55 hospital and health system CISOs and chief privacy officers to know | 2026

Advertisement

In healthcare, a data breach represents a threat to patient safety, institutional trust and the integrity of care. The leaders charged with defending against cyberattacks have become among the most critical figures in any hospital or health system. 

The CISOs and CPOs recognized on this list are building the cybersecurity frameworks that stand between their organizations and an ever-evolving landscape of digital threats. They are tasked with implementing cutting-edge technologies, recruiting the specialized talent required to deploy them, and ensuring that sensitive patient data remains protected.

Note: Becker’s Healthcare developed this list based on nominations and editorial research. This list is not exhaustive, nor is it an endorsement of included leaders, organizations or associated healthcare providers. Leaders cannot pay for inclusion on this list. Leaders are presented in alphabetical order. 

Contact Anna Falvey at afalvey@beckershealthcare.com with questions or comments.


Lisa Adkins. Senior Vice President and Chief Compliance, Privacy and Audit Officer at University of Maryland Medical System (Baltimore). Ms. Adkins is senior vice president and chief compliance, privacy and audit officer at University of Maryland Medical System in Baltimore. Ms. Adkins leads the health system’s enterprise compliance, ethics and privacy programs, working across the academic health system to safeguard protected health information and support regulatory compliance. She partners with privacy, legal, information security, clinical and operational leaders to strengthen safeguards protecting patient confidentiality. Ms. Adkins oversees programs that identify, assess and mitigate risks tied to privacy, compliance, governance, investigations and emerging technologies. She has helped advance enterprise initiatives focused on conflict-of-interest oversight, audit readiness, governance transparency and the responsible use of AI-enabled productivity tools. In addition to her compliance role, Ms. Adkins serves as chief compliance and audit officer for the health system. Previously, she was chief compliance and privacy officer for Children’s National Hospital in Washington, D.C. and vice president and regional compliance and privacy officer for Kaiser Foundation Health Plan of the Mid-Atlantic States in Hyattsville, Md.

Mauricio Angée, DBA. CISO for University of Miami Health. Dr. Angée, the CISO for the University of Miami, is instrumental in protecting the academic medical institution’s sensitive data, including health information and research data. He has developed and implemented a comprehensive information security strategy to ensure compliance with regulations such as HIPAA, strengthen the university’s cybersecurity posture and manage security technologies. Dr. Angée leads incident response efforts and fosters a culture of security across the institution, including UHealth, safeguarding intellectual property and research data. With over 30 years of experience in various sectors, including healthcare and financial services, Dr. Angée is recognized for his technical expertise, strategic vision, and leadership in cybersecurity. 

Christopher W. Baker. CISO at UVA Health (Charlottesville, Va.). Mr. Baker is CISO at UVA Health, where he leads enterprise cybersecurity strategy, risk management, information security operations, regulatory compliance and cyber defense initiatives across the health system. He oversees cybersecurity governance frameworks, enterprise risk assessments, incident response and recovery efforts, and vulnerability and threat detection programs. Mr. Baker provides strategic oversight for cloud security architecture, data privacy protections and insider threat prevention, while leading multidisciplinary teams responsible for security monitoring, vulnerability remediation and penetration testing. Under his leadership, UVA Health teams have implemented advanced threat detection and monitoring capabilities, improved vulnerability management processes and strengthened cloud security architectures. He also leads board-level cybersecurity education and simulation exercises, and develops enterprisewide security policies and standards. Before joining UVA Health, Mr. Baker held cybersecurity leadership roles at Jefferson Health in Philadelphia, Takeda Pharmaceuticals and GlaxoSmithKline, and has served as an instructor with the SANS Institute.

Connie Barrera. Corporate Director and CISO of Jackson Health System (Miami). Ms. Barrera joined Jackson Health in February 2014 as director of information assurance and CISO and was promoted to corporate director and CISO in May 2017. Her responsibilities include developing policy and standards related to privacy as well as ensuring the integrity and availability of IT services. She has previous experience at the University of Miami, where she served in management and executive roles for seven years.

Miroslav Belote. CISO of Valley Health System (Ridgewood, N.J.). Mr. Belote became director and CISO of Valley Health System in March 2019 after spending 22 years of his career at JFK Health System in Edison, N.J., most recently serving as the director of information systems infrastructure. He has experience in infrastructure design, information security, telecommunications and data center operations. Mr. Belote has also built high-performing teams and been responsible for major IT initiatives. Prior to joining JFK, he spent 10 years with Dreyfus Service Corp.

Robert Carvajal. CISO at BayCare Health System (Clearwater, Fla.). Mr. Carvajal is CISO at BayCare Health System, where he leads the enterprise cybersecurity strategy for the 16-hospital academic health system. He oversees an information security program spanning IT risk management, business resiliency, incident response, threat intelligence and alignment with regulatory frameworks. Mr. Carvajal works closely with executive leadership to align cybersecurity strategy with the system’s broader priorities, supporting digital health initiatives while maintaining a secure infrastructure. With more than 20 years of IT experience, including nearly two decades focused on cybersecurity, he previously served as BayCare’s director of information services security and threat management. Mr. Carvajal advances proactive threat mitigation through policy development, enterprisewide security awareness and the implementation of advanced technologies. He also mentors the next generation of cybersecurity professionals while serving as a strategic advisor to leaders across the organization.

James Case. Vice President and CISO at Baptist Health (Jacksonville, Fla.). Mr. Case is vice president and CISO at Baptist Health, leading the day-to-day operations of the six-hospital system’s information security function. This encompasses incident response, workforce education, vulnerability management, risk assessments, intrusion prevention and forensic investigations. He has spent more than 30 years in IT services, nearly 15 of them at Baptist Health, where he began as a senior project manager before rising to the C-suite in December 2021. Mr. Case has operational oversight for nearly two dozen information services functions, including Epic security, cybersecurity awareness, threat hunting, vulnerability management and incident response. He works closely with IT governance to align cybersecurity safeguards with business strategy, and establishes metrics and key performance indicators to drive accountability across his teams. In December 2022, Mr. Case was elected to the board of directors of the Association for Executives in Healthcare Information Security, later serving a three-year term as board chair. He also sits on the Healthcare and Public Health Sector Coordinating Council’s executive committee and the board of the Jacksonville/Northeast Florida chapter of the Information Systems Security Association.

