I Am Wiser Podcast with Dr. Laura Purdy
The I Am Wiser Podcast with Dr. Laura Purdy explores the ideas, relationships, and lived wisdom shaping the future of healthcare.
Hosted by Dr. Purdy—a family physician, entrepreneur, and founder of a constellation of specialized care brands—the podcast explores the intersections of healthcare innovation, AI in medicine, care delivery, telehealth policy, and the evolving patient and provider experience. Through honest, insightful conversations, guests share how they are actively reshaping healthcare from the inside out.
This podcast goes beyond theory. Each episode dives into real stories behind groundbreaking healthcare innovations and the lived experiences driving meaningful change—highlighting the human impact on both patients and providers. From care delivery, telehealth policy, and more, the conversations are grounded in real-world insight and practical wisdom.
Whether you’re a medical professional, healthcare leader, startup founder, or someone ready to rethink how healthcare works, The I Am Wiser Podcast is an invitation to ask better questions, explore what’s possible, and grow wiser with every conversation.
New episodes release regularly on Apple Podcasts, Spotify, and all major podcast platforms.
I Am Wiser Podcast with Dr. Laura Purdy
Ignorance Is a Vulnerability
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this episode, I sit down with Tom Barberio, Chief Information Officer at Thinc Forward, to talk about healthcare data, cybersecurity, privacy, and the risks that businesses often don't see coming.
But this conversation isn't really about technology.
It's about awareness.
Tom explains why healthcare data is so valuable, why even small organizations can be targeted, and why trusting the wrong person with too much access can create serious vulnerabilities.
His advice is surprisingly simple: educate yourself.
You don't need to become a cybersecurity expert. But you do need to understand what you're protecting, what risks exist, and where your vulnerabilities may be.
The one piece of foundational wisdom that I give to people is you have to educate yourself. Don't be naive to the fact of saying, hey, I'm just an individual, no one's gonna come after me. Those type of people are actually the ones that are actually more highly targeted because um say people think that they're not educated and they're gonna be a little bit more naive. And and my one advice is you've got to pay attention to this and you know, do a little reading, listen to a podcast on security. Um, you know, there's a lot of great resources out there.
Dr. Laura PurdyWelcome to the I Am Wise Podcast, with the biggest questions in healthcare and wellness, meet the collective wisdom of industry leaders and innovators. I'm Dr. Mark Burke, and here we explore the intersections of AI, care delivery, telephony, and the lens of those who are reshaping healthcare. This is not just about theory, it's about lived experience and real industry insight. Let's dive in and get wiser together. Welcome to today's episode of the I Am Wiser Podcast with Dr. Lara Purdy, where we explore the moments of breakthrough, resilience, and reinvention that shape the way we live, lead, and care. I am thrilled today to welcome Tom Barberio, Chief Information Officer at Think Forward. Tom has spent more than 20 years safeguarding patients, organizations, and leaders as technology continues to evolve, sometimes faster than we can even keep up. He believes that security and healthcare is not just about protecting our data, it's also about protecting trust, dignity, and people's most vulnerable moments. As AI reshapes what's possible in clinical care and business operations, Tom is here to help us understand the massive shift happening beneath the surface and how we can prepare wisely without slowing innovation. Welcome, Tom.
SPEAKER_00Well, thank you very much for having me.
Dr. Laura PurdyI'm excited that you're here. We were talking off-camera just before we got started, that healthcare information security is near and dear to my heart. So before we get to that, let's set the stage. Tell us who are you and what do you do?
SPEAKER_00Yeah, thank you. So as you mentioned, um I'm the CIO of a uh healthcare information uh security MSSP, which stands for um master service security provider. So um I oversee all the security aspects, and our customers come to us. Um, they're in the healthcare sector to essentially protect their data um as well as their systems and their processes for all of their security needs. And that across multiple uh venues of healthcare.
Dr. Laura PurdyWow. I that feels really intimidating to me because I don't do what you do and I don't know what you know. How did you where how did you progress through your career to the point where you feel comfortable entrusting yourself with other people's healthcare information?
