Carlos Fuentes
Chief Information Security Officer · Modernizing Medicine, Inc. (ModMed)
Carlos Fuentes is Chief Information Security Officer at ModMed (Modernizing Medicine), the healthcare technology company behind the EMA electronic medical record platform. He has spent more than three decades securing information assets in regulated industries, including seven years at the Federal Reserve Bank of New York running technology and security strategy for the Fedwire payment system, and a tenure as the first Chief Information Security Officer of Pegasystems.
Last reviewed: Sep 18, 2026
Carlos Fuentes
Chief Information Security Officer Modernizing Medicine, Inc. (ModMed)
Last Reviewed: September 18, 2026
Executive Summary
Carlos Fuentes is Chief Information Security Officer at ModMed, the healthcare technology company whose EMA electronic medical record and practice management software is used by specialty medical practices across the United States. His career has been spent almost entirely inside environments where a security failure is not an inconvenience but a systemic event: seven years at the Federal Reserve Bank of New York running security for the Fedwire payment system, then insurance and telecommunications, then the first CISO role at Pegasystems, and now protected health information at scale. The thread through all of it is regulated data under continuous audit — the ISO, SOC 2, HITRUST and PCI regimes that sit between a technology company and the customers who have to trust it. He describes his own priority as keeping user experience intact while carrying that weight.
Career Highlights
- Chief Information Security Officer of ModMed, leading global enterprise information security, risk management and IT compliance strategy.
- Appointed the first Chief Information Security Officer of Pegasystems in June 2019, a role created for him, covering security and compliance across roughly 90,000 endpoints.
- Maintained Pegasystems’ ISO 27001, ISO 22301, SOC 2 Type 2, HITRUST and PCI DSS certifications and worked on early alignment with the ISO/IEC 42001 AI management system standard.
- Spent seven years at the Federal Reserve Bank of New York as Vice President of Security and Data for the U.S. payment system, covering settlement of more than $200 trillion in securities and daily transactions on Fedwire.
- Held senior IT and security leadership roles at Verizon, Mitsui Sumitomo Insurance, AIG and Fujitsu Consulting.
- Named six times to the HITEC 100 list of most influential Hispanic technology executives, in 2009, 2010, 2013, 2014, 2015 and 2018.
- Certified Information Systems Security Professional (CISSP).
Professional Journey
Fuentes came up through consulting and large-enterprise IT, with earlier security and technology management roles at Fujitsu Consulting and AIG. He went on to serve as Senior Vice President and Chief Information Officer of Mitsui Sumitomo Insurance, and as Vice President of IT Strategy and Planning at Verizon — two industries, insurance and telecommunications, that shaped a habit of thinking about security as an operating-continuity problem rather than a purely technical one.
The Federal Reserve Bank of New York was the formative posting. For seven years he was Vice President of Security and Data for the U.S. payment system, directing technology and security strategy for Fedwire, the real-time gross settlement service through which the safekeeping and settlement of more than $200 trillion in securities and daily transactions passes. There is little slack in that environment: availability, integrity and confidentiality are all simultaneously non-negotiable, and the adversary set includes nation-states.
In June 2019, Pegasystems named him Chief Information Security Officer — a newly created position at the enterprise software company, based in Cambridge, Massachusetts. His remit there covered information security strategy, risk management, physical security, business continuity planning, crisis management, privacy and compliance. The practical shape of the job was scaling a cloud compliance architecture across roughly 90,000 endpoints while holding ISO 27001, ISO 22301, SOC 2 Type 2, HITRUST and PCI DSS certifications, and beginning to map the company against the then-emerging ISO/IEC 42001 standard for AI management systems, a concern that arrived early at a company selling AI-driven decisioning software.
He subsequently moved to ModMed as Chief Information Security Officer. The healthcare technology setting brings its own regime — HIPAA and HITRUST alongside the general cloud compliance stack — and a customer base of medical practices for whom downtime is clinical, not commercial. Alongside his corporate work, Fuentes has been a visible figure in Hispanic technology leadership circles, named to the HITEC 100 list in six separate years.
Education
Northwestern University
Master of Science, Predictive Analytics
Saint Peter’s University
Bachelor of Arts, Humanities
