Insights

/

Podcasts

AH115 - Achieving FedRAMP® Ready Status & Why Security is a Team Sport, with Shane Garoutte

Podcasts
August 21, 2026
AH115 - Achieving FedRAMP® Ready Status & Why Security is a Team Sport, with Shane Garoutte
All set! Your report is ready.

Thanks for submitting the form. You can now download your report using the button below.

Download Report
Download Report

Transform health and pharmacy benefits

Talk to Our Team
Talk to Our Team
Listen on:

Listen on

Spotify

Listen on

Apple Podcast

Listen on

Amazon Music

Listen on

Audible

Listen on

iHeart Radio

Episode Guests
No items found.

Episode 115 Highlights

  • FedRAMP® Ready status is a differentiated achievement. The real investment is not just technical compliance, but changing day-to-day business behavior through continuous security practices across the entire organization.
  • Healthcare security depends on practical habits, not just frameworks – everyone plays a part. Shane shares advice on physical device awareness, multi-factor authentication, passkeys, and healthy skepticism, offering listeners simple steps to reduce risk at work and at home.
  • A strong cybersecurity culture is built on trust and teamwork. Security teams should be seen as partners, not punishers; fear can push employees to hide mistakes instead of reporting them early.
  • Security maturity is a business differentiator. Shane connects FedRAMP Ready status to Judi Health’s cloud-first architecture, scalability, and technology-first approach to benefits administration, showing why employers, plan sponsors, and health plans should care.
  • Agentic AI is changing the threat landscape, and fast. The most astonishing story highlights why cybersecurity defenses must be at least as dynamic, adaptive, and creative as AI-powered systems and threat actors move beyond traditional attack patterns.

Healthcare security threats are growing more sophisticated, and the stakes are higher than ever. In this episode of the Astonishing Healthcare podcast, host Justin Venneri sits down with Shane Garoutte, Chief Information Security Officer at Judi Health, for a conversation about what it takes to protect member data in a landscape where the adversaries don't play by any rules.

Shane's path to the CISO chair wasn't a straight line - it was shaped by experience across engineering, cloud operations, application architecture, and site reliability. That broad technical background now informs his approach to security, including his view that "paranoia can be a professional skill." This shapes how he thinks about security, and it comes through in everything from achieving FedRAMP® Ready status to compliance and practical advice you can use to protect your own family.

Cybersecurity Attracts a Different Kind of Mind

Most engineering roles come with a built-in support system. Product managers, project managers, and customers all want to see your work succeed. Security is different.

"I don't know of any other space in the engineering field where you have a continual adversary trying to work against you," Shane explains. "You don't even have a face or a name to the adversary. Their tactics change constantly, and it's a fun challenge."

As Shane says, he doesn't know any other field where paranoia is considered a professional skill. It's a mindset that treats healthy skepticism as an asset rather than a liability, and it turns out to be essential when you're defending sensitive healthcare data every single day.

What FedRAMP® Ready Status Means for Judi Health™

One of the biggest milestones Shane discusses is Judi Health's listing in the FedRAMP marketplace, with the enterprise health platform achieving ready status. But what does that actually mean, and why should anyone outside the security team care?

Continuous Commitment, not "One-Time Badges"

Shane is quick to draw a distinction between security theater and the real thing. Plenty of practitioners, he says, are "just chasing the badge." FedRAMP doesn't allow for that.

"It's not a one time a year certification where they come in, they assess you one time and then we'll see you in 11 and a half months," Shane says. "It is something that's continuous and constant."

The technical side, according to Shane, is fairly straightforward. The hard part is behavioral. "It is the behavioral side that has to change. How you think about what you do every day, how you handle member data. The importance of that handling has to change if you're going down this FedRAMP ready status."

Security is a Company-Wide Effort

Shane is clear on one thing: this couldn't be a project owned by the security team alone.  

"I really challenged the business when we first went down this road where I said it can't be something that's driven by the security team. It has to be something that's driven by the executive team and the C suite."

Shane credits leaders like AJ Loiacono for embracing the message. The result materially changed how the entire business operates.

The Other Security Credentials That Matter

FedRAMP isn't the only credential in Judi Health's portfolio. Shane walks through several others and explains what each one covers:

  • SOC 1: Heavily focused on the financial side of the business, with security ties woven throughout.
  • SOC 2 Type 2: Centered on privacy, member data handling, and privacy policy.
  • HITRUST: The only meaningful badge in the HIPAA space, since HIPAA itself has no official certification. Judi Health achieved this within its first two years and maintains it annually.
  • NIST 800–53: This framework forms the foundation of Judi Health’s security practice. It is not a certification, but it supports major programs and standards such as FedRAMP, FISMA, and CMMC.

