Blog & news

Healthcare Cybersecurity and AI Governance Speakers: Which Expertise Does Your Event Need?

Cybersecurity, AI governance and clinical risk need three different experts. Learn which one your healthcare event needs and how to build a risk track.

Healthcare cybersecurity and AI governance speakers, Signal & Stage guide

By Harvey Castro, MD, MBA, emergency physician and founder of Signal & Stage.

Quick answer: “AI risk” covers three different jobs. Book a cybersecurity expert when your audience must stop attacks, an AI governance leader when it must decide who approves and answers for AI, and a clinical risk expert when it must protect the patient. Many events need two of the three.

Speakers in this guide: Richard Staynings, Viv Babber, Erkeda DeRouen, Gil Bashe and David Rhew.

Picture this. You booked a session called “Managing AI Risk.” Half your audience is the security team. The other half is the board. The speaker gives a careful talk on AI ethics. The CISO checks email. The board chair asks, “So who signs off on these tools?” Nobody on stage answers.

The villain here is the vague word “risk,” which lets you book the right expert for the wrong room.

So which kind of risk expert does your room need?

I have worked shifts when the computers went down. Paper charts come out, lab results arrive by runner and every decision slows. Nobody in that department needs a lecture on why security matters. They lived it. What they need is the right expert for the right problem.

What are the three kinds of AI risk speaker?

  • Can someone break in, steal data or shut us down? What they need: threats, attacks, medical device security, resilience. The speaker you want: a healthcare cybersecurity expert.
  • Who decides which AI gets used, and who answers when it fails? What they need: policy, oversight, accountability, regulation. The speaker you want: an AI governance leader, ideally with clinical or executive experience.
  • Is this safe and fair for the patient in front of us? What they need: clinical risk, bias, patient experience. The speaker you want: a clinician focused on digital health risk.

If your audience mixes CISOs, compliance officers and clinical leaders, consider a short keynote from one expert and a panel that brings in the other two.

When do you need a healthcare cybersecurity speaker?

Choose one when your audience includes IT, security, biomedical engineering, compliance or the executives who sign the security budget. Look for a speaker who:

  • Explains a real attack path in plain language, step by step.
  • Talks about connected medical devices, not only laptops and email.
  • Gives the audience something to check on Monday: an inventory, a drill or a vendor question.
  • Does not use fear as the whole message.

On the roster: Richard Staynings speaks on healthcare cybersecurity, medical device security and cyber risk for healthcare leaders. His speaking sample, “Anatomy of an Attack: Inside the Mind of a Hacker,” is on his profile.

When do you need an AI governance speaker?

Choose one when your audience is deciding how AI gets approved, monitored and retired: boards, C-suite, medical staff leaders, quality and legal. Look for a speaker who:

  • Describes who owns an AI tool after go-live, by role.
  • Separates what the law requires from what good practice requires.
  • Talks about human accountability, not just model accuracy.
  • Brings a framework the audience can adapt.

On the roster:

  • Viv Babber, MD: physician executive focused on AI governance and human accountability.
  • Gil Bashe: healthcare leadership, AI accountability and patient experience.
  • David Rhew, MD: responsible healthcare AI and clinical workflows.

When do you need a clinical risk speaker?

Choose a clinician focused on digital health risk when your audience is medical staff, nursing leadership, quality or patient safety. These audiences want to know how an AI error reaches a patient and how to catch it first.

On the roster: Erkeda DeRouen, MD speaks on digital health risk, AI governance and patient experience.

How do you build a full AI risk track?

  1. Keynote, 30 minutes: cybersecurity. Make the threat real.
  2. Panel, 45 minutes: governance and clinical risk together. Give the moderator one scenario for every panelist: “An AI tool gave a wrong recommendation and a patient was harmed. What happens in the next 24 hours?”
  3. Workshop, 60 to 90 minutes: small groups draft an AI tool approval checklist for their own organization.

The audience moves from the threat, to who is accountable, to a written next step.

What should you ask before booking?

  • What happened in healthcare security or AI regulation this year, and is it in your talk?
  • Can you speak without naming or blaming specific vendors or hospitals?
  • What will my audience be able to check or change the week after?
  • Have you spoken to boards, technical teams or both?
  • Do you have product or vendor ties I should disclose to attendees?

Planner checklist

  • I know whether my audience needs security, governance, clinical risk or a mix.
  • My speaker has spoken to an audience at this level before.
  • The talk includes this year’s events, not only old examples.
  • The panel moderator has a scenario ready.
  • Conflicts of interest are disclosed.
  • Recording rules are agreed, since some security content should not be posted publicly.

Frequently asked questions

Is a healthcare cybersecurity talk too technical for executives? It should not be. The right speaker tells the same story at two depths: what happened, and what leaders must decide. Ask for a sample given to a non-technical audience.

What is the difference between an AI governance talk and an AI ethics talk? Ethics talks explore what is right. Governance talks decide who acts, when and with what authority. Boards usually need governance.

Should security sessions be recorded? Agree in advance. Some speakers share attack details live but not on a public recording.

Can one speaker cover both cybersecurity and governance? Some can give an overview of both. For depth, book two experts and let them talk to each other on stage.

Build your risk track

Tell me who is in your audience and what keeps them up at night. I will suggest the right mix of security, governance and clinical risk speakers. Have a question this guide missed? Send it.

Discuss your event

Related reading: How to choose a healthcare AI speaker | Keynote, fireside chat, panel or workshop?

Harvey Castro, MD, MBA is a board-certified emergency physician, 5x TEDx speaker and author of over 45 books on AI and healthcare. He founded Signal & Stage to help event planners find the right healthcare, AI and leadership speakers.

www.HarveyCastroMD.com | /HarveyCastroMD | #DRGPT