Gary S. Chan. System Vice President and CISO at SSM Health (St. Louis, Mo.). Mr. Chan is system vice president and CISO at SSM Health, overseeing the health system’s enterprise information security program and guiding strategy, governance, risk, compliance, architecture, engineering and security operations across the multi-state organization. He partners with executive leadership and SSM Health’s board of directors to align cybersecurity priorities with organizational goals, patient care and regulatory requirements. Mr. Chan is known for translating complex security issues into clear, actionable guidance for executives, caregivers and the broader community. He has built and led comprehensive enterprise security programs that strengthen governance and resilience in highly regulated environments. Mr. Chan also serves in advisory roles with the FBI Citizens Academy Alumni Association and the Washington University cybersecurity education advisory board, and previously worked in information security leadership at World Wide Technology and Accenture.

Monte Coulter. Vice President and CISO at OU Health (Oklahoma City). Mr. Coulter leads a high-performing cybersecurity team that has significantly improved Oklahoma’s flagship academic health system’s cyber resilience. In 2025, the team launched a robust cybersecurity training program and implemented software to automate identity and access management, significantly improving account provisioning across the organization. Under his leadership, OU Health has leveraged automation and frameworks from the National Institute of Standards and Technology to streamline operations, reduce costs and enable focus on proactive security measures. He emphasizes the potential of AI and machine learning in enhancing threat detection and response alongside trends such as zero trust architectures and privacy-by-design principles to strengthen healthcare security. With more than 25 years in IT and 17 years in information security, Mr. Coulter previously established an information security program at Caris Life Sciences and led a multinational security initiative at GAF Materials. He serves on Microsoft EDU Security’s CISO advisory panel, and contributed to advisory boards at Rutgers University and Forcepoint.

Wayman Cummings. Vice President and CISO at Ochsner Health (New Orleans). Mr. Cummings aligns cybersecurity strategy with enterprise goals to safeguard patient data and ensure uninterrupted care delivery across the Ochsner Health system. He integrates security intelligence, incident response and vulnerability management to protect the environment while enabling clinical operations. Under his leadership, Ochsner Health strengthened protections that support its standing as Louisiana’s top-ranked health system and a Healthcare Information and Management Systems Society “Davies Award” recipient. Mr. Cummings serves on the boards of advisors for cybersecurity companies SlashNext and ISTARI Global and is president of the board for Capital of Texas InfraGard. He previously served as deputy CISO at food distribution company Sysco and CISO at technology solution company Unisys. 

Erik Decker. Vice President and CISO at Intermountain Health (Salt Lake City). Mr. Decker is vice president and CISO at Intermountain Health, a multistate integrated delivery network. With about 25 years in IT and nearly two decades focused on security, he has built information security and identity-management programs at major academic medical centers, including service as chief security and privacy officer at the University of Chicago Medicine. His work bridges daily enterprise security operations with national health-sector policy, and he is widely regarded as a trusted voice on protecting patient data and critical clinical infrastructure. In addition to his leadership at Intermountain Health, Mr. Decker chairs the Healthcare Sector Coordinating Council’s joint cybersecurity working group, a public-private partnership representing hundreds of organizations and more than a thousand members. He also co-leads the federal 405(d) task group, which develops cybersecurity practices for the health sector under the Cybersecurity Act of 2015.

Lou Dignam. Vice President of Cybersecurity at Virtua Health (Marlton, N.J.). Mr. Dignam is vice president of cybersecurity at Virtua Health, a five-hospital, nonprofit academic health system. He oversees the security strategy, policies and operations for the health system’s more than 400 care locations and leads a team of cybersecurity experts and analysts. He is responsible for developing and implementing Virtua’s information security and resilience strategy, establishing security policies and standards, and managing governance, risk and compliance functions. Mr. Dignam has more than 40 years of IT experience, including the last 23 focused on cybersecurity, and has led Virtua’s security program since joining the organization in 2008. He played a key role in Virtua earning a level 10 “Most Wired” designation from the College of Healthcare Information Management Executives for the third consecutive year in 2025. Mr. Dignam has reduced costs and increased security team efficiency through security tool consolidation, helping the organization identify more potential threats in less time. He also serves as a planner for Cyberstorm V, a national cybersecurity exercise, and sits on multiple local and national security advisory committees.

Brian Elrod. Vice President and CISO at St. Jude Children’s Research Hospital (Memphis, Tenn.). Mr. Elrod has led St. Jude’s information security program since 2013, providing executive oversight for all information security strategy, architecture, policy and operations. He is accountable for the security of more than 39,000 devices and 12,000 users across a network supporting a 38-building campus that serves clinical care, research and administrative operations. Mr. Elrod organized the information security office into five programs spanning IT risk management and compliance, cybersecurity, awareness and outreach, identity and access management, and disaster recovery. He established and chairs an information security council of senior leaders and created the organization’s cybersecurity incident response team. He serves as chairman of the board for the Greater Memphis IT Council and is a member of the CrowdStrike customer advisory board. Mr. Elrod received the “CISO of the Year” award at the 2025 Tennessee ORBIE Awards.

Jesse Fasolo. Assistant Vice President of IT and CISO at St. Joseph’s Health (Paterson, N.J.). Mr. Fasolo is assistant vice president of IT and CISO at St. Joseph’s Health, providing strategic leadership for technology operations and cybersecurity across the health system/ He works to ensure reliable, secure and innovative IT services that support patient care. He oversees IT infrastructure, enterprise systems and telecommunications while guiding digital transformation and leading the organization’s information security program. Mr. Fasolo manages cyber risk, regulatory compliance, and incident response and business continuity capabilities for the system. He has led initiatives to modernize IT infrastructure and implement cybersecurity programs that reduced organizational risk and ensured compliance with HIPAA and other regulatory requirements. Mr. Fasolo has built and mentored IT and cybersecurity teams and championed organizationwide security awareness initiatives. He was named a New York City ORBIE CISO finalist and included among NJBIZ‘s list of chief privacy officers to know.