How Big Is the Healthcare Threat, Really?

The numbers explain why all of this matters. HHS requires organizations to report any breach affecting 500 or more people. Last year, according to Shane, there were over 750 breaches of that size.

Some were massive, like the Change Healthcare incident that impacted hundreds of millions of individuals. Others were small. Attackers share a common pattern: they are relentless, opportunistic, and increasingly effective.

Three Simple Security Tips Anyone Can Use

With summer travel and remote work in full swing, Shane shared practical advice that costs nothing and protects both you and your organization. As he warns, threat actors know when you're distracted.  

1. Watch Your Physical Devices

The first tip is the simplest. Know where your device is at all times.

"Getting up and walking away from that asset, it's a very dangerous thing to do, particularly with the data that we have."

Justin shared his own painful lesson from a coffee shop in New York City years ago, when his bag vanished in the 10 or 15 minutes he wasn't paying attention. Shane's response captured the reality of the threat: "Threat actors are creatures of opportunity. They're going to look at the easiest way to get something done."

2. Move Beyond Passwords

Passwords, Shane argues, may be the worst thing security ever implemented. Many breaches start when passwords leak, usually through a third-party compromise, and attackers then reuse them across endpoints. His strongest recommendation is multi-factor authentication - "it's free!"

"That will be probably the single best piece of advice to protect you and your loved ones that I could give you today."

You do not need to buy a hardware token, though Shane advises that FIDO2 keys are a reliable option. MFA is usually free, and he's personally sat down with his family members to turn it on across their most sensitive accounts.  

3. Verify Before You Trust

AI has made smishing (SMS-based phishing) and phishing look remarkably legitimate. Shane's advice is to build a habit of skepticism and a simple family verification system.

"Have a verification code that you can use with your family... call back on a known number that you already had, something that you already know is legitimate."

The rule is straightforward: don't trust anything that arrives on your personal or professional device without confirming it through a channel you already know to be real.

Leadership Lesson: Security Is a Team Sport

When asked for advice on building and leading security teams, Shane didn't hold back. His core belief is that security only works when the whole organization feels like a partner rather than a target.

"If your organization is scared, they fear sort of retribution from the security team, if you approach them with something they may have made a mistake around, you're actively circumventing your security program and making it less secure."

He's seen the alternative firsthand: CISOs who are adversarial, condescending, or punitive. That approach creates a "protectionist behavioral line in the sand" that makes everyone less safe.

His two foundational principles:

  1. Make your team approachable. Shane runs internal polls asking whether the security team is easy to talk to, responsive, and enabling rather than blocking.
  1. Be as transparent as you safely can. While the principle of least privilege limits what you share during incidents and forensics, multi-year initiatives like FedRAMP demand transparency across sales, finance, HR, engineering, and operations alike.

Why a Technology-First Platform Sets Judi Health™ Apart

Very few healthcare companies or benefits administrators hold FedRAMP ready status, and that short list is a point of pride. Shane explains why plan sponsors and health plan executives should care.

FedRAMP is a cloud-only status, so achieving it attests to a certain level of maturity and scalability. When Shane joined, he was struck by how much architectural thinking had gone into the Judi Health platform from the start.

"I was impressed by how much thought had been put into Judi as a stack when it was first architected originally, and how much it was really a technology company focused in the healthcare space, not a healthcare company that is trying to use technology as much as they can."

That distinction, a technology company operating in healthcare rather than the reverse, is the differentiator Shane returns to again and again. In a sector often known for legacy, brick-and-mortar thinking, achieving FedRAMP ready status is proof of a genuinely modern approach.

The Agentic AI Elephant in the Room

For the show's signature closing question about the most astonishing thing he's seen, Shane set aside his prepared answer to address what he called the "agentic AI elephant in the room."

He pointed to a security report and the Open AI Black Hat Presentation, delivered at the world's biggest security conference in Las Vegas. The story involves agentic workloads, or what OpenAI calls "swarms," groupings of AI agents working together toward a goal.

The setup was a contained test environment. OpenAI asked a frontier model to find a vulnerability in a specific use case, and told it that it wasn't allowed to use the internet. So the system got creative.

