Archimedes Medical Device Security 101 Workshop

Confirmed Speakers Include:

David Brumley - Headshot Cropped
David brumley
CEO
ForAllSecure
 

David Brumley is the CEO of ForAllSecure and a full professor at Carnegie Mellon University. His research focuses on novel program analysis and verification techniques that prove the presence of bugs and vulnerabilities.  He has published numerous academic papers, won several test-of-time and achievement awards, competed and won the DARPA Cyber Grand Challenge, and holds a black badge. ForAllSecure created Mayhem to bring the same technology used by the world’s best hackers into commercial software development pipelines.

 


image005

 

Kevin Fu
Professor; Director Archimedes Center for Health Care and Medical Device Cybersecurity
Former Acting Director, US FDA CDRH Medical Device Security
IEEE Fellow; ACM Fellow, AAAS Fellow
 

Kevin Fu is credited for establishing the field of medical device security beginning with the 2008 IEEE paper on defibrillator security.

Kevin is a former MIT Technology Review TR35 Innovator of the Year and Fellow of the AAAS, ACM, and IEEE. He has testified in the House and Senate on matters of information and medical device security and has written commissioned work on trustworthy medical device software for the Institute of Medicine of the National Academies. He was a member of NIST Information Security and Privacy Advisory Board, the CRA Computing Community Consortium Council, and the ACM Committee on Computers and Public Policy. He received the Dr. Dwight E. Harken Memorial Lecturer Award from the Association for the Advancement of Medical Instrumentation (AAMI) for his leadership on medical device security standardization.


 

Cropped_Image-19

 

gREG GARCIA
Executive Director, 
Health Sector Coordinating Council
 
Greg Garcia is the Executive Director of the Health Sector Coordinating Council Cybersecurity Working Group, the government-recognized critical infrastructure industry advisory council of more than 400 healthcare providers, pharmaceutical and medtech companies, payers and health IT entities partnering with government to identify and mitigate cyber threats to health data and research, systems, manufacturing
and patient care.

Greg was appointed by President George W. Bush as the nation's first Assistant Secretary for Cybersecurity and Communications for the U.S. Department of Homeland Security.
 
Throughout his 32-year career in national service he has influenced and implemented change at the intersection of business, public policy and national security, including
executive positions in healthcare, financial services, high technology and the United States Congress.

Greg is a 2024 recipient of the Baldrige Foundation Award for Leadership Excellence in Cybersecurity.
 

aginter-sq-upr-mr

 

aNDREw Ginter
VP Industrial Security
Waterfall Security Solutions
 
At Waterfall Security, Andrew leads a team of experts who work with the world's most secure industrial enterprises, focused on manufacturing, heavy industry, critical industrial infrastructures, and building automation.
 
Before Waterfall, he led the development of high-end industrial control system products at Hewlett-Packard, products that automated some of the world's largest pipelines and power grids. At Agilent Technologies he led the development of IT/OT middleware products that connected industrial automation systems to SAP and other business automation systems. At Industrial Defender he led the development of the world's first industrial Security Information and Event Management (SIEM) system.
 
Andrew is the author of three books on industrial / OT cybersecurity, a co-author of the Industrial Internet Security Framework, and a co-author of the UITP report on cybersecurity requirements in rail system tendering. He co-hosts the Industrial Security Podcast and contributes regularly to industrial security standards and best-practice guidance.
 
 

image001-2

 

ERic Henry
FDA & Life Sciences Practice
King & Spalding

 

Eric Henry is a 35+ year veteran leading global technical and regulatory compliance organizations, with a particular focus on medical device software design controls.

He currently works in the FDA & Life Sciences Practice of the law firm King & Spalding, where he provides advisory and management consulting services focused on regulatory compliance, enforcement, and policy matters involving industries regulated by the FDA and other global life sciences regulatory competent authorities. He also advises corporate management, boards, and staff concerning their responsibilities, regulatory expectations, and how to navigate through compliance and enforcement complexities during crisis events.


Cropped_Image-5

 

jack kufahL 
Chief Information Security Officer
Michigan Medicine
 

Jack Kufahl is the Chief Information Security Officer for Michigan Medicine at the University of Michigan, one of the nation’s top academic medical centers that brings together world-class experts from research, patient care, and education to make groundbreaking discoveries that create life-changing medicine. 

