Healthcare Summit
In-Person Summit July 18, 2023
ISMG Summits feature carefully curated agendas delivering a Keynote Address from an Industry Luminary, Case-Based Learning, Networking and more. The Summits are geo-targeted, industry-specific, and topic-driven events designed for security leaders.
ISMG's agendas provide actionable education and exclusive networking opportunities with your peers and our subject matter expert speakers.
Peter Halprin
Partner
Pasich LLP
Halprin is a partner in Pasich LLP’s New York office. He represents commercial policyholders with a focus on recovery strategies in relation to cyber breaches and cybercrime, COVID-19 and natural disasters, professional services, regulatory investigations and technology disputes.
Nitin Natarajan
Deputy Director
CISA
Dee Young
CISO
University of North Carolina Health
Suzanne Schwartz
Director for Strategic Partnerships & Technology Innovation at the Center for Devices and Radiological Health
FDA
Suzanne B. Schwartz, MD, MBA is the Director of the Office of Strategic Partnerships and Technology Innovation (OST) at FDA’s Center for Devices & Radiological Health (CDRH). Suzanne’s work in medical device cybersecurity includes raising awareness, educating, outreach, partnering and...
Greg Garcia
Executive Director
Health Sector Coordinating Council
Greg Garcia is executive director of cybersecurity at the Health Sector Coordinating Council, a private-sector critical infrastructure advisory council to the U.S. Department of Health and Human Services. Prior to joining HSCC, Garcia was the nation's first Department of Homeland...
David Holtzman
Principle
HITPrivacy LLC
Privacy attorney David Holtzman, founder and principal of consulting firm HITprivacy LLC, previously served on the health information privacy team at the Department of Health and Human Services, Office for Civil Rights and as a consultant at security and privacy...
John Frushour
Vice President and Chief Information Security Officer
New York-Presbyterian Hospital
Seasoned IT leader with demonstrable experience leading highly performing teams in 24x7x365 environments. Expert abilities in enterprise architecture, telecommunications, information security, and metrics-based decision-making. Proven track record in leveraging IT Service Management to align IT services with the needs of...
Anahi Santiago
Chief Information Security Officer
ChristianaCare
Santiago is CISO at ChristianaCare, the largest healthcare provider in the state of Delaware. Prior to ChristianaCare, she spent over 10 years as the information security and privacy officer at Einstein Healthcare Network. She is an active contributor and member...
Kim Sassaman
CISO
Universal Health Services
Phillip Eglert
VP Medical Devices Security
Health ISAC Inc
View Agenda
A View from the Field - A Reality Check on the State of Security in Healthcare

Healthcare providers are under pressure like never before. With the recent news bombarding us with breaches and bad stories, how do we understand what’s really happening out in the wild? In this conversation, we will speak about what we are seeing and experiencing in the real world. We will talk about recent findings from analysts, cloud providers and plain old firsthand account knowledge. We will understand what the bad guys are doing in the wild and discuss how to prevent yourself from becoming another statistic - or worse, a news story.

  • 09:00 AM
  • 09:29 AM
A Call to Action for Healthcare

An analysis of the state of healthcare sector cybersecurity - including where progress is being made, but why the urgency to address the industry's top security weaknesses is growing more serious.

This session will cover:

  • How and why the pandemic has set back healthcare sector cybersecurity efforts
  • Lessons from devastating ransomware attacks on the healthcare sector
  • What healthcare sector players can and should do better - sooner rather than later.
  • 09:30 AM
  • 09:59 AM
Collaborative Cybersecurity Solutions: CISA's Vital Role in Safeguarding Healthcare Infrastructure
Nitin Natarajan, Deputy Director, CISA

Join Nitin Natarajan, Deputy Director of the Department of Homeland Security's Cybersecurity Infrastructure and Security Agency (CISA), as he presents an insightful exploration of the healthcare sector's cybersecurity challenges. Through this interactive fireside chat, attendees will have the opportunity to delve deeper in how, to  building effective partnerships to enhance cyber threat information sharing, Leveraging CISA's expertise to bolster incident response and recovery capabilities and discuss CISA's role in supporting the healthcare sector, 