SPEAKER_00Yeah, it's actually a really interesting story, right? So I started my career actually um in the banking industry, which was a very highly uh heavily regulated industry, and over time um migrated into healthcare because one of the things that was noticed is I was always looking for, hey, where are people underserved, right? And healthcare historically has always been an underserved market um when it comes to technology in general, as um, and then as the advent of technology became more prevalent within healthcare, um, security became a major factor, right? So we started really seeing a need there, and I personally always uh my background has always been in information security. So the two kind of married up very nicely to be able to work together to be able to provide a service that is uh very much needed.
Dr. Laura PurdyI get that. So healthcare and banking, so health information, financial information, are they equally regulated? Is one more regulated than the other from your experience?
SPEAKER_00So what we've noticed is banking actually is a much more um, we'll say historical um type of industry, right? So they've had regulations for many, many years, 25, 30 years as technology started going into that. We've only started seeing more regulations in healthcare as of recent, right? As people are probably familiar with the acronym of uh HIPAA. Um that actually started um back in the early 2000s. However, as technology is advented, um, healthcare has become more regulated. And as of 20 end of 2024, as we went into 2025, it is actually one of the most regulated industries now that is out there as far as uh security and information goes.
Dr. Laura PurdyAs it should be, right? When you talk about people's most vulnerable moments, their health data, it is just as, if not even more, private and personal than their financial data. So I'm glad that that's the direction it's gone in.
SPEAKER_00100%. Because if you think about it, right, if your banking data is a bunch of numbers, essentially, right? So that's not per that, yes, that's personal to people because it's you know, how much you know, money do I have or what's my net worth, but that information um of you know what medical conditions do you have, or very private things that, you know, that's personal information to you as an individual. You, you, you and you alone are entitled to that information and should be the one who's dictating who has that information, not um not it being publicly out there, um, which unfortunately in today's society, and we can where I get into that a little later with a lot of things going on in cyber, um that's a big, a big problem, right? And you should be able to control that as an individual.
Dr. Laura PurdyI agree completely. I mean, this is something we've been talking about in healthcare for a long time. You having the control over who owns your records. So this is actually a very common conversation that we have in the digital health tech startup industry because we're all cash pay. Everybody that I work with and all of the jobs I've done for the last 10 years have 99% of them have been entirely cash pay, which means institutions don't really own our records. It's not the insurance companies that own our patients' records, I should say. Um, but in the real world, the hospital andor the insurance company is really the custodian of record. And for me as a patient, if I want to get my medical record or if I want to get my child's medical record, I actually have to go ask permission from the hospital or the institution or the insurance company to be given my information, which might take it, might never happen. I mean, I guess it's a little better now that they've put some laws into place that says they have to give you your record if you ask for it and they can get in trouble if they don't give it to you. But I've always thought it was strange that we aren't the owners of our medical records and it has to be given to us from the institution and not the other way around. Do you agree?
SPEAKER_00Well, I do. And it's kind of a very interesting topic, right? Because if you think about it, um, it is one of the industries that even though it's highly regulated as to who can do what, what a lot of people don't realize is the amount of information sharing um that goes on in that space, um, you would think is um a lot. And in some cases it is, because people don't realize, hey, I go to the hospital, right? They actually might be sharing that record with five, 10, 15, 20 different entities that are affiliated with those healthcare systems and things like that. People don't understand that on the fine print when you sign the forms. Now, however, on the flip side of that, though, you would say, well, there's not a national database or one place for me to go to see all my health records. My dentist has my dental records, my general physician who's probably affiliated with the hospital system there. But now, if I go down the street, um, that record is not there, right? So, to your point, I agree 100% that us as the individuals should be the owner of it. Unfortunately, we're the recipient, and there's not a what we call in the space a uniform, um, uniform space for that, right? So every entity is pretty much entitled to do whatever they want with it and structure that data however they want. There's not a standard, right, that goes across the industry to allow one spot. Now, outside of this country, when you go into like the European Union and things like that, if you have any international uh listeners, um, they're actually a little bit ahead of us in the United States than we are in the United States in that um juncture because they set some standards that are kind of uniform throughout the country, but in the United States of North America, that's not the case.