Melissa Bateman Fitzgerald. Chief Privacy Officer at Mass General Brigham (Boston). Ms. Fitzgerald is a seasoned privacy attorney with more than two decades of experience advising global organizations on data governance, digital strategy and privacy law. At Mass General Brigham, she oversees enterprisewide data privacy operations spanning academic medical centers, community hospitals, ambulatory practices and the system’s health plan. She leads efforts to embed privacy by design across digital initiatives and is driving systemwide frameworks for AI governance, ethical data use and lifecycle management. Prior to joining Mass General Brigham, Ms. Fitzgerald held senior leadership roles including privacy officer and AI center of excellence co-founder at Olympus, head of privacy operations at Dell Technologies, and general counsel at Gryphon Networks. 

Chase Franzen. CISO and Vice President of IT Risk Management at Sharp HealthCare (San Diego). Mr. Franzen is vice president of IT risk management and CISO at Sharp HealthCare. He leads enterprise cybersecurity, identity and access management, and risk governance across the integrated health system. Under his leadership, the system fully migrated to the Okta identity platform, transitioning all remote access and strengthening identity verification enterprisewide. Mr. Franzen created the “Cybersecurity Ambassador Program,” which had grown to more than 700 ambassadors as of June 2026, and helped more than 625 registered nurses and licensed vocational nurses voluntarily complete a cybersecurity education program for continuing education credit. The program earned a Sharp HealthCare “C.O.R.E Award” in 2024 and 2025 and the “San Diego Cyber Center of Excellence Innovation Award” in 2026, and was presented at Health-Information Sharing and Analysis Center in Tampa, Fla. Mr. Franzen also serves as vice president and board member of the San Diego Cyber Center of Excellence. He previously worked in investment banking capital markets technology and corporate information security at Wells Fargo.

Greg Garneau. System Vice President and CISO of Hospital Sisters Health System (Springfield, Ill.). Mr. Garneau is a seasoned information security leader who is currently CISO of Hospital Sisters Health System. He brings over 25 years of IT and information security experience to the role, which he assumed in January 2024. Prior, he served as CISO of Marshfield (Wis.) Clinic Health System for over seven years. There, he managed security for the $3 billion integrated system, which is one of the largest rural health systems in the nation. 

Gordon Groschl. System Vice President and CISO at City of Hope (Duarte, Calif.). Mr. Groschl is system vice president and CISO at City of Hope, where he leads the organization’s enterprise cybersecurity strategy across clinical care, research and corporate operations. He’s been tasked with protecting sensitive patient information and critical research data since joining the organization in January 2026. He oversees risk management, security operations, threat and vulnerability management, identity and access governance, data protection and incident response, and has advanced the adoption of “zero trust” security principles. With more than two decades of cybersecurity experience, Mr. Groschl previously served as CISO and director of healthcare technology management at Houston-based Texas Children’s Hospital, where he directed a $65 million enterprisewide cybersecurity and infrastructure transformation. At Texas Children’s, he reduced ransomware risk by 80%, cut zero-day remediation time from 60 days to 24 hours and remediated more than 900 control deficiencies, all while cutting disaster recovery times by 75% and identity and access management provisioning times by 80%. Mr. Groschl has earned recognition including “Top Global CISO” for 2025, CISO Connect “A100” honors in 2025 and 2026, and more. He also serves as a board member for Gartner C-Level Communities’ Houston CISO group and SecureWorld Houston.

Karen Habercoss. Vice President and Chief Information Security and Privacy Officer at UChicago Medicine. Ms. Habercoss is vice president and chief information security and privacy officer at UChicago Medicine. Ms. Habercoss has enterprise responsibility for cybersecurity and privacy across the University of Chicago Medical Center, Ingalls Memorial Hospital in Harvey, Ill., UChicago Medicine Crown Point (Ind.) and the health system’s biological sciences research division. Her portfolio includes security operations and engineering, identity and access management, security architecture, privacy operations, disaster recovery and cybersecurity resilience. Under her leadership, incident report capture increased more than 300% in three years, the audit program expanded more than 200% and training reach grew more than 500%, gains achieved through five audit and monitoring tools using predictive data analytics. Ms. Habercoss chairs the executive cyber risk committee and the privacy and security steering committee, and co-chairs the AI steering committee. She holds nine professional certifications and co-authored the Health Sector Coordinating Council’s February 2024 publication on coordinated privacy and security partnerships. Ms. Habercoss received the “A100 Award” from CISOs Connect, naming her one of the top 100 accelerated CISOs nationally in 2025.

Kevin Hamel. CISO and Vice President of IT Operations and Technology Platforms at Hartford (Conn.) HealthCare. Mr. Hamel is vice president of IT operations and technology platforms and CISO at Hartford HealthCare. He is tasked with the oversight of foundational technology platforms, including cloud technologies and cyber and information security across a health system spanning 500 locations, eight acute-care hospitals and more than 47,000 colleagues. He leads the system’s strategy and execution to move its technologies and platforms into the cloud through the system’s data and digital platform, a centralized layer that enforces access controls and end-to-end data encryption. Mr. Hamel brings more than 30 years of experience in IT infrastructure, cybersecurity strategy and organizational risk management. In addition to his executive role, he directs university-level cybersecurity competitions, including Quinnipiac University’s “Cybercase” simulations that prepare students for corporate ransomware attacks. Mr. Hamel also serves on the cybersecurity advisory board at Bay Path University and speaks publicly on safely scaling AI deployment in hospital networks. Under his leadership, the system has been a multiyear recipient of “Most Wired” awards from the College of Healthcare Information Management Executives and received the American Hospital Association’s “Quest for Quality” award in 2025.

Denise Hathaway. Vice President and Chief Compliance Officer at TMC Health (Tucson, Ariz.). Ms. Hathaway leads TMC Health’s enterprise compliance program, ensuring consistent interpretation and application of federal and state regulations. She strengthens HIPAA privacy practices, appropriate billing and patient-rights protections while cultivating a culture of trust, accountability and open reporting. Ms. Hathaway designed and enhanced a systemwide compliance framework that spans hospital and ambulatory settings and supports eligibility for federal funding. She helped transition clinical research studies into the TMC Health Cancer Center to streamline care and expand access across Southern Arizona. Ms. Hathaway staffs the board of trustees’ audit, compliance and privacy committee, aligning oversight with operational priorities. She has rapidly risen from administrative assistant to chief compliance officer in a decade.

