In a Help Net Security video interview, Drew McCombs, CTO and CISO at Cylerity, describes how he balances security with product development. Security is treated as a core feature that is never complete and is scheduled into every sprint. When priorities conflict, issues affecting patient data or funds disbursement win, and core security projects are tracked and reviewed with leadership so progress is visible.

McCombs also explains how Cylerity keeps protected health information away from its bank partner. Cylerity is not a bank and uses a bank credit facility, but bank diligence can create pressure to discuss claims at the line level. His approach is to use the minimum data required, summarize at the payer or customer level, replace claim identifiers with custom ones, and keep PHI separate from financing data across the platform.

On AI, McCombs is blunt: the model does not act. AI can recommend, summarize, or flag, but a person is always in the loop before anything releases funds or exposes patient data. Explainability means showing the source data the model relied on, not the model's own explanation of its reasoning. He also warns about reviewer drift, where careful approval turns into rubber-stamping, and says Cylerity mitigates that with multiple reviewers and post-decision reviews.

The cheapest and most impactful fix for small practices, he says, is turning on MFA, starting with email. He also notes that deposit account changes are confirmed by phone using a number already on file. For hospital CISOs vetting fintech vendors, he suggests asking vendors to list every party that touches their data, including subprocessors, AI services, and financing partners.