Dr. Laura PurdyIt's not at all. And the way that I've told this story is imagine if you didn't own your credit card or debit card. And every time you go somewhere to make a purchase, let's say you go to the grocery store and you're going to the grocery store to make a purchase, and the grocery store says, hold on, before you make a purchase, I must contact your bank to find out what your credit card number is. And only once they've given me your credit card number, uh, I'll give you a copy of your credit card number. But uh you can't give me your credit card number. It has to come from the bank. And oh, by the way, you can't make your purchase until the bank has the time to send me your credit card number. And that's exactly how it works in healthcare. And and you have to sign a piece of paper that says, yes, I give the bank permission to give the grocery store my credit card number so that I can make a purchase at the grocery store where I'm trying to use my credit card to buy something. Can you imagine? I mean, that's crazy. And then in the future, you go somewhere to buy something, and let's say they have they can't communicate with your bank and they say, Okay, what's your credit card number? And what was your credit card number five years ago? And what was your credit card number three years ago? And can you tell us every credit card number that you've ever had? That's what it's like in healthcare.
SPEAKER_00Yes, and it and it's worse than that too, because with uh all the cyber incidents and everything going on, um, it's very, very, very fragmented, right? And and you don't even realize, and there's pieces of that information that's living in multiple spots and it's not in a uh in one spot in a standardized format, and it makes it very difficult as the consumers of those types of things. It's not product friendly in any in any way.
Dr. Laura PurdyNot at all, not even remotely. And unfortunately, again, I come from the digital health tech startup industry, and in the immediate post-COVID, so 2021, 2022, 23, all of the GWS kind of bright and up-and-coming founders, this is what everybody was talking about. Everybody wanted to talk about putting medical records on the blockchain and interoperability and creating, I don't know, APIs, I guess. I'm not a tech person, that all these systems would talk to everyone about, and your medical record could live in your maybe we'll say digital wallet, and then you can boop, like you can boop it. I don't know what the tech word for booping is, but you know what I mean when I say boop. You can contact lists, share it. And I don't really hear people talking about that anymore. Now they're all talking about AI, but that's what they talked about before they talked about AI. From your vantage point, what happened with all of that? Is that still a thing? Is it a dream? Is it not gonna happen?
SPEAKER_00Yeah, so that's a really good question. And in technology, that's there's kind of what we call the utopia of that, right? Of where we want to try to get to in order to get to that. The problem that we see with that is um that's not really attainable today. And the reason that that's not attainable is it comes down to a cost factor. There are so many different systems, and not to beat a broken record or be a dead horse on this, is because there's no standards across the industry, it is not obtainable to have a standard where each person would be able to carry that record in like a digital wallet. And then when you went from organization A to organization B to do like what you do with photos, right? Or people who have an iPhone to be able to transfer it. The reason that that kind of um, the reason that that kind of works is because the um because those devices have standards. So when you're going from one phone to another, you can do that transfer. When you're dealing with medical records, when you're going from one system to another, they're not standardized, so they don't um allow that information to do that. Now, 10 years down the road, do we hope something like that could change? Yes, but there has to be an appetite for it, right? Unfortunately, in that space, it's a um consumer-driven um space that you have to have the consumer say, Hey, I really want this, and then they have to be able to push uh to do that. Healthcare has become such a commoditized space of unfortunately, even though it's people's health, you should say you're looking out for the best interest of the patient. That's not necessarily the case. Some of these organizations are so focused on the bottom line and the dollars and cents that they have to say, well, is there really a demand for that? That they would, you know, essentially, uh, essentially want that.
Dr. Laura PurdySo would it have to be driven then from the regulatory level? Would the government have to decide that now they're mandating that everybody owns their own health data and now all of a sudden the solutions have to be created? Like with the FHIR, I don't know if I'm saying that if you pronounce it or if you say it, but with the with the FHIR format of the health records, right? We have to store our records in that format so that if patients ask for them, we must release them in that format. Do I have that right? Yeah.
SPEAKER_00You do. You do. You you you hit the nail right on the head. Um, that is exactly what would have to happen at the federal level. They would have to be a mandate to say this is the standard that everybody has to follow. Um, and then there'd be a very long adoption period of that, right? It goes back to you might remember um when people were doing prescriptions, right? I I use this as a classic example. They left that unfortunately to the state level. So every state had different laws of when you could do electronic prescribing or otherwise known as e-prescribed versus when you used to get the prescription on uh a prescription pad. Um, they never actually were able to get that over the finish line at the federal level beyond um regulated um certain things that are uh DEA regulated for you know class three narcotics. But beyond that, um, they weren't able. So every state has their own laws and timeline of when electronic prescribing had to go into place. And shockingly, out of the 50 states, not all of them even are on electronic prescribing today. There's still a handful, I believe 15 or so, that it is not uh actually a little bit more, that that is not the the law. Now, a lot of systems do it, but it is not they're not required.
