This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon talks to Jake Belcher. Jake is the SR. Director of Security Strategy at VillageMD. He has over 20 years of IT and Security experience building, operating, and enhancing Risk Management, Security Awareness, and governance. He has worked with many “C-suite” executives and boards of directors. He is a graduate of the University of Pittsburgh Katz School of Business.
Chapter Titles:
00:00 Introduction
02:04 VillageMD
03:28 Walgreens and the Minute Clinic
05:01 How has Cyber security changed the Healthcare business?
07:50 Why is patient healthcare data worth more money than credit card information?
10:30 How to make data less valuable
16:50 What are some policy positions we could take?
18:57 What is motivating bad actors to get healthcare data?
22:50 Cyber insurance
26:40 3rd party risk
30:05 Doctors and mobile devices vs HIPAA?
39:10 More on Jake
Audio:
Important Links:
Transcript
Manoj Tandon:
Hello everyone, welcome to another episode of Dark Rhino Security: Security Confidential. Today, we are honored to have Jake Belcher join us. Jake is a seasoned cybersecurity professional and the Senior Director of Security Strategy at VillageMD. He has over 20 years of IT and security experience building, operating, and enhancing risk management, security awareness, and governance programs. Jake has worked closely with C-suite executives and boards of directors and is also a graduate of the University of Pittsburgh’s Katz School of Business. I’m glad to have another Pittsburgh person on the show—it’s rare we get anyone else besides me. There are dozens of us, right? Welcome to the show, Jake. Thank you so much for being here.
Jake Belcher:
Thank you. I appreciate it.
Manoj Tandon:
We recently had the CEO of Gift Health on the show, and it was a really interesting conversation about how the healthcare landscape is evolving—especially with the growing online presence and how that’s changing the business. It really highlighted how cybersecurity is no longer a “nice to have,” but absolutely essential, given the wide range of risks involved. Since you’re with VillageMD, can you tell us a bit about what your organization does?
Jake Belcher:
Absolutely. VillageMD focuses on managing physician practices and building a network of them across the U.S. We help onboard and support these practices as they grow. Recently, we received a significant investment from Walgreens, which has helped accelerate our mission. We’re working to expand access to primary care by placing more physicians directly in communities, especially underserved ones. Unlike some models that rely more heavily on nurse practitioners, we’re focused on increasing access to primary care doctors. With Walgreens’ footprint, we’re able to reach more communities effectively. We’re still a late-stage startup, but with that investment, we’re rapidly maturing as an organization.
Manoj Tandon:
That’s really interesting. Does that model conflict at all with something like MinuteClinic?
Jake Belcher:
Not really. It’s more of a strategic shift. Walgreens is moving toward a model centered more on physician-led care. While clinics like MinuteClinic serve a purpose, this approach is about expanding access to primary care doctors, especially in underserved communities. It aligns well with their broader mission, and the investment reflects that commitment.
Manoj Tandon:
That makes a lot of sense, and it sounds like a much-needed service. With that kind of visibility and growth, I imagine you’re also attracting attention from threat actors. We’re constantly seeing healthcare breaches—just today there was a report about a major breach in Texas affecting over a million records. How has cybersecurity impacted healthcare overall?
Jake Belcher:
Healthcare is going through a transformation similar to what other industries experienced when they became more digital. If you look at retail, for example, security concerns grew significantly once online transactions became common. Healthcare is now catching up in that sense. Historically, the focus has rightly been on patient care, but as technology becomes more integrated into how care is delivered, the risks increase.
What makes healthcare unique is the value and sensitivity of the data. Protected Health Information is highly regulated, extremely personal, and much more valuable than something like credit card data. That raises the stakes significantly. From my perspective, cybersecurity in healthcare is really about risk management—understanding those risks and investing appropriately to address them.
Manoj Tandon:
That’s a great point. I’ve seen data showing that stolen credit card information might be worth a couple of dollars, whereas healthcare data can be worth significantly more. Why is that?
Jake Belcher:
It really comes down to usability and longevity. Credit card data has a short shelf life. Once it’s compromised, it can be canceled quickly. But healthcare data is persistent—it doesn’t change. It can be used in many different ways, from fraud to targeted phishing campaigns. There’s simply more you can do with it, and it remains valuable for much longer.
Manoj Tandon:
That persistence is really the core issue. And unlike credit cards, where you can monitor transactions easily, there’s no equivalent for tracking how your medical data is being used.
Jake Belcher:
Exactly. Credit cards come with built-in monitoring—alerts, statements, fraud detection. But healthcare data is scattered across multiple providers and systems, making it much harder to track. There’s no centralized way for individuals to monitor their data, which makes detection and response much more difficult.
