Episode 334 ·

Ryan Patrick - Cybersecurity in Healthcare, and Leadership Lessons from the U.S. Army

Today we are talking to Ryan Patrick, the SVP of Security at Intraprise Health. And we discuss how being HITRUST certified can save you tons of time on risk assessments when working with other companies. How we can incentivize better cybersecurity practices in the healthcare industry, and leadership lessons learned from his time serving in the US Army. 

All of this, right here, right now on the Modern CTO Podcast!

To learn more about Intraprise Health, check them out here: https://intraprisehealth.com

To learn more about HITRUST, check them out here: https://hitrustalliance.net

About Patrick:

Intraprise Health’s Vice President of Security Products and Strategy, Ryan Patrick, MBA, CISSP, CCSFP, brings 17 years’ experience in security and information technology for both the public and private sectors.

Ryan brings an innovative perspective in protecting information and organizational resources. Prior to joining Intraprise Health, Ryan served as the Vice President of Client Services & Operations with Fortified Health Security where he developed and led a team that was named the 2018 North American Health IoT Company of the Year by Frost & Sullivan and a Top Provider of Medical Device & IoT Cybersecurity Solutions by Black Book. Ryan previously served as the Director of Security, Privacy and Compliance at Blueprint Healthcare IT.

Working within organizations like MetLife and Memorial Sloan-Kettering Cancer Center as a security analyst, Ryan has gained a wealth of experience conducting risk assessments against HIPAA, ISO 27001, NIST 800-53 and PCI-DSS. He has been Battalion Commander at United States Army Reserve since April 2017. His previous military assignments include serving as Global Enterprise Operations Center Team Chief for the US Special Operations, Chief Information Officer of 42d Infantry Division within the New York Army National Guard, as the Deputy Chief Information Officer, and Chief Information Officer of FEMA Region II Homeland Response Force.

About Intraprise Health:

Intraprise Health is a Certified HITRUST Assessor and award-winning eHealth technology firm. The company provides health information security products and services to assess, remediate, and monitor customers'​ cyber security risk, regulatory compliance programs, organizational resilience, and third-parties’ security posture. 

Intraprise Health’s deep healthcare experience in both security and privacy as well as consumer/patient engagement gives us the ability to provide unmatched solutions to the unique challenges present in the world of healthcare today.

Transcript

(Joel Beasley at 00:00:00) Hello, my friends. Today we are talking to Ryan, the SVP of Security at Enterprise Health. And we discuss how being HITRUST certified can save you tons of time on risk assessments when working with other companies, how we can incentivize better cybersecurity practices in the healthcare industry, and leadership lessons Ryan learned from his time serving in the U.S. Army. All of this right here, right now on the Modern CTO Podcast. Here we go.

(Ryan at 00:00:31) This is the Modern CTO Podcast.

(Joel Beasley at 00:00:32) Where exactly are you? Are you in Tampa?

(Ryan at 00:00:46) Yeah, just outside of Tampa in a town called Apollo Beach. So it's right between Brandon and Bradenton.

(Joel Beasley at 00:00:51) Okay, I'm in Bradenton.

(Ryan at 00:00:52) Okay.

(Joel Beasley at 00:00:53) Yep. Were you born around here or did you relocate?

(Ryan at 00:00:56) We relocated. So I'm a military background. Born and raised in New York, have lived in a lot of different places, but mostly in the Northeast and then throughout the South.

(Joel Beasley at 00:01:09) And so what brought you, like, what specific project brought you down to Tampa?

(Ryan at 00:01:14) So my parents retired down to Florida. And afterwards, my mom started to have some health concerns and health issues. So my wife and I moved the family down to help my parents out, getting to medical appointments, taking care of the dog when she had to stay overnight in different places. So we moved down to the West Palm Beach area. We've since obviously moved to Tampa, so that's what kind of brought us to Florida. Although we were ready to get out of New York because New York is pretty expensive. The weather's are pretty brutal, or the winters are pretty brutal. So we were ready to go.

(Joel Beasley at 00:01:50) So when you were traveling around as a kid while your dad was, you know, serving the country, is that when you started getting into technology, or was it much later in life?

(Ryan at 00:02:00) So for me, my father actually was a United States Marine, but that was before I was born. So most of my travels were actually when I entered the service. And it's actually kind of funny the way I got into technology and security because when I was in college, I was a business major. I'd bought my first computer in college. I was the guy who was asking my computer science friends how do I open Word and all that fun stuff. And when I got commissioned as an officer in the Army, I immediately was sent overseas to Iraq. So this is right around 2003. Well, about eight months into my deployment, I was a tank platoon leader. Like, I was the cool guy you see on the commercials, rolling down the streets of Iraq doing all that fun stuff. And the Army, in its infinite wisdom, one day looked at me and they said, hey, Ryan, tomorrow you're going to transfer you to this other unit. We're going to make you a signal officer, which is Army speak for IT. So they ship me about 200 or 300 miles north from where I was in Iraq, and they put me in charge of the entire northern Iraqi network, the entire thing. They were like, hey, Ryan, great. We're happy to have you here. You know, super excited. We need help. While we're sleeping, you're going to be in charge of all of it. And I had absolutely no training whatsoever. So I went from being the guy who was getting shot at every day on the streets to making decisions about this really complex network that, you know, was kind of in a box that was stood up with zero experience. So it really taught me a lot about relying on other people because I did have people working with me, and they were subject matter experts. But I had to give that trust to them because I was making decisions where if I made the wrong decision, I mean, it literally could have been life or death for soldiers and trigger pullers that were on the ground. If they can't talk, then they can't call in for help. They can't call in for artillery. They can't call in for air support, all that fun stuff. So the pressure was really high. The learning curve was super high, but it definitely taught me a lot about myself and then, you know, how to rely on other people.

(Joel Beasley at 00:04:15) Yeah. How do you manage that level of pressure?

(Ryan at 00:04:19) Well, you just kind of have to do it because, you know, there was really no other choice. I mean, my training in the military up until that point was all about kind of pressure situations and, you know, leadership training, and they teach you that you don't always have to make the absolute best decision, but you need to make a decision because if you get paralyzed in the moment, that can have negative consequences. So you learn to kind of weed through the noise, if you will, and really focus in on the important information or the important inputs that are coming to you from your subject matter experts or even outside factors, and you just have to make the best decision you can.