Key Discussion Points:

  • CISA's Collaborative Approach: Overview of CISA's initiatives and resources available to healthcare organizations
  • Strengthening Cyber Resilience: Empowering Entities to Combat Modern Cyber Challenges
  • Enhancing cybersecurity education and awareness across healthcare entities
  • Future-proofing Cyber Planning: Developing a comprehensive understanding of the evolving cyber threat landscape
  • Addressing regulatory and compliance requirements while strengthening cybersecurity posture


Attendees will leave this session equipped with actionable insights and practical strategies to fortify their cybersecurity defenses, effectively leverage CISA's support, and adapt their cyber planning to address the ever-changing healthcare landscape. Don't miss this opportunity to gain a comprehensive understanding of the healthcare cyber threat landscape and discover innovative approaches to protect patient data and critical infrastructure.

Nitin Natarajan
  • 10:30 AM
  • 11:29 AM
Networking and Exhibition Break
  • 11:00 AM
  • 11:29 AM
Solutions Showcase

Solutions Showcase: Gain insight into leading security trends and technology from cutting-edge solution providers. Walk away with practical solutions to apply in your place of work

  • 11:30 AM
  • 12:29 PM
Lunch and Exhibition Break
  • 12:30 PM
  • 01:14 PM
Solution Room Workshop

The Solution Room is a highly engaging and interactive conference session that aims to provide cybersecurity leaders with peer-to-peer support and subject matter expertise to tackle their most pressing challenges.

To enhance your learning experience, we invite you to join one of the ten tables for this collaborative session co-moderated by a CyberEdBoard Member and esteemed Secruity Leader.

To kick off the session, Tom Field, Senior Vice President of Editorial at ISMG, will set the stage with a fictitious security scenario. Each group will receive identical sets of questions and work collaboratively to find the answers. As the exercise progresses, new information will be revealed, adding unexpected twists and turns to the scenario. Through this dynamic approach, participants will be challenged to apply critical thinking skills and work as a cohesive team to effectively respond to the evolving situation. Our goal is to provide a stimulating and engaging learning experience that equips you with the skills and knowledge needed to handle real-world security scenarios.

  • 01:15 PM
  • 02:29 PM
Networking and Exhibition Break
  • 02:30 PM
  • 02:44 PM
Enhancements to the HICP Guide: Safeguarding Healthcare Cybersecurity
David Holtzman, Principle, HITPrivacy LLC

Join renowned privacy attorney David Holtzman, along with a member of the HHS 405(d) Task Group, as they shed light on the crucial updates incorporated into the Health Industry Cybersecurity Practices (HICP) guide. The HICP 2023 Edition has undergone comprehensive revisions by esteemed professionals from the industry and government sectors. It now encompasses the top 10 cybersecurity practices that are highly pertinent and cost-effective in mitigating the prevailing cybersecurity threats faced by the healthcare industry.


During this informative session, we will delve into the following crucial areas of focus:

  • Unveiling the New Topics and Changes: Discover the pivotal updates introduced in the HICP guide and understand why they hold immense importance for healthcare CISOs and their teams.
  • Navigating the Latest Cybersecurity Challenges: Discover practical strategies for implementing these practices to safeguard your organization's sensitive data.
  • Achieving Regulatory Compliance and Avoiding Penalties: Gain a deeper understanding of how adherence to these practices can provide a safe-harbor, protecting your organization from regulatory fines and penalties in the event of a cybersecurity incident compromising health information. 


We are grateful for the generous support of this presentation, made possible by a grant from the Cyber Trust Alliance. 

David Holtzman
  • 02:45 PM
  • 03:14 PM
Cyber Insurance: The Latest Hurdles to Jump Through

A look at the latest demands cyber insurers are making on healthcare sector entities in order to renew policies or obtain new coverage.