Dr. Laura PurdyI have actually never had a paper prescription pad. And occasionally, but I don't need it. What am I gonna do with that? Right? I and I would feel at this point in time, I would feel irresponsible. I would feel reckless going like this and ripping it off and saying, here, take this somewhere and maybe you'll get a prescription. I sometimes people ask me for it, and I say, No, I'm gonna send you an electronic prescription, and I'm there, there's no paper. There's no paper here.
SPEAKER_00Well, you'd be surprised. We still see it. You go to your dentists, a lot of dentists still write, uh, you know, are still writing paper scripts. Um, it's it it it it it's ripe for fraud, right? I I it's just it's not a good situation, and in this day and age, with the advent of technology, it really shouldn't be happening. But unfortunately, um it still it still is.
Dr. Laura PurdyWell, we'll get there. So what I'm hearing from you, we'll we'll look for that little piece of wisdom. What I'm hearing is, especially when it comes to tech and innovation in tech, good ideas are sometimes only that good ideas, especially if they're in regulated industries that require the state or federal or local uh legislations, statutes, laws, and regulations to be in alignment and be supportive of that innovation. And if it's not, then the ideas that we sit around at the conferences networking, networking groups talking about are just that. They're great ideas that aren't going anywhere anytime soon.
SPEAKER_00Yeah, unfortunately, it but although that is correct, although, but you got it, there has to be a push, right? If if that's what people want and those focus groups and you know those special interest groups, they they have to push that fortunately and fortunately or unfortunately in government, that's how things get done, right? So it has to be a push from below to say this is something we want, and then enough people, squeaky wheel gets gets things done. But until that gets done, I uh on its own organically, um, something like that just will not happen until there is a standard across the industry.
Dr. Laura PurdyWell, all right. I mean, well, I'm sure we'll talk about it at the conferences in the upcoming year, but you're right, we should have it, we should be interested in it, we should be future thinking, but we don't we should also be wise to what the current regulatory environment allows so that we don't get in trouble. Speaking of getting in trouble, let's shift gears just a little bit. So uh we talked about innovation, healthcare, health information, privacy. I want to take a step back and be a little bit more broad and talk about just systems and privacy in general, right? So I'm a business owner, I have a digital health tech startup, and I've had a lot of employees, I've had a lot of vendors, and I've had a lot of contractors over the last eight years. And I have had to learn the hard way that I have to take security, not even just patient data security, not even PHI, not even HIPAA. I'm just talking about things like policies, SLPs, workflows, emails, back office systems, things that over the years I've allowed people to have access and control over that maybe I shouldn't have. I've had entire domains shut down with years of emails lost by people who called themselves my director of technology. I've had clinical workflows disrupted, pharmacy orders tampered with, patient contact lists taken by people who were supposed to be my head of product operations. And I've had to learn the hard way that the only person who should ever really own anything in my business is me. How common is that problem from your vantage point?
SPEAKER_00So that's a very common problem, right? Now, on the I'll add another dynamic to that, right? The problem is that um this is not a problem just in the startup space. This type of problem um runs rampant throughout um the whole sector, right? The issue comes down to um trust factor, costs, and knowledge. Because what people don't realize is that they say, hey, I don't want to trust in one individual or an individual um having that level of access to do that. So, which is totally understandable, particularly in a in a medical or a tech startup, because IP is king, right? That's that's things that it's your name, it's your brand. Um, that's that that's your lifeblood of how you're making money. Where that becomes challenging, though, is that the cyber landscape is evolving so quickly. And when I say quickly, it literally changes on a daily basis of what some of the new tactics and things like that are. And people that are not formally trained or staying up on that become victimized a lot easier, even unintentionally. Um, because you could have the best of intentions and say, hey, I'm smart enough to know this is a phishing email. That's not real. I shouldn't click on that, right? And give out my passport. However, there's new techniques and new attacks that are happening daily of things that you may never even think of because you're busy running the business or doing other things, and people that are focused uh 100% on the cyber are staying more up to date on that. So, what we're trying to see as an industry as a whole of the advent of more user-friendly tooling to be able to allow that control so that you don't have to um entrust into one person to do that because to your exact point, because then that person has to one person should never have that much control, right? So that is uh kind of a classic chicken before the egg type of syndrome that is going on today in that that in that space.