(Joel Beasley at 00:05:05) Yeah. Sometimes I notice myself getting a little sluggish with decision making or feeling a little back and forth on something. And that's typically my trigger to just make a decision because what's going to happen is the moment you make that decision, the parameters change. And so you can then make another decision. But if you just sit there with the same parameters and make no decision, then you're just stuck in neutral.

(Ryan at 00:05:28) Yeah. So there's a quote by Patton that I like that says a 70% plan executed with ferocity is way better than a 100% plan that's never executed. So I use that a lot when, you know, making decisions that I may not feel like I have all the pertinent information. But I have what I need to at least move forward, and I continue to try to bring in information because I may make a decision. And now I'm speaking both on the civilian side and because I'm still currently serving as a United States Army officer in the Army Reserve. But those decisions that I have to make on the military side, you know, you may make a decision. And then several hours later, you may get new information that kind of changes the game, and you have to analyze that. You have to ingest it. You have to go forward and maybe even, you know, change what your previous decision was. It's just leadership.

(Joel Beasley at 00:06:24) What has the experience been like going from the structure? So growing up, my dad was Air Force. That's why I automatically assumed you traveled around as a kid for that. But how has it been going from that structure where you're, you know, running a team in a military type situation into the private sector or the commercial industry where people have jobs?

(Ryan at 00:06:46) Yeah. I think the hardest part for me was not only navigating kind of the get the job part of transitioning from the military, but some of the more cultural differences between the civilian world and the military world. I mean, as a leader in the United States Army, I literally was responsible for people's lives. Even when we weren't in a combat zone, if someone did something that they weren't supposed to do and let's say ended up in jail, it wasn't their family that went to go pick them up and bail them out of jail. It was me because I was responsible for them. So there's a very distinct cultural mindset within the military about, you know, getting the mission done and taking care of people. Whereas going to the civilian world, people care. I don't want to say that people don't care, but there are those people out there that are just here for a paycheck. And having to learn how to deal with that was somewhat of a hard transition for me because I used to be able to just tell them what to do, and they would do it or face the consequences. Now I've learned through, you know, progressing as a more senior officer in the Army, but even on the civilian side, that democratic leadership is a better form of leadership when it comes to working within the civilian sector versus military. Not to say that democratic leadership isn't important in the military because even that culture is changing, but it definitely, I think, resonates more on the civilian side.

(Joel Beasley at 00:08:29) Yeah. It's just two entirely different animals. And by the way, we're just hanging out. We can speak freely, and if you want to edit anything after the episode or whatever, we're all on the same team. So I love having conversations about things that are somewhat difficult to talk about too because those are some of the best conversations.

(Ryan at 00:08:47) Oh, yeah. Well, I used to say that there's civilian Ryan and then there's Army Ryan because Army Ryan would, you know, get up in your face and be very direct and be very blunt. And I'm sure some of my coworkers would still say I'm direct and I can be blunt, but I've turned it back a little. So, yeah, there's definitely a difference between the military side and the civilian side. Although I do think that they're starting to merge to a certain degree. The military, at least on the Army side of my experience, is starting to take a different approach to leadership and the way that they're building leaders and scenarios in which leaders have to make decisions.

(Joel Beasley at 00:09:28) And that's how you gain experience. You can't just learn everything about leadership in a classroom. You have to go take action and make it real and personal to yourself.

(Ryan at 00:09:36) So one of the best lessons I learned actually was before I got commissioned as an officer. I was still in ROTC in college and, we were a tight group and all the ROTC folks, and we would hang out, you know, because we're college kids, but we had this military structure that we also had to balance. And I learned a really hard lesson about peer leadership because a lot of my friends were of lower rank than me based on their year group. And when I was in my senior year, I was top dog. So I can remember we were doing something called drown proofing, which is basically training where we teach people how to use their physical uniforms, like their shirts and their pants, to create flotation devices and things like that just by blowing air in them. It's actually pretty cool that the military, you know, for random soldiers who would likely not necessarily be in the water, to have that on their body. Anyway, I digress. We were doing this training, and I was standing on the pool deck, you know, like Patton with my arms crossed and, you know, supervising and yada yada yada. And my friends, these people that I hang out with, I truly call them my friends, were like, Ryan, why are you not in the water with us? And I'm like, well, because I know how to do this stuff, and, you know, I don't need to. And they were like, yeah. But as a leader, you should be here and doing the work with us, showing us the right way by example. And it became this huge issue between me and my friends, and I learned that I was wrong. So it's leadership is ever-evolving. I mean, like I said, I started out as the, you know, the Patton type of leader where I thought I knew everything and everybody just had to listen to me. Now I think if you, you know, talk to the people that I work with now, I very much am looking for everybody to give me input and even ideas and help me make decisions as opposed to me just saying this is the way it's going to be.

(Joel Beasley at 00:11:42) Yeah. It's like we're AI algorithms, right? We get a lot of input, and then we can make our decisions better.

(Ryan at 00:11:48) Oh, yeah. Without a doubt. It's definitely taught me a lot. I tell people all the time that my military service, as it, you know, likely is for everybody, is life-changing, but I think it made me a better person just generally. It's had its difficult times, but it's definitely been a huge benefit to me personally.

(Joel Beasley at 00:12:09) And while I didn't serve in the military or armed forces at all, growing up with my dad being in the Air Force, the discipline that he had and how he raised us, I was resistant to it as a kid. He would come in and check on the quality of how we made the bed. And, yeah, it was pretty intense. But you're resistant to it as a kid and then when you grow up, I look back on it and I'm grateful for it because him showing me what discipline looks like even though I was resistant to it helped me out later in life. And so I've talked to him as an adult and I was like, man, thank you so much. I know I was a handful back then, but I really appreciate it.

