Health-e Law Podcast Ep. 27
Emerging Cybersecurity Threats in Healthcare with Erik Pupo
Thank you for downloading this transcript.
Listen to the podcast released July 16, 2026, here:
Welcome to Health-e Law, Sheppard’s podcast exploring the fascinating health tech topics and trends of the day. In this episode, partner and host Sara Shanti sits down with Erik Pupo, Director of Commercial Health IT at Guidehouse, to discuss how healthcare’s push toward greater connectivity and data sharing creates new cybersecurity risks, and what health systems need to do to stay ahead of emerging threats.
About Erik Pupo
Erik Pupo has spent more than 25 years advising healthcare organizations on technology, cybersecurity and business transformation. As Director of Commercial Health IT Advisory at Guidehouse, he helps healthcare organizations modernize their IT infrastructure as a principal strategist in cloud, security, data and AI.
Prior to joining Guidehouse, Erik served as Global Principal Practice Manager for Healthcare Cybersecurity at Amazon Web Services, helping health systems navigate the security challenges of moving critical infrastructure to the cloud. Before that, he served as Chief Information Officer at Columbia University Irving Medical Center, leading IT strategy and operations for one of the nation’s most complex academic medical environments.
Earlier in his career, Erik spent nearly a decade in global consulting, first as Senior Manager at Deloitte, where he led health IT initiatives for the Office of the National Coordinator for Health IT, the Department of Defense, and the Department of Veterans Affairs. He later served as Managing Director at Accenture, where he led strategic and technological transformation initiatives for providers, payers, and life sciences companies across North America.
About Sara Shanti
A partner in the Corporate practice group in Sheppard’s Chicago office and co-lead of its Digital Health team, Sara Shanti’s practice sits at the forefront of healthcare technology by providing practical counsel on novel innovation and complex data privacy matters. Using her medical research background and HHS experience, Sara advises providers, payors, start-ups, technology companies, and their investors and stakeholders on digital healthcare and regulatory compliance matters, including artificial intelligence (AI), augmented and virtual reality (AR/VR), gamification, implantable and wearable devices, and telehealth.
At the cutting edge of advising on “data as an asset” programming, Sara’s practice supports investment in innovation and access to care initiatives, including mergers and acquisitions involving crucial, high-stakes and sensitive data, medical and wellness devices, and web-based applications and care.
Transcript
Michael Orlando:
From hospital boardrooms to startup war rooms, this is Health-e Law. Powered by Sheppard’s Digital Health and Innovation team, we bring you quick and candid conversations with industry leaders bringing sharp analysis and critical insights into what’s next.
Sara Shanti:
Welcome to the Health-e Law podcast. I’m Sara Shanti, a partner at Sheppard, and joining me today is Erik Pupo. Erik is the director for commercial health IT at Guidehouse, which is a Bain Capital portfolio company. Guidehouse is a global AI-led professional services firm delivering advisory, technology, and managed services to both commercial and government sectors.
With 23 Best KLAS awards, Guidehouse’s healthcare segment helps providers, government agencies, life sciences companies, payers, and more organize and modernize and innovate the healthcare services space. Erik, a former CIO with Columbia Medical Center and the former director of healthcare cybersecurity at Amazon, has more than 25 years of tremendous viewpoints to share today on cybersecurity and what’s coming to healthcare innovation.
Erik, it is such a pleasure to have you join us. I recently saw a really interesting header saying connectivity also brings contagion, and I think that’s where you come into play. You see a lot of cybersecurity incidents, a lot of interesting attacks and risk factors as this connectivity grows. So you’re really on the ground with hospitals, payers, and some of the biggest tech companies in the world. How would you describe the current situation in the landscape of healthcare and cybersecurity?
Erik Pupo:
It’s definitely been a situation where we see more and more with hospitals and health systems moving faster and faster, and that applies to data, data sharing, the opportunities that are presented with data interoperability with TEFCA, the rules associated with TEFCA, and also HIEs. So what you’re seeing is, you’re seeing a landscape where you’re seeing a lot of initiatives in AI, a lot of initiatives in data, initiatives where certainly there’s modernization efforts going on with electronic health record systems.
And as those proceed, cybersecurity has got to keep up. It’s a challenge of there’s more and more threats. There’s more and more data availability. There’s more and more challenges where you have initiatives that have been put together for AI, clinical AI, for example, in terms of consuming and working with large amounts of data, building models, training models, model inference, chatbots being used, agents being used within hospitals and health systems as an example, and then there’s a whole associated set of issues and risks with AI as you start to roll that out.