He has over 20 years of experience in information technology, primarily in leadership roles. He is one of the incorporating officers of the Michigan Healthcare Cybersecurity Council and is a current board member. The MiHCC is a public-private partnership in the State of Michigan and the healthcare industry supporting the citizens, patients, workforce , and students of Michigan. MiHCC seeks to protect the critical healthcare infrastructure and institutions of Michigan by providing relevant knowledge, meaningful relationships, and information security services to the partnering individuals, agencies, organizations , and vendors. Jack is also a graduate of the esteemed FBI CISO Academy and has completed the Masters of Legal Studies program with a concentration in compliance law at Washington University in St Louis. 

As the Chief Information Security Officer, he is currently responsible for planning, developing, implementing, and maintaining the Michigan Medicine information assurance program. He directs all information assurance activities across the academic medical center to ensure the confidentiality, integrity, and availability of electronic information resources critical to the tripartite mission of patient care, research, and education at Michigan Medicine.  

 


Soundharya Nagasubramanian -smallFile

 

Soundharya Nagasubramanian 
Senior Leader of Software and Cybersecurity
Vapotherm
 
Soundharya is a Senior leader of software and cybersecurity with extensive experience in delivering products. She is passionate about medical device design and delivery of innovative and secure products by building highly talented and collaborative teams. She likes learning and deploying technology as a tool to build products. She has worked as a leader in product development and product security at companies such as Baxter, Hill-Rom, Welch Allyn. Having worked with the medical device industry for over 24 years, she is still fascinated by the opportunity to help in delivering secure products that can help diagnose and treat patients. She has a rare blend of product development and cybersecurity experience.

NimiHeadshot

 

nimi ocholi
Vice President, Research & Development, Product Security
BD
 

Nimi is the Vice President, Research & Development, Product Security at BD. Nimi leads the team of Product Security Officers focused on implementing security by design, security in use and product end of life strategies across BD’s portfolio of software-based products. He is responsible for establishing clear product security process/technology expectations and enabling increased product security maturity.

Prior to joining BD, Nimi was Senior Director for Product Security & Technical Fellow at Medtronic and has more than 18 years of experience in the Medical Device Industry. He previously assisted the Cardiac Rhythm Management and Neuromodulation businesses in managing ongoing challenges related to Product Security. He is involved in several external forums including the Health Sector Coordinating Council - Joint Cybersecurity Working Group.

Nimi earned his BS and MEng degrees from the Massachusetts Institute of Technology and security training from the SANS Institute.

 


Salwa

 

Salwa Rafee
Senior Key Expert
VP - Healthcare & Life Sciences Transformation, Technology & Cybersecurity
Siemens Advanta Consulting
 

Salwa Rafee has 20+ years of experience in healthcare consulting (IBM, Accenture, PwC, Life strategy Consulting); 60+ HCLS projects. Her expertise is in MedTech and Healthcare industries, Strategy & Business Transformation, Cloud Migration, IT/OT Cybersecurity, Process optimization, Market access, Regulatory compliance, and Global Business growth. She is a great public speaker and advisor to many government health entities in NA, Europe, MEA and AP. She led a comprehensive security assessment for a leading Life Sciences company, Evaluating potential risks and opportunities associated with strategic outsourcing initiatives. She has also led cloud migration initiatives, implemented robust cybersecurity solutions, and collaborated with healthcare providers in large US hospitals to fortify their IT/OT infrastructure.

She has an M.Sc. in Biomedical Engineering at Boston University, and Fellowships with University of Alberta Medical Sciences, Harvard University Security Program, And London School of Economics.


Cropped_Image-12-1

 

Bill Reid
Security Advisor, Office of the CISO
Google Cloud

Bill is a member of Google Cloud’s Office of the Chief Information Security Officer (CISO), where he advises Health and Life Sciences customers on ways to achieve their business goals while adopting a high security bar.  

Prior to Google, he was VP and Chief Security Officer for National Resilience, a bio-manufacturing company, where he established and ran the Security and Privacy organization, including physical, IT, and OT/ICS systems.  Before Resilience, Bill was the CISO for Amazon Care, a telemedicine and in person care service.  Also at AWS, Bill led the AWS Security Solution Architecture team.  Earlier, Bill held CISO roles at healthcare technology and medical device companies, and was Director of Product Management for Microsoft’s Health Solutions Group and member of their Trustworthy Computing initiative.