(Ryan at 00:12:48) Yeah. I, so I have three children and my wife and I have a very deliberate mindset about the way we want to raise our children and probably more importantly, the way they interact with other people. So we're very sensitive in trying to be considerate not to have our children be disruptive to other people. That doesn't mean that, you know, if they're having a bad day or, you know, my two-year-old, if she's crying uncontrollably that it would be this big huge issue. But, you know, it's simple little things where, let's say, we're walking through the mall and my kids are doing this. They're walking, cutting people off. We stop that behavior, and we show them, hey, you're stopping people around you. You can't be walking and then just stop because the world doesn't revolve around you. So I think that has a lot to do with, you know, my mindset. I do not go in and check hospital corners on them, although that's a pretty good idea. But, you know, I do think that it's helpful, and I hope my kids will one day learn to appreciate it because we do get a lot of positive feedback that our kids are very well-behaved and very considerate and, you know, very helpful. So it's interesting.

(Joel Beasley at 00:13:59) Yeah. And that's one of the, I was researching, you know, as a parent, you want to do well. So I was researching some of the top tips for, like, raising good kids. And I was getting all nerdy on it, looking at some of the research and stuff as they followed kids throughout their lives. And I can't remember exactly all the items right now, so I wasn't completely prepared for this. But I do remember one that stuck with me, and it was that you could determine the child's success based off of how they interact with other kids at a young age. So I'm constantly asking the preschool, like, you know, is Aria social? Does she have friends coming up? Is she isolated? Like, where is she at? And the other one was, if they have good manners, if you can teach them to say, like, excuse me when they're interrupting adults or just behave well, then what happens is the other parents will want your kid around their kids that also value good behaviors and then that will create better connections and that just helps with the child's progress in life. And so I said, alright, I'll focus on those two things.

(Ryan at 00:14:58) Yeah. So that reminds me of two things. One, one of my best friends, he once said to me because, you know, as a young parent, you're always worried about, am I doing something wrong? Am I going to mess this kid up for life? And he said to me, he's like, if you're worried about messing up your kid, that means you're doing it right. You're a good parent if you're concerned that your actions are going to mess up a child. It's the people who don't care that, you know, have issues. But, ironically, you know, we have friends and neighbors where we'll plan an adults-only trip. We don't have childcare, and they're like, oh, yeah, bring the kids. They're like little adults anyway. So, luckily, they're starting to show the results of our strict ways, I guess.

(Joel Beasley at 00:15:50) What's the age range for your kids?

(Ryan at 00:15:53) So we have an 11-year-old, a nine-year-old, and a two-year-old. So two boys and then we have a little girl and she is pretty cool. The other two, I call them meatheads. Yeah. They're clowns, but we keep them around.

(Joel Beasley at 00:16:08) So for the other people in my family that have kids, siblings between me and my wife, one has two boys and one has two girls. And so it's impossible for me to connect with my brothers-in-law on the concept of what it's like to have a boy and a girl because the love you feel for both of them is completely unique and different.

(Ryan at 00:16:27) Oh, yeah. I mean, even from child to child. I can remember when we found out we were pregnant with our second son, I remember having like a moment of panic. And I was like, well, my heart is full. You know what I mean? Like, I can't afford more love. Like, that's impossible. But you really do find—I mean, it's not that you find a way. It's just indescribable. It just happens.

(Ryan at 00:16:52) You have the love for all your children. That doesn't mean they can't annoy you. They definitely annoy you. It's okay to not like your children sometimes, but yeah, I agree. It's raising a little girl now compared to the boys—it's different. It's not bad or good different. It's just different.

(Joel Beasley at 00:17:09) Yeah. Oh, man. This is exciting. So how did you go from that, like, working and doing all of that stuff in the army to working at Enterprise Health? Is that how you say it? Enterprise Health?

(Ryan at 00:17:22) Enterprise. Yep. Yeah. Oh, I have a storied history. I'm probably much like everybody else. So I left active duty after about five years. And my first job out of the army, I worked for a manufacturing company making boxes, like corrugated boxes. So there's a lot of junior military officer programs where they recruit transitioning military officers, larger companies, because they recognize the leadership skills that the military instills in people. Well, this is one of those programs. So it was the first job I had out.

(Ryan at 00:17:58) I did it for a little while. Ended up leaving. The work-life balance—it was not ideal. So it was a manufacturing plant. Well, if we had work that needed to be completed, you would have to work through the weekend. Like, there was no choice. So depending on when orders came in, you may work straight thirteen, fourteen straight days or more, and you wouldn't even know until the Thursday before whether you're going to work that weekend or not. So it just wasn't ideal. I'm very family-oriented. The fact that I wasn't able to travel to see my family because I was unmarried at the time just didn't sit well with me.

(Ryan at 00:18:42) So I left, ended up getting a few contract jobs based on my IT background, bounced around, you know, doing contract work. Ended up working for Memorial Sloan Kettering Cancer Center in Manhattan in their IT security office, went to work for MetLife, just bouncing kind of between the civilian healthcare sector and the Department of Defense. Because after about two years, I decided that I missed the military, and I needed to be a part of it again. So I joined the New York Army National Guard. I was living in New York at the time. So they would put me on orders full time, or they actually made me a full-time employee before we moved to Florida. So I've kind of balanced between the two a bunch.

(Ryan at 00:19:21) Ended up getting a job when I was looking to move to Florida for a company called Blueprint Healthcare IT. Fast forward several years later, Blueprint merged with another company called Enterprise Solutions, and it formed Enterprise Health. So it's kind of how I got where I am, or I came to where I am, and enjoying it. You know, healthcare security is—it is not easy. Let me tell you. It's pretty demanding, and it's only getting worse.

(Joel Beasley at 00:19:50) People want that data.

(Ryan at 00:19:52) They really want that data. And sadly, historically, it's been very easy to get that data.

(Joel Beasley at 00:19:59) What does the company do? Like, when you meet with people and you tell them for the first time, how do you explain—because cybersecurity is such a broad array of products. Like, what exactly does Enterprise Health do?

(Ryan at 00:20:12) Yeah. So we're a, let's say, a cybersecurity consulting firm. We offer services and solutions for the healthcare industry. So we do everything from, you know, pen testing to risk assessments, tabletop exercises, and kind of everything in between. The only thing we don't really do is kind of managed services where we're going to put hands on a keyboard and, you know, manage your SOC or something like that.