So what we see in our landscape is really just everybody moving really fast. Cyber is trying to keep up with that, and organizations that can keep that gap kind of small or closely aligned certainly are much less at risk of cyberattack. There’s nothing in terms of a full environment where you’re ever going to have no issues on cybersecurity, but you’re also seeing this kind of gap opening up with health systems and hospitals that do not have the funding, do not have the expertise in order to keep up with that healthcare cybersecurity landscape.
Sara Shanti:
You mentioned TEFCA, which I know a lot of us who work day in, day out in healthcare are familiar with some of the alphabet soup. Maybe you can just describe briefly how impactful TEFCA is and really what it is at the end of the day.
Erik Pupo:
Yeah. So what we’ve seen with TEFCA is a set of interoperability rules, requirements surrounding data sharing that have really changed, particularly for hospitals and health systems, how they approach and want to approach the areas related to data interoperability to sharing data. So there are requirements in there, for example, to use a standard we call FHIR, which is designed to be more open, API-driven.
We’re able to share information through HIEs and through other forms of healthcare systems much faster, and with that level of speed that’s required and that TEFCA is pushing where you’re seeing more hospitals, health systems share data as part of value-based care initiatives, population health initiatives, their care management programs, care coordination activities.
There’s a need to protect that information, and there’s a need to have in terms of how you focus on your support for TEFCA, in terms of the governance associated with that, in terms of things like bulk export controls, scope of SMART on FHIR, third-party app authorization, because you have more and more apps using data.
There’s a whole set of rules and controls that you build surrounding that, and we’ve seen a gap. I mean, on the compliance side, anytime a new law program, a new initiative gets introduced from the federal side, from the state side, there’s always a gap for our hospitals, our health systems, or our clients to keep up and catch up with that.
So there’s been that gap of how do we handle things like... Hospitals are constantly dealing with this... It’s not even a threat. It’s more of a perception of information blocking. So hospitals being perceived as not willing or able to share healthcare information for patients, whether individually or in groups, to share that with other parties that may want to use that information, and that’s a serious challenge for hospitals, because there’s fines. There’s regulatory action associated with that for information blocking through the Office of the National Coordinator through HHS. They don’t want to have to deal with that.
So TEFCA introduces this challenge of, for example, going back to that landscape, speed. We’ve got to go fast. We’ve got to move. We’ve got to be more open. We’ve got to share. At the same time, we’ve got the cybersecurity angle of we need to make sure we’re doing this in a way that’s very safe in terms of privacy and security controls, and that we do that both technically with privacy and security, but also operationally. How we operate as a culture, how our legal and compliance team becomes much more integrated, automated within our activities in terms of data sharing.
Sara Shanti:
Well said, and I think that brings up this really incredible point with this federal framework for information exchange at the TEFCA level. Everyone has the opportunity to have more access, and I think that brings more risk to everyone’s door. I think it’s always when will it happen as opposed to if it’s going to happen. And in your experience, what’s the best way some of these providers, large scale, small scale... I know some of what you counsel on is pretty consistent about the really core things that healthcare systems can do knowing that door is always going to have some risk knocking at it.
Erik Pupo:
Well, we’re unique at Guidehouse, because what we can do is work very closely when it comes to TEFCA, another kind of construct called QHINs in terms of quality health information-sharing networks on how they operate, and the overall work that we do with HIEs at the state level. So a lot of what we are working with is what we would call the early movers in the space—the national networks, TEFCA—in terms of that implementation. How they’re going to gain competitive advantage as health systems or hospitals in terms of reducing the point-to-point integration costs, network effects, and to have road maps and execution plans to do that.
So we will spend a lot of time on gap analysis, readiness assessments with an organization, with a health system that very much would focus on the cybersecurity aspects as well. It’s not just like, “How do we onboard on TEFCA as a road map?” It’s, “How do we make sure we do identity proofing, credentialing? How do we handle in terms of connection testing, the certification steps of QHIN, the integration within eHealth Exchange, CommonWell-Carequality connectivity in terms of their security requirements?”
So the readiness of an organization to deal with those cybersecurity requirements directly, and then even to get into areas like... In my past experience, I worked on standards like ENWINconnect and ENWINdirect, and now with DirectTrust and CHA bridging activities are occurring. Just the ability to support some of the security aspects beyond health systems when HIE start to bridge together, “What are the cybersecurity implementations of that, and how do we help support health systems in dealing with that?”
