Abstract: Old “data security first” and HIPAA compliance paradigms in healthcare can’t address the patient safety concerns of a hyper-connected healthcare future built (currently) on the back of insecure software. Healthcare devices and infrastructure are generally poorly secured and are rapidly advancing towards the potential to harm or kill patients if compromised (if they haven't already). New healthcare security paradigms must include diverse and novel team members including clinicians working closely with software developers to identify risks to patient privacy and safety.