The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Cybersecurity at ViVE Podcast
Cybersecurity at ViVE Podcast artwork

Compliance Isn’t Security: The Biggest Cybersecurity Myth in Healthcare (HITRUST Explained)

Cybersecurity at ViVE Podcast · 2026-04-01 · 23 min

0:00--:--

Key moments - from our scoring

Substance score

58 / 100

Five dimensions, 20 points each

Insight Density12 / 20
Originality10 / 20
Guest Caliber14 / 20
Specificity & Evidence11 / 20
Conversational Craft11 / 20

Compliance frameworks like HITRUST are often mistaken for security programs, but Srish Badarai of Align clarifies this critical distinction. Compliance represents a baseline - passing an audit doesn't mean an organization is secure, especially if controls aren't embedded operationally year-round. Badarai walks through HITRUST's three assessment tiers (E1 as foundational, I1 as moderate, R2 as the gold standard), emphasizing that organizations should select the level matching their risk profile and compliance maturity rather than chasing the largest certification. The episode explores how mature organizations like Butterfly Network successfully juggle multiple audits (SOC 2, ISO 27001, FedRamp, HITRUST, HIPAA) by designing holistic compliance programs cross-mapped across frameworks and leveraging GRC platforms like Vanta, Drata, and Secure Frame. Badarai also addresses HITRUST version updates (currently 11.7), the importance of AI governance planning, and how organizations can avoid duplicative audit work by using HITRUST's mapped reporting to satisfy multiple regulatory requirements from a single assessment. This is essential listening for healthcare technology vendors, SaaS platforms, and business associates navigating compliance complexity.

Key takeaways

  • →The biggest cybersecurity myth is treating compliance as equivalent to security; compliance is only a baseline and passing an audit while remaining insecure is a significant risk.
  • →Organizations that treat audits as programs with embedded controls and defined control owners sail through assessments, while those scrambling in the final three months struggle because security programs cannot be built retroactively.
  • →HITRUST assessment selection should match your risk profile and maturity level (E1, I1, or R2), not ambition; starting with E1 and progressing to R2 allows reversible advancement rather than overextending resources.
  • →GRC platforms and cross-framework mapping eliminate audit fatigue by automating processes and aligning multiple certifications (SOC 2, ISO 27001, FedRamp, HIPAA) to work together rather than duplicating effort.
  • →Organizations must develop an AI governance plan and policy now - either through ISO 42001 or HITRUST's AI cybersecurity assessment - to prevent shadow AI and unauthorized use of sensitive data in uncontrolled systems like ChatGPT.

In this episode

  1. 1Introduction to HITRUST and Align's Assessment Services
  2. 2Compliance vs Security: The Biggest Myth in Healthcare
  3. 3Project vs Program Approach to Audit Success
  4. 4HITRUST Assessment Levels: E1, I1, and R2 Explained
  5. 5Navigating HITRUST Version Updates and Authoritative Sources
  6. 6Avoiding Duplicate Work Across Multiple Certifications
  7. 7Preparing for AI-Enabled Healthcare: Governance and Risk Management

Mentioned

AlignHITRUSTErnst YoungVantaDrataSecureFrameAuditBoardButterfly NetworkAWSMicrosoft AzureGoogle CloudSrish Badarai

Guests

Srish Badarai

Topics in this episode

FedRAMPHIPAAISO 27001SOC 2DrataGRC platformsHITRUSTAlignVantaSecure Frame

Questions this episode answers

What is the difference between compliance and security in healthcare?

Compliance is the minimum baseline that does not guarantee security; passing an audit doesn't mean an organization is secure. Security is an ongoing daily exercise, while compliance is often treated as an annual audit exercise, creating a false sense of protection.

What are the three levels of HITRUST assessment and how do they differ?

E1 (crawl) covers 43 foundational controls for organizations starting their compliance journey, I1 (walk) includes 182 controls for moderate assurance, and R2 (marathon) is the comprehensive gold standard for mature programs processing significant PHI data.

