Expert Profile
I have spent the past 20+ years as an IT, Security and Privacy executive, with the past 17+ years primarily in the healthcare industry as a Security, IT, Privacy and Compliance leader. My clients have included a variety o ***** hospitals, academic medical centers, niversities, healthcare and mobile healthcare companies. I recently completed a chapter for a book on healthcare incident response and breach notification, due for publication in 2013.
***** Consulting works with healthcare organizations to review their operating environment; reviews business policies, practices and processes; assesses current risk; advises on current security and privacy strategies; and assists Boards of Directors, executives, product managers, engineers, and other stakeholders by breaking down regulatory requirements into technical and business requirements.
Recent engagements include:
• Providing guidance on strategic privacy practices and security controls for multiple healthcare companies Boards of Directors and executive teams
• Creating and managing IT Security/Privacy functions for multiple startups
• Advisory Board member for telehealth organization and big data analytics firm providing regulatory and technology guidance
• Clients include: Medical centers, healthcare startups, payor organizations; technology / software / services companies
• Providing HIPAA / FERPA / PCI privacy and security policy / procedure gap analysis and remediation
• Keynote speaker at national and international conferences such as UP 2011 Cloud Computing Conference (Cloud Standards: Portability, Privacy & Security)
• Lecturer and advisor, Draper University: International Data Use Security, Privacy and Breach Notification Requirements
• Lecturer, University of California-Santa Cruz Extension: Date Privacy and Security for Healthcare and Biosciences
***** Consulting works with healthcare organizations to review their operating environment; reviews business policies, practices and processes; assesses current risk; advises on current security and privacy strategies; and assists Boards of Directors, executives, product managers, engineers, and other stakeholders by breaking down regulatory requirements into technical and business requirements.
Recent engagements include:
• Providing guidance on strategic privacy practices and security controls for multiple healthcare companies Boards of Directors and executive teams
• Creating and managing IT Security/Privacy functions for multiple startups
• Advisory Board member for telehealth organization and big data analytics firm providing regulatory and technology guidance
• Clients include: Medical centers, healthcare startups, payor organizations; technology / software / services companies
• Providing HIPAA / FERPA / PCI privacy and security policy / procedure gap analysis and remediation
• Keynote speaker at national and international conferences such as UP 2011 Cloud Computing Conference (Cloud Standards: Portability, Privacy & Security)
• Lecturer and advisor, Draper University: International Data Use Security, Privacy and Breach Notification Requirements
• Lecturer, University of California-Santa Cruz Extension: Date Privacy and Security for Healthcare and Biosciences
Vice President Information Technology, Security and Compliance, Chief Security/Compliance/Privacy Officer
StayWell Health Management
Vice President/Chief Security and Compliance Officer
LifeMasters Supported SelfCare
Chief Information Security Officer
Lucile Packard Children's Hospital at Stanford
M.A.
B.A.
CGEIT, CRISC, CISSP, NSA-IEM, NSA-IAM certifications.
Member of InfraGard, ISACA, ISSA, IAPP