Andy Heins. Senior Vice President, Deputy CIO and CISO for Lifepoint Health (Brentwood, Tenn.). Mr. Heins serves as senior vice president, CIO and CISO for Lifepoint Health, overseeing a broad range of responsibilities including cybersecurity, information protection, identity management, cloud security, IT risk management and enterprise customer support. He took on his current role in May 2026 after serving as the system’s vice president and chief security and privacy officer for nearly three years. Known for his visionary approach, he has successfully integrated cybersecurity with digital transformation initiatives, ensuring that innovation is matched with robust security measures. His prior experience includes roles in information security compliance at Franklin, Tenn.-based Community Health Systems and roles in information security and internal audit at Nashville, Tenn.-based HCA Healthcare.

Dan Henke. Vice President of Information Security at Mercy (St. Louis). Mr. Henke has over 20 years of experience in information security. He joined Mercy Hospital and Healthcare in 2013 as the vice president and information security officer responsible for disaster recovery and business continuity of clinical systems. He also is the system’s chief HIPAA security compliance officer and has a reputation for building strong technical teams. Mr. Henke is also a permanent deacon for the Archdiocese of St. Louis and assists the pastor at Holy Infant Church.

Bruce James. Vice President and CISO at Boston Children’s Hospital. Mr. James is Boston Children’s Hospital’s vice president and CISO. Mr. James is responsible for developing and executing the hospital’s enterprise cybersecurity strategy, overseeing protection of its clinical, research, administrative, cloud, infrastructure, identity and digital environments. He leads security operations, cyber risk management, incident response preparedness, identity and access management and security architecture. Mr. James has built a cybersecurity career spanning more than two decades, with leadership roles in identity and access management and security architecture before becoming CISO. He founded the Healthcare Hacking Community at SAINTCON and has organized the event for the past three years, creating a forum for healthcare cybersecurity professionals to collaborate. Mr. James has also volunteered with the Biohacking Village at DEF CON since 2019 and became its lead in 2024, a role that included representing the community at DEF CON Singapore. He guides the hospital’s long-term cybersecurity roadmap, advising executive leadership on evolving cyber threats while helping the organization adopt new technologies and digital capabilities.

Mark Johnson. Vice President and CISO at Hackensack Meridian Health (Edison, N.J.). Mr. Johnson serves as vice president and CISO for Hackensack Meridian Health. There, he leads the cybersecurity program for the largest healthcare provider in New Jersey, overseeing a team of more than 36 professionals across a system with roughly 60,000 users. He presents cybersecurity strategy and budget to the system’s board of trustees, and has developed and executed a three-year strategic plan to enhance cybersecurity resilience. Under his leadership, the system maintains more than 100 intrusion prevention systems and more than 75 firewalls, with his team patching and scanning the entire environment monthly. Mr. Johnson began his career as a U.S. Navy flight officer, submarine hunter and security officer, and brings more than 33 years of information security experience to the role, including personally leading more than 500 cybersecurity incident responses. He is consistently recognized by Cyber Defense magazine among the top global CISOs. Mr. Johnson previously served as CISO or chief security officer for organizations in healthcare, financial services, travel and leisure, and technology.

Benjamin Koshy. CISO at Indian Health Service (Rockville, Md.). Mr. Koshy is CISO for Indian Health Service, an enterprise serving 2.5 million American Indian and Alaska Native people, overseeing risk management, compliance, incident response and modernization. Within nine months, he stood up a 24/7/365 Cybersecurity Operations Center, unifying defenses across over 170 care sites with zero trust principles, machine-learning threat detection and real-time analytics. Mr. Koshy couples technical rigor with cultural stewardship, mentoring a diverse cyber workforce and embedding sovereignty-aware governance that respects tribal priorities. Thanks to his leadership, the impact of the organization’s cybersecurity operations center was recognized with Government Executive and Nextgov/FCW‘s “Fed100” award in 2025. He advises the U.S. Department of Health and Human Services CISO council and advances workforce development while hardening critical clinical infrastructure. His approach is informed by earlier federal and consulting roles in incident response, information system security officer work and enterprise risk.

Jack Kufahl. CISO for Michigan Medicine (Ann Arbor). Mr. Kufahl has over 20 years of experience in IT, primarily in leadership roles. As CISO officer for Michigan Medicine, Mr. Kufahl directs all information assurance activities across the enterprise, simultaneously working to build strong teams and support novel talent pipelines. He is also an incorporating officer and current board member of the Michigan Healthcare Cybersecurity Council, a public-private partnership that seeks to protect the critical healthcare infrastructure and institutions of Michigan by providing relevant knowledge and information security services. 

Hugo Lai. CISO at Temple Health (Philadelphia). Mr. Lai is Temple Health’s CISO, responsible for the oversight of the health system’s information security framework. He is tasked with safeguarding the confidentiality, integrity and availability of its IT systems and biomedical devices. He leads incident response and IT continuity efforts during high-pressure events and oversees the organization’s information security operations and identity access management strategies. Mr. Lai modernized Temple Health’s information security program, standardizing access controls across common platforms and automating account lifecycle management, which eliminated the need for external identity and access management contractors. He has partnered with human resources and managers across the system this year to better educate staff against phishing and other cyber threats. Mr. Lai has served as a panelist at various conferences in the healthcare space, including Boston HealthSec, GPSec Tysons, SecureWorld Philadelphia and the CS2AI Symposium on Healthcare Sector ICS/OT Cybersecurity in 2025. He also serves on the CISO advisory board for Rubrik and the client advisory board for Trustwave.

Tony Lakin. Vice President for Information Security and CISO at UT Southwestern Medical Center (Dallas). Mr. Lakin joined UT Southwestern Medical Center in March 2023 as vice president and CISO. He brings nearly three decades of management and leadership experience to his role, over a decade of which have been spent in information assurance and cyber operations management. Prior to assuming his current role, he served as CISO for Moffitt Cancer Center in Tampa, Fla. 