(Ryan at 00:20:37) But my specific role is doing HITRUST certification. So the HITRUST Alliance is the governing body for this framework, the CSF, that was born out of healthcare. It started in 2009. And you can equate it, if you're not familiar with it, to things like the NIST CSF. It uses a lot of NIST 800-53 for its control sets. It's based on ISO 27001. Actually, the way they position it—and, you know, I will likely get on my soapbox because I'm somewhat of an evangelist for it—is there's genius behind it. They call it the "framework of frameworks." So they didn't go and try to create this brand new framework. They realized that there's a lot of good work that's already been done. Let's bring it together and create this kind of single framework that applies to all.

(Ryan at 00:21:24) And they really push the kind of "assess once, report many." So for the folks out there that are listening, you know, I'm sure you're inundated with security risk assessments where you want to do business with somebody, and they're like, "Hey, we need you to fill out this questionnaire," and you're probably doing it, you know, two or three hundred times a year. Well, the idea is that HITRUST satisfies that. You won't have to do those risk assessments anymore. It's becoming such a well-known framework and certification that they're willing to accept that HITRUST report.

(Ryan at 00:21:56) And there's good reason for it. I mean, the level of assurance that you get through a HITRUST journey, as I call it, is way higher really than anything else because of the way it's all structured. So to me, it's—I don't want to say it's the future, but it's kind of the future, not just for healthcare security and privacy, but really for any industry. It really applies across the board. You can focus on healthcare. You can focus on other industries because it is tailorable.

(Ryan at 00:22:27) But to me, it really works because it kind of forces you to do what you need to do in order to maintain the certification from a security and privacy perspective. So there's a forcing function in there, and that to me is the real genius because it kind of forces you to adopt a framework. You actually have to adopt it. You actually have to do it every single day in order to maintain the certification, which is great because, you know, something like the NIST CSF—as great as it is, and I know the government's, you know, this is the standard for the government—but there's nobody kind of making you follow it day in and day out. You can choose to adopt the NIST CSF and kind of craft it the way that you want to craft it. But if you don't feel like working on it or there's, you know, conflicting priorities where someone else said, "Hey, you know, for healthcare, we're going to roll out a new EHR." Well, that just became priority number one, and security and privacy kind of gets pushed by the wayside. So with HITRUST, you can't really do that, or your major investment in both time and money is for naught.

(Joel Beasley at 00:23:44) You know, it's funny. So I met Jason and had him on the show from HITRUST, and that's how we got connected. But I was learning about it there. And it's weird. It's like when you see a car and then you start seeing the same car everywhere. Right? So from the moment I met him, you know, I was learning about HITRUST. That was my first introduction to the company. And then now I see it, like, at the bottom of so many of my guests' websites. I see it everywhere.

(Joel Beasley at 00:24:09) And so I personally really identify with the struggle because I've integrated software within the past, you know, year or so into a Fortune 500 company. And that process, like, the whole process is like eight months. But that security process, I'd say, was a solid three months of this back and forth. And, "Is this question applicable?" "No, because, you know, we're like cloud software, so that's not an applicable thing. We're remote. We don't even have like an office network." Right? And like half the questions are about our office internal network. Like, we're a cloud-first company, you know?

(Joel Beasley at 00:24:39) Like, and so it was just fascinating going through that process because I had never been through that at that level of detail before. So to have the concept of "let's just adhere to one set of standards"—and so tell me more about this. So, like, I get the forms, right? I remember going through this process recently. We fill them all out and it's like, "All right, we've got this procedure in place, this procedure in place." But they don't know because I just filled out the form and submitted to them and they approved it. They don't know if this is actually happening within my four walls. Right? So is this something that HITRUST solves?

(Ryan at 00:25:14) It does. And, you know, I would be remiss in my duties because, you know, everybody in Enterprise now has become somewhat of a—it's a cliché because I say it so often. HITRUST is a significant emotional event, like, 100% emotional event because it solves that exact problem. Right? So a lot of different risk assessments that organizations will go through—it's basically, "Hey, are you doing this?" "Yep, I'm doing it." "Are you doing that?" "Yep, I'm doing it." And there isn't—you know, depending on who you're working with, there isn't a check to make sure that you're actually doing those things.

(Ryan at 00:25:51) Well, the great thing about HITRUST is it's a "trust but verify" certification where you are required to fill out what's called a readiness assessment. Think of it like a risk assessment where there's a number of controls that you have to basically demonstrate your compliance to based on different maturity levels. Is there a process that complies with this requirement? Is there a policy process, and is it implemented? So you take that entire assessment, and you have to send it to an organization like Enterprise, and this is where my team would come in. And you have to have them come in and double-check every single thing. So they read every single policy. They read every single process. They look at every single piece of evidence for every single requirement. So you have to actually prove that you're doing these things. So there's required on-site testing. There's remote testing. There's interviews. And it's actually really, really hard.

(Ryan at 00:26:50) And like, our planning timeline, our planning horizon for most new clients is about twelve months, and that's on the quicker side. We've had folks, organizations that have been doing it a lot longer because it's—like I said, it's a significant emotional event. Nobody's job is HITRUST, generally. So everybody's wearing another hat, and it really just—it's a culture change for the organization. And this is where, you know, bring it back to my comment about adoption. It's really about the adoption of the HITRUST CSF and that mindset.

(Ryan at 00:27:22) So as you're making changes—you just mentioned, you know, doing a software implementation for a Fortune 500 company—the way that HITRUST works is they want you, as you're making decisions on implementing a new piece of software or making changes on the network or changing your hiring and termination procedures, you're going back to the CSF, and you're saying, "Well, how will this impact my certification?" And if you're doing that on a daily basis, if you're consulting your sort of your certification, so to speak, then the level of effort when it comes time to demonstrate your compliance becomes a lot less because you've done the work for pretty much that whole time leading up to it.

(Ryan at 00:28:04) So everybody typically asks me, you know, "What's the difference between HITRUST and, say, a SOC 2 audit from the AICPA?" And the biggest difference is that HITRUST is really like five levels of checks, whereas for SOC 2, maybe you have two. Right? So for SOC 2, you have the organization who's being assessed. Their management will attest that everything's in place. Right? And then the AICPA firm will come in, and they'll do their tests. One, two.

