Sutter Health operates a sprawling not-for-profit integrated healthcare system across Northern and Central California - over 57,000 employees, more than 3.5 million patients annually, a network of hospitals and medical centers that forms one of the largest attack surfaces in the state's healthcare infrastructure. The threat model here isn't theoretical: healthcare is the most targeted vertical for ransomware and data exfiltration, and the payload is protected health information under HIPAA, medical device networks, and clinical systems where downtime carries direct patient-safety risk.
For security professionals, the challenge is defending a federated environment - thousands of endpoints across geographically dispersed facilities, legacy clinical systems that can't be easily patched, medical IoT with its own firmware and protocol quirks, and a workforce of tens of thousands who need fast, low-friction access to systems that hold some of the most sensitive data in existence. This is infrastructure-scale defense work: identity and access management across a massive organization, network segmentation between clinical and administrative environments, endpoint detection in a world where BYOD meets regulated data, and incident response where the blast radius includes patient care.
Founded in 1921, Sutter Health has operated for over a century as a community-anchored health system. The organization describes itself as people-centered with a focus on collaboration and continuous improvement. For a security team, that cultural posture means the work is consequential - you're protecting systems that clinicians depend on to deliver care to millions of people, in an environment where the regulatory and operational stakes are unambiguous.





