← Back to episodes

Episode 174 ·

Cybersecurity Risk Management in Healthcare & Compliance: A Discussion with Matthew Toussain, Founder of Open Security

Send us Fan Mail Attackers only win when you have no choice left. In this episode, Captain Integrity Bob Wade breaks down the importance of cybersecurity in healthcare & compliance with Matthew Toussain, Founder of Open Security. Hear how to focus on the basics, why you shouldn’t trust anyone, how to know your risk and the enemy, how to stay ahead of cybersecurity attacks, and Matthew’s background in the Air Force. Learn more at CaptainIntegrity.com

  • Cybersecurity

Listen to the episode

Audio

Ready to play. Audio loads only after you press Play.

0:000:00

Prefer Buzzsprout? Listen on Buzzsprout.

Companion article

Cybersecurity Risk Management in Healthcare Compliance: A Discussion with Matthew Toussain, Founder of Open Security

Episode Date: June 25, 2025

In this episode of Stark Integrity, Matthew Toussain, Founder of Open Security, joins Bob Wade (Captain Integrity) to explore a critical and rapidly evolving area of healthcare compliance:

Cybersecurity risk management—and why it has become a central issue for healthcare organizations.

The discussion highlights a key reality:

Cybersecurity is no longer just an IT concern—it is a core compliance responsibility.

The Growing Importance of Cybersecurity

Healthcare organizations rely heavily on:

  • Electronic health records (EHRs)
  • Connected systems and devices
  • Digital communication platforms
  • Third-party technology vendors

As Matthew Toussain explains, this reliance creates:

  • Greater efficiency
  • Improved access to information

But also:

Expanded exposure to cyber threats.

The takeaway:

The more connected healthcare becomes, the greater the risk surface.

Why Healthcare Is a Target

The episode emphasizes that healthcare organizations are prime targets because they possess:

  • Sensitive patient data
  • Financial and billing information
  • Critical operational systems

Cyber threats can include:

  • Ransomware
  • Data breaches
  • System disruption attacks

The key point:

Attackers are focused where the data—and disruption potential—are greatest.

A “Know Your Enemy” Approach

One of the most compelling insights from Matthew Toussain is the need to:

Understand both your risks and your adversaries.

Cybersecurity is not just about technology—it is about:

  • Knowing how attackers operate
  • Identifying vulnerabilities
  • Anticipating threats

The takeaway:

Effective cybersecurity requires a strategic—not just technical—mindset.

Back to the Basics

A recurring theme in the discussion is:

Focus on the fundamentals.

Matthew Toussain stresses that organizations often overlook basic protections in favor of more complex solutions.

Key fundamentals include:

  • Access controls
  • Employee awareness training
  • System updates and patching
  • Strong authentication practices

The key point:

Most breaches exploit basic weaknesses—not advanced systems.

“Trust No One” Mindset

Another critical concept discussed is:

Adopting a “trust no one” approach.

This reflects a modern cybersecurity framework where:

  • Every user and system must be verified
  • Internal threats are treated as seriously as external ones
  • Continuous validation replaces assumed trust

The takeaway:

Security must be built on verification—not assumption.

Cybersecurity as a Compliance Issue

The discussion reinforces that cybersecurity failures can lead to:

  • Regulatory violations
  • False Claims Act exposure
  • Financial penalties
  • Reputational harm

As a result:

Cybersecurity must be integrated into the compliance program—not handled separately.

Incident Preparedness

Matthew Toussain also emphasizes the importance of:

Being ready before an attack happens.

Organizations should:

  • Develop incident response plans
  • Run simulations and testing
  • Train staff on response protocols
  • Clearly define roles and responsibilities

Because:

In cybersecurity, response time and preparation are critical.

The Human Element

Cybersecurity is not just about systems—it is about people.

Risks often arise from:

  • Phishing attacks
  • Weak passwords
  • Lack of awareness

Organizations must:

  • Train employees regularly
  • Build a culture of vigilance
  • Reinforce best practices

The takeaway:

People are both a vulnerability and a defense.

Practical Compliance Considerations

Healthcare organizations should:

  • Conduct regular risk assessments
  • Strengthen basic security controls
  • Evaluate third-party risks
  • Integrate cybersecurity into compliance programs
  • Monitor threats continuously

Because:

Cybersecurity is an ongoing process—not a one-time effort.

Key Takeaways

  • Cybersecurity is a core healthcare compliance issue
  • Healthcare organizations are prime targets for cyber threats
  • Understanding threats and vulnerabilities is essential
  • Basic security controls are often the most important
  • A “trust no one” mindset strengthens defense
  • Incident preparedness is critical
  • Human behavior plays a major role in cybersecurity risk
  • Compliance programs must incorporate cybersecurity

Final Thoughts

This episode reinforces a fundamental shift in healthcare compliance:

Cybersecurity is no longer optional—it is essential.

With insights from Matthew Toussain, the message is clear:

  • Organizations must understand their risks
  • Strengthen foundational protections
  • Prepare for inevitable threats

Ultimately:

Cybersecurity is about maintaining control in an environment where threats are constant.

Because in healthcare:

If you cannot protect your systems and data—you cannot protect your organization.

Click here to listen to this Stark Integrity Podcast Episode:
https://podcasts.apple.com/us/podcast/cybersecurity-risk-management-in-healthcare-compliance/id1588939373?i=1000714440544&l=fr-FR