How can organizations avoid duplicating work across multiple compliance frameworks like HIPAA and HITRUST?

Organizations should design a holistic compliance program with cross-mapped frameworks, use GRC platforms like Vanta or Drata to automate processes, and leverage HITRUST's mapped reporting to export results (such as HIPAA reports) from a single assessment rather than conducting separate audits.

What should organizations do now to prepare for AI security risks?

Develop an AI governance policy and procedure internally, consider ISO 42001 certification or HITRUST's AI cybersecurity assessment, and implement guardrails to prevent shadow AI where employees put sensitive data into uncontrolled systems like ChatGPT.

What separates organizations that pass HITRUST audits easily from those that struggle?

Successful organizations treat compliance as a program with embedded controls in day-to-day workflows and defined control owners, while struggling organizations treat audits as projects and scramble to retrofit evidence and policies in the three months before testing.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

12 / 20

The episode delivers moderate insight density with some substantive takeaways (compliance vs. security distinction, project vs. program mentality, framework consolidation), but relies heavily on broad generalizations and lacks deep analytical content. While the guest explains HITRUST assessment types and practical recommendations, there is considerable filler around introductions, product plugging, and surface-level discussion without granular evidence or surprising revelations.

The biggest misconception that I hear, Sandy, is that people think, uh, compliance and security are equal. They're absolutely not. That's probably the biggest myth in our industry. Compliance is really the minimum, right? It is the baseline.
The biggest risk in compliance is not failing the audit, it's passing the audit while still being insecure.

Originality

10 / 20

The core insight - compliance is not security - is valuable but well-established in the compliance world and not particularly novel. The project vs. program framing is conventional advice, and recommendations around AI governance and GRC tools are standard industry talking points. The episode lacks contrarian takes or first-principles thinking; it mostly reinforces conventional wisdom.

Compliance is really the minimum, right? It is the baseline. Now compliance can really help you build a strong security posture, no question, but it does not guarantee one.
So the one that treat it like a project. It's your typical organization that is scrambling right before the exam, right? Three months before the audit.

Guest Caliber

14 / 20

Srish Badarai is a legitimate practitioner with 9+ years at Align and prior Big Four experience (Ernst & Young), giving him real operational exposure to compliance audits across many organizations. However, he is primarily a service provider/auditor, not a client-side operator who has built security programs at scale from the inside. This limits depth of hands-on insight into day-to-day security trade-offs and implementation challenges.

So I started my career at the big four, worked at Ernst Young for about three and a half years. Then I did a lot of Sox 404 testing, a lot of SoC1, SoC2 reviews, HIPAA, what have you, internal audit. Then I transitioned over to align in 2017.
when I joined though, the hitrust program was just getting started. It was in its infancy stage. We had, I think three people at the time trying to build it because the adoption wasn't as, you know, what it is today. But you know, over the course of the last nine years we really built it to really performing one of the highest volume assessor, you know, certifications in the M market now.

Specificity & Evidence

11 / 20

The episode contains some concrete details (HITRUST versions 11.5-11.7, assessment control counts: E1=43, I1=182, framework names like GDPR/FedRamp), but sparse named examples or real data. The Butterfly Network mention (9 audits in 5 quarters with 5 people) is the closest to a specific case, but lacks granular metrics or deeper analysis. Most claims remain generic without supporting numbers, timelines, or dollar figures.

E1, 43. Controls i1, 182.
Butterfly Network, just for a background, they have completed nine different audits, nine different attestations and certifications in the last five quarters with a team of five people total.

Conversational Craft

11 / 20

The host Sandy Vance asks competent questions that follow the guest's points, but rarely pushes back, challenges assumptions, or explores contradictions in depth. Questions are largely confirmatory rather than investigative (e.g., 'shouldn't everybody in healthcare choose R2?' gets a brief directional answer without hard challenge). There is little productive disagreement or follow-up that tests the guest's reasoning.