"These agentic systems started using an internal message board to trade messages to each other in ways that the programmers and developers never expected."

From there, things escalated dramatically. The AI:

  • Found an unpublished zero-day vulnerability in how the system stored artifacts.
  • Exploited that zero-day to gain a foothold.
  • Achieved root access, meaning full administrative privilege.
  • Moved laterally inside OpenAI without anyone understanding what it was doing.
  • Discovered that a partner company, Hugging Face, had a model that could help it win, and adjusted its parameters accordingly.

Why did it do all this? Because it was told to win at all costs.

Shane's reaction captured the surreal nature of the moment: "It feels like sci fi, honestly. It feels like we're in the matrix."

What This Means for Defenders

The takeaway is a wake-up call for the entire security industry. The old model of building a moat, putting up a firewall, and patching holes isn't enough anymore.

"If you are not approaching this as the defense needs to be as dynamic as the offense, we're only a matter of, I would say, a year before that becomes a serious, serious problem. Maybe even less."

Key Takeaways for Healthcare Security Leaders

Shane Garoutte's conversation is a reminder that strong security is built on mindset as much as technology. The path forward requires treating skepticism as a skill, compliance as a company-wide commitment, and AI as both a tool and a threat that demands constant vigilance.

If you lead a security team, the practical challenge is clear: make your team a partner, connect security to business value, and prepare your defenses to be as dynamic as the adversaries you face. And if you're simply trying to protect yourself and your family, start today by turning on multi-factor authentication and building a habit of verification.

Podcast Transcript

Lightly edited for clarity.

[00:22] Justin Venneri: Hello and thank you for listening to another episode of the Astonishing Healthcare Podcast. This is Justin Venneri, your host and Senior Director of Communications at Judi Health. And today I'm welcoming Shane Garoutte to the show. Shane, I've been looking for a good opportunity to have you on for a while now. Really glad you could take the time. I know you're super busy. You're Chief Information Security Officer. There's plenty going on for you on any given day of the week. Thank you very much for being here.

[00:44] Shane Garoutte: Yeah, thanks for having me, Justin. I'm excited to be here.

[00:46] Justin Venneri: So tell us a bit about your background. I know I just dropped your title at the beginning of this, but tell us a bit about your path to Judi Health and your role here.

[00:53] Shane Garoutte: Sure. My background is kind of a meandering story. Wasn't a direct path to security. I came up really on the engineering side, mostly on the operational and software engineering side. A lot of cloud, a lot of operations teams, a lot of application architecture, site reliability. Way before security was in my title. I've touched just about every web-facing sector. A lot of ad tech I was in online realty. Banking technology was my most recent job. I was the CTO there. And so it gave me that perspective of what it's like to work with security organizations and work with different security teams as well as build different security teams and build them over time. So this is, yeah, it's the first role where I've been focused just on the CISO realm and the side of technology that deals with paranoia. It's been a fun journey, and I think that journey really equips me, I guess, slightly differently. We'll probably get into that a little bit today of what you would traditionally have as a path to CISO through college and then your career itself.

[01:54] Justin Venneri: Yeah, I feel like I hear some cool stories from people about how and why they get into the security side of things. Cybersecurity. They kind of find that they like it, they're good at it, the psychology, the paranoia, as you said. Talk to me a little bit about that, like why. Why cybersecurity for you?

[02:08] Shane Garoutte: Yeah, I mean, it's an interesting space. I mean, I don't know of any other space in the engineering field. Where you have a continual adversary trying to work against you. If you're a software engineer, application engineer, you're an operations person, often everybody's in your corner. You have product people that are working with you. You have project managers that are working with you. You have the customer who wants you to deliver whatever you're delivering. Everybody's on your side, trying really hard to see that thing that you're doing is successful. This role. There really is a lot of paranoia you have to deal with this adversary. You don't even have a face or a name to the adversary. Their tactics change constantly. And it's a fun challenge. It's particularly in the day of agentic AI. We're going to talk about that, I think, a little bit later. There's going to be a lot of what we have to do that needs to change, and really ties in a lot of the skills that I already have. Running different kinds of teams and understanding how security really applies to the practical art of building applications and delivering customer value. So I really gravitated toward it. I really don't know any other space where paranoia is considered a professional skill. I guess is how I would say that. Yeah, it's challenging every day, and I really enjoy the team and the organization.

