Hospital Sisters Health System is a Catholic healthcare operator running 13 hospitals across Illinois and Wisconsin, backed by more than 10,000 staff and over 1,000 physician partners. Founded in 1875, the organization carries a 150-year operational footprint - which, in cybersecurity terms, means legacy infrastructure, sprawling attack surfaces, and a threat model shaped by the healthcare sector's relentless exposure to ransomware, phishing, and data exfiltration targeting protected health information (PHI).
For security professionals, the scope is concrete: a multi-site hospital network generating high volumes of sensitive patient data, connected by clinical systems that can't afford downtime. The environment spans electronic health records, medical devices, and partner-facing portals - all subject to HIPAA compliance obligations. Defending that means endpoint detection across hospital floors, network segmentation between clinical and administrative domains, incident response planning that accounts for patient safety, and identity management scaled to thousands of users with varying access levels.
HSHS operates under a mission rooted in Franciscan values, emphasizing relationships built on respect and competence. Practically, that translates to an organization where security isn't just a technical function - it's a trust obligation. The stakes are legible: a breach doesn't just mean regulatory fines or downtime; it means compromised care delivery. Teams working here are securing infrastructure where the consequences of failure are measured in more than dollars.