Yeah, I mean, that's what I was thinking to myself. Like, shouldn't everybody that is dealing with healthcare Data be choosing R2?
So start small and build as your advice on that.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker C82%
  • Speaker B14%
  • Speaker A4%

Most-used words

organizations32audit26compliance19hitrust16security13assessment12healthcare11program11controls11trying10high10trust10different10risk10hipaa9last9

Episode notes

In this episode of the Cybersecurity at Vibe series on The Beat Podcast, host Sandy Vance sits down with Shreesh Bhattarai , Director of HITRUST at A-LIGN , for a candid and practical conversation about one of the most misunderstood topics in healthcare cybersecurity. With nearly a decade of experience building one of the highest-volume HITRUST assessment practices in the market, Shreesh breaks down the difference between checking a compliance box and actually being secure, walks through the three levels of HITRUST certification, and shares what organizations need to do right now to prepare for an AI-driven future. Whether you are just starting your compliance journey or managing nine certifications with a team of five, this episode has something for you.

Full transcript

23 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Welcome to the Cybersecurity at Vive series on the Beat podcast where we break down the fast moving world of cybersecurity and what it means for your healthcare business, your data and your everyday life. In this series, we'll go beyond the headlines to explore real threats, real defenses, and the people on the front lines keeping our digital world secure. And now your host, Sandy Vance.

Speaker B: Hey everybody. Welcome back to the Cybersecurity at Vive series on the Beat podcast. I'm your host, Sandy Vance and today I'm here with Srish Badarai, who's the director of hitrust at Align. Welcome to the show.

Speaker C: Thank you, Sandy. Thanks for having me.

Speaker B: So Srish is the director of hitrust, Ed Align. And in this role he plans audits, oversees the fieldwork of HITRUST and SOC reviews, and then, uh, basically prepares final reports, makes recommendations to the management at various organizations. So we're going to dive, dive into what hitrust is all about and how Align is performing these reviews. But first, shresh tell us a little bit about yourself and how you came to Align.

Speaker C: So I started my career at the big four, worked at Ernst Young for about three and a half years. Then I did a lot of Sox 404 testing, a lot of SoC1, SoC2 reviews, HIPAA, what have you, internal audit. Then I transitioned over to align in 2017. So I've been here a little more than nine and a half, nine years I think. Uh, it was in January. So when I joined though, the hitrust program was just getting started. It was in its infancy stage. We had, I think three people at the time trying to build it because the adoption wasn't as, you know, what it is today. But you know, over the course of the last nine years we really built it to really performing one of the highest volume assessor, you know, certifications in the M market now. So we do everything, we can get into all the assessment types within hitrust and uh, so that's where we're going and it gives us that level of volume of HITRUST assessments that we do, gives us a very good sense of what organizations are doing in terms of building their compliance program and really sometimes struggling to really scale that program. So it's a good spot to be in.

Speaker B: So what types of organizations do you typically work with when you're doing these assessments?

Speaker C: It's across the board. So a lot of the organizations, you know, if you kind of look at the journey of a up and coming company, right, they start out with a SOC 2 attestation, we kind of joke that's the gateway drug to compliance. And then, you know, the next natural tier is the ISO 27001. If they're trying to sell into the international market or set up their isms internally and then after that it's okay, what industry I'm, um, am I going to try to sell my product into? Is it healthcare? Is it FedRamp? If it's with the federal government, is it CMMC? If I'm trying to do business with the Department of Defense? So if you are trying to sell into the healthcare market, then HIPAA is the law that you obviously going to go and get. But then the much more comprehensive and robust framework is high trust. So we, you know, organizations that hold Phi or they process Phi or they transmit Phi in their systems, they are your, you know, the business associates, they are our typical customers.

Speaker B: So this would be any, um, solutions provider for clinical applications, for revenue cycle, anything that touches healthcare, anything or even

Speaker C: they don't even, uh, you know, a few years ago HyTrust went industry agnostic. So a lot of the organizations, yes, they are trying to sell into healthcare, they have Phi Pii. And so high trust is the natural progression. But we also audit a lot of different companies that don't have any Phi, they don't have any pii, but they just default to the high trust framework, given how robust and comprehensive it is, that they believe that it can help, uh, strengthen their security posture.