(Ryan at 00:28:34) Well, with HITRUST, similarly, the assessed organization, their management team has to sign a letter attesting that everything that's in the assessment is actually there. It's factual. It's true. It's compliant. Yadda yadda yadda. You send it to someone like Enterprise where my team is going to very meticulously go through that, check every single requirement on all the maturity levels. Once that is done, I am required by HITRUST—by the methodology—I have to take a separate team, and I have to do a QA of that assessment. So not the folks that did the assessment, a completely separate team and myself included as the executive sponsor. I have to go through that assessment to make sure that my assessors did the things that they were supposed to do, and, oh, by the way, make sure that the assessed organization is doing the things that they do.

(Ryan at 00:29:33) Once that comes back as, you know, A-OK, we submit to HITRUST. HITRUST will then do a QA check of that assessment. Once it gets through the—and there's usually, you know, a back and forth between the third-party organization like Enterprise and HITRUST, clarify any questions or anything like that. Once that gets done, it goes actually into a compliance review within HITRUST before a report is submitted. So five levels of checks on that one assessment to make sure that what people are saying they're doing is actually happening.

(Joel Beasley at 00:30:24) That's pretty intense. So how do they sell this into the company? I'm going to guess a little bit and you tell me how wrong or right I am. So you get the hook is, "We can speed up sales and implementation. We can speed things up." Right? That's one of the reasons you could get HITRUST. But then, when they start going into this emotional event, I'm curious—how does HITRUST help the company learn these new cultural rituals, if you will?

(Ryan at 00:30:49) So that's usually done between what they call the third-party assessor, external assessor, like Enterprise. There's about a hundred external assessors globally, Enterprise being one of them. That relationship to get an assessing entity compliant in that cultural shift and all that stuff that we just talked about—usually happens between those two groups. HITRUST is there. They're available to ask questions and, you know, help guide and mentor, but it's primarily between the external assessor and the assessed entity.

(Ryan at 00:31:23) The biggest selling factor for HITRUST, at least in my opinion, is the fact that you can assess once, report many. Right? So if I'm a CISO out there somewhere or even a CTO, you know, I'm going to get—I'm likely being bombarded with risk assessment questionnaires. That alone likely will save me, I can't—countless hours annually not having to fill it out. And, you know, "We filled this out last week, but these four questions are a little bit different. So we need to tweak it or we may need to go find the answers." You just send them the HITRUST report, and they can do their own check on it, or they may just accept it. So to me, that's one of the biggest benefactors is the fact that it actually alleviates work for the organization that has been assessed and certified.

(Ryan at 00:32:07) The other piece is that it really kind of applies across the board. Like I said, HITRUST was born out of healthcare, but they've created it and they've massaged the CSF itself to make it industry agnostic. Now if you're a healthcare organization, you can still make it very much about healthcare, focused on ePHI and HIPAA security rule and so on and so forth. But it's industry agnostic where if you're a financial services firm, retail, manufacturing, hospitality—this applies because, you know, I always tell people, we're generally not creating new ways to implement security controls. Yes, there's new technologies and stuff like that, but it's still all about confidentiality, integrity, and availability. Right?

(Ryan at 00:32:49) So the fact that the CSF is kind of all-encompassing because it's going to touch every facet of your organization—facilities, hiring and termination, obviously the IT stuff, privacy, legal, finance. It touches really every aspect. So you can take that information, obviously get better. It's automatically going to make you better. But you can then, as you deem necessary, share that with prospective business partners or prospective clients and say, "Hey, look. Look what I've been doing. Look what I am doing from a security and privacy perspective. I will have your best interest in mind."

(Joel Beasley at 00:33:41) Okay, so I'm almost understanding what your business does. So I've got some clarifying questions. Help me understand, because you're in it all day, right?

(Joel Beasley at 00:33:48) But I'm all over the place with all these different awesome companies that I'm learning about. So I'm trying to oversimplify it so I understand, right? So what it sounds like to me is HITRUST is this framework.

(Joel Beasley at 00:34:02) You're almost like a HITRUST vendor, or you provide the service. So if I'm a CTO and I'm bombarded with these assessments because I'm selling software into another company, and in order to get that sale done, I have to, because you can't count the revenue, right, until it's integrated and delivered or part of it. So I'm getting a lot of pressure as the CSO or CTO or CIO from the parts of the organization to get these assessments done, right? So I notice this issue and I come over and start searching, like, let's say I'm a healthcare company selling healthcare software.

(Joel Beasley at 00:34:36) And then I go over and I find, you know, what's the solution to this? It's HITRUST. I would go to Ryan. I'd go to Enterprise Health, and they would help me do the single assessment, the assess once report many. Is that what we were saying?

(Ryan at 00:34:50) Yeah. So the HITRUST Alliance is the governing body, right? So they're the only ones that can certify. Enterprise are the ones that are actually going to get you to a certifying state, and that's what I tell my customers is this is really tough. I don't care what type of assessment you've been through before. I don't care what certifications you have. This is different, and it's tough, and it's rigid. So what we're doing is we are taking you through that journey. HITRUST is going to get you from where you are today to a certifying state and hopefully beyond to that adoption that I was telling you about, because the way that the certification lifecycle works is you work to get certified.

(Ryan at 00:35:35) Let's say it takes twelve to fourteen months. From the time that you're certified, the clock starts ticking. Twelve months later, you have to do what's called an interim assessment. And what that consists of is you have to bring back in the external assessor like Enterprise again, and we are required to take a look at a random sampling of the controls within the assessment to make sure they're still in place. We also have to check to make sure that any controls that were deemed to require a corrective action plan from the original certification, we have to check to make sure that the organization has made meaningful progress against those.

(Ryan at 00:36:14) They don't have to close everything out, but they have to be working on them. I mean, some should be closed, some should be in progress, some could be future state. So that's twelve months afterwards. So that's that first kind of forcing function to make sure that you've adopted the CSF. Twelve months after that, your certification expires.

