rf IDEAS focuses on identity and access technologies, and this discussion examines third-party cybersecurity risk in healthcare, passwordless authentication, FIDO standards, and stronger identity and access management. Pulse 2.0 interviewed rf IDEAS president and CEO David Cottingham to learn more.
David Cottingham’s Background

When asked about his background, Cottingham shared:
I am currently the president and CEO of rf IDEAS with over 25 years of extensive experience in identity and access management, authentication, as well as hardware and software, which allows me to provide guidance to organizations such as health systems, on why there might be misalignment between what they say they want, including stronger security, phishing resistance and modern user experience, and what they’re willing to invest in.
Lessons From The TriZetto Breach
When asked about the key takeaways from the TriZetto Provider Solutions breach and what the incident reveals about vulnerabilities in healthcare IT environments, Cottingham explained:
While suspicious activity started being observed on TriZetto’s systems back in October 2025, over the course of a few months, the company began to uncover that unauthorized third-party access first occurred back in November 2024, almost a year before the unauthorized access was detected.
It’s now been confirmed that the protected health information (PHI) of at least 3.4 million individuals was exposed or compromised.
Incidents like this underscore that the question isn’t just how attackers got in, but how long they were able to move freely once inside, and that points directly to gaps in how access is monitored and controlled at the identity level.
Third-Party Vendor Risk
When asked why third-party vendors are increasingly becoming a major entry point for cyberattacks in healthcare, Cottingham noted:
Healthcare organizations currently rely on a growing network of vendors, from cloud providers to SaaS platforms, billing partners, medical device manufacturers, and IT service firms, which overlap into clinical and operational systems.
Third-party vendors often have weaker security measures, outdated systems, and more access to sensitive data today than ever, making them prime targets for cyberattacks.
Confidence In Vendor Assessments
When asked why only 4% of healthcare organizations feel confident in their vendor risk assessments, Cottingham said:
This gap in confidence from healthcare organizations stems from vendor risk assessments not fully accounting for how identity and access are managed across third parties.
In healthcare, vendors frequently require access to internal systems, devices and data, but if organizations lack visibility and control over who is accessing systems, it makes it difficult to confidently assess or validate vendor risk in practice.
The Password Problem
When asked how weak passwords and phished credentials continue to expose healthcare systems despite growing cybersecurity awareness, Cottingham explained:
Passwords remain a core weakness for healthcare systems because they slow down operations, are easily phished, and create security risk.
Clinicians authenticate across many endpoints throughout the day, including EHRs, imaging systems, nurse workstations, medication carts, printers, and Internet of Medical Things (IoMT) devices.
When a single password can unlock access to all of these endpoints, even a minor breach can ripple across an entire organization.
FIDO And Passwordless Authentication
When asked how FIDO standards and passwordless authentication work and why they are more secure than traditional login methods, Cottingham detailed:
Passwordless authentication solutions replace passwords with secure, user-friendly methods like mobile credentials, smart cards, and passkeys. Moving to passwordless authentication streamlines access, reduces IT overhead, and creates a faster, more reliable login experience.
FIDO passkeys replace shared information with cryptographic credentials and are phishing-resistant due to the fact that they rely on a public/private key pair. The public key is stored by the server, while the private key stays on the user’s device and is never shared.
During login, the system issues a cryptographic challenge that only the private key can satisfy. That design makes passkeys resistant to password theft and phishing in a way traditional passwords are not.
FIDO standards also support multiple authentication forms, including biometrics, security keys, smart cards, and mobile credentials, which makes it flexible as well as more secure.
Transitioning To Passwordless Authentication
When asked how healthcare organizations can transition to passwordless, cryptographic authentication without disrupting existing workflows, Cottingham recommended:
While going completely passwordless immediately may not be possible, healthcare organizations should look to take a phased approach to implementing passwordless solutions.
First, organizations should conduct an audit of their current authentication methods, then make any necessary hardware and software upgrades.
The next step requires choosing the right authentication methods that fit their setting. Mobile credentials, digital wallets, or biometrics may work well for some administrative or non-urgent workflows, while other clinical settings may need different approaches.
For healthcare settings, the transition to updated security measures and credentials should center on minimizing password-entry friction so staff can focus their time and resources on patient care.
Stronger Identity Management
When asked about the role stronger identity management plays in preventing unauthorized access across complex healthcare ecosystems, Cottingham explained:
Stronger identity and access management (IAM) is the foundation of preventing unauthorized access in complex healthcare environments, turning authentication from a login event into an access-control strategy.
An IAM approach gives users access to devices and data only where and when they need it, while providing complete visibility for IT and security management.
Effective IAM ensures visibility into who is accessing what and when, and continuously aligns permissions with roles to prevent misuse.
By integrating identity across systems and applying least-privilege principles, organizations can close security gaps, eliminate the administrative burden of password management, and help streamline access control while maintaining compliance.
Reducing Healthcare Breach Risk
When asked what healthcare organizations should prioritize to reduce breach risks and better secure sensitive patient data, Cottingham concluded:
The starting point for healthcare organizations should be an honest audit of how authentication works in the current environment. Not how that process is documented in policy, but how clinicians and vendors are actually getting into systems.
More often than not, the audit surfaces shared credentials and insecure endpoints that haven’t been effectively addressed in years.
From there, organizations should prioritize eliminating passwords at the point of care. Clinicians shouldn’t be typing passwords dozens of times a day, as that friction creates risk.
Passwordless or tap-and-go authentication gets staff in quickly, keeps sessions tight, and removes the incentive to take shortcuts.
Finally, organizations need to close the gap between what they say they want and what they’re willing to implement. Many health systems list security as a top priority, but when it comes to upgrading authentication infrastructure, it gets deprioritized.
The TriZetto breach is a reminder that attackers will find the weakest link, and right now, that link is still the password.

