Healthcare Cybersecurity Strategist

What does the failure do to the patient?

I assess clinical AI and medical technology the way an emergency department experiences it: by the harm at the bedside. It's evidence your hospital buyers, clinical leaders, and safety committees can act on.

28+ yrsin healthcare
23 yrsin the emergency department, on nights
200+clinicians trained as Epic Super User
1 of 52Featured Defenders in Semperis Midnight in the War Room
The gap

Security teams measure the data. Clinicians live with the consequences.

Most cyber and AI risk work stops at the system: what was exposed, what went down, how fast it came back. Hospitals, regulators, and AI governance committees now ask a harder question: what happened to the patient in between?

Answering that takes someone who has worked the floor when the systems go dark. I've done both.

"At 3 a.m. the downtime plan is 'figure it out' unless someone made you write one first."

Services

Three services, each one fixed in scope.

Every engagement is scoped in writing before it starts, and none of them requires access to patient data.

For digital health & AI vendors

Clinical AI Harm Review

An independent review of your ambient scribe, patient-facing chatbot or prior-authorization AI, with every finding scored by what it would do to a patient.

  • Adversarial testing against clinical workflows
  • Findings mapped to OWASP LLM Top 10 and NIST AI RMF
  • A Bedside Impact Report written for hospital security and AI governance reviewers
Fixed-scope engagements from $12,000
For hospitals & health systems

The 3 A.M. Downtime Drill

A clinical ransomware exercise for ED leaders, nursing and emergency management, built on what really happens when the EHR, alarms and neighbors all go down at once.

  • Diversion cascades, unannounced arrivals, paper triage
  • Run virtually, led by a former trauma-center clinical leader
  • After-action report with owners and dates
Virtual exercises from $7,500
For AI & health tech teams

Fractional Clinical Safety Advisor

A clinical voice on your security, product and customer calls each month. It's for teams selling into hospitals who need someone who speaks both languages.

  • Hospital security reviews and AI governance questions
  • Clinical risk input on roadmap and release decisions
  • Standing monthly review plus on-call questions
Retainers from $3,500/month

Medical device manufacturers: The PSTM Clinical Harm Assessment, the clinical-consequence layer of your premarket cybersecurity threat model, is available through regulatory and engineering partners. Ask about partnering.

The approach

Patient-Side Threat Modeling™

My framework, PSTM, scores cyber and AI risk the way a clinician triages: by how fast harm arrives and whether anyone at the bedside would notice.

First question: what fails, the therapy, the data, or the truth?

Therapy loss. The device stops or changes treatment. Harm can arrive in minutes.
Data loss. Information stops flowing while treatment continues. Harm depends on staffing and detection.
Integrity loss. Something is wrong but looks normal. It's the hardest to catch at the bedside.
  1. Physiological dependencyHow much the patient's body relies on the system right now.
  2. Latency to harmMinutes, hours or days between failure and injury.
  3. Bedside detectabilityWhether the care team would notice, and how.
  4. Workaround pressureWhat staff will do to keep care moving, and the new risk that creates.
  5. Downtime survivabilityHow long safe care can continue without the system.
```html
About

Twenty-three years on the night shift taught me what happens when the normal way of working disappears.

I spent more than two decades in emergency medicine across two Level II trauma centers. Over those years, I became a clinical leader, preceptor, Epic Super User, and the person teams trusted when situations moved fast and there was no room for guesswork.

I learned what it takes to keep patient care moving when the normal process breaks down: assess the situation, find the safest workaround, communicate clearly, and keep the patient at the center of the decision.

During Epic implementation, I trained and supported more than 200 clinicians. Later, I moved into interventional radiology and vascular surgery, coordinating complex procedures and referrals across two surgical centers.

Then I took that clinical perspective into healthcare technology and cybersecurity. I earned my MS in Information Technology and joined DeepScribe, where I helped clinicians adopt ambient AI in real-world workflows. Today, I bring that same clinical perspective into cybersecurity, medical device, and clinical AI decisions.

Same instinct. New frontline.

  • Emergency Medicine Leadership23 years | Level II Trauma | Clinical Preceptor
  • Clinical Systems & WorkflowEpic Super User | 200+ Clinicians Trained
  • Procedural Care CoordinationInterventional Radiology & Vascular Surgery
  • Clinical AI & Health TechnologyDeepScribe | Ambient AI Implementation
  • Healthcare Cybersecurity StrategyvCISO Advisory | Clinical Risk & Threat Defense
  • EducationMSIT (Cybersecurity) & Health Tech Cert | Kennesaw State University
  • Signature FrameworkPatient-Side Threat Modeling™
```
Featured Defender

Midnight in the War Room

A Semperis documentary highlighting the people who defend critical infrastructure when cyberattacks strike. Featured as one of 52 global defenders, the film premiered at Black Hat USA 2026 and is currently on a 30-city world tour.

Global Screening Tour (30+ Cities): Frankfurt · London · Singapore · Mumbai · Ireland · Mexico · Australia · Brazil · and more

See the work

The DFR Lab holds IoMT failure scenarios, clinical-AI red-team scenarios, and healthcare ransomware threat briefs, all scored with PSTM.

Open the DFR Lab →
Start here

Tell me the patient-facing system you're worried about.

A 20-minute Fit Call tells us both whether one of the three services fits. You'll leave with a scope and a price, not a sales pitch.

Book a Fit Call connect@chaundacdallas.com