Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Channel
Podcasts Hosted by Bill Russell, Sarah Richardson, and Drex DeFord
In-depth interviews with healthcare CIOs, CISOs, and technology leaders. Bill Russell explores the decisions, strategies, and innovations shaping healthcare transformation.
Jul 10, 2026·2 Minute Drill
A threat researcher at Sysdig was picking through the logs of a recent breach when something stopped him cold. The attacker moved too fast. No pauses, no fumbles, no fatigue. Over 600 payloads fired in sequence. When one failed, it read the error and adjusted. One time, from a failed login to a working fix in thirty-one seconds. No human does that. Buried in the attacker's code were comments -- the kind a chatbot writes when it's reasoning through a problem. No person was at the keyboard. An AI agent had run the entire heist: reconnaissance, credential theft, lateral movement, persistence, and finally locking up 1,300 configurations before leaving a ransom note. Sysdig calls it Jade Puffer, and they believe it's the first ransomware attack ever run end-to-end by an AI. The entry point was a vulnerable open-source AI tool sitting on the internet with cloud credentials right behind it. Health systems are bolting AI onto every workflow right now. Every one of those tools is a new door. The skill floor for running a full ransomware operation just dropped to the cost of an agent subscription. Drex has a few questions for your next leadership meeting. Remember, Stay a Little Paranoid X: This Week Health LinkedIn: This Week Health Donate: Alex's Lemonade Stand: Foundation for Childhood Cancer
Jul 10, 2026·Executive Interview
July 10, 2026: Bill Reid , Healthcare and Life Sciences Lead in the Office of the CISO at Google , has spent his career working with health system security leaders, and he keeps running into the same blind spot: healthcare is underestimating the browser as an attack surface. Drex DeFord sits down with Bill to explore why the shift from thick client infrastructure to a secure, browser-first endpoint model is no longer theoretical. It is what resilient health systems are building. From managing tr
Jul 3, 2026·Executive Interview
Why the Browser Is Your Health System's Biggest Security Gap | Google Fridays with Andrew Rollo July 3, 2026: Andrew Rollo , Sales Engineer at Google , has led browser deployments for organizations with 10,000-plus endpoints, with a dedicated focus on healthcare. Drex DeFord sits down with Andrew to unpack why the browser has become the most vulnerable and most overlooked tool in a health system's security stack. They cover how identity, update cadence, and extension governance define whether a
Jun 30, 2026·UnHack the Podcast
June 23, 2026: Jason Elrod , CISO at MultiCare , unpacks why traditional identity and access management doesn't map to AI agents, what happens when an employee leaves and their agents keep running with no one accountable, and why exploitability management is replacing vulnerability management as the right frame for security leadership. They also get into social engineering of AI models, the Harvard degree story, and what walk-up song Jason would pick for a 25,000-person keynote. Key Points: 09:0
Jun 17, 2026·2 Minute Drill
A dormant Instagram account tied to the Obama White House started posting pro-Iranian content. No hacked password. No malware. No phishing email. Just a polite conversation with Meta's AI support agent. Researchers are calling it out plainly: AI agents are built to be helpful, and that eagerness is exactly what attackers are starting to exploit. The attack surface isn't the password anymore -- it's the agent. Health systems are deploying AI right now for scheduling, intake, and benefit verificat
Jun 10, 2026·2 Minute Drill
That UAC prompt -- the little shield asking you to approve a publisher -- is one of the most foundational trust signals in Windows security. Your tools rely on it. Your team relies on it. Two people figured out how to sell it. What they built, and which ransomware gangs bought access, has a direct line to at least one recent health system breach. Drex breaks it down. Remember, Stay a Little Paranoid
Jun 10, 2026·Executive Interview
June 10, 2026: In healthcare where downtime means lives, identity security is no longer just about who logs in. Bill Russell sits down with Peter Barker , Chief Product Officer at Ping Identity , to unpack why the agentic AI era demands a fundamental rethinking of identity. From giving AI agents first-class credentials to shifting the security boundary from login to the point of action. If your health system is deploying AI and you have not addressed non-human identity, this conversation is wher
Jun 9, 2026·2 Minute Drill
CISA -- the federal agency whose job it is to protect America's critical infrastructure -- had its own internal credentials sitting in a public GitHub repository for six months. Plain text passwords. AWS GovCloud keys. SSH access tokens. Visible to anyone on the internet with a browser.What makes this worse: the contractor who created the repository didn't slip up accidentally. They actively disabled the default GitHub protections designed to prevent exactly this from happening. And when the rep
Jun 3, 2026·Executive Interview
June 3, 2026: Adnan Iqbal , co-founder and CEO of Luma Health , joins Bill Russell for a direct conversation about one of healthcare's most stubborn problems: patient access. With 14-day average waits for a PCP appointment, 18% no-show rates, and call centers buried in fax workflows, the problems haven't changed, but the tools finally have. Adnan shares how Luma built a platform from scratch to orchestrate access, intake, financial experience, and patient engagement in one unified system, why de
Jun 1, 2026·2 Minute Drill
In late 2025, cyber attackers slipped into New York City Health + Hospitals through a third-party vendor and stayed undetected for nearly three months. When they left, they took more than records and Social Security numbers. They took fingerprints and palm prints -- biometric data belonging to some of the most vulnerable patients in the country. You can cancel a credit card. You can get a new password. You can even navigate a stolen SSN. You cannot get new fingerprints. What walked out of that n
May 26, 2026·UnHack the Podcast
May 26, 2026: Krista Arndt , Associate CISO at St. Luke's University Health Network , and Anahi Santiago , CISO at ChristianaCare , join Drex DeFord for an unfiltered conversation about what it actually takes to lead healthcare security in 2026. From saving nearly 200 hours a month with Microsoft Security Copilot to building a team culture so strong that people rarely leave, Krista and Anahi pull back the curtain on AI adoption, mental health advocacy, and the intentional choices that separate t
May 21, 2026·Executive Interview
May 20, 2026: Mark Ferrari , VP of Advisory Services at Fortified Health Security , joins Drex DeFord on UnHack for a candid conversation about the threat landscape keeping healthcare security leaders up at night. From asset inventory gaps to the explosion of identity-based attacks, Mark brings a rare perspective shaped by military service, 30 years as an EMT, and deep healthcare IT experience. He pulls no punches on why healthcare keeps buying tools before defining the problem, and what it actu
Page 1 of 28