Josh Lewis, J.D.

Director, Cyber Risk Management

Josh is an analytical, energetic, and detail-oriented security leader with legal, audit, compliance, governance, risk management, information security, and data analytics experience. Josh is adept at using this experience to identify problems and solve them through innovative solutions implemented through collaboration with colleagues. Josh is also licensed to practice law in the state of Tennessee.

Josh currently leads a team within HCA Healthcare’s Cyber Risk Management area focused on governance, risk management, regulatory compliance, and data analytics. In this role Josh helps ensure cyber risk management activities are defined, implemented, reported, and aligned with company objectives. This includes ensuring policies, standards, and processes reflect regulatory requirements and applicable authoritative frameworks, a risk register mapped to threats and controls is maintained, and appropriate treatments are applied to risks falling below threshold. Josh also leads a team that makes risk visible through analytics and reporting.

Josh’s prior experience includes leadership roles within Internal Audit, where he was responsible for managing all aspects of complex IT audits of clinical and operational applications, infrastructure technology, HIPAA Security and HITECH Meaningful Use compliance, and Sarbanes-Oxley key controls. 

Josh has also lead the enterprise deployment of various controls, including email retention, data loss prevention, and reducing the prevalence of SSNs within key systems. He has also served as an interim leader of the Information Lifecycle Management function, where he lead the maintenance of the company’s record retention schedule, consulted with stakeholders on retention requirements and strategy, and enhanced the relationships with the company’s off-site paper storage vendors.

Josh holds an Associate’s degree in Political Science from Volunteer State Community College. He also holds a Bachelor’s degree in Management Information Systems and a Master’s degree in Business Administration, both from Tennessee Technological University. He also holds a Juris Doctorate from the Nashville School of Law and is a licensed attorney in the state of Tennessee. 

Josh was born and raised in the Nashville area and remains active in the community. He is married with one child.