Nate Lesser. Vice President and CISO at Children’s National Hospital (Washington, D.C.). Mr. Lesser is vice president and CISO at Children’s National Hospital, where he leads the enterprise cybersecurity program protecting patient care, research and hospital operations at the pediatric academic medical center. Mr. Lesser is responsible for cybersecurity strategy, security operations, architecture and engineering, governance and risk management, identity and access management, incident response, third-party risk, and security awareness and training. He leads a multidisciplinary cybersecurity organization that partners closely with clinical, research, IT, legal, compliance and executive leaders to embed security into daily operations while enabling innovation. Mr. Lesser oversees enterprise cyber risk management, regulatory and audit readiness, business continuity planning and preparedness for major cyber events, regularly briefing senior leadership and the board on cyber risk and resilience. He led the development of “Code Dark,” a coordinated ransomware and major cyber disruption response model that empowers all hospital staff to act as cyber first responders during incidents, a framework that has since been shared broadly across U.S. hospitals. Through the “Cyber Champions” program, Mr. Lesser has built a network of frontline staff serving as local security advocates who translate cybersecurity expectations into everyday clinical and operational practice. Before joining Children’s National, he served as deputy director of the national cybersecurity center of excellence at the National Institute of Standards and Technology, leading national collaborations on cybersecurity challenges affecting healthcare and medical devices.

Derrick Lowe. Vice President and Chief Security Officer at Orlando (Fla.) Health. Mr. Lowe is vice president and chief security officer at Orlando Health in Orlando, Fla. Selected by the CEO to build and scale the function, Mr. Lowe oversees the protection of a health system spanning 49 hospitals and emergency rooms, 300 ambulatory sites and more than 45,700 team members. He leads a security portfolio integrating cybersecurity, physical security and resiliency, including more than 400 security officers and specialized cybersecurity and enterprise security operations teams. Mr. Lowe joined Orlando Health in 2019 in the newly created CISO role and was promoted to chief security officer in 2024, when he assumed additional responsibility for corporate security. He implemented a program based on the National Institute of Standards and Technology cybersecurity framework, and Orlando Health has achieved consistent year-over-year improvements in external audit and assessment scores under his leadership. Mr. Lowe led the development of enterprisewide “clinical operation playbooks” for every hospital and ambulatory site, and participates in the City of Orlando’s multi-agency mass casualty drills. A decorated U.S. Army veteran, he was recognized as a 2024 “Veteran of Influence” by the Orlando Business Journal.

Hassnain Malik. Vice President and CISO at Tufts Medicine (Burlington, Mass.). Mr. Malik, vice president and CISO at Tufts Medicine, reports to executive leadership and the audit and compliance committee of the board. His role involves modernizing cloud security and revamping enterprise cybersecurity to protect critical assets. He established an agile, rapid-response capability and democratized security through education and embedded governance. Mr. Malik manages enterprise infrastructure alongside an outsourced team of 250, aligning resilience and scalability with system strategy. With over 25 years of experience spanning security, engineering, analytics and digital platforms, he brings deep experience across healthcare, academia and consulting. He is widely recognized for technical acumen, mentorship, and advancing best practices as a fellow of both American College of Healthcare Executives and Healthcare Information and Management Systems Society. Previously, Mr. Malik held roles with Oakland, Calif.-based Kaiser Permanente, served as CISO at Mountain View, Calif.-based El Camino Health, directed security compliance at Seattle-based Accolade Health, and taught as adjunct faculty at Boston University.

Trevor Martin. Vice President and CISO at UW Health (Madison, Wis.). Mr. Martin is vice president and CISO at UW Health. Mr. Martin is responsible for protecting patient data, research information and operational systems across clinical, research and administrative environments. He leads risk management, identity management, cyber operations, cyber incident response and threat intelligence functions, and ensures the health system’s information systems align with frameworks like HIPAA. Mr. Martin has worked to reposition information security as a strategic partner rather than a barrier, building strong relationships with operational leaders so security supports patient care. He has led the adoption of the National Institute of Standards and Technology cybersecurity framework and the vulnerability management maturity model, along with enhanced cybersecurity measures across the system. Mr. Martin serves as an advisor and subject matter expert for senior leadership and board members on cybersecurity risk posture, business continuity and third-party risk management. He previously served as executive director and information security officer at Urbana, Ill.-based Carle Health and as global IT director at Wolfram Research.

Ron Mehring. Vice President of Technology and Security and CISO at Texas Health Resources (Arlington). Mr. Mehring leads enterprise cybersecurity and technology operations for Texas Health Resources, directing risk management, regulatory compliance and systemwide security programs. He secured board approval for multiyear IT modernization and data center consolidation, aligning with the system’s 10-year growth plan. Mr. Mehring implemented a business-aligned security roadmap and transformed operations into a data-driven, risk-centered model. He launched enterprisewide education that reached 29,000 employees with 99% training completion and improved awareness scores. His efforts also reduced significant enterprise risks, strengthened resilience and improved incident response readiness. A nationally recognized security leader, Mr. Mehring has been honored with a CSO50 Magazine award for advancing information security and risk programs.

Julian Mihai. Chief Technology Officer at Penn Medicine (Philadelphia). Mr. Mihai is chief technology officer at Penn Medicine in Philadelphia, where he oversees the digital ecosystems supporting clinical care, research and everyday operations across the health system. Mr. Mihai’s role touches nearly every aspect of Penn Medicine’s digital backbone, from end-user computers to critical infrastructure. He first joined Penn Medicine as CISO, developing the health system’s first comprehensive cybersecurity strategy and a multiyear roadmap reflecting the scale of the organization and the gravity of its mission. Before Penn Medicine, Mr. Mihai held senior and technical leadership roles in enterprise cybersecurity and technology at Cleveland Clinic, HCSC/Blue Cross Blue Shield of Illinois, Microsoft, Motorola and several technology startups. Mr. Mihai positions cybersecurity as a key enabler of Penn Medicine’s mission in addition to its traditional role in risk management, and he advises security technology companies and speaks at leading security and healthcare technology conferences on emerging cybersecurity topics. 

Matthew Modica. Vice President and CISO of BJC HealthCare (St. Louis). Mr. Modica is a servant leader with nearly three decades of experience in the information security and technology fields at multiple Fortune 1000 companies. For nearly a decade, Mr. Modica has served as CISO for BJC Health System, a $12 billion-plus healthcare provider that serves communities across Missouri, Illinois and Kansas. He is a certified information security manager and has served on multiple nonprofit and advisory boards. Additionally, Mr. Modica sits on the Autism Speaks executive leadership council, supporting research and services for those on the autism spectrum.

