AI can write a policy document in five seconds. But when a high-stakes system drifts, a regulator asks hard questions, or a board needs to know who owns the risk, code and compliance checklists can't raise their hands. That is where I step in.
My work is translating what AI, automation, and emerging technology actually do into decisions a board, a clinician, or a regulator can comfortably stand behind. I help healthcare, MedTech, and regulated technology organizations move AI from theory to accountable operation: designing the human oversight, procurement controls, and lifecycle governance that keep humans securely in charge.
I bring over a decade of cross-functional leadership spanning governance, legal strategy, and cybersecurity risk management. With an LL.M. from Cardozo School of Law and an M.S. in Cybersecurity Risk & Strategy from NYU, my specialty is bridging the gap between complex legal mandates and real-world technical controls. Whether I’m operationalizing multi-million-dollar programs, building privacy frameworks from scratch, or advising leadership through critical tech transitions, my focus is singular: building the structural resilience you can legally and operationally rely on.
My career has been built at the intersection of high-stakes technology, law, and operational risk. I’ve managed a $3 million health technology portfolio, guided HIPAA/HITECH-compliant product launches, and streamlined data-compliance onboarding across complex stakeholder groups. Previously at EY, I served as a GRC and forensic intelligence practitioner supporting high-risk global matters: conducting multilingual regulatory and threat intelligence research, building HIPAA/GDPR risk-mitigation frameworks, and translating dense investigative findings into actionable guidance for legal and technical teams.
My research and technical focus center squarely on emerging AI governance. For my NYU graduate capstone, I applied the NIST AI Risk Management Framework to lifecycle governance for AI-driven surgical robotics, navigating the complex regulatory landscapes of both the U.S. and the EU.
I hold an M.S. in Cybersecurity Risk & Strategy jointly from NYU Tandon and NYU School of Law, an LL.M. in Business Law from Cardozo School of Law, and a foundational law degree (LL.B. equivalent).
Beyond advisory work, I lead as President of a Toastmasters chapter and Chair of a Rotary education initiative. For me, these roles aren't separate from governance: they are the exact same skill: the ability to walk into a room, translate something deeply complex, and make people trust the direction forward.
Sincerely,
Galina Barbascumpa
Merging Passion with Professionalism and Proven Expertise