I didn't leave healthcare.
I learned to defend it.
The work of defending healthcare systems from ransomware, protecting connected medical devices, and bridging clinical reality with cybersecurity strategy was already underway. Semperis recognized it. Selected as one of 50+ global defenders in their groundbreaking cyberwar documentary — exploring what it truly means to defend critical infrastructure when nation-states attack.
Watch the Trailer →For 28 years I worked high-pressure clinical environments — the ER and outpatient surgical care — where physicians, nurses, and leadership depended on my judgment. When ransomware and digital risk began threatening patient safety, I earned my MSIT in cybersecurity to keep protecting patients — same mission, wider perimeter: the bedside, and now every connected system behind it.
Started on the floor. Learned the system from the ground up.
Clinical decision-making under pressure. Zero margin for error.
Leadership and scope across ER and outpatient surgical care.
Kennesaw State University. Medical device security concentration.
IoMT security, GRC, clinical risk — at enterprise scale.
Midnight in the War Room. Semperis. Global stage.
In the ER and OR, there is no "IT ticket" for a life-critical system failure. You need security that understands the velocity of care. We bridge the gap between technical defense and clinical reality — approaching cyber risk like trauma triage: prioritize what harms patients first, stabilize fast, build defenses that hold under extreme pressure.
Born from emergency triage principles, the DFR Framework maps clinical emergency response directly onto cybersecurity incident response. It's not a metaphor — it's a methodology. The same instincts that stabilize a crashing patient stabilize a compromised network.
Identify what's critical, what's stable, what's failing. Prioritize by patient — and patient safety — impact first.
Stop the bleed. Isolate compromised systems without shutting down care delivery.
Targeted intervention. Evidence-based controls. No unnecessary disruption to clinical operations.
Return to full operation. Build stronger defenses. Document for the next incident.
A branching tabletop: ransomware hits the med room. 12 decisions across Triage → Stabilize → Treat → Recover. Rookie, Pro, and Command tiers.
Run the Range →Live threat intel, ranked by clinical impact — not just CVSS.
Open in the Lab →Device and system threat modeling in live clinical environments. AI governance for FDA- and audit-facing products.
HIPAA, NIST, SOC 2 alignment without operational disruption. Policy clinicians actually follow.
Ransomware and downtime planning for EHR and device environments. Tabletops that prepare real clinical teams.
"Behind the Scenes of Midnight in the War Room" — April 2026, with Krista Arndt, moderated by Heather M. Costa (Mayo Clinic)
Last Month in Security · 2024. Healthcare ransomware threat landscape and clinical impact analysis.
2025. Volunteer leadership coordinating scholar badge access across Hacker Summer Camp.
Diana Initiative / BlackGirlsHack · 2025. Selected for professional development recognition.
2024. Selected through competitive grant program for cloud and technology leaders.
Active contributor to medical device and healthcare security research at the annual event.
Senior healthcare cybersecurity expertise without the overhead of full-time staff. I never left healthcare — I learned to defend it. Remote-first with on-site availability. Engagements structured to integrate cleanly into existing delivery teams and protect clinical operations.
Ready to discuss subcontract availability, advisory support, or a custom engagement? Reach out directly — remote-first, available immediately.
HIPAA Security Risk Assessments — 5-day delivery, from $2,500.
Send an Email →Three ways to connect — office hours, 1:1 sessions, or drop into Saturday Study Hall. No gatekeeping. Just show up.