This session will examine:

  • What is driving operational investment decisions
  • The growing influence of insurers on the security programs of healthcare providers
  • If cyber policy payouts are guaranteed in the wake of major incidents
  • The fine print in what cyber insurers expect from their healthcare clients
  • 03:15 PM
  • 04:14 PM
Essential Updates to the HICP Guide: Navigating Healthcare Cybersecurity Challenges
Phillip Eglert, VP Medical Devices Security, Health ISAC Inc
Suzanne Schwartz, Director for Strategic Partnerships & Technology Innovation at the Center for Devices and Radiological Health, FDA

Delve into the forefront of medical device security,  featuring Dr. Suzanne Schwartz, Director of the Office of Strategic Partnerships and Technology Innovation at the FDA's Center for Devices and Radiological Health, as she provides a comprehensive update on the latest regulatory developments in medical device cybersecurity. The briefing will be followed by a panel discussion with esteemed expert,  Phil Englert, Vice President of Medical Devices Security at the Health Information Sharing and Analysis Center. Together, they will explore the implications of the FDA's enhanced authority and explore emerging  threats and challenges facing the medical device industry.


Key Discussion Points:

  • Vetting Cybersecurity in Pre-Market Submissions:. Attendees will gain insights into the FDA's "refuse to accept" policy, set to take effect on October 1, and its impact on ensuring early consideration and mitigation of cybersecurity risks during the development phase.
  • Implications for Device Makers and Healthcare Entities: Understand the necessary adjustments required to meet the enhanced cybersecurity requirements and ensure patient safety.
  • Emerging Cyber Threats and Challenges: Insights and strategies to address these evolving risks, empowering attendees to proactively protect patient privacy and the integrity of medical devices.


Join us for this thought-provoking session, which aims to equip stakeholders with the knowledge and tools necessary to navigate the evolving landscape of medical device cybersecurity and safeguard the future of healthcare.

Phillip  Eglert
Suzanne Schwartz
  • 04:15 PM
  • 04:29 PM
Closing Comments
  • 04:30 PM
  • 04:44 PM

ISMG Summits feature carefully curated agendas delivering a Keynote Address from an Industry Luminary, Case-Based Learning, Networking and more. The Summits are geo-targeted, industry-specific, and topic-driven events designed for security leaders.
ISMG's agendas provide actionable education and exclusive networking opportunities with your peers and our subject matter expert speakers.

Peter Halprin
Partner
Pasich LLP
Halprin is a partner in Pasich LLP’s New York office. He represents commercial policyholders with a focus on recovery strategies in relation to cyber breaches and cybercrime, COVID-19 and natural disasters, professional services, regulatory investigations and technology disputes.
Nitin Natarajan
Deputy Director
CISA
Dee Young
CISO
University of North Carolina Health
Suzanne Schwartz
Director for Strategic Partnerships & Technology Innovation at the Center for Devices and Radiological Health
FDA
Suzanne B. Schwartz, MD, MBA is the Director of the Office of Strategic Partnerships and Technology Innovation (OST) at FDA’s Center for Devices & Radiological Health (CDRH). Suzanne’s work in medical device cybersecurity includes raising awareness, educating, outreach, partnering and...
Greg Garcia
Executive Director
Health Sector Coordinating Council
Greg Garcia is executive director of cybersecurity at the Health Sector Coordinating Council, a private-sector critical infrastructure advisory council to the U.S. Department of Health and Human Services. Prior to joining HSCC, Garcia was the nation's first Department of Homeland...
David Holtzman
Principle
HITPrivacy LLC
Privacy attorney David Holtzman, founder and principal of consulting firm HITprivacy LLC, previously served on the health information privacy team at the Department of Health and Human Services, Office for Civil Rights and as a consultant at security and privacy...
John Frushour
Vice President and Chief Information Security Officer
New York-Presbyterian Hospital
Seasoned IT leader with demonstrable experience leading highly performing teams in 24x7x365 environments. Expert abilities in enterprise architecture, telecommunications, information security, and metrics-based decision-making. Proven track record in leveraging IT Service Management to align IT services with the needs of...
Anahi Santiago
Chief Information Security Officer
ChristianaCare
Santiago is CISO at ChristianaCare, the largest healthcare provider in the state of Delaware. Prior to ChristianaCare, she spent over 10 years as the information security and privacy officer at Einstein Healthcare Network. She is an active contributor and member...
Kim Sassaman
CISO
Universal Health Services
Phillip Eglert
VP Medical Devices Security
Health ISAC Inc

