
BLOG
Expert Spotlight - Bethany Page Ishii
Published On August 6, 2026
Meet Bethany Page Ishii, Vice President of Cybersecurity Strategy and Advisory at Meditology.
Bethany leads our advisory and professional services practice, helping healthcare organizations strengthen cybersecurity, governance, risk management, and regulatory compliance. She works closely with executive leadership teams to translate complex security challenges into practical, business aligned strategies while overseeing cybersecurity program assessments, strategic advisory services, and long term security program development.
What area of healthcare cybersecurity or GRC are you most passionate about?
I am most passionate about cybersecurity program assessments because they provide the most comprehensive view of an organization’s security program. A well-executed risk assessment tells a story, not just about technical controls, but about governance, operations, culture, and overall program maturity.
One of the aspects I enjoy most is benchmarking clients against their healthcare peers using our industry data. It allows us to highlight where they are leading the way and where they are falling behind. Those insights help executives understand their relative risk and make more informed decisions.
From there, the real value comes from turning those findings into a practical, prioritized security roadmap that helps clients focus their time, resources, and investments on the initiatives that will have the greatest impact on reducing risk and strengthening their overall security posture.
What is one common misconception you hear from clients?
One of the most common themes I see is that organizations do a good job identifying risks, but they struggle to operationalize and manage them across the enterprise.
Two areas stand out consistently. The first is Enterprise Risk Management. Many healthcare organizations manage cybersecurity, IT, compliance, operational, and financial risks independently, but few have a truly integrated enterprise risk register that gives leadership a holistic view of organizational risk. Without that centralized view, it is difficult to prioritize investments and make informed business decisions.
The second is third party and supply chain risk management. Most organizations have the foundations of a vendor risk management program, but scaling that into a mature supply chain risk program is challenging. It requires strong collaboration across security, procurement, legal, privacy, compliance, and business leaders, something that is often easier said than done.
Artificial intelligence governance is quickly becoming the next frontier. Healthcare organizations are eager to leverage AI to improve efficiency and patient care, but many are still developing the governance, security, and risk management practices needed to ensure AI is deployed responsibly and securely. Just like Enterprise Risk Management and supply chain risk, success will depend on strong cross functional collaboration rather than technology alone.
What’s the biggest opportunity for security teams when it comes to organizational resiliency?
Most organizations already have many of the right pieces in place, including vendor due diligence, business impact analyses, disaster recovery plans, incident response, and business continuity. The challenge is that these efforts have historically been managed and tested independently, when in reality, they’re deeply interconnected.
As a result, executives may not have a complete picture of resiliency. Do we know which critical business services depend on which systems, vendors, people, and processes? Do we understand where those dependencies create breaking points, and have we actually tested our assumptions?
A recovery plan tells you what should happen. Resiliency is knowing what will happen.
This is where security teams can be the heroes by connecting the pieces to give leadership an enterprise-wide view of resiliency, understand how risks can cascade, and focus investments where they matter most.
What is one piece of advice you would give healthcare leaders?
Benchmark your cybersecurity program against your peers.
Healthcare leaders often know where they stand internally, but not where they stand within the industry. One of the most effective ways to gain executive attention and build support for security investments is to show where the organization stands relative to similar healthcare organizations. If there is one thing executives do not want to hear, it is that they are lagging behind their peers. Benchmarking provides objective context, helps prioritize investments, and turns cybersecurity discussions from opinions into data driven business decisions.
What emerging trend should organizations prepare for?
Healthcare organizations should prepare for a shift away from point in time assessments and toward continuous cybersecurity assurance.
Rather than going through a risk assessment or penetration test on an annual exercise, organizations should establish a strategic security roadmap for the year and break it into manageable, continuous activities.
For technical validation, this means focusing testing on the areas that matter most at that point in time. For example, if an organization is rolling out Microsoft Copilot or another AI solution, perform a targeted assessment of AI governance, data protection, and identity controls. If a major Epic upgrade is planned, assess application security and privileged access. If the organization is deploying network segmentation or expanding cloud services, validate those specific controls through targeted penetration testing or adversary simulation exercises. This approach allows organizations to quickly implement improvements while those initiatives are still underway, rather than discovering issues months later during an annual penetration test.
The same philosophy applies to security risk assessments. Rather than waiting until the next annual assessment to measure progress, organizations should continuously track remediation efforts, coordinate workflows across stakeholders, validate that risks are being addressed, and leverage GRC platforms and workflows to automate accountability, reporting, and enterprise risk visibility.
Organizations that embrace this continuous approach gain better visibility into their security posture, respond to emerging risks more quickly, and make cybersecurity an ongoing business process instead of an annual event.
What is one thing people may not know about you?
Outside of work, I love to travel and have been fortunate to visit more than 40 countries. One of my favorite parts of traveling is trying local foods and experiencing different cultures firsthand. I also see travel as one of the best forms of continuous learning. Every trip offers new perspectives, challenges assumptions, and helps me better understand how people think, communicate, and solve problems.
What is the biggest risk management challenge healthcare organizations are facing today?
The biggest challenge is not identifying risks. It is prioritizing and addressing them with limited resources. Healthcare organizations are balancing increasing cyber threats, evolving regulatory requirements, staffing shortages, aging technology, and constrained budgets.
In many cases, organizations also struggle to hire and retain experienced cybersecurity talent. The reality is that it is often easier to gain approval for a solution or service than it is to add a new full time employee. That is where augmentation and strategic advisory partners can help organizations fill capability gaps, accelerate progress, and provide specialized expertise while they continue building their internal teams. Ultimately, the organizations that are most successful establish strong governance, leverage the right mix of internal and external resources, and use risk to drive investment decisions rather than trying to solve everything at once.