Blog

There’s No Straight Line to the CISO Chair

Tamra Durfee’s Path Through Healthcare Cybersecurity

When Becker’s Hospital Review named its 2026 “Women in Health IT to Know,” Tamra Durfee was again one of 170 honorees.

While many think of cybersecurity as firewalls and frameworks, Tamra has a different perspective, focused on the people behind them. “Every time I reduce risk,” she says, “I am making it better for our patients and the staff who care for our patients.” Care first, security second has been guiding Tamra for more than a decade in healthcare.

Today she is a Senior Virtual Chief Information Security Officer (vCISO) at Fortified Health Security, but her path started nowhere near a hospital.

An accidental start

Tamra learned about information technology almost by accident. In high school she edited the school paper, but it was not the writing that held her attention. “What I liked most about the class was work done on the computer related to the school paper,” she recalls, “not the school paper or the writing.” An IT career was not an obvious path; as far as she knew, it was not a path at all. “I am dating myself, but there were no computer classes when I was in high school, just typing classes. I did not even know there were IT careers.” It was her journalism teacher, Ms. Lindstrom, who first pointed her toward Management Information Systems (MIS) as a major. “I researched it and chose it for a major at U of A, where it was ranked third in the country at the time.”

Finding the work that mattered

Her first stop was IBM, working across industries for 17 years as a Solutions Architect. It was good work; it just was not the work. “I always enjoyed my job and felt it was rewarding,” she says, “but I don’t know that I was making a real difference. But healthcare cybersecurity – I know I am making a real difference.”

She learned exactly what that difference meant the hard way, watching what a ransomware attack did to a hospital in real time. “Seeing the ED back up, having to go on diversion, nurses crying because the technology tools they are used to are not available and they are overwhelmed trying to care for their patients – while I knew it before, I saw it firsthand how a cyber event affects patient care.”

An emergency department backing up, a facility on diversion, nurses in tears: a cyberattack in healthcare is not a costly IT problem. It is an attack on people and on their care.

Why healthcare is different

That firsthand knowledge shapes how she advises clients. She sat in their chair. “I know a client is under a multitude of pressures – from budget, to staffing, to regulatory pressures, maybe a new EHR or ERP implementation,” she says. “Having been through it all, I can relate and provide realistic and actionable recommendations versus pie in the sky, unreasonable recommendations.”

Healthcare security, she is quick to point out, is its own discipline. “It is not black or white. It is much harder due to the specialized knowledge of healthcare required.” An operating room may run a system that displays real-time 3D imaging (CT/MRI) of a patient’s spine, which the surgeon relies on to guide placement of screws and implants. “You have to protect this workstation like all others, but factor in this dynamic.” You cannot patch and reboot your way through a hospital; protecting that workstation like any other endpoint while respecting what the surgeon needs from it mid-procedure is the essence of one of the specialties, she’s developed over the years: risk-based medical device security.

Learning to translate risk

Tamra has also earned a reputation for making complex risk clear to executives, a skill she says came down to “practice, coaching, feedback, and a lot of failure first.” It also requires a broader perspective of the organization’s needs beyond just the IT and security departments.

Early in Tamra’s healthcare career she worked with a CIO who she said, “saw something in me and invested in me,” pushing her to take on responsibility across a hospital’s IT and business areas and giving her a well-rounded understanding of how a healthcare organization runs. It was incredibly beneficial to her career. “Cybersecurity affects every aspect of a hospital,” she says, “so the more you know about how a hospital operates, the better you are able to have the conversations in a meaningful way and relate to those outside IT.”

Earning the trust

Ask Tamra what she is proudest of, and she reaches not for a title but for a moment of trust: her first cybersecurity role in healthcare. “While I had a lot of IT experience and experience in other industries, I did not have healthcare cybersecurity experience,” she says. “Getting the job was based on the belief that I had the core abilities to do the job and the aptitude to learn what I did not know.” A strong security program got built on that trust, and she delivered. It was a quiet win. “I don’t know that many were aware I did not have specific healthcare cyber experience, but I knew – and invested the time and energy to learn and grow and ensure I did right by those that put trust in me.”

Lifting others

These days she spends as much energy opening doors as walking through them. A founding member of Women in CyberSecurity (WiCyS) and a member of Bluebird Leaders, Tamra mentors’ women in healthcare IT and has carried her insights to HIMSS, CHIME, ViVE, MUSE, ISC2 Security Congress, InfoSec Nashville, CHA, and SOAR, and articles published in Healthcare IT News, Chief Healthcare Executive, and Fortified’s Horizon Reports. Recognition still surprises her, including this recent one from Becker’s.

“If you asked me ten years ago if I would receive this recognition, I would have said no way. But we are only limited by ourselves and what we think we can or cannot accomplish. This recognition means I have grown as a person and am not putting those limits on myself – which means others can too.”

 

For anyone eyeing the same path but unsure about their approach, her reassurance is that there is no one “right” way. “There is no clear or direct path to a CISO in healthcare IT. There is no right or wrong way to get there. But I do think that a wide and varied background helped me to become a CISO, and the best CISO I can be.”

The legacy she’s after

Tamra’s aim is to make cybersecurity more approachable. More than just establishing strategy and programs, she wants to give “the why, so people understand, not just say no and dictate policy.” Tamra’s end goal with her work is to shift the culture of the organizations she served and reduce cyber risk in the process. At Fortified Health Security, she now brings that approach to hospitals and health systems nationwide. The measure of the work has not changed since the day she understood the stakes: that care is there when people need it most.

About Tamra Durfee

Senior Virtual Chief Information Security Officer (vCISO), Fortified Health Security (Brentwood, TN). More than 27 years in information security, compliance, regulatory risk, strategy, and technology transformation, with the past decade focused on healthcare and deep expertise in risk-based medical device security.

Prior roles include Solutions Architect at IBM, Director of IT, Interim CIO, and CISO at various healthcare organizations. Certifications: CHCIO, CDH-E, GSLC, CPHIMS, and IBM Certified Solutions Architect.

Named to Becker’s “Women in Health IT to Know” in 2025 and 2026. Founding member of Women in CyberSecurity (WiCyS), active member of Bluebird Leadershttps://chimecentral.org/, and a CHIME member of 10 years.

LinkedIn: linkedin.com/in/tamradurfee

Share

Related Articles

When AI Agents Start “Moving Like Attackers”

CISO Brief July 2026: Cybersecurity Threat Recap & Key Insights

Why Audit? True Stories of What’s Hidden Inside Your Healthcare Cyber Program