Why this belongs on the board agenda now

For most of the history of the nonprofit healthcare and pregnancy help sector, data security was something quiet that happened in the background — if it happened at all. That is no longer a defensible posture, and not because the risk suddenly appeared. It is because the number of people now looking has changed.

Regulators look. State attorneys general have opened consumer-protection inquiries into whether healthcare nonprofits’ public privacy statements match their actual practices. Insurers look: cyber-insurance applications now ask detailed questions about safeguards, and the answers function as warranties. Accreditors look, and increasingly expect organized evidence of working risk management. Donors and the people you serve look, too, and their trust is the asset the whole mission rests on.

This is an observation, not a warning. A board does not need to feel alarmed to act responsibly. It simply needs to recognize that oversight of privacy and cybersecurity has quietly joined the short list of things a healthcare board is expected to govern — and that the volunteer-and-mission model that makes this sector work does not exempt it from that expectation. The good news is that board oversight is exercised through questions, and asking good ones does not require a technical background.

The questions

Below are the questions worth putting to leadership. Under each is a one-line sketch of what a good answer sounds like — not a script to grade against, but a sense of the shape of a reassuring response. Weak answers tend to be vague, verbal, and undocumented. Strong answers point to a named owner and something written down.

Ownership

“Who owns privacy and security here — with the time and authority to actually do it?”

A good answer names a specific person, not a committee or “everyone,” and confirms that person has dedicated time and the standing to change how things are done. “Our IT volunteer handles it when he can” is not ownership; it is a gap wearing a name tag.

Exposure

“Which rules actually apply to us — and do we have that in writing?”

A good answer distinguishes what genuinely governs the organization from what merely sounds impressive, and it exists as a documented determination rather than an assumption. Many pregnancy help organizations, for instance, are not HIPAA covered entities — but that finding should be established deliberately, not guessed. We walk through this in does HIPAA apply to your organization.

Fundamentals

“Are the basics in place — multi-factor authentication, tested backups, and disciplined updates?”

A good answer confirms that multi-factor authentication is turned on for email and key systems, that backups are not just running but have been restored in a test, and that someone keeps software and devices patched on a schedule. These three unglamorous habits prevent a large share of real incidents.

People

“Are our staff and volunteers trained — and does access end the day someone leaves?”

A good answer covers both paid staff and volunteers, since attackers do not distinguish between them, and confirms a routine that disables accounts and access promptly on departure. Training does not need to be elaborate; it needs to be real and repeated.

Vendors

“Who else holds our data — and do we have agreements with them?”

A good answer can list the outside tools and services that touch client or health information — scheduling, email, forms, storage — and confirms there are appropriate agreements in place. You remain accountable for data even when a vendor is holding it. Our vendor risk checklist gives boards a practical way to work through this.

Insurance

“Are the answers on our cyber-insurance application accurate — and could we prove them?”

A good answer treats the application as a set of warranties, not a formality. Every “yes” on that form is a promise that should be backed by evidence, because an inaccurate answer can void coverage at the exact moment you need it. If leadership cannot say confidently that the answers are provable, that is worth knowing before a claim, not during one.

Incident readiness

“Do we have a tested, one-page plan for the day something goes wrong?”

A good answer describes a short, usable incident response plan — who decides, who to call first, how affected people and regulators would be notified, where the plan is stored so it is reachable even if systems are down — and confirms it has been walked through at least once. A plan no one has practiced is a document, not a capability.

Artificial intelligence

“What is our written rule on putting client information into AI tools?”

A good answer is a clear, written policy that staff and volunteers know: what may and may not be entered into AI assistants and chatbots, and why. Sensitive client details pasted into a general-purpose AI tool can leave the organization’s control entirely. The absence of a rule is itself the risk.

Evidence

“If a surveyor or insurer asked, could we hand over organized proof in days — not months?”

A good answer reflects an organization that keeps its risk assessment, policies, training records, and vendor agreements in order as a matter of routine, so evidence is a retrieval task rather than a fire drill. This is where a security risk assessment checklist earns its keep — it turns scattered practice into examinable proof.

How to run the conversation without a technical background

Board members sometimes hesitate to raise these questions because they fear they will not understand the answers. That fear misreads the role. You are not there to evaluate a firewall configuration; you are there to evaluate whether the organization is being governed responsibly — and you already know how to do that from finance and program oversight.

The tell is not technical. When you ask who owns security and hear a confident name; when you ask about the incident plan and someone can describe it plainly; when you ask for proof and are shown something written — those are signs of a healthy program, in any language. When the answers are vague, deflect to “the tech person,” or promise a document that never quite materializes, that is the signal, regardless of how technical the topic sounds. Ask the question, listen for whether the answer points to something owned and written down, and follow up on the ones that do not. Calm, repeated attention from the board is itself a control.

The honest limit

Here is the part that is easy to leave out. A board that asks these questions once, hears reassuring answers, and moves on has done something valuable — but it has also, in effect, graded its own homework. Self-assessment is where real oversight begins, not where it ends.

The organizations that handle this well treat the board’s questions as the first pass and then arrange for the answers to be reviewed independently, by someone whose job is to look at the evidence rather than to have produced it. That is not a vote of no confidence in your staff; it is the same instinct that puts financials in front of an outside auditor. Ask the questions honestly, and then let the answers be checked by someone who was not in the room when they were written.

Questions boards ask next