A cybersecurity expert has outlined key questions hospital CISOs should pose to healthcare fintech vendors to assess their security posture, particularly concerning patient data and financial transactions. Drew McCombs, who holds both CTO and CISO roles at Cylerity, emphasizes that security should be an integral part of development processes, not an afterthought, especially when patient data or funds disbursement are involved.
McCombs highlighted that his company, Cylerity, operates as a funding provider for healthcare organizations through a bank credit facility, serving businesses rather than consumers. This distinction means that while core banking regulations don't apply directly, the partner bank's expectations are conveyed through credit agreements and due diligence, covering customer types, fund movement, reporting, and audit capabilities. A critical area of focus is collateral, as Cylerity lends against healthcare claims that contain Protected Health Information (PHI). To manage this, Cylerity employs a strategy of using the minimum necessary data, providing summarized information at the payer or customer level, and creating unique identifiers for claim-level details to prevent PHI exposure to banking partners. PHI is consistently kept separate from financing data across their platform.
When it comes to artificial intelligence, McCombs insists on a strict "human-in-the-loop" control. AI models are permitted to recommend, summarize, or flag information, but a human must always be involved before any action is taken that could release funds or expose patient data. This approach integrates AI insights into underwriting and monitoring processes, providing teams with more information for decision-making without relinquishing human oversight. Explainability is crucial, with models required to show the source data for their recommendations, allowing human reviewers to verify against original sources rather than the model's self-explanation. To combat "gradual drift" where reviewers might become complacent, multiple individuals are involved in decisions, and regular post-decision reviews are conducted.
For small practices, a common and easily rectifiable weakness is the underutilization of multi-factor authentication (MFA). McCombs stresses that enabling MFA, particularly for email, is the most impactful and cost-effective fix, as it is often already included in existing email services. This measure significantly reduces the risk of account takeover and payment fraud. Furthermore, Cylerity actively monitors customer claims and funding activity for unusual patterns and confirms all deposit account changes via a pre-registered phone number, never one provided in the change request.
McCombs proposes three essential questions a hospital CISO should ask a fintech vendor. First, "Can you list every party that touches our data, including subprocessors, AI services, and any financing partners or their auditors?" A vendor's inability to quickly produce this list indicates a lack of awareness regarding data flow. Second, "How do you verify a change to where funds are sent?" The desired answer should detail an unskippable, out-of-band confirmation step, rather than a vague statement about careful review. Finally, "Walk me through the first 24 hours after you discover a breach involving our data. Who calls whom?" CISOs should seek specific names, roles, and timelines, not just a policy document.
A definitive red flag that should prompt a CISO to disengage from a vendor is the claim, "We're HIPAA certified." McCombs clarifies that no official HIPAA certification exists, indicating either a misunderstanding of the regulations or an attempt to mislead.