Dr. Laura PurdyAnd when you say cyber, just because I I'm not in the industry, you mean crime, cybercrime. You're talking about people who use the cyber environment to be nefarious, cybercrime.
SPEAKER_00Correct, correct. We're talking about it, it is a it is they're criminals. They're essentially cyber criminals. Uh, you call them criminals, you know, terrorists, foreign actors, whatever term you want to use for. It's right, but they're literally people that are stealing your personal information or your business information, committing a crime and then selling it um in illegal fashion uh on the on the dark web and on the internet.
Dr. Laura PurdyAnd they're hard to find, I would imagine. They're hard to pick up.
SPEAKER_00They're very hard to find because these people are not they're they're usually people sitting, they could be sitting halfway across the globe and they're underground somewhere. And it is it it's it's virtually sometimes impossible to track these, uh to track this down. I mean, there's the the statistics are astounding of how much of this goes on on a daily basis.
Dr. Laura PurdyWow. But what I'm hearing you say is that nowadays, nowadays, there are systems, maybe programs, maybe software that can be implemented. And by the way, thank you for telling me that it's not just us poor little digital health tech startups that have these problems. Because I I, you know, coming from healthcare where in healthcare, most people know better. And most people who work in healthcare don't dare do anything with their patient data because we've had ingrained to us since day one that you don't do this, and usually they're not that stupid, if I can say. But coming into, you know, shifting a little into this kind of startup world, I'm just happy to hear that it's not just me.
SPEAKER_00No, it is, it runs from the startups up to the multi-billion dollar corporations, right? Everybody, as people have to understand when you're talking about these types of things, is that it does not matter if you're a multi-billion dollar corporation or a startup. A patient record is a patient record. That value of that individual record in the what we call the dark web, which is the illegal space where this stuff is sold, is the same value if I'm taking that from a startup or I'm taking that from one of the biggest healthcare companies in the world. It doesn't matter. That one patient value has that same exact value to those criminals.
Dr. Laura PurdyHuh. So how do we get wise then? How do I how excuse me? How do I know? Let's say I've decided because I've been burned five or six times by the wrong people with the wrong access in the wrong place, that I want to shift to using a system or a technology or a program to help me safeguard my IP and my patient data, because I do need to safeguard both of those things. Um, for example, these podcasts are stored on my drive and there's people that have access to them and they cannot delete them because I took away that access. But what sort of how do I vet these technologies in order to pick one that's gonna help me?
SPEAKER_00So that's a very good, very good question. The best way to do that is you gotta have some self-education, right? There's there's tools out there, there's educational websites. Um, you really need to, um, there's videos, you really as a as a business owner, as a startup, you really need to look at what cyber tools are out there. Um, there's certain products that that do a better job that are very good in that space. And there's there's educational sites out there um that you can actually go. And actually, one of the really good spots to start when we say where the government tried to put something together, you could go to the CISA, um, the SISA website, which is uh, and they have a bunch of links to education out there that's the cyber, um, the National Cyber Institute. And it gives some really good advice to do that. And then you could start to learn, you know, what are some of the tools and things that are out there? Um, you know, and there's companies out there and consultants that can help you learn as your company grows. You say, hey, I probably want to get the um advice of somebody who's in that space who could tell me, you know, I don't have a budget of, you know, millions of dollars to do this, but I want to spend X and what are the core things that I need to make sure that I'm basically protected at a level? So as a business and as a startup, we always encourage uh going uh to the resources out there that can help with that.
Dr. Laura PurdyI think that's fantastic. So if the government's working on it, does that mean that cybercrime is a federal, is a is a is a federal crime? Is it also a state crime? It's a federal crime, I'm guessing?
SPEAKER_00It's a federal crime. It's actually a federal crime. If you get convicted, it's uh it it's it's equivalent to doing uh you know what they would call wire fraud and money laundering, right? If you actually get caught um doing um doing a cybercrime, that is, that is you can be prosecuted uh federally for that and and in and internationally in some cases, depending on where the crime is actually occurring.
Dr. Laura PurdyOh wow. Okay, so it even can cross borders and you can be located somewhere else, which you mentioned, underground on another side of the world, doing cybercrime in a different country and still get in trouble from another country.
