Hello everyone. My name is Omar Sangurima, and I'm based in New York. I'll be leading the course on Data Security, Privacy, and Ethics.
I currently serve as Head of Program Management and Cyber Third-Party Risk Management at a major academic medical center in New York City, where I lead cybersecurity programs across vendor risk governance, AI security, governance/risk/compliance, and medical device oversight. My professional background is grounded in information technology and cybersecurity, with deep roots in enterprise risk management and a growing focus on clinical and operational risk in healthcare settings. I hold a Doctor of Information Technology, an MBA, an MIS, and a Master of Health Administration.
My interest in health informatics is inseparable from the work I do every day. In cybersecurity leadership inside a clinical environment, the further I move into governance and enterprise risk, the more I see that security decisions are clinical decisions. The systems this program teaches learners to build, implement, and optimize are the same systems my team works to protect. I believe health informatics professionals need to understand security, privacy, and ethics not as a compliance exercise but as a foundational layer of patient safety, and I'm looking forward to bringing that perspective into our sessions together.
One of the most pressing challenges I see in the health system where I work is the fragmentation of governance around connected clinical technologies. Medical devices, EHR integrations, AI-enabled tools, and third-party data flows often fall under separate oversight structures, even when they touch the same patient. Closing those gaps requires the kind of cross-disciplinary fluency this program is designed to build.
What I hope to learn from this program, and from all of you, is how informatics practitioners in different health systems and settings think about the problems I spend my career trying to solve from the security side. I expect this cohort will sharpen my understanding of clinical workflows, data governance in resource-limited environments, and the real-world constraints that shape how digital health systems get adopted. The best security and privacy frameworks are built with, not imposed on, the people who use these systems. I'm here to teach, but I'm also here to listen.