Speaker B: Diving into this, what do you think is the most common misconception about being compliant versus being secure? And why does a gap in that trip organizations up?

Speaker C: So the biggest misconception that I hear, Sandy, is that people think, uh, compliance and security are equal. They're absolutely not. That's probably the biggest myth in our industry. Compliance is really the minimum, right? It is the baseline. Now compliance can really help you build a strong security posture, no question, but it does not guarantee one. So where I see organizations really make mistakes is that they treat compliance like a once in the, once in a year exercise, right? They sign up for an attestation, they go through the audit, they get the report, they're really happy, they throw a happy hour, uh, they celebrate and it's all right, team, until next year, we'll come back. Unfortunately, security doesn't work that way. Security is not a once in a year, uh, exercise. It's an ongoing exercise. It's an everyday exercise. And especially in the time that we live in now, where the threat landscape is changing faster than it Ever has. Right. The bad actors are getting more and more sophisticated. The attack surface has really expanded from the vendor ecosystem to the cloud, getting more technical. And now with the emergence of AI, your innovation. Yes, but also the risk of that innovation has really accelerated. But that's the bad news. But the good news is that organizations are identifying. Look, security can no longer be just a, uh, check in the box exercise because if we take compliance the right way, if done well, we can truly enhance our security posture, which then instills confidence, right? Trust in our vendor base, in our customer base, in our regulators, and, uh, you know, that's really going to help the business objective long term. And I say this last thing, I say this all the time. The biggest risk in compliance is not failing the audit, it's passing the audit while still being insecure.

Speaker B: From your vantage point, what separates organizations that can sort of sail through a high trust audit versus those that struggle? And this is just, uh, you know, obviously on that passing the audit piece.

Speaker C: So I bifurcate organizations into two different buckets. The one that treat high trust, or any other audit for that matter, as a project, and then the other ones that treat it like a program. So the one that treat it like a project. It's your typical organization that is scrambling right before the exam, right? Three months before the audit. They're trying to go retroactively and trying to prove that the controls are operating effectively. They are updating their policy and policies and procedure until the last minute. Right. They don't have defined control owners. They everything just seems disjointed, right? Because look, security programs are not meant to magically appear three months before the audit. That's just not how it works. But then the ones that treat it like a program, everything is smooth during the audit because they're not trying to do something new. All the controls are just embedded as part of the day to day workflow. They have defined control owners, things like user access reviews or uh, vendor risk management. Everything is happening in such an organic manner that the audit, I always say the best audits are always the boring ones. You're not scrambling to do everything. Everything is kind of done throughout the year. And then when the time for the audit comes, you're just basically producing those evidences naturally. And so I think a true high trust or a true audit compliance program is a reflection of your operational maturity rather than just your compliance preparation.

Speaker B: So high trust is not just one path, right? There's multiple paths and multiple levels of high trust. Can you kind of walk us through those at a high level.

Speaker C: So the way I like to frame these three assessments that you just alluded to, we have three within the high trust portfolio. E1, I1, R2. So I kind of frame them as crawl, walk, and marathon. E1 is the. Is the crawl. So E1, which is the foundational cybersecurity hygiene kind of an assessment really, designed for organizations that are trying to start their compliance journey or they work in a space where the risk exposure is not as much. Right. And then you go to an i1, which is the walk analogy, where, all right, you've kind of established you've done a SOC report, you've done ISO, now you've done an E1. You're really maturing your security posture. What's that next step? A moderate level of assurance kind of an audit. Still a static audit, like an i1 hydrous assessment. E1 and i1, by the way, are static. Number of controls, e1, 43. Controls i1, 182. So that really helps you set the foundation. And then the marathon, which is the R2. Right. That's the gold standard. That's the North Star that everybody aspires to get to. But that's once you have really mature your compliance program, that's if you're operating in a space where you're, you know, transmitting or processing or storing a lot of phi data, that's the right one for you.

