The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Cybersecurity at ViVE Podcast
Cybersecurity at ViVE Podcast artwork

Security vs. Convenience: Can Healthcare Have Both?

Cybersecurity at ViVE Podcast · 2026-05-27 · 20 min

0:00--:--

Key moments - from our scoring

Substance score

24 / 100

Five dimensions, 20 points each

Insight Density5 / 20
Originality4 / 20
Guest Caliber5 / 20
Specificity & Evidence6 / 20
Conversational Craft4 / 20

Chandra Melalee Durai, chief evangelist for cybersecurity solutions and digital signatures at Zoho Corporation, explores how healthcare organizations can achieve security without sacrificing employee productivity. With 15% of Zoho's customer base in healthcare, the conversation centers on the persistent tension between IT administrators demanding tight security controls and employees seeking convenience - exemplified by the 2024 Change Healthcare breach, which occurred because a single compromised account lacked multi-factor authentication. Durai discusses Zoho's approach to passwordless authentication via passkeys, single sign-on (SSO), biometric verification (face ID, touch ID), and integrated password vaulting that reduces login friction while maintaining compliance with FDA 21 CFR Part 11 requirements. The episode covers practical implementation strategies including Zoho Directory for identity and access management, role-based and time-based access controls, behavior threat analytics powered by AI, and seamless onboarding/offboarding workflows. For healthcare CIOs and security leaders evaluating identity solutions, Zoho Marketplace bridges, and workforce management platforms, this discussion provides specific guidance on reducing the 7,000 password attacks occurring per second while keeping clinicians and administrative staff productive.

Key takeaways

  • →The Change Healthcare breach demonstrates how a single compromised account without MFA can expose millions of records, emphasizing that even one weak security implementation point can be catastrophic.
  • →Passwordless authentication using passkeys and biometrics (face ID/touch ID) can reduce login time by 30% while improving security by eliminating traditional password vulnerabilities.
  • →Zoho's identity and access management platform integrates with existing Microsoft and legacy systems through APIs and bridges, allowing organizations to implement role-based and time-based access controls without complete infrastructure replacement.
  • →CIOs should start with environmental scanning and a phased 0-3 and 3-6 month adoption plan for AI security tools rather than adopting all features immediately, while establishing responsible AI policies.
  • →Seamless SSO integration combined with MFA and password vaulting can eliminate the 10-second friction penalty that causes employees to disable security measures.

In this episode

  1. 1Introduction to Zoho's Healthcare Solutions
  2. 2The Security vs. Convenience Tradeoff in Healthcare
  3. 3The 2024 Change Healthcare Breach and MFA Importance
  4. 4Reducing Friction with Passwordless Authentication and Passkeys
  5. 5Identity and Access Management for Employee Onboarding and Offboarding
  6. 6Implementing Security Solutions in Legacy Healthcare Environments
  7. 7AI-Driven Security Analytics and CIO Recommendations
  8. 8Getting Started with Zoho Solutions

Mentioned

Zoho CorporationManageEngineChandra Melalee DuraiSandy VanceZoho SignZoho VaultZoho DirectoryZoho PeopleFIDOChange HealthcareMicrosoft Active DirectoryEntra ID

Guests

Chandra Melalee Durai

Topics in this episode

Microsoft Entra IDMulti-factor authentication (MFA)PasskeysZoho CorporationZoho VaultZoho DirectoryManageEngineChange Healthcare breachFIDO passwordless authenticationActive Directory

Questions this episode answers

What caused the 2024 Change Healthcare breach and how could it have been prevented?

The breach occurred because millions of data were compromised through a single account that lacked multi-factor authentication, allowing attackers to penetrate the network and steal millions of confidential records. Implementing MFA on that one account could have prevented the entire incident.

How can healthcare organizations implement multi-factor authentication without adding 10+ seconds of friction per login?

Zoho recommends tightly integrating password vaulting with MFA using single sign-on (SSO) and biometric authentication (face ID, touch ID), enabling seamless, passwordless login mechanisms that eliminate additional friction while maintaining security.

