Eighteen months ago, if you asked our team how many laptops, servers, or licenses we actually had in production, you would have gotten three different answers depending on who you asked and which system they pulled from. Our CMDB said one thing. Flexera said another. Whatever ServiceNow tickets happened to be open that week said a third. Nobody was lying. The data was just wrong, and it had been wrong for so long that people had quietly stopped trusting it and built their own workarounds instead.
That is the part people miss about asset data problems in healthcare. It is not just an IT hygiene issue. Every unaccounted asset is a device or a data store nobody is actively securing, which in a health insurance environment means a live risk to member PII and PHI. When leadership asked me to fix our asset data accuracy, I did not think of it as a cleanup project. I thought of it as closing a door that had been left open for years.
Why a Full Platform Rebuild Was Never the Plan
The instinctive fix, and the one a few vendors pitched us, was to rip out our existing stack and start over with something newer and supposedly smarter. I pushed back on that early. We already had Flexera for discovery, ServiceNow for the CMDB and service management, and Snowflake sitting underneath everything as our data warehouse. The tools were not the problem. Nobody had ever forced them to agree with each other.
A rebuild would have meant a multi-year program, a huge budget ask, and at least two more years of bad data while the new platform got configured and adopted. In a regulated healthcare environment, that is two more years of audit exposure we could not justify. So instead of replacing the stack, we made the existing systems reconcile against each other, using dbt models to enforce the business rules that had only ever lived in people’s heads.
What Actually Moved the Numbers
Three things did most of the work.
First, we stopped treating discovery coverage and data accuracy as the same metric. Discovery coverage tells you whether you can see an asset at all. Accuracy tells you whether what you are seeing about it, owner, location, lifecycle status, is actually correct. We had been improving the first number for years and assuming it would drag the second one up with it. It does not. We built separate scorecards for each, which is the only reason we could tell, eighteen months in, that discovery coverage had moved from 70% to 95% and accuracy separately from 50% to 95%.
Second, we built reconciliation logic in dbt that flagged conflicts between Flexera, ServiceNow, and Snowflake automatically, instead of relying on quarterly manual audits that only ever caught a fraction of the drift. If Flexera saw a device that ServiceNow’s CMDB did not know about, or a CMDB record pointed to an owner who had left the company two years earlier, the pipeline surfaced it the same week, not the next audit cycle.
Third, we assigned an actual human owner to every asset category, not just a team name in a spreadsheet. Data governance work dies quietly when a discrepancy shows up and there is no single person whose job it is to resolve it. Once every category had a named owner and a service-level expectation for closing reconciliation gaps, the backlog of unresolved conflicts started shrinking instead of growing.
The Conversation We Had to Force With Leadership
None of this was free, and it was not fast. There was real pressure early on to declare victory once discovery coverage looked good, since that number is easier to show on a slide and easier for leadership to understand at a glance. I had to be direct about the difference between a system that can see everything and a system you can actually trust, and about which one an auditor or a security incident actually cares about.
The turning point was reframing the whole program around risk instead of hygiene. I stopped saying we needed cleaner asset data and started saying we needed to know exactly where PHI-adjacent infrastructure lived, because that is the framing that gets budget approved in a health insurance company. Once leadership saw the accuracy problem as a PHI exposure problem rather than a spreadsheet problem, the eighteen-month roadmap stopped needing to be defended every quarter.
How It Turned Out
Eighteen months later, asset data accuracy sits at 95%, up from 50%, and discovery coverage is at 95%, up from 70%. Just as important, the reconciliation logic we built did not stop running once we hit those numbers. It is still catching drift every week, which means the 95% is not a one-time snapshot we got lucky on, it is a number we can actually defend to an auditor on any given day.
The bigger win was cultural. Teams that used to keep their own shadow spreadsheets because they did not trust the CMDB have mostly stopped, because the CMDB now agrees with reality often enough to be worth trusting again. That is a harder thing to put on a dashboard than a percentage, but it is the part that actually sustains the improvement.
What I’d Tell Any Leader Starting This Work
Before you buy a new platform to fix bad asset data, ask whether your existing tools are actually the problem, or whether nobody has ever made them reconcile against each other. In our case, the second was true, and it saved us years and a large budget line we did not need to spend.
And measure discovery and accuracy separately. A number that only tells you what you can see will always look better than a number that tells you what you can trust, and in healthcare, it is the second one that protects patient data when it actually matters.
About the Author
Naveena Davay Arunkumar is a Lead Data Analyst in IT Asset Management at CareFirst BlueCross BlueShield, where she leads data governance and reconciliation strategy across the organization’s asset discovery and CMDB infrastructure. Her work across Flexera, ServiceNow, Snowflake, and dbt took enterprise asset data accuracy from 50% to 95% and discovery coverage from 70% to 95% over eighteen months, reducing audit risk and closing data quality gaps with direct implications for patient data protection in a healthcare payer environment. Connect with her on LinkedIn.