(Ryan at 00:36:33) So you have to recertify like you did the first time. So HITRUST, like I said, I use this term a lot, has a lot of genius built into it because it understands that environments change. Technology is dynamic. Just because you're certified on 01/01/2021 doesn't mean that your environment's going to be exactly the same one year later. So they force us to come back in year over year and do these checks to make sure that your environment is still compliant to all the most recent and applicable security controls.

(Joel Beasley at 00:37:05) That's interesting. I can see how that's a big pain point for people and that they would want to solve that because I want the other part of the organization to love me as the CSO. I want to get those security assessments done fast and the product delivered.

(Ryan at 00:37:18) Oh, exactly. And this really, for the most part, this solves that problem, right? Because you can walk away with a very detailed report that, obviously, you know, you would share confidentially with business partners that can show them exactly where you stand. And depending on the risk profile, and now we're going to get real into the weeds real fast if you want.

(Ryan at 00:37:42) Depending on your risk profile determined by HITRUST, you may have some really stringent requirements that you have to demonstrate compliance to. So the way the HITRUST Alliance kind of develops their assessments is based on a series of questions. Your risk profile is developed. If you're considered risky, then the level of stringency of the controls and the number of controls actually expands based on that increased risk. So your potential business partners as a CTO, they are going to have a laundry list of information about your organization that should answer really every question they have.

(Ryan at 00:38:26) Because the way the assessment works is for every single requirement for all five levels of maturity—policy, process, implemented, measured, and managed—there's going to be a score, and there's going to be a comment, and there's going to be evidence to back up those scores and comments. So you can walk away or read that report and feel really confident that what they're saying is in place is actually there.

(Joel Beasley at 00:38:51) That's very neat. I got a really good understanding of it now. At least, I think I do. We'll see. I'll start sending you people that come up and you'll be like, all right, Joel, nope. But I did want to talk about something else though because it fascinated me in our prep call. My team was telling me about government subsidizing digital transformation in healthcare. I was like, get out of here. That's something that happens? I had no idea. Tell me what that is.

(Ryan at 00:39:16) Well, it hasn't happened. So I had this brainchild, and I'd like to think that I'm the only one that thought of it. I'm probably not. Several years ago, because in healthcare, the HITECH Act was passed. And as a part of the HITECH Act, there was something, a program called meaningful use. And really, what it was for was to drive digital record adoption. So these electronic health record platforms, the Cerners of the world, the idea was if we can make medical records more easily accessible and available, then patient care becomes easier, especially for people who travel out of state for whatever reason. You can get your medical records easily accessed somewhere else, whereas typically they're all paper records sitting in some cabinet somewhere in a hospital, not super easy to access. So this program was designed to drive healthcare organizations to adopt digital platforms, and there was a number of criteria. There was different phases of it also. But the bottom line was if you adopted this digital platform and you could demonstrate that you were meeting the criteria, you get reimbursed by the government. And there was big bucks, millions of dollars that were, as an individual organization, available to offset your costs of migrating to this digital platform. And that was really, you know, because the government cared. The government wanted to make patient care that much easier for the healthcare industry that they wanted these digital records available.

(Ryan at 00:40:59) Quick side note, it also made it a lot easier for people to get at who should not have access to it. But I digress. My argument is if we really care about healthcare cybersecurity, which you would say HIPAA signed in '96, HITECH in the mid two thousands, these laws that have been signed into legislation, if we, that require us to do all the right things from a security and privacy perspective, why are we not incentivizing the healthcare industry similarly like we did for digital platform adoption? Let's create an incentive. And if you were able to meet X criteria, whether that's, you know, adopting a specific framework, having certain technologies in place, whatever it may be, there should be reimbursement there because security is not a profit center.

(Ryan at 00:41:53) I mean, and I'm not, this isn't, I'm not telling anyone anything they don't know. Security for a healthcare organization and other organizations typically doesn't make you money. It only costs you money. So if you're balancing spending your precious revenue on something that's going to make you more money or security, we're always going to go towards what's going to make us more money. So, again, and there's a lot of politics involved with this, so that's why I kind of chuckled when you brought it up.

(Ryan at 00:42:19) You know, if we really cared about, if the government really cared about healthcare security, why would they not create a similar plan to incentivize healthcare and whatever other industry they deem important to really adopt sound and safe security and privacy practices through technology and all the rest of it.

(Joel Beasley at 00:42:39) Yeah. That's interesting. Have you ever been a part of any of those committees or anything that actually vote or propose these sort of incentives at a federal level?

(Ryan at 00:42:49) No. I mean, this podcast is probably the coolest thing I've ever done.

(Joel Beasley at 00:42:54) Oh, this is so cool. Awesome. Do you listen to the podcast? Have you listened before?

(Ryan at 00:42:58) I have. I have.

(Joel Beasley at 00:43:00) Any feedback?

(Ryan at 00:43:01) Yeah. I mean, I do a lot of presenting for my job and stuff like that. And, but no, I've never been invited to present this idea. I think when I first had it, this is probably going back to 2016 or 2015. I tweeted it once to see if it would pick up steam, and it never did. So I was like, oh, I guess it's not a good idea.

(Joel Beasley at 00:43:22) No, no. It's just the Twitter algorithm. We'll talk to Jack about it. I want to talk about leadership. I was excited to hear some of your thoughts on this. You have all of this experience in the Army. Do you pick and choose which ones, which attributes of yourself that you pull from the Army to kind of make your own style? Or do you read and pick different parts from different leaders that you like? How do you come up with Ryan as a leader?

(Ryan at 00:43:51) Yeah. That's a great question. I would say that it's probably all the above. Actually, I actually want to write a book on leadership. I have notes, so this may help me formulate some thoughts. I think it's a combination, right? So I think leaders, it's both nature and nurture in the sense of some people are just kind of born with leadership attributes, but they still need to be honed and molded to be really effective leaders. And for me, I think my leadership style has completely evolved going back to my earlier comments, and it will continue to evolve. I personally don't think that leaders should get really set in stone on well, this is always the way I lead because situations change.