What percentage of users save login time when switching to passwordless authentication with passkeys?

According to Zoho's data shared with the FIDO organization, more than 30% of end users save login time monthly when offered secure, convenient passwordless authentication via passkeys, with over 40% of organizations moving from password-based to passwordless authentication.

How does Zoho Directory integrate with existing Microsoft Active Directory and Azure environments?

Zoho Marketplace and Zoho Directory bridges enable healthcare organizations to sync their existing Active Directory or Entra ID with Zoho Directory, automatically provisioning and deprovisioning users across both systems without requiring a complete migration.

What is Zoho's approach to AI adoption in identity and access management for healthcare?

Rather than pushing all AI features immediately, Zoho recommends CIOs first scan their current infrastructure, start with basic AI capabilities (like automated password resets), educate users, establish AI responsibility policies, and adopt AI incrementally over three to six months with proper training and governance.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

5 / 20

The episode is almost entirely recycled cybersecurity hygiene 101 (don't reuse passwords, use MFA, do SSO) with a thin vendor product pitch layered on top. The Change Healthcare reference adds momentary grounding but is not analyzed beyond 'they lacked MFA,' and the AI advice boils down to 'start slow and have a plan.'

the major problem is uh, the trade off between security and convenience I would say
don't just go with the bus. First, understand your environment. See what works best for your company.

Originality

4 / 20

Every framing here - security vs. convenience, password reuse is bad, passkeys are the future, AI needs responsible adoption policy - is standard vendor-conference boilerplate. There are no contrarian arguments, no first-principles reasoning, and no counterintuitive claims anywhere in the episode.

the most reused password or the most used password, they come up with this password. 1, 2, 3 or uh, admin123test123. These are all the passwords that come up every year that are topping the charts every single year
we see more than 40% of organizations are moving from password based authentication to passwordless authentication

Guest Caliber

5 / 20

The guest is Zoho's chief evangelist - explicitly a marketing and product strategy role, not a practitioner CISO or security engineer who has built or defended these systems at scale. The guest self-identifies as a marketer mid-episode, which explains the product-pitch tone throughout.

Chandra Melalee Durai, who is the chief evangelist for cybersecurity solutions and digital signatures at the Zoho Corporation
Mellie brings over 12 years of experience. Uh, you've been in this space as a leader of marketing and product strategy at Zoho

Specificity & Evidence

6 / 20

A small number of real statistics appear (7,000 password attacks/second in 2025 vs. 4,500 in 2024; 30% login time savings; 40% passkey adoption) but they lack sourcing, methodology, or named customers. The guest explicitly refuses to name any client, and the Change Healthcare example is surface-level and publicly known.

the number of password attacks Per second is 7000. In 2025 it is 7000 password attack per second. In 2024 it was somewhere around 4500 per second
we see more than 30% of end users are able to save the login time in most of the organization every single month

Conversational Craft

4 / 20

The host asks purely product-enabling questions with zero pushback, no probing follow-ups, and no challenging of unsourced statistics. The conversation functions as a vendor demo script rather than an interview, and the host openly validates every claim the guest makes.

That never happens, right? Like who does that? Yeah, we all, it's crazy to think about like how important that one little thing is
Sandy Amazing. So as you go into work with healthcare organizations, how difficult is it to implement solutions like this?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Chandra Melalee Duraiguest78%
  • Sandy Vancehost18%
  • Narrator4%

Most-used words

zoho41access24healthcare22password22authentication17offer15management15security15data12today11system11solution10employee10sandy9directory9single9

Episode notes

Workforce security in healthcare is no longer just about compliance - it’s about creating a seamless, secure digital experience for employees and patients. In this episode, host Sandy Vance chats with Chandramouli Dorai , Chief Evangelist - Cybersecurity Solutions and Digital Signatures at Zoho.com . Today, they will explore how password management, secure browsers, multi-factor authentication (MFA), identity and access management (IAM), and identity verification in document signing all come together to build a zero-trust, future-ready healthcare workforce. Healthcare organizations are under constant pressure to strengthen cybersecurity without slowing down clinicians and staff. In this episode, they talk about: Healthcare organizations face a constant challenge in balancing strong cybersecurity protections with the need for convenience and productivity. Weak and reused passwords remain one of the most common vulnerabilities across organizations, despite years of awareness efforts. The 2024 Change Healthcare cyberattack demonstrated how a single account without multi-factor authentication can lead to massive data breaches and operational disruption.