Bill began his career in healthcare administration for Group Health Cooperative (now Kaiser).  He has a Masters from Tufts University and Bachelors from the University of Pennsylvania. 

 


Cropped_Image-21

 

Naomi Schwartz
Vice President of Services
Medcrypt Inc.
 

Naomi is the Vice President of Services at Medcrypt, a medical device cybersecurity specialty firm.  She is a former premarket reviewer and consumer safety officer at FDA’s CDRH, with 6.5 years of expertise in software, cybersecurity, interoperability, and wireless coexistence for connected diabetes devices.  She was the recipient of multiple awards at the FDA, including 5 Commissioner’s Special Citations, for outstanding service, group achievements, customer service excellence, and plain language communication at CDRH.  Naomi has been recognized as a team recipient of the Samuel J. Heyman Service to America Medals for Management Excellence. 

Prior to her time at FDA, Naomi spent 15 years as a defense contractor developing radar systems and jammers for live field tests with operational DoD assets.  Naomi holds a distinguished track record of ensuring cybersecurity and operational safety across the medical and defense sectors.

 


image002-3

 

Hans-Martin von stockhausen
Principal Key Expert for Cybersecurity
Siemens Healthineers
 
 

Dr. Hans-Martin von Stockhausen holds a position as Principal Key Expert for Cybersecurity at Siemens Healthineers. In this position he leads the company in developing security requirements for all products gathered from international regulations and customers around the globe with a focus on supporting the operational risk management on the operator’s side. Inside the Siemens security community, he leads a team that that works on improving and maintaining the security posture of products and security related customer communication. He has extensive domain knowledge from 20+ years of work experience in the medical device industry holding various positions throughout the product lifecycle from SW developer to SW platform architect to product manager.

For 10+ years, his focus has been on cyber security while holding a position as product security officer for medical IT systems and image acquisition devices. Hans-Martin participates in expert workshops and talks at conferences held by European and internationally recognized organizations. Furthermore, he is a member of the board of directors of Health-ISAC.

 


Cropped_Image-20

Co-Chair

AXEL Wirth
Chief Security Strategist
Medcrypt Inc.

Axel Wirth is a seasoned professional with a passion for medical device cybersecurity. He has been involved in the medical device industry for more than 40 years. Over the past 15 years, he has developed a deep understanding of the unique cybersecurity challenges posed by these devices. Axel has a proven track record of developing and implementing effective security solutions that ensure the confidentiality, integrity, and availability of medical devices and the sensitive data they manage. He is known for his exceptional problem-solving skills, technical knowledge, and excellent communication and leadership abilities.

As Chief Security Strategist, Axel Wirth provides strategic vision and industry leadership to Medcrypt and its customers. In this role he helps guide the company in critical security strategy decisions and supports the adoption of security technologies to the healthcare industry. He is committed to advancing the field of medical device cybersecurity and ensuring that patient receive the best possible care – safely and effectively.

He is an active participant in industry and standards organizations, serves on boards and committees, and is a frequent speaker on subjects such as healthcare cybersecurity and privacy, medical device security, regulatory
compliance, and related healthcare-specific topics.

As adjunct professor, Wirth teaches a Medical Device Cybersecurity course at the University of Connecticut clinical engineering graduate program as well as is the co-editor / co-author of two books on the topic. Further, he guides healthcare-focused cybersecurity startup companies as an advisory board member.

In recognition of his accomplishments, he has been awarded the “2018 ACCE/HIMSS Excellence  in Clinical Engineering & IT Synergies Award” and the “ACCE 2019 Clinical Engineering Advocacy Award” as well as has been recognized as a Fellow by AAMI (Association for the Advancement of Medical Instrumentation) and HIMSS (Healthcare Information and Management Systems Society).

His extensive background in the healthcare IT and medical device industries includes engineering leadership as well as business development and marketing roles with Siemens, Analogic, Mitra, Agfa, and Symantec. His education includes a BS in Electrical Engineering (BSEE) from the University of Applied Sciences, Düsseldorf (Germany) and an MS in Engineering Management (MSEM) from The Gordon Institute of Tufts University.