Speaker B: Yeah, I mean, that's what I was thinking to myself. Like, shouldn't everybody that is dealing with healthcare Data be choosing R2?

Speaker C: Eventually, yes, but not right away. So that's the mistake that organizations typically make, is that they try to go for the biggest certification. Right. The goal should not be obtaining the biggest certification. It should be obtaining the right certification that matches your compliance maturity as well as the risk profile. I mean, we have a lot of organizations that are, you know, that come to a line and we, we. They say, you know what? We have absolutely no bandwidth to do an R2, nor do we have the need to go directly to an R2. Right. We work in a vendor space where we don't hold a lot of phi, we don't hold a lot of PII. So let us start out with the E1. Let's traverse up. We start out with an E1, we go to an I1, then we go to an R2 as our risk profile changes. And we do have a lot of organizations. That's the beauty of hitrust, is that it allows that reversible nature of assessment. Right. Everything that you do for an E1 is not lost when you move up the ladder.

Speaker B: So start small and build as your advice on that.

Speaker C: Yes. Now I mean the other angle which we also see is organizations that are already, they're that enterprise level, their internal compliance program is already very mature. They've done all the other frameworks under the sun, right? Soc, ISO, HIPAA, uh, PCI, FedRamp, what have you. And now they're like trying to sell into the healthcare space. They're like all right, we gotta get an R2 or maybe it's a regulation, right. It's a uh, stipulation from their stakeholders to say that you directly need to go to an R2, then what do you do? Uh, it's gonna take some time for you to get there cause Hitrust is a pretty uh, stringent audit. They, the R2 is, that is, and so it's going to take time but we see organizations of both sides.

Speaker B: So Hitrust version 11.5 noted continued consolidation of requirement statements and introduced updated multiple authoritative sources including items tied to secure AI system development and govramp naming. When you see these updates for V11, what practical changes do teams need to make in their day to day security and compliance operations in order to, to keep the pace especially in healthcare environments with lots of vendors and inherited controls.

Speaker C: Yeah. So let's take a step back, right? So Hitrust, when it was incepted the original one, the R2 back in 2007 Hitrust was just a, ah, amalgamation of all these other frameworks that already existed. You talk about ISO, you talk about NIST. And so within the R2 or within the Hydro CSF there are a lot of other authoritative sources that you can attach to your existing baseline assessment. So if you're doing an R2 you can attach, right. Uh, you can pick for example GDPR or you can pick like a FedRamp 20x as part of your hydros assessment. So a lot of these changes that you see within 11, 11.1 now we are all the way to 11.7. They're doing a couple of different things. A, they are maybe ingesting a new authoritative sources, right? The one when we went from 11.6 to 11.7 I think I saw a few authoritative sources from India that was uh, that was ingested into the CSF. There was one from UK when they went from 11.5 to 11.6 it was, you know, it was a couple from Abu uh, Dhabi, what have you. So that's one, the other two, they're always Consolidating requirements, they are decommissioning requirements. They are maybe bringing on different, you know, requirements as well. So what does that truly mean for the organizations that are going through the audit is a couple of things, right? One, if you are those organizations that are not only doing the baseline R2E1 or the i1 that you are also ingesting one of these regulatory factors that I mentioned, well, if there have been changes to that, you need to go back and see. All right, I'm ingesting all of these new controls into my audit. Do I have the documentation? Do I have the artifacts? Do I have the controls in place that map to these new requirements? Because what. So it requires a very meticulous due diligence on behalf of the organization to go back and say, all right, I do have coverage from a policy, from a procedure, from an implementation standpoint for all these new requirements that have been added. That's number one. Number two, a lot of the organizations that go through the audit, especially now, if you were like a business associate, you were getting your SaaS platform certified, very likely those platforms are hosted in one of the big cloud service providers infrastructure, aws, Microsoft Azure, Google Cloud. Right? So if you are ingesting new controls into your assessment, then if there are some requirements that you have historically inherited from these cloud service providers, well, you need to go back and check. Well, can you do the same for these new delta requirements? And if the answer is no, then you need to find alternative paths to ensure the coverage is there. Right? So those are some of the due diligence that you need to happen. So, uh, my recommendation would be for organizations to read up on what's going on. Ask your auditors. That's what they're there for, right? They're the experts. They're the SMEs. Ask them what's really changed from between the versions. We put out a lot of information on our website, align.com I, uh, do a lot of these quick videos, uh, that I post on YouTube when things change. So definitely keep up on what's going on so that when the time for the audit comes, you're not blindfolded.