David O’Brien. Vice President of IT and CISO at Covenant Health (Knoxville, Tenn.). At Covenant Health, Mr. O’Brien is vice president of IT and CISO. He leads the organization’s overall technology strategy, operations and cybersecurity posture, overseeing infrastructure, applications, cloud strategy, service delivery and vendor management. In his role, he is accountable for establishing and maintaining a cybersecurity program covering risk management, regulatory compliance, incident response and threat mitigation. Mr. O’Brien positions IT as a strategic partner rather than a support function, aligning technology initiatives with enterprise goals and building relationships between IT and business units. He has led infrastructure and application teams, managed large cross-functional project portfolios, and implemented governance frameworks that enhance decision-making and accountability. Mr. O’Brien also emphasizes talent development, mentorship and succession planning within his teams. He serves on the boards of directors for OutThink, the Tennessee Healthcare Information and Management Systems Society chapter and the National Organization for Disorders of the Corpus Callosum. He previously held IT leadership roles in health insurance, consulting, automobiles and medical devices.

Elizabeth Ortmann-Vincenzo. Chief Privacy Officer and Counsel at Banner Health (Phoenix). Ms. Ortmann-Vincenzo joined Banner in 2024, bringing over 30 years of healthcare and privacy experience, including the last decade providing legal and compliance support to privacy, cybersecurity and data use. At Banner, she is creating a best-in-class privacy program with a multi-year roadmap to substantially expand the program beyond the core HIPAA mandate with an overall risk-based approach, including expanding privacy work to include AI, consumer privacy, tracking technology and third-party oversight. She is working to increase privacy’s reach through enhanced auditing, monitoring and communication. She has also redesigned and launched a privacy risk assessment process and implemented compliance with the HIPAA reproductive rule. Ms. Ortmann-Vincenzo supports and enables Banner Health’s digital transformation in social media and patient communications using a privacy-by-design approach, has introduced collecting and tracking privacy metrics and effectiveness, began third-party oversight by privacy, and is a founding member of Banner’s AI executive steering committee. She chaired the Missouri Bar health and hospital committee, taught privacy and information security law at Missouri University of Science and Technology, and remains active in the privacy community through speaking, education and mentoring. 

Rob Perry. Vice President and CISO at HonorHealth (Scottsdale, Ariz.). Mr. Perry serves as vice president and CISO for HonorHealth, where he leads the enterprise cybersecurity and information risk programs that support nine hospitals, more than 270 care locations, 17,000 team members and more than 4,000 medical staff members. He also oversees information security for Innovation Care Partners, HonorHealth’s accountable care organization, and reports to the senior vice president and chief legal and risk officer. Mr. Perry oversees security governance, risk management, regulatory compliance, identity and access management, security operations center functions, incident response and business resilience. He champions ongoing security awareness across the organization and works closely with IT, legal, privacy, compliance and clinical leaders to embed cybersecurity into everyday decision-making. Mr. Perry is a graduate of the FBI CISO Academy, an active member of InfraGard and a past president of the Healthcare Information and Management Systems Society Virginia Chapter. He previously served as CISO at Roanoke, Va.-based Carilion Clinic.

Michael Prakhye. CISO at Adventist HealthCare (Gaithersburg, Md.). With more than 20 years of progressive IT and cybersecurity leadership experience in healthcare and federal sectors, Mr. Prakhye is CISO at Adventist HealthCare. He is responsible for establishing and maintaining the $1.2 billion health system’s enterprise security vision, strategy and compliance, ensuring information assets, medical devices, data and networks are adequately protected. Mr. Prakhye leads the development and execution of a cybersecurity strategy tailored to Maryland’s all-payer hospital reimbursement model, in which hospitals operate under globally budgeted revenue structures rather than traditional fee-for-service billing. His work has focused on aligning cybersecurity strategy with business goals, building resilient cyber defense and incident response capabilities, and enabling business objectives through enterprise security controls. Mr. Prakhye is tasked with building enterprise resilience and enabling clinical innovation while aligning cybersecurity with patient safety and regulatory excellence. Under his leadership, Adventist HealthCare has earned a Leapfrog hospital safety grade “A” and recognition on Newsweek’s 2025 list of “Most Trustworthy Companies in America.”

Andy Price. Vice President, CIO and CISO at St. Claire HealthCare (Morehead, Ky.). Mr. Price directly oversees IT, cybersecurity, privacy, informatics, analytics, and clinical engineering for St. Claire HealthCare. His direction of IT strategy and innovation efforts has led to improved patient care and clinician satisfaction. He works with all departments to optimize systems. Mr. Price volunteers with the Health Sector Coordinating Council, and is a member of the 405d Task Group and several school technology boards and advisory groups. 

Steven Ramirez. Vice President, CISO and Chief Technology Officer at Renown Health (Reno, Nev.). Mr. Ramirez leads Renown Health’s enterprise cybersecurity program, overseeing identity and access management, cyber operations, governance-risk-compliance and third-party risk management. He is recognized for a modern, automation-forward security strategy that strengthens controls while enabling clinical operations. Mr. Ramirez is a leader in identity and access management, using orchestration to improve speed, accuracy and least-privilege enforcement. Under his guidance, the system’s program maturity has advanced in step with the organization’s growth and quality trajectory. He extends his influence through service on the University of Nevada, Reno advisory board, Fortified Health advisory board, Association for Executives in Healthcare Information Security board, and as Health Information Sharing and Analysis Center data protection chair. Previously, Mr. Ramirez served as CISO at Louisville, Ky.-based UofL Health.

Adam Rosen. CISO at Roswell Park Comprehensive Cancer Center (Buffalo, N.Y.). Since 2019, Mr. Rosen has served as the CISO of Roswell Park Comprehensive Cancer Center, a National Cancer Institute-designated comprehensive cancer center. Overseeing Roswell Park’s cybersecurity program, he has worked to bring broad awareness of cyber-risk issues to senior leaders and throughout the organization, providing deeper insight into risks, realities and opportunities. His work to engage stakeholders across the cancer center in effective cybersecurity strategy helps this high-performing organization to align and prioritize resources in accordance with strategic objectives. Mr. Rosen’s key accomplishments as CISO include expanding the security team to handle new challenges and overhauling cyber-risk management processes for greater effectiveness and efficiency. He applies nearly three decades of experience in IT and information security toward the care of more than 50,000 cancer patients each year.