SPEAKER_00Yes, you can. Yes, you can.
Dr. Laura PurdyI'm happy to hear that. Actually, I I'm really happy to hear that, and I hope they continue in their efforts to evolve that enforcement.
SPEAKER_00They do, and there's actually a lot of been a lot of things in the news recently where so there's been a lot of uh entities, um, you know, cross uh nation entities kind of coming together in the cyberspace to try to take down these crime rings and things like that to be able to do that because it is very, very difficult when you're dealing with people in you know places that are not um, you know, not they're not Western civilizations all of the time, right? So it becomes difficult, but it is definitely something that is on the forefront um and is becoming more and more prevalent.
Dr. Laura PurdyI'd love to hear that. And that that actually brings me a great sense of comfort knowing that people are working on it. Okay. Well, let's shift gears just a little bit. I want to hear about the company that you work for, the business that you're in right now. What sort of service do you provide to people and how how are you helping folks and making the world a better place every day?
SPEAKER_00Yeah, absolutely. So, as I kind of mentioned, one of the things we specialize in um is in cyber and security, right? So we get brought in all of the time um in consultative roles, um, particularly in regulated industries such as healthcare, we're primarily healthcare, to do just that. Um, and that is everything from your larger entities in the medical, dental, uh, physical therapy space, all the way down into that startup space. What we actually do look at is we look at, okay, what are you offering your customers and how can we help make sure we're educating you and providing proper services and um tools to be able to protect that? And then that depends on what your line of business is. And then we have a full plethora of uh offerings that we offer to be able to protect your data, your patients' data, your customers' data, whatever it is, um, as well as the process of the people to help uh implement those and secure those down.
Dr. Laura PurdyWow. I I only understood about like this much of what you actually said, which is great because it tells me that you really know what you're talking about. Because my assumption is that anybody can say that they are anything today, and anybody can profess to be someone, but really only somebody who talks like you do about these things can be an expert. So, what sets you apart? What makes you qualified and equipped to be able to properly legally uh advise these people with value on these things?
SPEAKER_00Yeah. Um, one of the things to be able to do that is um myself and our organization, we have to stay up to the latest on what's going on in the space, right? We spend a lot of time making sure we're educating ourselves on what the latest threats are that are out there and what's the latest products and services that can be offered to make sure we're combating those threats for our customers. So we spend a lot of time making sure we stay up to date on all the new rules and regulations for compliance, um, not only in the HIPAA space in healthcare, um, but there's a lot of different changing laws, uh, particularly in different states and also at the federal level, to make sure that we're staying up on that so that when we're advising our customers that we're advising from a place of, hey, here's not only best practice, but here's also what you're legally obligated to do as well, right? Um, and here's what this is gonna cost you, and here's what this will cost you if you don't do it. That's probably the biggest key thing that people don't realize is that no one knows they have a problem until they have a problem, right? And it's like I talk to people all the time, they're like, hey, well, I've never gotten hacked or I've never had a security issue, so I don't want to spend any money on it. And it's like, well, it's not a matter of if, it's a matter of when, right? It's it's the unfortunate world we live in today that you have to be proactive in those types of uh scenarios.
Dr. Laura PurdyYou really do. Actually, I remember one time a few months ago, I was having dinner with one of my friends who also owns a digital health tech startup, and he starts getting into his phone and going like this and taking calls and stepping away, and he's like, our uh our our website's getting hacked. Hold on, I'll be back. And and it just happened in real time. You know, whatever it was that the people were doing on the front end of his website, they had loaded it so much that it caused the site to crash and patients couldn't log in, they couldn't use their portal, they couldn't place orders and chat with customer service. And it's a very real thing, right? And he has a relatively you know small company too. And I see this happen all the time. I mean, we've had clients or people that I've worked for who've had their systems broken into, their information like their patient uh data downloaded, their CRMs hacked into. It happens all the time. And sometimes it happens from the inside, which is what's happened to me before, where people who are internal to your organization are able to obtain your data and then try to use it in some kind of a unsavory way.
