Episode 174 ·
Cybersecurity Risk Management in Healthcare & Compliance: A Discussion with Matthew Toussain, Founder of Open Security
Send us Fan Mail Attackers only win when you have no choice left. In this episode, Captain Integrity Bob Wade breaks down the importance of cybersecurity in healthcare & compliance with Matthew Toussain, Founder of Open Security. Hear how to focus on the basics, why you shouldn’t trust anyone, how to know your risk and the enemy, how to stay ahead of cybersecurity attacks, and Matthew’s background in the Air Force. Learn more at CaptainIntegrity.com
- Cybersecurity
Listen to the episode
Companion article
Cybersecurity Risk Management in Healthcare Compliance: A Discussion with Matthew Toussain, Founder of Open Security
Episode Date: June 25, 2025
In this episode of Stark Integrity, Matthew Toussain, Founder of Open Security, joins Bob Wade (Captain Integrity) to explore a critical and rapidly evolving area of healthcare compliance:
Cybersecurity risk management—and why it has become a central issue for healthcare organizations.
The discussion highlights a key reality:
Cybersecurity is no longer just an IT concern—it is a core compliance responsibility.
The Growing Importance of Cybersecurity
Healthcare organizations rely heavily on:
- Electronic health records (EHRs)
- Connected systems and devices
- Digital communication platforms
- Third-party technology vendors
As Matthew Toussain explains, this reliance creates:
- Greater efficiency
- Improved access to information
But also:
Expanded exposure to cyber threats.
The takeaway:
The more connected healthcare becomes, the greater the risk surface.
Why Healthcare Is a Target
The episode emphasizes that healthcare organizations are prime targets because they possess:
- Sensitive patient data
- Financial and billing information
- Critical operational systems
Cyber threats can include:
- Ransomware
- Data breaches
- System disruption attacks
The key point:
Attackers are focused where the data—and disruption potential—are greatest.
A “Know Your Enemy” Approach
One of the most compelling insights from Matthew Toussain is the need to:
Understand both your risks and your adversaries.
Cybersecurity is not just about technology—it is about:
- Knowing how attackers operate
- Identifying vulnerabilities
- Anticipating threats
The takeaway:
Effective cybersecurity requires a strategic—not just technical—mindset.
Back to the Basics
A recurring theme in the discussion is:
Focus on the fundamentals.
Matthew Toussain stresses that organizations often overlook basic protections in favor of more complex solutions.
Key fundamentals include:
- Access controls
- Employee awareness training
- System updates and patching
- Strong authentication practices
The key point:
Most breaches exploit basic weaknesses—not advanced systems.
“Trust No One” Mindset
Another critical concept discussed is:
Adopting a “trust no one” approach.
This reflects a modern cybersecurity framework where:
- Every user and system must be verified
- Internal threats are treated as seriously as external ones
- Continuous validation replaces assumed trust
The takeaway:
Security must be built on verification—not assumption.
Cybersecurity as a Compliance Issue
The discussion reinforces that cybersecurity failures can lead to:
- Regulatory violations
- False Claims Act exposure
- Financial penalties
- Reputational harm
As a result:
Cybersecurity must be integrated into the compliance program—not handled separately.
Incident Preparedness
Matthew Toussain also emphasizes the importance of:
Being ready before an attack happens.
Organizations should:
- Develop incident response plans
- Run simulations and testing
- Train staff on response protocols
- Clearly define roles and responsibilities
Because:
In cybersecurity, response time and preparation are critical.
The Human Element
Cybersecurity is not just about systems—it is about people.
Risks often arise from:
- Phishing attacks
- Weak passwords
- Lack of awareness
Organizations must:
- Train employees regularly
- Build a culture of vigilance
- Reinforce best practices
The takeaway:
People are both a vulnerability and a defense.
Practical Compliance Considerations
Healthcare organizations should:
- Conduct regular risk assessments
- Strengthen basic security controls
- Evaluate third-party risks
- Integrate cybersecurity into compliance programs
- Monitor threats continuously
Because:
Cybersecurity is an ongoing process—not a one-time effort.
Key Takeaways
- Cybersecurity is a core healthcare compliance issue
- Healthcare organizations are prime targets for cyber threats
- Understanding threats and vulnerabilities is essential
- Basic security controls are often the most important
- A “trust no one” mindset strengthens defense
- Incident preparedness is critical
- Human behavior plays a major role in cybersecurity risk
- Compliance programs must incorporate cybersecurity
Final Thoughts
This episode reinforces a fundamental shift in healthcare compliance:
Cybersecurity is no longer optional—it is essential.
With insights from Matthew Toussain, the message is clear:
- Organizations must understand their risks
- Strengthen foundational protections
- Prepare for inevitable threats
Ultimately:
Cybersecurity is about maintaining control in an environment where threats are constant.
Because in healthcare:
If you cannot protect your systems and data—you cannot protect your organization.
Click here to listen to this Stark Integrity Podcast Episode:
https://podcasts.apple.com/us/podcast/cybersecurity-risk-management-in-healthcare-compliance/id1588939373?i=1000714440544&l=fr-FR