And FHIR is the main standard to do it. So there’s a whole set of cybersecurity readiness activities and things like what’s called an OAuth framework to be able to support SMART on FHIR, to be able to support third-party application authentication in terms of using different types and available types of clinical data. And what we’ve seen as successful is you just want to be involved in terms of the planning, the road map, the execution. It’s not like you just drop cybersecurity into it. It’s got to be integrated into that operational planning right up front.
Sara Shanti:
Excellent. And I know you’ve had so much practical experience in how you’ve implemented this, rolled this out. I know Guidehouse really identifies as agenda-setting and moving the industry forward on not only cybersecurity, but healthcare innovation. Do you have any kind of stories, cautionary tales, or any great real-world examples that can really drive home why it’s so important that even when you have a sophisticated program, that it’s something that has to just be a living program, because the risks keep evolving as well? Any stories you want to share?
Erik Pupo:
Oh, yeah.
Sara Shanti:
Okay.
Erik Pupo:
No, I do. I mean, one of the things with cybersecurity, it’s a very sensitive area. So client sensitivity on our end is a big thing. Nobody wants to talk about breaches. Nobody wants to talk about weak security controls or operational security issues. But as examples, what we’ve seen is third-party risk issues that come about from the relationship of a clearinghouse like Change Healthcare with its third parties and what that meant, and I had a unique perspective, because I got to work on it from two sides where Change Healthcare was, as an organization, migrating to the cloud.
So they were working directly with AWS when I worked there to do that, and then they were also... When I joined Guidehouse and we started to work with different customers, they obviously went through their cybersecurity breach issue that had occurred. So I got the perspective to see some of the risks involved, which were things like concentration risk, where a health system is 99, 100% reliant on a clearinghouse. That’s Change Healthcare. What do I do in terms of cybersecurity operations to deal with that?
We had a whole set of solutions we had to roll out for teams in revenue cycle to be able to handle that. I can’t process any claims. I don’t know what to do. I don’t have a clearinghouse. Well, what do I do? So it’s an operational continuity issue. It’s not a technology problem alone. We can’t function and survive. In terms of cybersecurity insurance and dealing with some of the challenges there. One of the stories that we’re seeing more now is, more and more health systems are really seeing a price rise there that’s being driven by a lot of the data breach challenges, but it’s also being driven by HIPAA security rule updates and what we’ve seen more with state aid, cybersecurity laws.
So the more you have challenges in terms of just things like operational controls for security, they want to know you’re doing annual pen testing, that you have a complete asset inventory. If you are merging with other hospitals or health systems, that adds an additional layer of risk that can drive up your premiums, and they want to know that you’re taking on in terms of gap analysis and addressing particular risk mitigations, that you’re buying risk. You’re taking care of that risk as well.
It’s not like you’re just relying on another security team and it’s separated. So those are definitely some of the stories we see where cybersecurity might have used more of a technical issue. Now, it’s much more of an operational board level, CEO, CFO. We’ve got to be involved in these discussions, and not just involved when it’s a breach. Involved when it’s literally a strategic part of discussions that CFOs, COOs, CEOs would have at the hospital level.
Sara Shanti:
That’s such a great point, and that’s exciting to hear that you are seeing that operational level, and everything from IT to executives, to workforce, to the whole gamut is part of the conversation, because I think a few years ago, the industry was really saying, “You can’t just have these conversations at the IT level without management. You can’t have these conversations with the C-suite without the technical expert.”
So it’s great to hear that the industry is starting to really collaborate on how these projects need to come together.
Sara Shanti:
And that’s a wrap on this episode of Health-e Law, powered by Sheppard’s Digital Health and Innovation team, where health innovation meets legal expertise. Until next time, stay healthy and stay informed.
Contact Info:
* * *
Thank you for listening! Don’t forget to SUBSCRIBE to the show to receive new episodes delivered straight to your podcast player every month.
If you enjoyed this episode, please help us get the word out about this podcast. Rate and review this show on Apple Podcasts, Amazon Music, or Spotify. It helps other listeners find this show.
This podcast is for informational and educational purposes only. It is not to be construed as legal advice specific to your circumstances. If you need help with any legal matter, be sure to consult with an attorney regarding your specific needs.
