Rockin' HIT Sales Podcast

Podcast / Gary S. Chan

src="

Cybersecurity, Vendor Trust & Security Review: What Health IT Companies Need to Know


Gary S. Chan, Chief Information Security Officer at SSM Health, joins Rockin’ HIT Sales to discuss how health systems evaluate cybersecurity risk, what builds provider trust in a vendor, and what Health IT companies should prepare before entering provider security review.

Release Date:

Hosted by David Hacker, CPHIMS | Director, Elevate HIT Sales | MEDDPICC® Certified Trainer

Watch or Listen

Choose your preferred platform:

Also available on all major podcast platforms.

Episode Summary

For Health IT vendors, winning over an operational or clinical leader does not mean the sale is complete. Before a technology can enter a health-system environment, security teams need to understand the risk the solution introduces—not only from a technical standpoint, but also in terms of patient safety, operational continuity, regulatory exposure, organizational trust, and the vendor’s ability to respond when something goes wrong.

In this episode of Rockin’ HIT Sales, David Hacker speaks with Gary S. Chan, Chief Information Security Officer at SSM Health, about what security review actually looks like from the provider side. Gary explains when vendors should prepare for security scrutiny, what documentation builds confidence, why security culture matters as much as questionnaire answers, how AI is changing the review process, and why honesty remains one of the most powerful tools a vendor can bring into the conversation.

The episode closes with something unexpected: Gary uses mentalism to demonstrate why cybersecurity awareness has to be more than informative—it has to be memorable enough to influence behavior.

Why This Matters for Health IT Companies

Cybersecurity review is not simply an IT checkbox at the end of a Health IT sale. Health systems are evaluating whether introducing a vendor creates additional risk to patients, operations, regulatory compliance, data, reputation, and the organization’s ability to continue delivering care.

For Health IT companies, that means security readiness should begin before the first provider sales conversation. Vendors that understand their architecture, maintain appropriate security expertise, obtain independent validation, prepare documentation proactively, and communicate honestly about limitations are better positioned to build trust and move through provider review without creating avoidable friction late in the sales process.

What You’ll Hear

  • What Health IT vendors often misunderstand about provider security review
  • Why cybersecurity evaluation is fundamentally about organizational trust and risk
  • How patient care, operational continuity, regulation, and business impact influence security decisions
  • When security should enter the Health IT sales process
  • What security teams are really trying to learn about the vendor and the product
  • Why security culture can matter as much as technical controls
  • Which certifications, assessments, and documentation build provider confidence
  • Why honest disclosure of security weaknesses can actually strengthen trust
  • How AI is changing both security questionnaires and ongoing vendor oversight
  • Why Health IT companies need policies for rapidly changing AI functionality
  • What Gary believes every vendor should have before entering security review
  • How tailoring security communication to the audience improves understanding and adoption
  • A memorable mentalism demonstration showing why information alone does not change behavior

Questions This Episode Answers

What is a health system really trying to determine during a vendor security review?

At the highest level, the security team wants to understand whether the product or service is secure and whether the vendor can be trusted to operate responsibly over time. That includes technical controls, but it also includes the company’s security culture, internal expertise, independent validation, responsiveness, and willingness to address problems when they arise.

When should a Health IT vendor start preparing for security review?

Before the company begins selling into healthcare. Security expectations are not unique to one health system, so vendors should assess their own readiness before entering the market. For a specific opportunity, formal security involvement often begins once the operational buyer has established genuine interest in the solution.

Does approval from an operational leader mean the Health IT sale is nearly complete?

No. Operational approval may establish that the organization wants the solution, but security review is part of the broader buying and risk-assessment process. Vendors that mistake operational enthusiasm for final approval can become frustrated when security, legal, compliance, procurement, or other stakeholders enter the decision.

What factors influence how much security risk a health system is willing to accept?

Patient benefit, operational importance, regulatory requirements, available alternatives, and potential disruption all affect the calculation. A solution that provides significant patient value may justify additional investment or compensating controls, while a solution with multiple comparable alternatives may face a much lower tolerance for security deficiencies.

What makes a Health IT vendor appear prepared for security review?

Prepared vendors anticipate the process. They can provide security questionnaires, architectural documentation, information about policies and controls, independent assessments, penetration testing, certifications such as SOC 2 or ISO-related credentials where appropriate, and evidence that security has received meaningful organizational investment.

How important is having dedicated security expertise inside the vendor organization?

Very important. Gary identifies having a person whose full-time responsibility is information security as a significant positive signal. In his lightning-round answer, he says a Health IT company is not ready for security review until it has at least one dedicated security person.

Can being honest about a security weakness actually help a vendor?

Yes. Health-system security teams do not expect every vendor to be perfect. Clearly explaining a weakness, the risk it creates, and what the company is doing to address it can build more trust than trying to conceal the issue or presenting unrealistic answers.

Why can security weaknesses affect the economics of a Health IT deal?

A security limitation may require the health system to purchase additional technology, increase insurance, create compensating controls, modify infrastructure, or accept other costs. Understanding those requirements early allows the provider and vendor to plan for them rather than discovering unexpected costs after the contract is signed.

How has AI changed Health IT security review?

AI is affecting both sides of the process. Vendors may use AI to complete security questionnaires, which can create credibility problems when answers are inaccurate or inconsistent. At the same time, AI functionality is increasingly embedded into products and changes rapidly, making traditional point-in-time controls more difficult to apply.

What should AI-enabled Health IT vendors be prepared to explain?

They should have clear policies describing what they will and will not do with AI, how changes are managed, how security expectations are maintained as the technology evolves, and how customers will be notified when material changes affect the product or its risk profile.

What is one of the strongest positive signals a vendor can give a provider security team?

Proactively arriving with third-party certification, independent assessment results, security documentation, or other materials the company routinely provides to customers. Preparation signals that security is part of the company’s operating model rather than something assembled only after a buyer asks for it.

What is Gary’s advice for communicating with different stakeholders inside a health system?

Tailor the message to the audience. Security teams need the security information. Operational leaders need to understand functionality and outcomes. Trying to give every stakeholder the same presentation makes it harder for each person to understand the information that matters to their role.

David’s GTM Takeaways for Health IT Vendors

1. Security review is part of the buying process—not an obstacle added after the sale. An operational champion saying “yes” does not mean the deal is finished. Security, compliance, legal, procurement, and other stakeholders still have responsibilities to the organization. Sellers should map those stakeholders and expectations early instead of treating their involvement as an unexpected delay.

2. Preparation builds trust before the questionnaire is answered. Dedicated security expertise, architectural documentation, policies, third-party assessments, penetration testing, certifications, and a willingness to provide materials proactively all tell a health system that security is embedded in the vendor’s business rather than treated as a sales requirement.

3. Honesty can be more commercially valuable than a perfect answer. Health-system buyers understand that no technology is risk-free. A vendor that clearly identifies a weakness, explains its impact, and presents a credible mitigation plan can be easier to work with than a vendor claiming everything is perfect. Surprises discovered later are far more damaging to trust—and to the deal.

About the Guest

Gary S. Chan is Chief Information Security Officer at SSM Health, where his role includes helping the organization understand and manage cybersecurity risk across a complex healthcare environment.

IIn this conversation, Gary brings a practical and distinctly human perspective to security, emphasizing trust, communication, preparation, and transparency alongside technical controls. He also brings his work as the Security Mentalist, combining cybersecurity with psychology and mentalism to make security concepts more engaging, memorable, and actionable.

Learn more about Gary’s Security Mentalist work at SecurityMentalist.com .

Transcript

Prefer to read or download the conversation?