View Agenda
A View from the Field - A Reality Check on the State of Security in Healthcare

Healthcare providers are under pressure like never before. With the recent news bombarding us with breaches and bad stories, how do we understand what’s really happening out in the wild? In this conversation, we will speak about what we are seeing and experiencing in the real world. We will talk about recent findings from analysts, cloud providers and plain old firsthand account knowledge. We will understand what the bad guys are doing in the wild and discuss how to prevent yourself from becoming another statistic - or worse, a news story.

  • 09:00 AM
  • 09:29 AM
A Call to Action for Healthcare

An analysis of the state of healthcare sector cybersecurity - including where progress is being made, but why the urgency to address the industry's top security weaknesses is growing more serious.

This session will cover:

  • How and why the pandemic has set back healthcare sector cybersecurity efforts
  • Lessons from devastating ransomware attacks on the healthcare sector
  • What healthcare sector players can and should do better - sooner rather than later.
  • 09:30 AM
  • 09:59 AM
Collaborative Cybersecurity Solutions: CISA's Vital Role in Safeguarding Healthcare Infrastructure
Nitin Natarajan, Deputy Director, CISA

Join Nitin Natarajan, Deputy Director of the Department of Homeland Security's Cybersecurity Infrastructure and Security Agency (CISA), as he presents an insightful exploration of the healthcare sector's cybersecurity challenges. Through this interactive fireside chat, attendees will have the opportunity to delve deeper in how, to  building effective partnerships to enhance cyber threat information sharing, Leveraging CISA's expertise to bolster incident response and recovery capabilities and discuss CISA's role in supporting the healthcare sector, 


Key Discussion Points:

  • CISA's Collaborative Approach: Overview of CISA's initiatives and resources available to healthcare organizations
  • Strengthening Cyber Resilience: Empowering Entities to Combat Modern Cyber Challenges
  • Enhancing cybersecurity education and awareness across healthcare entities
  • Future-proofing Cyber Planning: Developing a comprehensive understanding of the evolving cyber threat landscape
  • Addressing regulatory and compliance requirements while strengthening cybersecurity posture


Attendees will leave this session equipped with actionable insights and practical strategies to fortify their cybersecurity defenses, effectively leverage CISA's support, and adapt their cyber planning to address the ever-changing healthcare landscape. Don't miss this opportunity to gain a comprehensive understanding of the healthcare cyber threat landscape and discover innovative approaches to protect patient data and critical infrastructure.

Nitin Natarajan
  • 10:30 AM
  • 11:29 AM
Networking and Exhibition Break
  • 11:00 AM
  • 11:29 AM
Solutions Showcase

Solutions Showcase: Gain insight into leading security trends and technology from cutting-edge solution providers. Walk away with practical solutions to apply in your place of work

  • 11:30 AM
  • 12:29 PM
Lunch and Exhibition Break
  • 12:30 PM
  • 01:14 PM
Solution Room Workshop

The Solution Room is a highly engaging and interactive conference session that aims to provide cybersecurity leaders with peer-to-peer support and subject matter expertise to tackle their most pressing challenges.

To enhance your learning experience, we invite you to join one of the ten tables for this collaborative session co-moderated by a CyberEdBoard Member and esteemed Secruity Leader.

To kick off the session, Tom Field, Senior Vice President of Editorial at ISMG, will set the stage with a fictitious security scenario. Each group will receive identical sets of questions and work collaboratively to find the answers. As the exercise progresses, new information will be revealed, adding unexpected twists and turns to the scenario. Through this dynamic approach, participants will be challenged to apply critical thinking skills and work as a cohesive team to effectively respond to the evolving situation. Our goal is to provide a stimulating and engaging learning experience that equips you with the skills and knowledge needed to handle real-world security scenarios.

