March 5, 2025
Building a Culture of Trust in Data Governance with Lyn Baluyot
Article is a summary of the Cyber Security in Healthcare Conference, Session 1, Data Governance and Data Protection Practices: Some Considerations Cyber Leaders Need To Be Aware Of.
Don’t Miss Out on Transformative Insights
Register for the next conference!
As healthcare data becomes a prime target for cybercriminals, the need for robust data governance and a culture of security awareness has never been more urgent.
Lyn Baluyot, CEO of TransForm, underscored a crucial but often overlooked aspect of cybersecurity: trust and accountability in data governance. Beyond firewalls and encryption, effective data protection hinges on understanding what data we are securing, how it is being used, and fostering a workplace environment where security is everyone’s responsibility. Her insights offer a roadmap for healthcare organizations to shift from reactive cybersecurity measures to a proactive, resilient data governance strategy.
Data Governance: More Than Just Security
Baluyot highlighted that data governance is a framework that ensures sensitive information is managed securely and responsibly. With digital health systems collecting vast amounts of data, organizations must be able to answer key questions:
What data is being collected? Why is it needed? How and where is it stored? Who has access?
She pointed out a critical issue: many organizations don’t actually know where all their data is. “Back in the day, when we all had paper, we knew exactly where our data was because we had to store it somewhere physically,” Baluyot explained. “But today, with electronic files, data is everywhere.”
A well-structured data governance framework enables healthcare organizations to identify and mitigate risks associated with data breaches. In Canada, cyberattacks against health information systems are increasingly common, with 48% of all reported 2019 Canadian breaches occurring in the health sector. These breaches have been associated with delays in care, diversion of patients to other sites, and increased mortality (cmaj.ca).
The Need for a ‘No Blame, No Shame’ Culture
One of the most compelling insights from Baluyot’s session was the necessity of a ‘No Blame, No Shame’ culture to encourage employees to report security concerns.
Employees should not be fearful of reporting clicking on a link that they are suspicious of and the sooner that they report, the sooner a team can assist with investigation. It does help to have technology that enable employees to easily report suspicious emails and remove them from the email systems.
Encouraging a no-blame culture is pivotal in promoting transparency and timely reporting of cybersecurity incidents within healthcare organizations. Studies show that nearly two-thirds of employees do not report security incidents out of fear of repercussions (cmaj.ca). By analyzing reported incidents without attributing fault, organizations can identify systemic issues and implement corrective measures to strengthen their overall cybersecurity posture
Balancing Privacy, Security, and Convenience
A recurring theme in Baluyot’s talk was the trade-off between security, privacy, and convenience. She cited former U.S. President Barack Obama’s perspective: “You can’t have 100% security and then have 100% privacy and absolutely zero inconvenience.”
This applies to cybersecurity in healthcare—strict security measures can sometimes slow down workflows, but they are essential to safeguarding patient information. Baluyot compared this to seatbelt laws: initially, people resisted them due to inconvenience, but over time, they accepted the necessity for safety.
A recent cybersecurity incident at Care1, a Canadian eyecare firm, underscores the importance of balancing privacy and security. The company exposed over 4.8 million records, totaling 2.2 terabytes of sensitive patient data, including medical records and personal information, due to a non-password-protected database (databreaches.net).
Data Awareness and Retention Policies
Another key area of discussion was data retention and awareness. Many organizations hold onto data for decades without understanding why.
“Do you really need a patient file from 30 years ago?” Baluyot asked. “Often, people keep records simply because they always have.”
She emphasized the need for legal teams to work closely with IT departments to ensure compliance with data retention laws while also reducing unnecessary storage of sensitive information.
A well-defined data governance framework helps organizations determine which data should be retained, archived, or deleted. The Canadian Institute for Health Information (CIHI) has developed a Health Data and Information Governance and Capability Framework to assist organizations in evaluating and improving their data governance practices (cihi.ca).
The Growing Challenge of Personal and Corporate Device Usage
Baluyot raised concerns about the blurring lines between personal and corporate device usage, especially in remote and hybrid work settings. With many professionals using personal devices for work, securing sensitive data becomes increasingly difficult.
“How many of us actually separate our personal and corporate data? People merge their devices because carrying two phones is inconvenient, but they don’t realize how much corporate data sits on their personal device.”
To mitigate risks, TransForm has implemented policies like regularly clearing download folders and restricting access to corporate data on personal devices.
Final Thoughts
Lyn Baluyot’s insights serve as a stark reminder that data security is no longer a responsibility exclusive to IT departments—it is an organizational imperative that requires engagement from every level of healthcare operations. The increasing frequency of cyberattacks against Canadian healthcare institutions illustrates the urgent need for proactive data governance, risk management strategies, and security education initiatives.
The reality is that no single policy, software, or firewall will provide complete protection. The key lies in fostering a culture of trust, accountability, and vigilance. Healthcare professionals must be empowered with the knowledge and tools to safeguard sensitive data, report suspicious activity without fear, and adopt best practices that reduce vulnerabilities. Leadership must prioritize investments in cybersecurity infrastructure and education while aligning policies with both patient care priorities and regulatory requirements.
As we move further into an era of digital healthcare, data security must evolve from an afterthought to a fundamental pillar of healthcare excellence. The organizations that succeed in this transition will be those that recognize data protection as more than a compliance requirement—it is a matter of patient trust, institutional resilience, and ultimately, saving lives.
View The Whitepaper
Get a detailed version of this article to access additional takeaways for your organization!