Texas Children's Hospital is a pediatric healthcare system that has been operating since 1954, now spanning four main campuses and dozens of community locations across Texas. It is consistently ranked #1 in the state and holds top-10 national rankings across all ten pediatric specialties, with particular dominance in Cardiology & Heart Surgery. The hospital also maintains a strategic affiliation with Baylor College of Medicine for research and medical education.
The threat model here is healthcare writ large: protecting pediatric patient data, clinical systems, and medical research infrastructure at scale. A security team operating within this environment is managing the intersection of HIPAA-regulated protected health information, connected medical devices, and a sprawling campus network that supports both acute care and active research programs. The attack surface is non-trivial - multiple campuses, community locations, international partnerships, and the data flows that come with a major academic medical center affiliation.
This is not a product company shipping code. It is an organization where the security function exists to safeguard the systems that directly support clinical outcomes for children. That means the domains are operational technology in clinical settings, identity and access management across a complex workforce, network segmentation, vulnerability management, and incident response in an environment where uptime is measured in lives. The work is grounded in healthcare compliance frameworks and the realities of protecting a mission-critical, high-stakes infrastructure.