  • 01:15 PM
  • 02:29 PM
Networking and Exhibition Break
  • 02:30 PM
  • 02:44 PM
Enhancements to the HICP Guide: Safeguarding Healthcare Cybersecurity
David Holtzman, Principle, HITPrivacy LLC

Join renowned privacy attorney David Holtzman, along with a member of the HHS 405(d) Task Group, as they shed light on the crucial updates incorporated into the Health Industry Cybersecurity Practices (HICP) guide. The HICP 2023 Edition has undergone comprehensive revisions by esteemed professionals from the industry and government sectors. It now encompasses the top 10 cybersecurity practices that are highly pertinent and cost-effective in mitigating the prevailing cybersecurity threats faced by the healthcare industry.


During this informative session, we will delve into the following crucial areas of focus:

  • Unveiling the New Topics and Changes: Discover the pivotal updates introduced in the HICP guide and understand why they hold immense importance for healthcare CISOs and their teams.
  • Navigating the Latest Cybersecurity Challenges: Discover practical strategies for implementing these practices to safeguard your organization's sensitive data.
  • Achieving Regulatory Compliance and Avoiding Penalties: Gain a deeper understanding of how adherence to these practices can provide a safe-harbor, protecting your organization from regulatory fines and penalties in the event of a cybersecurity incident compromising health information. 


We are grateful for the generous support of this presentation, made possible by a grant from the Cyber Trust Alliance. 

David Holtzman
  • 02:45 PM
  • 03:14 PM
Cyber Insurance: The Latest Hurdles to Jump Through

A look at the latest demands cyber insurers are making on healthcare sector entities in order to renew policies or obtain new coverage.

This session will examine:

  • What is driving operational investment decisions
  • The growing influence of insurers on the security programs of healthcare providers
  • If cyber policy payouts are guaranteed in the wake of major incidents
  • The fine print in what cyber insurers expect from their healthcare clients
  • 03:15 PM
  • 04:14 PM
Essential Updates to the HICP Guide: Navigating Healthcare Cybersecurity Challenges
Phillip Eglert, VP Medical Devices Security, Health ISAC Inc
Suzanne Schwartz, Director for Strategic Partnerships & Technology Innovation at the Center for Devices and Radiological Health, FDA

Delve into the forefront of medical device security,  featuring Dr. Suzanne Schwartz, Director of the Office of Strategic Partnerships and Technology Innovation at the FDA's Center for Devices and Radiological Health, as she provides a comprehensive update on the latest regulatory developments in medical device cybersecurity. The briefing will be followed by a panel discussion with esteemed expert,  Phil Englert, Vice President of Medical Devices Security at the Health Information Sharing and Analysis Center. Together, they will explore the implications of the FDA's enhanced authority and explore emerging  threats and challenges facing the medical device industry.


Key Discussion Points:

  • Vetting Cybersecurity in Pre-Market Submissions:. Attendees will gain insights into the FDA's "refuse to accept" policy, set to take effect on October 1, and its impact on ensuring early consideration and mitigation of cybersecurity risks during the development phase.
  • Implications for Device Makers and Healthcare Entities: Understand the necessary adjustments required to meet the enhanced cybersecurity requirements and ensure patient safety.
  • Emerging Cyber Threats and Challenges: Insights and strategies to address these evolving risks, empowering attendees to proactively protect patient privacy and the integrity of medical devices.


Join us for this thought-provoking session, which aims to equip stakeholders with the knowledge and tools necessary to navigate the evolving landscape of medical device cybersecurity and safeguard the future of healthcare.

Phillip  Eglert
Suzanne Schwartz
  • 04:15 PM
  • 04:29 PM
Closing Comments
  • 04:30 PM
  • 04:44 PM

Speaker Interviews

July 18, 2023

Healthcare Summit