Full transcript

20 min

Transcribed and scored by The B2B Podcast Index.

Narrator: Welcome to the Cybersecurity at Vive series on the Beat podcast, where we break down the fast moving world of cybersecurity and what it means for your healthcare business, your data and your everyday life. In this series, we'll go beyond the headlines to explore real threats, real defenses, and the people on the front lines keeping our digital world secure. And now your host, Sandy Vance.

Sandy Vance: Hey everybody. Welcome back to the Cybersecurity at Vive podcast series on the Beat. I'm your host, Sandy Vance, and today I'm here with Chandra Melalee Durai, who is the chief evangelist for cybersecurity solutions and digital signatures at the Zoho Corporation. Thanks for being here today. Welcome.

Chandra Melalee Durai: Thank you for the introduction. Thank you for the opportunity to be with you here today.

Sandy Vance: You got it. So Mellie brings over 12 years of experience. Uh, you've been in this space as a leader of marketing and product strategy at Zoho. Tell us, what is it that Zoho does in the healthcare space?

Chandra Melalee Durai: Zoho.com, so we offer 50 different solution. If someone lands on Zoho.com, our vision is to help them run their entire business operation online. With Zoho.com especially for healthcare, we have a healthcare vertical focus CRM and we also have all the supporting uh, software services to run a uh, healthcare service. So we have uh, the project management software, we have the scheduling software, we help with online meetings and uh, we also help you with the payment collection and accounting. And especially with Zoho sign, we have FDA compliant 21 CFR part 11 digital signatures that matters most for the healthcare business. Sandy. So Zoho is the part of the cloud offering from the larger Zoho Corporation. We also have our sister division called ManageEngine where we offer more than 50 different IT management solutions that also offers larger security solution, endpoint management, network management, privileged access management, AMD active directory management and things like that. Zoho Corporation, under Zoho.com and manageengine, we offer one of the broadest portfolio for the business operation wing and also for the IT management and cybersecurity.

Sandy Vance: Uh, awesome. So what percentage of your business would you say is in healthcare? In the healthcare space? How big are you guys in healthcare?

Chandra Melalee Durai: So we have more than uh, 15% of our customers from the healthcare vertical. And the largest names uh, are uh, from the North America, followed by uh, UK and the Euro. And in the Middle east we are seeing a huge traction. Yes, healthcare is one of the fastest growing vertical for Zoho Corporation. As a whole, which includes both Zoho.com and ManageEngine.

Sandy Vance: Fantastic. So today we're gonna talk about how you guys are facilitating workforce security in healthcare. Because this is uh, becoming I think a bigger and bigger deal with compliance issues and just helping organizations create a seamless, secure digital experience for their employees and patients. So you all handle everything from password management to secure browsers, uh, MFA multi factor authentication and identity and access management. Can you talk a little bit about what it looks like for healthcare provider organizations to build a sort of future ready healthcare ecosystem for their workforce.

Chandra Melalee Durai: So when it comes to uh, workforce security specifically for healthcare vertical, I would not just directly jump into something technical. Today all we need is behavioral change. Especially uh, most of us, all of us are a human being. So we tend to have a weak password for fewer cons, which we use regularly. And the habit that we all got is we reuse this password for multiple account. So this is very common among.

Sandy Vance: That never happens, right? Like who does that? Yeah, we all, it's crazy to think about like how important that one little thing is like, but I think we all are doing that in different places, right?

