St. Peter's Health is a healthcare organization operating more than 20 specialty clinics. The threat model here is the one that keeps every CISO in the sector up at night: protecting patient data and clinical systems across a sprawling, interconnected care delivery network. Healthcare's attack surface is wide - electronic health records, connected medical devices, clinic-to-clinic data flows - and the regulatory stakes are real under HIPAA.
The organization's emphasis on coordinated specialty services means data moves between departments and locations, not just within a single perimeter. That kind of lateral integration demands identity and access management that actually works at scale, network segmentation that reflects clinical workflows, and incident response plans built for environments where downtime isn't just inconvenient - it's a patient safety issue.
Beyond the clinical infrastructure, St. Peter's runs community-facing programs including certification courses for healthcare professionals and public health education classes. Each of those touchpoints - registration systems, learning platforms, public-facing portals - represents an additional attack vector that needs securing. This is the work: defending an org where the blast radius of a breach extends past the network and into the community it serves.