Manoj Tandon:
That’s a really important insight. Most regulations—HIPAA, HITRUST, SOC 2—focus on providers, not patients. There’s very little empowering individuals to monitor or control their own data, especially compared to something like GDPR in Europe.
Jake Belcher:
That’s right. In the U.S., we don’t have a unified federal approach like GDPR. Some states have stronger protections, but overall, there’s a gap. A lot of it comes down to incentives—data has value, and there are economic drivers behind how it’s collected and used.
Manoj Tandon:
And ultimately, it all ties back to money. Whether it’s bad actors, organizations monetizing data, or even ransomware-as-a-service, the incentives are financial across the board.
Jake Belcher:
Exactly. Financial motivation drives much of what we see—both from attackers and within the broader ecosystem.
Manoj Tandon:
Let’s shift to another challenge—third-party risk. How significant is that in healthcare?
Jake Belcher:
It’s huge, and honestly, it’s critical across all industries. Most organizations rely heavily on third-party vendors, whether for software, infrastructure, or services. In healthcare, that risk is amplified because of the sensitive data involved.
At VillageMD, we have a robust vendor risk management program. We assess vendors, review things like SOC reports, and even look at software bills of materials when applicable. But you can’t evaluate everything equally, so you have to prioritize based on risk—identify which vendors are critical and focus your efforts there.
Then there’s fourth-party risk—your vendors’ vendors—which adds another layer of complexity. You can’t go infinitely deep, so again, it comes back to risk-based decision-making.
Manoj Tandon:
That makes sense. I want to ask about something more specific—physicians. Historically, they’ve been difficult to manage from a security perspective. Has that changed at all?
Jake Belcher:
Not much, honestly. But the key is understanding their perspective. Physicians are focused on patient care—that’s their priority, and it should be. Security can’t get in the way of that.
So the approach has to start with empathy. You need to design solutions that are seamless and don’t disrupt their workflow. If controls are too complicated, people will find ways around them—that’s just reality.
The goal is to make secure behavior the easiest option. That means investing in user-friendly tools, automation, and education. Physicians are highly intelligent and lifelong learners, so awareness training can be effective. But beyond that, you need to provide systems—like secure, pre-configured devices or applications—that make compliance effortless.
If you can show that these solutions improve both patient care and user experience, you’re much more likely to get adoption. It’s not easy—it requires investment and coordination—but that’s the direction we need to move in.
Manoj Tandon:
That’s one of the most practical explanations I’ve heard. It really comes down to making security usable and aligning it with how people actually work.
Jake Belcher:
Exactly. If your security program depends on everyone being perfect all the time, it’s going to fail. You have to design for reality, including things like shadow IT, which is inevitable. Instead of fighting it, you need to build systems that account for it and manage it effectively.
Manoj Tandon:
Jake, I know we’re just about out of time. We really appreciate you being here. Before we wrap up, is there anything you’d like to share with the audience?
Jake Belcher:
Nothing specific to plug, but if you’re in a Walgreens and see the VillageMD name, know that there’s likely a physician practice there or coming soon. If you have the opportunity, check it out.
Manoj Tandon:
That’s great. Jake, thank you again. It was a pleasure speaking with you.
Jake Belcher:
Likewise. Thank you so much.
Manoj Tandon:
Take care.
To learn more about Jake visit LinkedIn
Check out the other episodes in Season 6:
Ep. 0 Bonus: Why do People Get Hacked?
Ep. 1 Brian Stoner – VP of StellarCyber
Ep. 2 Dr. Joseph – Russia, Ukraine, and Cybersecurity
Ep. 3 Tim Chase – Ethical Hacker, CISO
Ep. 4 Brian Haugli – CEO of SideChannel
Ep. 5 Nat Schere – Cybersecurity as a revenue
Ep. 6 Endre Walls – Starting in Cyber, Vendors, and Diversity
Ep. 7 Erika Carrara – Veteran, Mentor, C-suite executive
Ep. 8 Eddie Thomason – Podcast Host, Author, and Entrepreneur
Ep. 9 Greg Schaffer – vCISO, Author, and Podcast Host
Ep. 10 Jake Belcher – Sr. Director of Security Strategy
About Jake Belcher

Jake is the SR. Director of Security Strategy at VillageMD.
Jake has over 20 years of IT and Security experience building, operating, and enhancing Risk Management, Security Awareness, and governance.
He has worked with many “C-suite” executives and boards of directors.
He is a graduate of the University of Pittsburgh Katz School of Business.
About Us:
Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.
For inquiries, please email media@darkrhiinosecurity.com
Share and spread the word!