Joshua Roth. CISO of Children’s Hospital of Orange (Calif.) County. Mr. Roth is responsible for overseeing the quality and security of business partner, employee and patient information at Children’s Hospital of Orange County. He brings nearly two decades of experience in cybersecurity to his role, many of which has been spent in the healthcare industry. He has expertise in ensuring that security strategies align with industry standards and regulatory requirements.

Anahi Santiago. CISO at ChristianaCare (Newark, Del.). Ms. Santiago brings over 20 years in the IT field to her role as CISO at ChristianaCare. She has deep experience in areas of cybersecurity, privacy, regulatory compliance, program management and infrastructure services. In her role, she is responsibile for the organization’s information security program and strategic direction. She leads a team of information security professionals in supporting the system’s strategic initiatives by partnering with the business and managing risks, implementing policies and controls, and generating overall awareness.

William Scandrett. Vice President of Information Security and CISO at Baylor Scott & White Health (Dallas). Mr. Scandrett directs Baylor Scott & White’s information security program. He stepped into the role in the spring of 2026 after serving as Minneapolis-based Allina Health’s vice president and CISO for a decade. Mr. Scandrett is known for translating complex risks into clear business terms and proactively addressing emerging threats. Recognized by national outlets and industry groups, he was named a finalist for the 2025 Minnesota ORBIE awards. 

Michael Shrader. Senior Director of Information Security for WellSpan Health (York, Pa.). Mr. Shrader leads WellSpan Health’s information security program, ensuring the protection of the health system’s information assets, technology and infrastructure. His responsibilities include identifying and managing IT and cybersecurity risks while aligning security measures with business objectives. Under Mr. Shrader’s leadership, the information security team has expanded, with a focus on professional development and improving WellSpan’s overall security posture. He chairs key committees, such as the information security steering committee and a ransomware-focused workgroup, to drive operational advancement and innovation. He first joined WellSpan in 2014 as a senior information services security analyst and has taken on roles of progressive responsibility since. 

Pavel Slavin. CISO for Endeavor Health (Evanston, Ill.). Mr. Slavin has served as CISO for Endeavor Health since 2023, where he advises system executives on cybersecurity risk management and oversees information security programs across the organization. He works closely with the CIO, C-suite peers, and senior technical teams to prepare for and mitigate evolving cyber threats while ensuring regulatory compliance and long-term risk management. Mr. Slavin brings more than 30 years of cybersecurity leadership experience, previously serving as CISO of Milwaukee-based Froedtert Health and holding key roles with Cleveland Clinic, Baxter International and more. He is nationally recognized for building adaptable, business-focused security programs, fostering collaboration between cybersecurity and business leaders, and creating high-performing teams. Mr. Slavin has led major enterprise transformations, developed regulatory expertise across multiple industries, and holds a patent for Trusted Operating Systems.

Monique St. John. CISO and Associate CIO at Children’s Hospital of Philadelphia. Ms. St. John brings strategic vision, operational discipline and patient-centered leadership in healthcare cybersecurity to her role at CHOP, a $5.2-billion-a-year pediatric health system and research institute with a workforce of more than 31,000. She has repositioned security as a core safety behavior and business enabler by partnering with executive, clinical and operational leaders to connect cyber judgement to enterprise safety and shared accountability. This is accomplished by embedding three strategic pillars into the program strategy: safeguarding assets, modernizing the program and enabling responsible innovation. Under Ms. St. John’s leadership, the cybersecurity program applies measurable discipline through tabletop events and phishing exercises that strengthen organizational readiness and resilience. From 2022 to 2026, susceptibility improved by 84% and resiliency improved by 169%, showing strength and improvement in CHOP’s safety culture and ability to protect patient care. Her leadership has positioned security as a business enabler, advancing practical, risk-based solutions that protect the enterprise while supporting innovation and operational growth.  The program has also demonstrated strong financial stewardship by balancing operational demands while leading response efforts that mitigated millions of dollars in potential financial impact. Beyond the system, Ms. St. John serves on local nonprofit boards and advisory committees, sharing knowledge and supporting organizations that strengthen the broader community.  

Stephen Stallard. Assistant Vice President of Compliance and Ethics and Chief Privacy Officer at Orlando (Fla.) Health. Mr. Stallard is assistant vice president of compliance and ethics, as well as chief privacy officer at Orlando Health. Mr. Stallard helps shape the vision and strategy of the health system’s compliance and ethics program, ensuring adherence to privacy and information security laws like the Health Insurance Portability and Accountability Act. He joined Orlando Health in 1994, working in patient access, registration and revenue management applications before moving to the compliance and ethics team as an IT auditor in 2005. With more than 30 years of healthcare business experience, Mr. Stallard has served in progressive leadership roles overseeing privacy, compliance and information security. Recently, he led the expansion of compliance and privacy programs to incorporate newly acquired facilities, including Baptist Health in Birmingham, Ala. and the new Orlando Health Lake Mary (Fla.) Hospital, all while adapting processes to meet state-specific requirements. Mr. Stallard is a member of Orlando Health’s AI governance committee, helping establish policies and controls that support the organization’s use of AI while safeguarding protected health information. He co-chairs Orlando Health’s privacy and information security governance committee and is a founding board member of the Florida Compliance and Privacy Consortium.

Glynn Stanton. Senior Vice President, CIO and CISO at Yale New Haven (Conn.) Health. Mr. Stanton is senior vice president, CIO and CISO at Yale New Haven Health. There, he is responsible for information security across the health system’s three states, seven hospital campuses and more than 240 outpatient locations, providing direction over cybersecurity, IT audit, patient privacy and disaster recovery. He serves as the health system’s HIPAA security officer and has held the CISO role for nine years, spending 12 years overall with Yale New Haven Health. Mr. Stanton was brought in to build the system’s office of information security, which has grown from three full-time employees to more than 40 through the consolidation of functions such as identity and access management and disaster recovery from within IT. He previously held leadership roles at British Telecom, IBM, AT&T and Unilever. Mr. Stanton chairs the Connecticut Hospital Association’s information security committee and sits on Connecticut Health Information Exchange committees, having led the statewide security review for the exchange. Most recently, he led the health system through a cyberattack, and the cybersecurity protocols his team had in place allowed for quick detection and mitigation that minimized impacts on patient care.