Speaker B: You just mentioned sort of organizations not duplicating their work to meet regulatory requirements. But how do they avoid duplicative work across these two certifications and how do they sort of maximize the outcome of this process? I mean, to your point, the most successful organizations are the ones that do this sort of programmatically and build it into other things. So what do you encourage organizations to do to ensure that the outcome is real security and risk reduction versus a certification.

Speaker C: Yeah, I think it goes back to treating, uh, really building a compliance program as opposed to start chasing audits. You should not have one strategy to go obtain a SOC report. You should not have another strategy to go obtain a hiker certification or a fedramp or what have you. I was just on a panel a couple of weeks ago at Vive. I interviewed the uh, CIO and assisto of Butterfly Network and we're talking about this on stage. And Butterfly Network, just for a background, they have completed nine different audits, nine different attestations and certifications in the last five quarters with a team of five people total. Right. So I asked Mike, who's the CISO and the cio? I said Mike, I mean how does one thread the needle of accomplishing as much as you have and while doing that so successfully and leaning on a very small group of people that's doing that. And so what he said was very interesting. Right? He said a couple of things. One, you need to design a program which is holistic. It's a holistic compliance program which requires coming up with defined processes. But then really now relying on technology, the technology has come a long, long way in the last two years, you know, let alone um, the last 10 years. Right. Because of now with the integration of AI, there are so many different GRC platforms now. Vanta Drata Secure Frame Audit Board I could name on and on and on. That really helps you automate a lot of different processes. You know, it's no longer uh, you know that you're in this audit fatigue throughout the year. You gotta build a very robust compliance system where all different frameworks are cross mapped to one another. You have pointedly found out what those synergies are between each of the framework. You've aligned the timelines of each of these audits. And after that you let the process work itself. And that's how you go from being in this audit, perpetual audit cycle to obtaining results without spending uh, an enormous amount of resources. And so that's probably what I would say is that there's not been a better time where for organizations to say, you know what, we can really do this, we can achieve so much work from a compliance, from a security level because the tools do exist.

Speaker B: Yeah. So, and hitrust is actually expanding ways that organizations can translate these assessment results into mapped reporting. Can you explain what that means? A little bit.

Speaker C: So there you go through an E1, I1 or an R2 assessment. Right. Those are the three baseline assessments that Hydros offers. And there are, like I mentioned earlier, there's different regulatory factors there. So let's take a very simple example, which is hipaa. There are a lot of organizations that are, uh, working in the healthcare space. They absolutely, it's a law that you require HIPAA report. And so what you can do is you can ingest those HIPAA controls as part of your HITrust assessment. And then what Hydros does is they strip out, which they call a, uh, inside report, which you've gone through the Hydros assessment, which had all the HIPAA controls already embedded in it. So the testing is already done. Now all you need to do is reach out to Hydros and export that report and utilize that report to satisfy your stakeholders who are asking for hipaa. And that goes on for, you know, other frameworks as well. But that's just a true example of audit once, report multiple times. That's the forte. Because why duplicate the work when there's no absolute need to do so?

Speaker B: Awesome. So, all right, as we move in healthcare and really across industries into more AI, right, we've got AI is basically at every intersection, everywhere. And the level of continuous data movement and automation is just, it's happening so fast and it's so wild. Uh, the scope of what this is going to do for healthcare organizations and just for patient outcomes in general. What is one move that you would suggest any of your organizations make to be ready for this future of AI, uh, enabled everything?