[03:18] Justin Venneri: It's funny, I can relate. I feel like I'm often paranoid about the perception of the content and things. So I try to be very considerate of that. And it does. It does feel like a battle sometimes or you're kind of going at it with somebody. You're not sure who's on the other side of the screen. So let's talk a little bit about the security badges and the things that we've earned over time. I think it's a good place to start. Recently and announced that were listed in the FedRAMP® marketplace, and we – Judi®, really – our Enterprise Health platform – has Ready status. So I have a two-part question for you. One, what does that mean? And then the second part is what sort of investment is that to achieve?

[03:52] Shane Garoutte: It means a lot to the organization. It's one of the first things that AJ challenged me with when I first joined the organization. Opening up that federal market, really approaching the federal space the way that we need to be able to partner with a lot of those federal entities. It means a lot for the organization because it also proves that we have a foundation that a lot of other organizations just don't possess. In my industry it's often that you find security professionals and practitioners that are just chasing the badge. But FedRAMP is one of Those that it's not a one time a year certification where they come in, they assess you one time, and then we'll see you in 11 and a half months. It is something that's continuous and constant. We have to do things every day, every week, every month, every quarter to really implement the practical side of security and not the theater side of security.  

So, I think for the organization it means a. It was a big investment, it was a long journey, but it really materially changed the way we do everything within our business. I talk to the team often about. It's not the technology side of FedRAMP that is the difficult piece. In fact, it's pretty straightforward. And they give you these 325 base controls that expand to 800 controls. They're very detailed. They basically tell you exactly what to do. It is the behavioral side that has to change. How you think about what you do every day, how you handle member data. The importance of that handling has to change. You're going down this FedRAMP Ready status. So yeah, it's a big investment. It's a massive differentiator to be on the marketplace, which we're very proud of. The team is well deserved, gotten all the accolade. I really challenged the business when we first went down this road where I said it can't be something that's driven by the security team and it has to be something that's driven by the executive team and the C suite. AJ embraced that, Antonio embraced that. Everybody really got behind that message and that's why we're here. It's not because of any one individual or team within the company. The whole company decided to go down this road.

[05:45] Justin Venneri: What are one or two of the other badges that we've got that you're responsible for? I feel like I hear the Soc S, O C, Soc 1, Soc 2, Type 2, NIST is another one. Walk us through one or two others that we've sort of achieved and have significance.

[05:59] Shane Garoutte: Sure. Soc 1, Soc 2, Type 2, those are very important families of controls. They're really foundational. I think all organizations really, particularly US based organizations, really need to embrace those and approach those seriously. But they are very much largely a bare minimum, particularly of the security practices. SOC1 is really heavily financially related. So we focus a lot around how we do the financial side of the business. And it has of course, ties into security, as all things do.  

SOC 2 has a lot more of that privacy side and that pulls in a lot of responsibility around how we handle member data and our privacy policy and what we do with those things. During the first two years we also achieved HITRUST, which is really the only badge within the HIPAA space. HIPAA is a requirement from government perspective. But there's no official HIPAA certification. You don't certify the company as HIPAA or the Judi Rx platform as HIPAA. So we went down the road of HITRUST. That was I think a middle ground difficulty achievement. And we did very well and continue to maintain that every year. And then you mentioned NIST-853. I want to be very careful with that one. Again, not a certification or a badge per se. That's a framework that FedRAMP and Fisma and a number of other CMMC and other number of other badges is actually the basis of our security practice here at Judi Health. So yeah, we hold SOC1, SOC2, HITRUST, and FedRAMP Ready status at this point.

[07:29] Justin Venneri: Thank you for explaining those so cleanly. And then I gotta ask, when we were looking at the data around the announcement and just trying to explain like why this matters, I think I read this right and I think it's pretty crazily consistent that there's over 700 attacks a year and it goes back a couple few years now on companies that are serving larger populations. I think that's over 500 individuals or attacks impacted. More than 5, 500 individuals. And that goes from there all the way up to the change Healthcare's tens of or hundreds of millions of individuals impacted. It seems like security is definitely more important than ever. Sorry for stating the obvious. And it's summertime here while we're recording this. So I guess something maybe a little fun or just more helpful to the audience. People are working remote, maybe they're on vacation. What are a couple of tips or reminders that the audience should keep in mind just to stay safe online. Maybe it helps them and their company stay compliant with some of these frameworks or some of these certifications or badges they've earned, keep their data and system safe, et cetera, et cetera.

