CISOs working in healthcare are concerned about protecting medical data in the future. The real question is: Who will decide what information should be accessed? Once the policy decision is made, how will the CISO enforce it? A national database of individual medical data would require a root at the national level and potentially even globally. The root has the ability to access all information, thus giving the institution that owns the root great power. It will be difficult to determine who has access to different portions of health care data.”]