Speaker C: That's a million dollar question. Right? So I'll start by saying you're absolutely right. Things are changing so fast. You know, the change in AI is just unprecedented. Of everything that we see, you know, what has come out in the last month, let alone in the last year, there's so much changes that are happening in the landscape. And so my biggest recommendation would be have a AI plan. You need to have an AI governance plan internally. Whether that's a big need or not, that's a big ask from your stakeholders or not at this point of time is irrelevant. The risk exists. AI, ah, is not going anywhere. It is the present, it is going to be the future. So it all starts out by ensuring that you have a policy and a procedure in place of how you're going to govern all, uh, the risks that are associated with AI. Now the risk may change over time and we expect them to change. But at least if you have a framework where you know exactly how individuals within your organization are using AI, then you can, it's a lot Easier for you to maneuver when things change. But if everything is happening, uh, willy nilly people are, you know there's a lot this concept of shadow AI where people are just going out of governance to, they're just putting things, sensitive information on ChatGPT or Copilot, absolutely not knowing where that's going. Let's not do that. And so now there, there, now there are a couple of tangible things I'll point out that organizations can do. So so far There is a ISO 42001 certification that's out there that a lot of our customers are already performing. Right. It looks at the AI from uh, a governance standpoint. And then hitrust also has a AI cybersecurity assessment that it has started to offer as starting last year. So my recommendation would be to go through those audits because that is like, you know, because Hytrus is a very comprehensive and a robust framework. The controls are extremely prescriptive. And so that is going to help you from ensuring the systems that are in your organization that hold these sensitive information that utilize AI, that there are proper guardrails around it so that the risk exposure is mitigated long term. So don't wait because AI seems such a buzzword, but I think it's real, it's happening right now, it's going to happen in the future. I think uh, it bodes really well for companies to be proactive and how

Speaker B: can organizations get in touch with you or learn more about the services that Align provides to help them get ready for this?

Speaker C: I think align.com would be the best approach. Uh, we're on LinkedIn. Uh, we post everything on LinkedIn. We have a YouTube channel, you guys can check that out. We offer basically everything from SOC, ISO, PCI, FedRamp, Hitrust, HIPAA. Uh, so we're a one stop shop that does audits for organizations and you know, we can help you really enhance your security posture.

Speaker B: Thanks so much for your time today, really appreciate it.

Speaker C: Thank you Sandy. Thanks for having me.

Speaker A: Hey, if you enjoy listening to this podcast, be sure to check out all the content around data innovation in 520 by visiting health.com that's HLTH.ah com from there go to the Events tab and you will find recordings of nearly 100 case study presentations, podcasts like this and white papers presented by leading technology solution providers. Be sure to subscribe so that you don't miss the next vive event presented by Health and Chime.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • CMMC Is an HR Problem, Not an Enclave Problem - Here's the ProofSecure Talk Podcast · on ISO 2700195 / 100
  • The $443 Billion AI Lending Bias: Why 65% of Good Customers Get Declined | Carla Canino, Founder and CEO KindleePurpose Driven FinTech · on ISO 2700185 / 100
  • Justin Greis: AI Meets CybersecurityKitecast · on SOC 285 / 100
  • AI Governance Essentials: Navigating Security and Compliance in Enterprise AI with Walter HaydockCyber Sentries: AI Insight to Cloud Security · on HIPAA85 / 100
  • The four phases of a CMMC assessmentTrust Issues · on FedRAMP84 / 100
  • Sean Falconer - SkyflowDemand Generation Club Podcast · on HIPAA80 / 100

More from Cybersecurity at ViVE Podcast

All episodes →
  • Trust, Verify, Repeat: Securing Healthcare in the Age of AI Voices 62 / 100
  • Security vs. Convenience: Can Healthcare Have Both? 44 / 100
  • Rethinking Network Defense in Healthcare 59 / 100
  • Why Healthcare Organizations Are Losing the Cyber War (and How to Fight Back)66 / 100
  • Why Healthcare Needs Cyber Resilience, Not Just Cybersecurity
All Cybersecurity at ViVE Podcast episodes →