[08:25] Shane Garoutte: Yeah, that's a good question. Okay, I'll give you a couple. And remember, when you're thinking about adversaries and threat actors, they understand when their target is on vacation, they understand that in the summer in the US that people aren't watching as closely. Or maybe they're just kind of focused on other things. They're focused on that family outing to the beach and not really focused on the day to day where I'm peppering you with security trainings and all. Of that. Right. It might not be top of mind.  

So the first one is just the physical layer. Just be very aware of where you have your asset. A remote organization, we have a lot of assets that are all over the United States and keeping track of that, knowing where you're at, even getting up for a second at a. Where you're having coffee, you might be at a local Starbucks or whatever, you're having a nice cup of coffee and you want a pastry. Getting up and walking away from that asset, it's a very dangerous thing to do, particularly with the data that we have. So that's the first one. Just be really aware, hyper aware of where do you have that asset? Do you have eyes on it and is it safe and secure?

[09:23] Justin Venneri: I can relate to that one. It was one. When I was young and interviewing in New York City, Wig, way back in the day, I had my bag hanging on the back of a chair at a coffee shop and I like shuffled for a second and I didn't realize it for about 10, 15 minutes. My bag was gone. Thankfully. I had my phone, my laptop, my stuff was in front of me on the table, but my bag was gone. I was miserable. It was not a fun afternoon.

[09:45] Shane Garoutte: And then you had to tell the security team that that happened. Right? Yeah, that's.

[09:48] Justin Venneri: I was more scared of my wife at that point. I was like, yeah,

[09:52] Shane Garoutte: yeah, that's a good story. And it's fortunately is a very common one. I mean, it's something we talk about a lot in security. Threat actors are a creat creatures of opportunity. They're going to look at the easiest way to get something done so they get the value that they're expecting. And yeah, I mean, somebody not paying attention to their bag, even for 30 seconds is. That's an opportunity. So it's a good story. And I wish I said that that was the first one I'd heard, but not even 100. So it happens often.

[10:17] Justin Venneri: So give us another one though, for security tips, for sure.

[10:20] Shane Garoutte: Yeah. So the second I would say, and I think it's a lot of people don't think about it in their personal lives. My three boys would tell you their dad harps on this regularly. And that is we have to really get away from relying on passwords. It's a very common practice. A lot of security practitioners believe it's the worst thing that we ever implemented in some ways because it's just. It's not safe whatsoever. To your point, we have seen a massive increase, not just in healthcare, but particularly in healthcare. Of compromises that have been more than 500 people. HHS requires that you report a breach of 500 or more. And I think last year was something in the neighborhood of 756 breaches that were that size. And to your point, some very large and some very small. In many of these cases, what happens is these passwords get out in the wind, right? Usually from a third party compromise and then they're again creatures of opportunities. So they're harvesting all that data, they're figuring out where those people work and then they're trying to use those passwords they harvested towards endpoints. The Change Healthcare one was interesting. It was literally an administrative interface that allowed you to have access to all of the end users endpoints. And when I say endpoint, sorry, it's a bit of jargon, but I'm talking about laptops and desktops and mobile devices and that's that and the like. So passwords are both a necessity, I suppose, but also something we should also be very, very skeptical of if it's possible. And in most cases it is, particularly in the banking space and other spaces. Think about a passkey or a hardware token. As you know, we use Fido 2 keys here, which is just a hardware token we plug into the laptop. That is so much safer than something that is easily reused across multiple different applications. And so with my own family I've actually sat down and verified do you have multi factor auth? You know, on all of very sensitive data access points. You know, whether that's banking, it could be doordash. A lot of these companies now are standardizing on MFA as a good standard and unfortunately because it's a bit of an inconvenience, people just don't turn it on enough. That will be probably the single most best piece of advice to protect you and your loved ones that I could give you today. You don't have to go down the road of buying a ub key or some other hardware device if you don't want to. That incurs expenses. MFA is usually free. So that's the second one.  