Chandra Melalee Durai: Every year, uh, when the security audit happens and the IT admin who runs the uh, security operation in your company, the most uh, reused password or the, the most used password, they come up with this password. 1, 2, 3 or uh, admin123test123. These are all the passwords that come up every year that are topping the charts every single year. On the other end, IT admins are uh, doing the best, doing a uh, very hard job to protect the IT environment, critical infrastructure, confidential data and things like that. So there are two sets of people. On one hand, people are very uh, uh, not okay to change their behavior. On the other side there is a group of people who are very paranoid about security to protect the business data at all costs, failing which the company is going to pay a huge fine. The greatest example is the 2024 change healthcare breach which happened because millions of data uh, got breached because one compromised account, that one account lacked multi factor authentication which was a loose end. And the attacker was able to get into the network and get away with millions of confidential records, which again breached a lot of complaints which became a huge, huge loss for the company. And also the personal data of millions of uh, end users are addressed. So things like that. So uh, the major problem is uh, the trade off between security and convenience I would say. So the IT admins want more tighter security, employees are seeking the convenience. So that is exactly where um, we see the major challenge.

Sandy Vance: Sandy for sure. So I mean I think when you state it the way that you did, like this change healthcare thing may not have happened if that one user would have had multi factor authentication, that really puts the things in perspective. You know we have tools like password managers and multi factor authentication and we all know that they work to improve security. Right? But I think there are also a lot of challenges with that because when especially you're logging into, you know, 10 systems an hour for your job, it can cause a lot of friction. So how can organization use these tools without adding friction to healthcare staff who are already overburdened?

Chandra Melalee Durai: Good question. So uh, in the last year the number of password attacks Per second is 7000. In 2025 it is 7000 password attack per second. In 2024 it was somewhere around 4500 per second. So every single layer the number of password attack is increasing in a huge margin. But uh, when it comes to the productivity and the friction that you said, most of us are not okay to have a multi factor authentication on top of our everyday accounts because it uh, increases maybe 10 seconds extra to log in one single account. If we are going to jump between multiple account to get our job done, this is going to add a lot of time loss to an average employee. So what happens is they remove the MFA from their everyday apps so that they get easy login access to the system. So what as ah, a vendor or what technology companies like Zoho and Manage Engine should do do here is we should tightly integrate our login system and MFA together but via single login sso. The password vaulting solution and the multi factor authentication should do a uh, seamless login mechanism maybe via face ID or touch ID to make it seamless without having an additional friction. Maybe add another 10 seconds. Not uh, to open an app manually, do uh, something else but this is something uh, seamless. We can make use of the biometrics, we can make use of the face ID and touch ID and make it simple for the end users so that they don't skip the multi factor authentication part but they make it easier but also secure the data without compromising their productivity. That's what we are trying to do Sandy, with password vaulting and MFA tightly integrating with each other and without compromising on trading off between security and convenience.

Sandy Vance: So do you have a favorite case study or uh, maybe a client story where you've been able to implement this and help an organization become more secure without. I don't want to say upsetting employees but with satisfied employees.

Chandra Melalee Durai: So uh, uh, I would give uh, you a quote that we shared with the FIDO organization. Uh, Fido is something uh, Zoho has recently become a member with as a company. We also want to offer passwordless authentication. We also move away from the traditional password based authentication to pass keys and passwordless authentication. So what we see is when we started to offer them a secure, convenient passwordless authentication mechanism like passkeys, uh, we see more than 30% of end users are able to save the login time in most of the organization every single month. We see more than 40% of organizations are moving from password based authentication to passwordless authentication. I don't want to name one single company here but uh, the industry is moving towards uh, the passwordless authentication mechanism which kind of makes them to not trade off between security and convenience. Because passkeys today replace traditional password. It is tied to a device you need to do face ID or touch ID so that you get access granted to your role based system or time based access and things like that. So this is what we are seeing and we are seeing some good traction for passkeys, uh based authentication. And uh, most of our customers are from the regulated industries like healthcare, insurance and uh, fintech. So this is what we see in terms of adoption.

Sandy Vance: Can you talk about the role that Zoho can play in helping organizations have tighter identity and access management and how that helps to streamline onboarding and offboarding of staff in hospitals and clinics and why that's so important?