SPEAKER_00Yeah, inside there's a term for that. It's called insider threat. That's kind of the uh insider threat. The night insider threat is the buzzword, right? That people like to use. And unfortunately, um, insider threats are actually, I would say they're prevalent across all organizations, but particularly in smaller organizations, it's a bigger problem because there typically is not the um budget or the tooling to necessarily sniff that out. And there tends to be a higher level of trust of certain individuals in a smaller organization compared to if you're an organization that has 10,000 employees, um, you're gonna be handling that a little bit differently when you may have three or four or five, right? So, and that that trust factor tends to be a lot greater in the smaller organizations, and unfortunately, some people have um nefarious means that they want to get to, and they'll take and take that trust and be able to capitalize on that for uh unsavory actions, unfortunately.
Dr. Laura PurdyWell, to the person who says, but we've never been hacked or had security issues before, I will return my response to that would be well, you've also never had astronomical legal bills before, have you either? And let me tell you how high your legal bills get when you do get hacked and have these problems happen. Well, here's another question for you is it unrecoverable? Like, have you worked with clients or interacted with individuals who've been victims of these cyber crimes that it is not possible to recover and the things that they've lost are lost forever or they've sustained unrecoverable damage? Hi, Angela. We'll be on with you in just a second.
SPEAKER_00Yeah. So um, yes. And unfortunately, what we've actually seen happen now is it's recovering the data is only half the battle. What people don't realize is the reputational harm of having that data resold on the dark web. And what the dark web is, is the illegal space where that that is uh that stuff is traded. And that being the case, that is actually more damaging to organizations than the fact of being able to get the data. Most organizations have some sort of backup, and if you got, you know, encrypted data where you where they go in and you can't get it. Um, people now, um, and this has been a pivot in the last probably year and a half to two years, are more worried about the data being resold than they are of not being able to recover the data. But both are very important things to consider when you're looking at your strategy.
Dr. Laura PurdySo, okay, I I'm a lay person for the most part when it comes to this. So I'm gonna ask you a couple of probably very silly basic questions, but probably people who are listening to this have the same questions as me because they don't come from your industry. So what you're saying is that people hack in or whatever it is they do with cybercrime and they obtain the data. You can probably get your data back. But when you're talking about the dark web, you're essentially saying there's this underground um market where people, bad actors, criminals, nefarious individuals, are going to buy and sell our company's data. It's like a it's a commodity that people specifically go there to buy these things, and people specifically go there to sell these things. Where where is this happening? Is it like websites? Is it forums? Is it is there a Google workspace? Like, I don't know. Like where like where is I I think of like Harry Potter or something, you know, like the the dark web. Like where where is this happening and why is it still happening?
SPEAKER_00It's happening because they're because as we mentioned a little earlier in the in the podcast, is because these this is happening in foreign foreign countries where there's little to no regulation, and it's exactly that. It's an underground space where people are buying this data, and what they do is then they come to you and say, Hey, I have your data. I'll give it back to you if you give me X amount of millions of dollars, right? That's exactly how this works. And some people have insurance policies and things like that. You may have heard of cyber insurance that will pay these millions of dollars to get the data back. And then they say, okay, if you don't pay me, it's literally a ransom. And if you don't pay this ransom, I'm then gonna go sell your data to the highest bidder in this illegal underground space. And because this is happening um across the ocean in, you know, in unregulated space, there is no uh, there's no way to uh to fix that problem, unfortunately. And that it is a huge, I mean, there's billions and billions of dollars. Last year alone, it was the highest year ever of billions of dollars of ransom money was paid for people to say not to sell the data. But here's the catch you can pay the money and they can tell you they're not gonna sell it, but these are criminals and they're gonna sell it anyway, right? So it's uh, citizens.
Dr. Laura PurdyI mean, they're not doing it because they're gonna do what they say they're gonna do. So it sounds like you're talking about in other countries where the governments are not regulating their uh spaces like ours are being regulated. So it's basically like 1980s or early 1990s internet where it's kind of a wild, wild west free-for-all, and everybody's out there just do it because we can't really relate to that in America. It's not like that anymore. And you can't just open up a website that says I sell people's healthcare data and www.darkweb.com. Like it does, it doesn't. We we can't do that here because the laws prevent it, but in other parts of the world, it is still very unsophisticated, primitive, unregulated. And so it's actually pretty easy for them to do that.
SPEAKER_00Yes, and in some parts of the world, unfortunately, the government actually funds some of that activity in some of these countries. Um it's not not great, but it is the truth.