(Ryan at 00:44:47) We talk about IT environments being dynamic and changing on a daily basis, but leadership scenarios are changing every single day. You have different personalities that you're trying to inspire and lead, and there's different factors that are influencing those personalities or the things that you have to lead through. So for me, I've learned that that democratic leadership, that doesn't mean that I shirk responsibility on making decisions. What it means to me is that I own the responsibility of the decision, but I am going to gather as much input from everywhere. One thing that I learned in the military is the lowest ranking person probably has the best idea because they're closest to the situation.

(Ryan at 00:45:38) So I want to listen to that person, and I'm going to ask them questions, and I'm going to use their input to help form my decisions. So to me, democratic leadership is really flexible in its application and its practicality. Being very draconian and it's my way or the highway, you know, driver type of leaders, which, you know, taking the personality test, I am a driver. There's a lack of flexibility there that I think inhibits, excludes, and can alienate the people that you're trying to lead. So for me, it's been a lot of good lessons and some bad lessons, some successes, some failures that has gotten me here.

(Ryan at 00:46:21) And I know that I don't know everything about leadership, and I don't think that I should stop learning about leadership. And every single day is a new opportunity to mold me. And recently, I actually got selected last month for promotion to colonel in the Army. And, you know, all my neighbors, they were like, hey, Ryan. Congratulations. And I was like, you know what? This is just as much about you all as it is about me because my interactions with the people around me shape me and shape my leadership style. So, I mean, to me, it's ever changing. It's ever evolving. It's always about continuous learning.

(Joel Beasley at 00:47:03) I love it because it's just true. It's what works. I'm curious to know. So if you were going to design the perfect leadership training program specifically for your direct reports, right, what is the most important thing that would be in that program?

(Ryan at 00:47:19) As far as lessons, like, what points am I trying to get across?

(Joel Beasley at 00:47:22) Like, what behaviors do you want them to emulate? Like, if you're training your direct reports on leadership and you want them to understand these concepts, what's one of the concepts?

(Ryan at 00:47:33) Clear communication is critical, and one thing that I try to do, sometimes it's almost to a fault, is transparency. People need to know what's going on. Whether they have an ability to influence that or not, being transparent in the problems we're trying to solve or the issues we're trying to tackle is really, really critical. That doesn't mean you tell everybody everything. You know, there's some things that as a leader, you're going to learn some things you need to say and not say.

(Ryan at 00:48:06) But generally, you should be talking to your people and getting them to know exactly what you know. Because like I said, you never know where the best idea is going to come from. And if you arm people with all the information, then they have a different perspective than you. And different perspectives sometimes is the absolute key to solving complex problems. So I think transparency and communication are really paramount. I think there's some assumed traits, you know, integrity, honesty, ethics, morality, legality, all those things that come with being a leader. But I would say communication and transparency are absolutely critical. And I'll quickly digress into what taught me that. So the military, they, what makes the, again, I'm willing to speak for the Army, but the Department of Defense, we're pretty successful generally. What makes the Army so successful is that we empower junior leaders to make decisions.

(Ryan at 00:49:13) We don't reserve decision making for the top generals when there is a young sergeant on the ground who is seeing what's going on to make a decision. And that's actually what makes us a really difficult enemy to beat, and we've had adversaries that have said exactly that. The reason why we can't beat the U.S. is because they don't follow their own doctrine. Because all of our doctrine is publicly available. You know what we're supposed to do to set, you know, an ambush, you know, an L-shaped ambush.

(Ryan at 00:49:46) But based on the situation, we empower those young leaders with, we empower them with information to make decisions on the ground as the situation changes because that L-shaped ambush, we may have been expecting the enemy to come from this direction. Well, he or she may see the enemy coming from a different direction, and they need to adjust. And that's really what taught me that arming people with information and understanding intent. You know? What is, what am I trying to do as a leader? What is my intent to get over this problem or tackle this project or what have you? Because if my teammates try to bring every single thing to me, nothing's ever going to get done. It's impossible. So I need them based on the information that I've armed them with, based on the empowerment to make decisions with guidelines, right?

(Ryan at 00:50:37) You know, I usually tell my folks, this is where you can make decisions for everything except for X, Y, and Z. Usually has to do with money. And as long as they understand what we're trying to get done, the information that I have, it's impossible to beat that. It's impossible to beat that because people are going to make things happen in real time as opposed to sitting and waiting and getting the information all the way up just to come all the way back down with more questions all the way up. It's that yo-yo, and it's proven throughout history.

(Joel Beasley at 00:51:08) It has fascinating. I have never thought about it from—I've never even heard about it from that perspective about why the Army is successful. That is—that—I don't—I can't even—I'm speechless, bro. I don't know what to say right now, Ryan. This doesn't happen much.

(Joel Beasley at 00:51:23) Congratulations.

(Ryan at 00:51:25) Hey, listen. I was, you know, during the prep call, I said, hey, you know, they said, you know, get emotional, you know, have fun with it. And I said, there is no shortage of emotion when it comes to, you know, when I get on my soapbox.

(Joel Beasley at 00:51:37) I love it. I want to know, what's the most impactful leadership lesson that you have ever learned?

(Ryan at 00:51:42) Oh, that's a tough one. I would say the story that I told you about when I was in ROTC, that one really shaped me. And that was reinforced when I actually was in Iraq as a tank platoon leader. I had a really great platoon sergeant. And without getting into, you know, the history of the military structure, for a platoon leader, the platoon sergeant is like the right-hand person, the go-to. They're the ones who—you know, as a young lieutenant, as a platoon leader, you may have like six months experience. That platoon sergeant probably got fifteen, eighteen years experience. I had a really great platoon sergeant in Iraq, and we were a tank unit. So tanks require a lot of maintenance. And a lot of leaders will tell their soldiers, hey, go change the track pads on your tank or go change, you know, the—go fill it with more grease or something. Like, this is really labor-intensive stuff. You know, really, really labor-intensive stuff. And my platoon sergeant, he looked at me—and not that I had an issue with it—but he looked at me. He's like, LT, we're changing track with our soldiers. And we're going to be greasing our own tanks, and I want them to see it. And they're going to feel it, and they're going to know that we're in that hole with them. We're in that suck fest with them. And, you know, that went a long way for me, and we actually had the best maintenance program of all the platoons in my battalion. And not to say that, you know, I had anything to do with that, but I think it was because of that mindset that my platoon sergeant instilled not only in me, but our soldiers—that we're in this together. Not, hey, go fix your tank. I'm going to stand here because my tank's good. We're all going to help that person get what needs to be done done. And that, you know, it still resonates with me today. Yeah, I could probably tell war stories for some time, but now they're all a blank at the moment.