Chandra Melalee Durai: Uh, as I stated in the initial part of our conversation, Zoho offers you both the business operation platform and also the IT management platform together under the Zoho Corporation umbrella. So we do offer them the most uh, comprehensive HRMS solution which we call it as Zoho people. When we onboard a new employee and when a new assert is granted to an employee, we share the credential uh via Zoho Vault which is our password vaulting solution. By this way, when a new employee gets onboarded, usually what happens is this machine password is printed and pasted on that laptop, uh and the employee get access uh to the corporate network and all the information that they need to get started. Uh, this is the fundamental break in the chime where the password gets exposed in the plain text. We want to start uh from the first point where we offer password vaulting right from the employee onboarding. Once this employee is onboarded and he becomes part of the active directory or uh, the entra ID or one login or any system of truth that they have. We uh also have an alternative called Zoho Directory which is our own workforce identity and access management solution. So we work with both Zoho ecosystem and also third party ecosystem. We have Bridges and Marketplace to connect with them. Uh once the employee is onboarded they are of offered with the uh provision with the right set of apps and devices based on their roles and responsibilities. So if I am someone in marketing I get access only for the marketing websites. I don't get access to the financial website that is very very critical. So I get role based access and I also only get time based access. My access to the system will only be between 9am to 5pm If I try to access a critical information beyond this time limit from a different location. Say for example someone from Tex, uh, he can only log in into the Zoho system only between 9am to 5pm only from this particular Texas location. If the system is noticing uh a uh login activity from India or Japan the system is going to trigger an alarm to the admin to terminate the suspicious activity. So this is what we are trying to do with AI. We are embedding AI into the identity and access management platform which kind of offers you behavior threat analytics without even you notice that have AI playing with you. Uh that is how we are trying to embed AI to offer real value to the end organization. When we offboard users we also terminate the sessions uh from one single source of truth which is the identity and access management platform which is Zoho directory. Once this access is terminated the employee cannot no longer access any confidential data or any other apps um from that single ah second so the password gets terminated, they cannot log into the work drive files, they cannot access critical files and um, by this way the employee onboarding and offboarding gets easier and the employees can also access to all these apps with single sign on and multi factor authentication enforced on top of it. This is how we help regulated uh industries to offer security and convenience hand in hand.

Sandy Vance: Sandy Amazing. So as you go into work with healthcare organizations, how difficult is it to implement solutions like this? I mean do you usually find that when you go in you're sort of starting with nothing or are you working with legacy systems? And what's sort of the starting point when someone wants to take control of these security problems?

Chandra Melalee Durai: M We see most of the regulated customers and healthcare customers they come from the Microsoft environment or the legacy infrastructure they are particularly uh, currently using with. So what uh Zoho offers them is the Zoho Marketplace and the Bridge that kind of helps them to bridge their existing environment with the Zoho Ecosystem. Okay, you have Entra ID or Azure or Active Directory, that is okay. You can still uh, import your users into Zoho Directory and you can create a sync and bridge. So your system and the Zoho ecosystem works hand in hand. So if you are going to add a user into your active directory, Zoho knows it and it is always in sync. And when you are going to remove this particular user from your existing traditional uh, system, Zoho also knows and terminates the user access immediately once you are offboarding a user. So the Zoho Marketplace and the Zoho Directory Bridge plays a crucial role here. By this way we are able to uh, offer our workforce security solutions uh, to the traditional environment. And if someone is willing to embrace the new Zoho Directory workforce identity and access management platform itself, we can also totally replace them from the traditional system into the Zoho environment as well. They can plug and play Zoho with their existing environment or they can totally move to the Zoho environment. We offer them both the choices.

Sandy Vance: Sandy, as you look to the future and what AI has to offer these security solutions in terms of the analytics and, and auditing how things are doing and maybe catching things that a human wouldn't catch in terms of being able to see patterns and logins and that sort of thing. What advice do you have for CIOs to take advantage of these tools?

