Image: img.helpnetsecurity.com · rights & removal
Three questions a hospital CISO should ask a healthcare fintech vendor
Reporting by Help Net SecurityRead the original at helpnetsecurity.com
Executive Summary
Facts Only
* Security work is scheduled into every sprint, prioritizing issues involving patient data or funds disbursement.
* The author holds both CTO and CISO titles.
* Core security initiatives are tracked and reviewed with leadership for visibility and accountability.
* Cylerity does not act as a bank and does not factor receivables.
* Collateral for lending against healthcare claims may contain Protected Health Information (PHI).
* The approach to handling PHI exposure involves working with minimum required data, removing claim-level details, and building unique identifiers rather than exposing claim identifiers.
* An AI model must recommend but never act regarding money or patient data; a person remains in the loop.
* MFA for email is presented as the cheapest fix to close common security gaps.
* Three key questions for a fintech vendor are: listing all data-touching parties, verifying fund changes, and detailing the first 24 hours of breach response.
Full Take
From the original · Help Net Security
In this Help Net Security video, Drew McCombs, CTO and CISO at Cylerity, explains how he balances both roles. Security work is scheduled into every sprint, and issues touching patient data or funds disbursement come first.Read the full story at helpnetsecurity.com
Sentinel — Human
The text reads like an expert synthesizing complex regulatory and security requirements into practical, prioritized guidance for hospital leadership, strongly indicating human authorship based on professional experience.