And then on the third, I would say with AI, it's becoming very, very easy to make. Smishing and phishing. Smishing is SMS based. Phishing look very, very valid. Look like it's legitimate. And so one thing I do with my family all the time is if you have an alert that comes out, and I actually just had this to me last week where you get a notification of an SMS code that pops up and you're thinking that's strange. I didn't log into that app. I don't even have that app on my phone. I don't even use that every single day. Have a verification code that you can use with your family. Right. So in other wor something happens and you're not sure if somebody else in your family did something, call back on a known number that you already had, something that you already know is legitimate, actually their number, and just validate that whatever's happening is actually happening. Don't trust anything that comes to your personal device or your professional device. There should always be a layer of skepticism there. I know that's not new information, but unfortunately it's just one that I think because security and convenience aren't always fast friends that we have to reiterate and we have to remind ourselves. So, yeah, I've sat down and done the MFA enabled with all of my boys and my family members. I've sat down and talked about, hey, if there's an alert that you're getting and you think it's dad or I think it's you, let's call each other and just double check that it actually is what we expect it to be. So those are really simple methods. And none of that, what I just mentioned, by the way, costs you any money. Right. Those were all very safe and easy things to implement the family, particularly right now, you know, during the holidays, you know, the summertime, and everybody's traveling a lot in different places.

[13:56] Justin Venneri: Yeah, I think those are great tips and that's great advice. Shane. I know the mfa, you know, two factor. Otherwise it's an extra step, but I think it's well worth it. I gotta talk to my younger one now. Cause he just got a phone finally. He's excited about it. So a question for other cybersecurity leaders out there. What is something you found most helpful in building your team and leading these sorts of longer initiatives that you've led here at Judi Health? Any advice for others?

[14:19] Shane Garoutte: So much advice for others, Justin? Yes, I am not without advice. So I would say this. The biggest lesson I learned throughout my career because of the path that we talked about earlier, is that security is a team sport. And I think that's sometimes lost if you perhaps had a more traditional path. What I mean by that is if your organization is scared, they fear sort of retribution from the security team. If you approach them with something they may have made a mistake around, you're actively circumventing your security program and making it less secure. I think that trust, that team sport attitude is paramount. I'VE seen it both ways in my career. I've seen it where the CISO organization is adversarial. They might be condescending in some way, or they might even be actively sort of working against you if you admit to making a mistake. And it just creates this protectionist behavioral line in the sand. And I think that, yeah, it's a very dangerous thing. So I would say is have a real honest conversation with yourself. Is my team feared when we engage in a program or an architecture or any kind of adoption of new tooling? Is my team a barrier that we're putting in front of everybody? Or does everybody really feel like. Like we enable and we empower and we really try to drive through with speed, too. There's this adage in security that, you know, nothing ever happens fast. I don't think that is truly the case anymore. Particularly empowering teams in a very safe way with agentic AR and other tools that are force multipliers. Yeah, I think that's just an honest question. I ask my team regularly. We, and we do polls, as you know, internally of how are we doing and are we approachable and is it easy to talk to us and are we responsive? Are we getting back to you quickly? All of those things are, I think, just a sort of inward eye that I really learned as practitioner of maybe a CTO role or a VP of software engineering role. That taught me that that's just a really important part of what we do as an organization.

[16:11] Justin Venneri: Yeah, we're definitely looking at you guys as more partners than coming over the top to crush us or make us feel bad about making a mistake. So that's a good thing.

[16:18] Shane Garoutte: Thank you. Yeah, I think that's the biggest compliment I could really receive. And then I would say be as transparent as you can. Again, we sometimes sort of fall back in this. You have to be very careful because of things like principle of least privilege, which is giving people only the information absolutely need to have based on the role and the things they need. But remember, that can be also something that you can leverage within your security program, where you can drive at a high level some transparency where it's helpful into the engineering teams, into the operational teams, where they should know where your head's at, where you're headed, and what your focus is during that timeframe. So try to be as transparent as you can. You can't always do that because of all the sensitive data that we have to handle every day. You know, when you're dealing with incidents or dealing with forensics or you're doing triage. You know, often it has to be a very, very small group and those who absolutely need to be involved because you don't know whether the threat actor is external or internal. But when you're talking about multiyear initiatives, FedRAMP is a great example here. There is no way my team could have done that alone. You know, that required adoption and understanding at every level of this business, from any contributor in sales to an individual in finance, to the HR team who was integral in getting us here, to of course, all the engineering and operations groups as well. So try to provide as much transparency as you're comfortable with to help them frame their thinking, even when they're working on their program and how it might dovetail into what you're doing. So those are, those are the kind of two that I foundationally believe in.

[17:41] Justin Venneri: Okay, you said you got plenty of advice. How about advice for yourself, your younger self about the business? What would you say?