Chandra Melalee Durai: I would say, uh, don't just go with the bus. First, understand your environment. See what works best for your company. First start with scanning your environment, how your current authentication and identity framework works in your company. Once you have a solid picture of how your current scenario is and then take or maybe have a plan for the first three months. Start with what will be the basic AI features that you can use. Maybe you can have an AI feature, uh, that can help you to pull information across your infrastructure. If someone uh, is going to reset a password, they don't need to go and ping an admin at 1am to get access to that mission. You can automate, uh, a couple of things between your help desk and the password vaulting solution. If the ticket ID is valid and genuine, you can automatically grant access. Things like that. Start with the basic that works for your company. And uh, do not go overboard, uh, just uh, the industry is going behind the A.I. stuff. Uh, you need to know where your company stands in terms of AI adoption. First you need to educate your users Train them. And you also need to have an AI responsible policy within your company. So your end user should know whether they are using AI, uh, with the right company policies and procedures in place because they are going to handle your customer data, they cannot just randomly plug and play with the customer data with any AI tool that they want to use. So this is going to put the company data and also the end user data at risk. So I would say uh, have a plan, scan your current infrastructure, start slow, have a plan for zero to three months and from three to six months and then expand. So it also depends on how much of training materials that you can offer to your company as well. So you need to have the right set of uh, resources, time and the long term plan for your company to begin with. Sandeep, that is what practically we tell our customers to start their AI journey. We don't just push because we are adding more AI features to our stack. As a marketer I would love to have all my customers use the AI feature. But uh, when it comes to consulting and when we work with customers hand in hand, we tell them okay, AI is all cool but you know where you stand today and then take it slowly, have a faced adoption and then go from there.

Sandy Vance: And how can folks get in touch with Zoho or learn more about your organization?

Chandra Melalee Durai: Just land to zoho.com so we have a very pretty website that offers all the tools that we have today, uh for the healthcare institution and also for businesses from any vertical. So the easiest way is just write to salesoho corp.com from there we can take you, we can start with a demo session, we can uh, understand your current business requirement and we can match you with the right solution that we have today. So today Zoho can offer you uh, uh, starting from solving your business operation problem to the IT infrastructure. So we want to first hear from the customer why they are here, what problem they want to solve, we want to listen and then offer them the right solution under the Zoho Corporation umbrella.

Sandy Vance: Sandy, thank you so much for your time today Mel, we really appreciate the conversation.

Chandra Melalee Durai: Thank you very much Sandy, thank you for the opportunity. Uh, very happy to be here along with you and um, share our thoughts.

Narrator: Hey, if you enjoy listening to this podcast, be sure to check out all the content around Data innovation in Vive 2026 by visiting health.com uh, that's HLTH.com from there go to the Events tab and you will find recordings of nearly 100 case study presentations, podcasts like this and white papers presented by leading technology solution providers. Be sure to subscribe so that you don't miss the next VIVE event presented by Health and Chime.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • We can't - and shouldn't - fix everything [The Industrial Security Podcast]The Industrial Security Podcast · on Change Healthcare breach95 / 100
  • Aaron McCray: Ferrari Security: Speed With GuardrailsKitecast · on Multi-factor authentication (MFA)88 / 100
  • Stop 90% of Ransomware Attacks with Basic Cyber HygieneThe Backup Wrap-Up · on Multi-factor authentication (MFA)82 / 100
  • How to Talk About Cybersecurity to Clients & Prospects with Mark Lamb from HighGround.iothe RocketMSP Podcast · on Multi-factor authentication (MFA)82 / 100
  • Treat AI agents like human employeesTrust Issues · on Microsoft Entra ID80 / 100
  • AI-Powered Forensics: How Attackers Automate BreachesCloud Security Podcast · on Active Directory78 / 100

More from Cybersecurity at ViVE Podcast

All episodes →
  • Trust, Verify, Repeat: Securing Healthcare in the Age of AI Voices 62 / 100
  • Rethinking Network Defense in Healthcare 59 / 100
  • Compliance Isn’t Security: The Biggest Cybersecurity Myth in Healthcare (HITRUST Explained)78 / 100
  • Why Healthcare Organizations Are Losing the Cyber War (and How to Fight Back)66 / 100
  • Why Healthcare Needs Cyber Resilience, Not Just Cybersecurity
All Cybersecurity at ViVE Podcast episodes →