Stacy Stika. Vice President and CISO for INTEGRIS Health (Oklahoma City, Okla.). Ms. Stika serves as vice president and CISO at INTEGRIS Health, where she leads the system’s cybersecurity strategy with a mission rooted in protecting patients and caregivers. She began her career as a medical assistant, an experience that continues to shape her belief that security is most valuable when it enables safe, compassionate care. Ms. Stika transitioned into IT to work on Walnut Creek, Calif.-based John Muir Health’s Epic EHR implementation project, where she developed a reputation for aligning security and innovation. She has since led transformational initiatives in risk governance, identity management and enterprise security strategy, building resilient frameworks. She currently serves as the INTEGRIS health system CISO, where she is a recognized advocate for responsible innovation and is focused on the safe adoption of AI in healthcare.

Les Stoltenberg. Chief Cyber Security Officer at The University of Texas MD Anderson Cancer Center (Houston). Mr. Stoltenberg is chief cyber security officer at The University of Texas MD Anderson Cancer Center, where he drives efforts to fortify institutional resilience, ensuring the continuity of life-saving clinical care and the advancement of breakthrough research. Mr. Stoltenberg leads a team of security professionals focused on institutionwide efforts to heighten cyber-readiness awareness and implement best practices across an increasingly interconnected healthcare landscape. He and his team establish governance, risk management and compliance for all of MD Anderson’s technologies and devices, working closely with the facilities and business continuity teams on the institution’s disaster recovery planning. Applying high reliability organizational principles, Mr. Stoltenberg partnered with MD Anderson’s quality and patient safety teams to implement institutionwide preparedness efforts, elevating targeted cyber-readiness metrics by 50%. He and his team were awarded a grant from the Advanced Research Projects Agency for Health to strengthen the institution’s medical technology innovation program, collaborating with institutions including The University of Texas at San Antonio, The University of Texas at El Paso and the University of Illinois. Mr. Stoltenberg also launched MD Anderson’s institutional medical device committee, which convenes stakeholders across clinical engineering, radiation oncology and diagnostic imaging to identify risks and coordinate best practices. He previously spent 17 years with PwC’s advisory practice, focused on information security, IT audit and compliance.

Hussein Syed. CISO at RWJBarnabas Health (West Orange, N.J.). Mr. Syed is RWJBarnabas Health’s CISO, driving the cybersecurity strategy that secures the technology and data assets of New Jersey’s largest academic healthcare system. He leads a comprehensive information security management program built on the National Institute of Standards and Technology cybersecurity framework, working with the CIO to determine acceptable risk levels and cybersecurity investment strategies. Mr. Syed joined Barnabas Health in 2002 as a security architect and was promoted to CISO as the organization grew through mergers, including the 2016 merger that created RWJBarnabas Health and the 2018 partnership with Rutgers University. He has expanded the security department into divisions focused on risk, architecture, operations, vulnerability management, and identity and access management. Mr. Syed and his team played a pivotal role in the security and architecture of the system’s Epic EHR standardization, which was completed across all acute care facilities by late 2024 and helped the system earn 10 “gold stars” from Epic for four consecutive years. He previously served on the board of AEHIS, an organization founded by the College of Healthcare Information Management Executives dedicated to advancing cybersecurity leadership in healthcare IT, and recently became a certified high reliability organization facilitator. 

Kevin Torres. Vice President of IT and CISO for MemorialCare (Fountain Valley, Calif.). With 27 years of progressive leadership experience at MemorialCare, Mr. Torres leads one of the nation’s top cybersecurity programs. His leadership goals include building a more accountable and resilient cybersecurity framework that is well positioned to anticipate and respond to the most pressing issues facing digital organizations. Objectives also include increasing employee awareness of data protection and cybersecurity and creating a cyber awareness culture that empowers staff to mitigate risks. To do so, the program has increased interconnectivity, security, reliability and accessibility of departmental and system shared services, as well as advanced technology capabilities and resiliency of patient technology. A popular speaker on IT and cybersecurity, Mr. Torres is frequently quoted in industry publications and media outlets.

Beth Witte. Senior Vice President and Chief Compliance and Privacy Officer for Community Health Systems (Franklin, Tenn.). Ms. Witte leads the development, implementation, and oversight of compliance and privacy programs across all Community Health Systems affiliates. She joined the organization in 2009 as a director in revenue management and has since advanced through several leadership roles. Ms. Witte previously served as vice president of internal audit and oversaw the enterprise risk management program beginning in 2017. Earlier in her career, she was an audit manager at Deloitte & Touche, where she supervised audits of large, publicly traded companies and healthcare organizations. Her leadership ensures that CHS maintains a culture of accountability, transparency and compliance across its network.

Randy Yates. Vice President and CISO at Memorial Hermann Health System (Houston). Mr. Yates is responsible for the development and execution of Memorial Hermann’s security strategic plan for its employees, providers and business partner users. He oversees the system’s data security program, ensures implementation of technical solutions for data security, access management, security risk assessment, cyberattack response, business resiliency and executive governance of the security program. He coordinates internal and external audit inquiries, manages digital compliance efforts and manages information security policies. He helped transform Memorial’s information security team into a full-service InfoSec and cybersecurity program. In 2021, his team organized an exercise for a common ransomware attack. He also established an internship program in the Memorial cybersecurity department to bring interns into full-time roles on the team.

At Becker's 4th Annual CEO + CFO Roundtable, taking place November 2–5 in Chicago, more than 1,500 hospital and health system executives tackle decisions that determine whether organizations thrive or merely survive: protecting margins under cost pressure, choosing where to grow, renegotiating payer relationships, stabilizing the workforce and proving real ROI on technology. This is where leaders work through them together, face-to-face. Apply for complimentary registration now.

Advertisement

Next Up in Cybersecurity

Advertisement