[17:47] Shane Garoutte: Oh, goodness. I guess I would say embrace the change, the volatility that happens through your career. I had a tendency when I was younger to take things very personally if I failed, if I didn't achieve not just what my supervisor was expecting of me, but what I expected of myself. And I took it probably too hard in many cases. Just learn from the experience, incorporate it and let it go. I learned that, I think a little later started out as being a bit defensive, maybe that security practitioner that, you know, I am the letter of the law and this is the law and that's it kind of attitude. And businesses are handcrafted, artisanal, small batch technology systems. Right? If everybody did what Judi Health does, there would be a million Judi Healths out there, right? So everything you do as a practitioner of your craft, you have to think about being creative and being okay when that creativity doesn't yield the same result you want it to. So I was really lucky. I had a lot of really good mentors. I had a lot of really wonderful people that I suppose I would say both that taught me what not to do, which are some of the best lessons in life. But also importantly, what taught me what good leadership looks like, what investing and trusting your team looks like, what aligning your roadmap to the business goals and objectives and really understanding that voice of the customer. All of that is things that I didn't really appreciate until I'd say I was in my maybe mid-30s to late-30s and started really embracing that. In fact, I remember one of the first times that was really relevant for me was my Life safety company that I worked for. I knew that we wanted to go down the Fed ramp road, but I didn't really tie that into how that affected the business directly. And once I did that, that program really took off it really because I was looking at it from an engineering perspective. Here's the 325 controls. I gotta go do these things, you know, get the teams working together and make that happen. But once you embrace business, actually looks at this like an enabler and a revenue stream, you completely approach the problem differently. I think that's something sometimes I lost perspective of.

[19:36] Justin Venneri: I think your younger self would appreciate that advice. Definitely helps speed things up up, right? I have two more questions for you. You brought up agentic AI twice. So I'm curious where this is going to work in because I didn't have a question specifically about AI, which is kind of nuts because we're. I probably should have an AI question for you. I do have a business question before my last question. He brought it up again there. There really aren't a ton of healthcare companies or benefits administrators that have this Ready status or in this class C. And I know that changed a little bit recently too. There are some wellness and other healthcare tech companies that have it, but it's a short list on the marketplace. We talk a lot about cloud open platform that Judi is and we juxtapose that with the legacy or traditional systems, you know, racking cables or AJ jokes cobalt sills the code. We'd love your thoughts on why an employer plan sponsor or health plan executive should care about this.

[20:27] Shane Garoutte: I think fundamentally it's an attestation of our maturity and it really explains that we are a cloud-first highly scalable organization. All of those things come into a FedRAMP Ready status. So one of the things I asked AJ right out the gate when I joined the organization is give me a sense of what the tech technology looks like, you know, the maturity of the technology. And I was very impressed that even though we're in a sector that is typically known as being very bricks and mortar, data center centric, as you put it, all the racking and stacking of routers and servers and switches, which I did plenty of through my whole career and taught me a lot around layer one in the physical plant. I was impressed by how much thought had been put into Judi as a stack when it was first architected originally and how much it was really a technology company focused in the healthcare space, not a healthcare company that is trying to use technology as much as they can. And I think that's a mindset that you don't often get when you're interviewing for healthcare companies or you're interacting with healthcare companies or even as a citizen. Your frustrations with dealing with healthcare companies, you don't think, oh, they must be very technically proficient. You think they're very legacy, they're very dated in their thinking and they're very old school. The thing that FedRAMP attests to is first, remember, it is a cloud-only status, right? For Ready status. So cloud only, you have to be in the cloud, your product has to be a cloud service, and that's why it was invented in the first place, is to enable federal entities to be able to engage with cloud service providers. CSPs is what we're called and they're parlance that means that you see on the marketplace a lot of very tech heavy kinds of offerings or sectors I would say are known traditionally to be tech heavy. So when you look at the healthcare part of the marketplace and you filter down to who in the healthcare space is achieving this, you're right, it's a really short list and we're very proud of that because I think the big differentiator always with Judi when we're competing, is our technology first, our engineering first, and our architectural and scalability mindset. And I think that's no better shown than achieving this thready status.

[22:25] Justin Venneri: All right, and here we are. Shane, last question. Thanks so much for taking the time today. Ask everybody and keep your compliance hat on for me because I know you've seen a whole lot in your role. What is the most astonishing thing that you've seen that's safe to share that relates to our discussion today? Tell us a good story to send us off.

