Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from Medical Tech Outlook
THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by our MedTech Outlook Advisory Board.

Jeremy Kryszan, Director of IT Security


Jeremy Kryszan is an IT leader with more than 25 years of experience driving cybersecurity, digital transformation, and IT strategy across healthcare, finance, and government. Certified in CISSP, CRISC, ITIL, and AWS, he delivers enterprise-wide solutions, aligns IT with business goals and safeguards the organization’s critical assets.
In an exclusive interview with MedTech Outlook, Kryszan shared his views on healthcare in the world of cybersecurity.
25 Years Driving Secure Digital Change
Over the past 25 years, I’ve had the privilege of leading IT and cybersecurity efforts across healthcare, finance, and government. Each industry faces unique regulatory pressures— HIPAA, SOX, FINRA, CJIS—and navigating those has shaped my philosophy: compliance is necessary, but security must go further. In finance, I learned the discipline of controls and audits; in government, the importance of resilience and transparency; and in healthcare, the critical connection between technology and human lives. That combination has influenced how I approach digital change— not as a technology project, but as an organizational transformation where trust, safety, and patient outcomes guide every decision.
Prioritizing IT for Patient Care
Every IT initiative must ultimately support two things: better patient care and stronger data protection. To prioritize, I start with impact. Will the project reduce risk? Will it improve the clinical experience or protect sensitive data? I also weigh scalability—whether the solution positions us for growth—and compliance alignment. At Parrish, for example, we’ve focused on projects such as multi-factor authentication, medical device segmentation, and Windows 11 security hardening because they simultaneously improve patient safety, reduce attack surfaces, and prepare us for future regulatory requirements. That balance of clinical benefit, risk reduction, and compliance guides our roadmap.
Securing Systems Without Disruption
Healthcare IT operates under constant pressure: 24/7 clinical operations, tight budgets, and increasing cyber threats. The challenge is introducing strong controls without disrupting care. To achieve that, we embed security into workflows rather than layering it on top. For example, our identity and access management policies automate account reviews, eliminating the need for manual processes that can slow down clinicians. We also run tabletop exercises and phishing simulations to strengthen response without interrupting patient services. Compliance requirements—from HIPAA to NIST 800- 53—are addressed through governance frameworks that integrate with daily operations, so we maintain protection without creating barriers to care.
"Protecting systems means protecting patients, and that alignment shapes every investment and project decision we make."
Staying Ahead of Cyber Risks
Several trends are reshaping healthcare security: Ransomware and supply chain attacks continue to target hospitals, putting patient safety at risk.
Cloud adoption is accelerating, requiring stronger identity management and third-party risk oversight.
AI—both as a tool and a threat—is emerging quickly. We’re preparing by utilizing AI for threat detection while also developing policies to manage its associated risks.
Medical device security is now a major topic, as legacy systems create vulnerabilities in clinical environments.
We are addressing these by integrating MDR/XDR, strengthening privileged account controls with YubiKeys, enforcing network segmentation for devices, and aligning policies to NIST, HITRUST and HIPAA. Preparedness and layered defenses are key.
Building a Future in Health IT
My advice is:
Learn the business of healthcare. Technology must align with clinical and operational needs; understanding those will set you apart.
Invest in fundamentals. Networking, identity management, and governance may not be glamorous, but they are the foundation of strong security.
Develop communication skills. The best cybersecurity leaders can explain risks and solutions to executives, clinicians, and patients in plain language.
And finally—stay curious. Cybersecurity evolves daily. The professionals who continually learn, adapt, and connect technology to patient care will have the most significant impact.
Cybersecurity: A Threat
At Parrish, we do not view cybersecurity as simply a technical safeguard; we see it as a patient safety initiative. A cyberattack can delay surgeries, disrupt access to critical patient records, or undermine trust in our hospital. Protecting systems means protecting patients, and that alignment shapes every investment and project decision we make.
We conduct regular tabletop exercises with IT, clinical, and executive teams. These exercises simulate real-world incidents in a calm, structured environment. The result is stronger communication, faster decision-making, and a culture of preparedness that directly benefits patient safety and regulatory compliance.
Parrish is a government entity that has operated independently of tax dollars for over 20 years. That independence makes community trust essential to our success. Cybersecurity is one way we protect that trust, ensuring our patients and partners know that their information — and their care — are in safe hands.
I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

However, if you would like to share the information in this article, you may use the link below:
www.medicaltechoutlook.com/cxoinsight/jeremy-kryszan-nwid-4116.html
