Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Channel
Podcasts Hosted by Bill Russell, Sarah Richardson, and Drex DeFord
In-depth interviews with healthcare CIOs, CISOs, and technology leaders. Bill Russell explores the decisions, strategies, and innovations shaping healthcare transformation.
Jun 11, 2026·The 229 Podcast
June 11, 2026: Michelle Stansbury , Associate Chief Innovation Officer and Vice President of IT Applications at Houston Methodist , joins Bill Russell to unpack the health system's bold "Intelligent Healthcare System of the Future" initiative. 10 strategic bets built around the opening of their most advanced facility yet, Cypress Hospital. From RTLS-enabled smart spaces and AI-powered care traffic control to virtual nursing programs that transformed skeptical nurses into advocates, Houston Metho
Jun 10, 2026·2 Minute Drill
That UAC prompt -- the little shield asking you to approve a publisher -- is one of the most foundational trust signals in Windows security. Your tools rely on it. Your team relies on it. Two people figured out how to sell it. What they built, and which ransomware gangs bought access, has a direct line to at least one recent health system breach. Drex breaks it down. Remember, Stay a Little Paranoid
Jun 9, 2026·2 Minute Drill
CISA -- the federal agency whose job it is to protect America's critical infrastructure -- had its own internal credentials sitting in a public GitHub repository for six months. Plain text passwords. AWS GovCloud keys. SSH access tokens. Visible to anyone on the internet with a browser.What makes this worse: the contractor who created the repository didn't slip up accidentally. They actively disabled the default GitHub protections designed to prevent exactly this from happening. And when the rep
Jun 1, 2026·2 Minute Drill
In late 2025, cyber attackers slipped into New York City Health + Hospitals through a third-party vendor and stayed undetected for nearly three months. When they left, they took more than records and Social Security numbers. They took fingerprints and palm prints -- biometric data belonging to some of the most vulnerable patients in the country. You can cancel a credit card. You can get a new password. You can even navigate a stolen SSN. You cannot get new fingerprints. What walked out of that n
May 26, 2026·UnHack the Podcast
May 26, 2026: Krista Arndt , Associate CISO at St. Luke's University Health Network , and Anahi Santiago , CISO at ChristianaCare , join Drex DeFord for an unfiltered conversation about what it actually takes to lead healthcare security in 2026. From saving nearly 200 hours a month with Microsoft Security Copilot to building a team culture so strong that people rarely leave, Krista and Anahi pull back the curtain on AI adoption, mental health advocacy, and the intentional choices that separate t
May 21, 2026·2 Minute Drill
Ransomware attacks don't always start with a ransomware gang. They start with someone who gets paid to find the door. Aleksey Volkov, known online as ChewbaccaCore, was an initial access broker. His job was identifying vulnerable companies, exploiting their networks, establishing a foothold, and selling that access on dark web marketplaces. Over 16 months in 2021-2022, his work enabled attacks on seven confirmed US businesses, resulting in $9M in confirmed losses and $24M in intended ransom dema
May 15, 2026·2 Minute Drill
Tyler Buchanan grew up in Dundee, Scotland and became one of the most consequential cybercriminals in the English-speaking world. His method was almost insultingly simple: text messages. Posing as IT help desks, he sent phishing texts to employees at companies like Twilio, LastPass, Mailchimp, and DoorDash. Directing them to convincing fake login pages that captured credentials and 2FA codes in real time. Find out how he got caught in this 2 Minute Drill Remember, Stay a Little Paranoid
May 8, 2026·2 Minute Drill
North Korean threat actors didn't breach a firewall. They built a fake company. UNC1069 spent two weeks constructing a convincing Slack workspace, fake team members, and LinkedIn profiles to earn the trust of Jason Seaman -- lead maintainer of Axios, a JavaScript library downloaded over 100 million times a week. One Teams call. One file. Within hours, malicious code was live and reaching health systems everywhere. The attack skipped the $50M security stack entirely and went straight to the human
May 2, 2026·UnHack the Podcast
From crippling outages to AI-powered deepfakes, 2025 tested healthcare cybersecurity like never before. This year-end recap explores the moments that mattered most: how teams built resilience during system failures, why users became partners instead of "weak links," how identity became the new perimeter, and what it means when you can't trust your own eyes. Through powerful stories from the front lines, we revisit the lessons learned and the community that kept us standing. Because at the end of
Apr 30, 2026·2 Minute Drill
Matthew Lane was 14 when he started probing the edges of online gaming systems. By 20, he had walked out of PowerSchool with data on nearly 70 million students and teachers using nothing but a contractor's stolen credentials he found on the dark web. Drex tells the full story and then lands the part that matters most for healthcare: Lane didn't exploit a sophisticated vulnerability. He used a username and password attached to someone who had legitimate access and simply walked through the front
Apr 28, 2026·UnHack the Podcast
April 28, 2026: When a hospital goes dark, the first 72 hours are everything. Laurie Campbell , Senior Manager of Clinical Ancillary Applications and Enterprise Imaging, and Rick McIntosh, VP and the Chief Technology Officer, at Children’s Hospital Colorado , break down the phased Code Dark response framework her team developed for ransomware attacks. They walk through real examples: how the supply chain keeps inventory moving without its systems, and how the radiology team built a sneakernet pr
Apr 24, 2026·2 Minute Drill
While the industry debates frontier AI models and nation-state threats, hospitals are still getting hit by ransomware through the same doors they've always left open. Drex zooms out to what's actually happening on the ground: massive patch cycles creating downstream operational pressure, countries reconsidering their software dependencies, and CISOs quietly doubling down on fundamentals. MFA, identity management, tested backups, network segmentation. The HICP documents are free, the roadmap alre
Page 2 of 98