nobody remembers provisioning, the ones that survived a merger without anyone updating the records, are usually where the actual risk lives. They’re also the hardest to find, which is exactly why they’re worth the effort. In healthcare especially, what you can’t see is the thing most likely to eventually become a problem you can’t ignore.
About the Author
Naveena Davay Arunkumar is a Lead Data Analyst in IT Asset Management at CareFirst BlueCross BlueShield, where she leads data governance and reconciliation strategy across the organization’s asset discovery and CMDB infrastructure. Her work spans Flexera, ServiceNow, Snowflake, and dbt, and focuses on the intersection of IT asset visibility, shadow IT risk, and PII/PHI protection in health insurance operations.
Disclaimer: This article reflects the author’s professional views and is for informational purposes only. It does not represent the official position of any organization and contains no confidential or protected information.