(Joel Beasley at 00:53:37) It's okay. It's okay. I'm curious to know, any cool cybersecurity attacks that you dealt with in the military that you can talk about?

(Ryan at 00:53:45) Probably none that I can talk about. I will tell you the probably some of the most fun that I ever had was when I was working for a hospital. And we had a really good—I was working in the Security Offices, and we had a really good relationship with the Compliance and Privacy Office. And they had a tip line. So this is a big hospital. They had a tip line to report issues, PHI spills, whatever. So one day, the tip line got a report that there was an employee—and this hospital had a lot of celebrity patients, which obviously that stuff is, you know, needs to be kept confidential. There was a tip that came in that said this employee was siphoning patient celebrity patient information and selling it to TMZ. And, like, high alert. Everybody's like, we've got to do something about this. So we, you know, gathered a lot of the information trying to find out exactly who this employee is, where they work, yada yada yada. So my boss looks at me. He's like, alright, Ryan. I need you to—this is going back several years. He's like, I need you to come back in tonight at like 11:00, and we're going to run this script. I need you to log in and see what you can find out. So we remote desktop into the person's computer. We install KeyLogger and all this other stuff, and we ran a script to roll back the last login. So when that person came in the next morning, it didn't say admin on it. It said their name. Like, and I got to watch this person for like three or four days, and I'm listening to their conversation. I'm looking at their IMs. It sounds really invasive, and it was. But this conversation that this employee was having with somebody, another employee, was talking about, you know, people dying and stuff like that. And I went to my boss, and I was like, hey, you know, they're talking about like people being dead. Like, this—well, you know, this person was killed and—I was like, we should call the cops. Like, this is a big deal. So lo and behold, long story short—or long story long—the tip came in from a malicious ex-boyfriend. The employee was not stealing anything or selling it to TMZ. But I felt really cool because I was still, you know, somewhat of a young security analyst where I had to like come in at night and be, you know, really cool about it. And I, you know, I had to write these reports. So that's probably my favorite story to tell because I felt really cool at the time.

(Joel Beasley at 00:56:11) I love it because it reminds me of like when you're young and you want to be like the secret agent. And honestly, that's one of the drivers when I first saw that, you know, like the script on the computer and I saw it in a movie and then I saw it at, you know, my dad's computer. And I was like, I want to be able to type in that—you know, I want to be able to like do that and make the computer do things. And, you know, it's just, you bring some of the like whimsy back into it, some of the energy back into it. And I love that. And I admire it so much in you. And I would say this, I would say it's rare that I see people who are able to hold on to that throughout the entirety of their career. I see people—it's like an interstate. I see them constantly exiting at different ages. And as I'm getting older, I'm still younger, you know, I'm only 33, but even as I'm progressing with my peer group, it's like I constantly see people exiting off the interstate. And I'm like, this is unbelievable. It's just, it's—I don't know. Aging is fascinating.

(Ryan at 00:57:14) I become more of the GPS now. Yeah. So I always talk to my, you know, my teammates, and I'm, you know, try to mentor them about, you know, the security industry and, you know, what it has available to them. Because even recent college graduates, they're not armed with the information on what they can actually do within the security industry. So I always tell them, I was like, yeah, so if you really want to do the sexy stuff, go get your ethical hacking cert, and if you want to do this—but I agree. Like, it's—I always—and this is going to sound like a cliché—but, you know, if you're only working at work, then it's work. And there has to be passion. And for me, I have passion in healthcare. It goes back to, you know, my mom's challenges from a health perspective several years ago. And, you know, I always tell people, you know, I'm not smart enough nor do I have the stomach to be a doctor, but this is my contribution to healthcare. And you just have to have that passion. I don't care what it is. I don't care if you like to color. Color, you know, in the lines, out of the lines, just be passionate about it. I don't—you have to have that passion.

(Joel Beasley at 00:58:18) Yes. Actually, when we were talking about—back to parenting real quick and we'll wrap up here—but my wife and I were talking as she was pregnant with our first. And I was like, what type of parents are we going to be? Like, what type of, you know, framework am I going to raise my kids under? And what—because you can't pick one that doesn't allow them to be their unique self because you don't know what you're going to get. But you still have to have some sort of like guiding principle. And so the thing I came up with is I don't care what they do as long as they do it very well. Like, master something and master something as quickly as possible because I didn't master anything in life really until my mid-twenties. But after you master one thing, you understand the effort it takes to achieve mastery somewhere. And then you can from there, you get the freedom to choose what the next thing you're going to master is, knowing the commitment that you're going to go into. So I was like, we just need to get them to master something and encourage them to be passionate and love it and follow through with it even when it's difficult.

(Ryan at 00:59:23) Yeah. I agree. I haven't had the same exact mindset, but, you know, my mindset similarly is I don't care what they do, but I don't want them to quit. Yeah. It—you have—and that doesn't mean you have to do something for the rest of your life. You just need to finish what you started. And if you're going to sign up for a sports team, you may hate that sport. And my oldest, he disliked sports. He does not like sports, and I've tried baseball, soccer, hockey, football. And he's, you know, he would come to me during the season. He'd be like, Dad, I just don't—I don't have fun. I don't want to play anymore. And I said, that's fine. You don't have to play anymore. But you made a commitment to this team, and we're going to finish the season and this commitment. Let's take the lessons that we learned in the meantime and, you know, figure out how we're going to apply those. But I agree. It's not about what they do. It's really how they do it that matters to me.

(Joel Beasley at 01:00:15) Well spoken. I—sign me up for the book when you write it. I will be on the preorder list. We will push it out through the audience. We'll let everybody know about it. I hope you do that because you've got some great perspective, and it's unique, and I enjoy it a lot. Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn or send me an email, [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.