[22:39] Shane Garoutte: Okay, Justin, so I have one. And what's going to surprise you is we were kind of talking about doing this together. I had a different response originally prepared, but I think we have to address, at least in the cybersecurity space, the agentic AI elephant in the room we just saw with OpenAI and their attack on a partner hugging face that agentic workloads and what they call swarms, which are groupings of agentic workloads working together to achieve a specific goal, are a pretty big watershed moment. When we saw that security report come out from OpenAI and I'm not blaming OpenAI necessarily, or hugging face or anthropic or anybody else's in this space trying to do the best thing they can do. But it is a big wake up call for all of Us. And I think if you're in cybersecurity, if you're not in cybersecurity security, you should really look at the video that was just posted. We just had Black Hat. It's the biggest security conference in the world. And there was a great talk by the OpenAI team where they were sort of just talking about these agentic systems and how they were trying to cheat the parameters they gave them. They were trying to circumvent the rule base that they were giving them because they're taught to win. Right. So that is, in all honesty, the most astonishing thing I think I've seen in my personal space that I work in over the last number of years. I don't see how it couldn't be that. I give you other stories about certain things that have happened, certain companies and how we handled them, but I think that's something that I would really challenge everybody to at least look at a cursory view of what happened there and what that means for your organization.  

Lastly, I would say what it means for our organization is we are very much embracing the fact that threat actors, the bad guys, they don't play by the same rules. They don't have change management, they don't have worries about what licenses we're using for what software and whether that's okay to use that software. They don't have regulatory or compliance or badges or FedRAMP or anything else because they're not playing by these same rules. And because we just saw the companies who invent this agentic model and how that works together, it is a watershed. We have to step back. We have to think about it as an organization, as a collective practice, and as a set of expertise. Because we can't approach this legacy thinking that we've had in the past where you build this moat, you put up a firewall and then you close all the holes in the firewall and you hope every day that you don't get the call at 2 o' clock in the morning from your SOC team that something bad is happening. Even that and the layered approach that we've been taking over the last 10 years as security practitioners, it's not good enough anymore. We're going to need to move faster. It is something that I would again encourage everybody to go watch. It was really fascinating. Even if you're not a geeky nerd like me, you'll get something out of it. A lot of it will be paranoia, which is good, and also just a little bit of healthy skepticism about these tools and what they Mean for technology in general.

[25:16] Justin Venneri: And the gist of that one was they wanted the agent to try to hack into the other system. Right?

[25:21] Shane Garoutte: Yeah. Is that they thought they had a perimeter where they were keeping all these agentic systems in check so that they could test out the latest, what they call frontier model, the very cutting edge stuff. And they were asking it to go find a vulnerability in a specific use case. And because of the use case, and because it was told it wasn't allowed to use the Internet, it got creative. These agentic systems started using an internal message board to trade messages to each other in ways that the programmers and developers never expected. It started looking at a zero day for the way that they keep artifacts in the system. That they keep artifacts. Artifacts are just a fancy way of saying components you use to build software. It found a zero day, exploited that zero day vulnerability, which was not published. Right. Got a foothold on that system, got what's known as root, which is administrative privilege, and started moving laterally inside of OpenAI without anyone in OpenAI understanding what it was doing, because it was told, at all costs, you have to win this challenge. Don't make excuses, figure out a way to win. And it did. And what it also figured out was that this other partner company, Hugging Face, also had a model that could help it win as well. And so it interactively and dynamically, dynamically adjusted to the parameters, it broke the parameters by which it was supposed to work intentionally, and it sort of went out of control and it went a little wild. And that's, that's a pretty interesting. It feels like sci fi. Honestly, Justin, it feels like we're in the matrix, you know, all those things that everybody always likes to say in technology as memes. That was an interesting moment. It is an interesting moment and I love the end of that talk because they really do publish a wake up call to everybody who does what I do for a living. If you are not approaching this as the defense needs to be as dynamic as the offense, we're only a matter of, I would say, a year before that becomes a serious, serious problem. Maybe even less. Maybe I'm being too optimistic. It was a fascinating talk, so I would encourage everybody to go check it out.

[27:11] Justin Venneri: Yeah. That is astonishing. Well, Shane, thank you so much for all you do and thank you for taking the time today. Really enjoyed this discussion and I look forward to having you back on.

[27:18] Shane Garoutte: Likewise. Thanks, Justin. Appreciate it.

SHARE

Copied!

It's time to build your benefits, your way.

Get in touch to learn about our health benefit administration and transparent pharmacy benefit management solutions.

Talk to Our Experts
Talk to Our Experts