Dr. Laura PurdyWell, I didn't know that. Nobody's ever told me that before. And so I guess I, you know what? I guess I'm getting a little bit of uh street street wisdom and like worldly wisdom right now, and maybe a little bit of disillusionment that there are other parts of the world that actively want to hurt us when it comes to data and privacy. And it's a hard pill to swallow, but it is a reality of the world that we live in. And we we, as doctors, as tech people, as uh business owners, as startup founders, as huge company owners, we need to know this because we have to understand that we do need to protect our data.
SPEAKER_00Absolutely.
Dr. Laura PurdyMy goodness. Well, I'm happy that you are an expert in the field. I'm happy that you know what you're talking about and that you really care about providing meaningful solutions for the companies that you work with, because I would imagine, just like in all industries, there may be some people who do the same thing that you do, but don't do it with as much of a conscience as you do. Is that the case? Are there people out there providing these services that can't really deliver like you can?
SPEAKER_00There is. Unfortunately, you know, you see this all the time where, you know, it's the the the the flavor of the day, right? And people say, hey, I'm the best, I'm gonna charge you, or I'm gonna do it either at a bargain rate to try to get quantity. You it it really you have to be compassionate, you have to understand you're not dealing with intangible assets, people's healthcare information that's very personal to people, right? So you really have to think of, hey, would I want my information, you know, broadcast around the world and people, it's very violating. It's very violating to people's rights and the and their personality. So I train my staff and kind of our company core values of thinking of, hey, you have to think about would you want your your mother or your father's or your personal or your kids' data doing it? And you have to kind of approach the business in that fashion because if you don't do it and you're doing it just for dollars and cents, um it's you're not gonna have a good outcome from that. You have to add the human element to it.
Dr. Laura PurdyWell, thank you for caring. Uh, you know, I've been on the receiving end of over-promising, under-delivering, unqualified vendors because I was ignorant and I didn't have my self-education, right? I didn't do what you recommended and educate myself first. And I know that it means a lot. It means a lot to the company, to the business owner, to the person on the other side of that client agreement for you to do right by us. Uh, that's that there's a lot of value to that. So thank you for that.
SPEAKER_00Yeah, absolutely. Thank you. Thank you for caring.
Dr. Laura PurdyIt means a lot. Like I like I said, I've been on the other side of that. So we have just a few minutes left. And I want to see if I can ask you one more question. And my one more question is this if you had to give one fundamental or foundational piece of wisdom as it pertains to security to people, what is that one piece of foundational wisdom that you have to offer?
SPEAKER_00Yeah, I would say the one day the one piece of foundational wisdom that I give to people is you have to educate yourself. Um, you have to, you don't be naive to the fact of saying, hey, I'm just an individual, no one's gonna come after me. Um, you know, I'm a nobody, right? You have to think about it that unfortunately those type of people are actually the ones that are actually more highly targeted because um of they people think that they're not educated and they're gonna be a little bit more naive. And I and my one advice is you gotta pay attention to this and you know, do a little reading, listen to a podcast on security. Um, you know, there's a lot of great resources out there on our website. Um, www.thinkforward.com t-h-in-c, we have a lot of links um that free educational material where you can read, you can listen to things, uh, and we update it quite frequently just to keep people updated for that because we really do feel that it's very important um for them to be able to know what's going on in the world and stay updated.
Dr. Laura PurdyThank you so much, Tom. So, in summary, knowledge is power, wisdom is power, but when it comes to the security of you, your business, and your patients, innocence and ignorance can be a vulnerability. So thank you for being here today, Tom. Thank you so much for doing what you do. Thank you for the wisdom that you've shared with us today. I wish you all the best in your endeavors.
SPEAKER_00Thank you very much, and we appreciate it. And to you and your audience, so we hope this was informative and thank you very much for having us.
Dr. Laura PurdyI know I learned a lot. Take care, Tom. Bye-bye.
SPEAKER_00Thank you. Bye-bye.
Dr. Laura PurdyThank you for tuning in to the I Am Wiser Podcast, where each episode brings us closer to a wiser, more human approach to healthcare. If today's conversation inspired you or sparked new ideas, share it with someone who's ready to rethink healthcare. And if you have a story or innovation that could light the way for others, reach out. We'd love to hear from you. This space is yours too. Don't forget to follow, rate, and review us on your favorite platform. Until next time, stay curious, stay courageous, and stay wiser.