University of Chicago Medicine operates a sprawling attack surface by any measure. The academic medical center, founded in 1927, anchors its main campus in Chicago's Hyde Park neighborhood alongside community hospitals and dozens of outpatient facilities spread across the region. Its roughly 13,000 employees span clinical care, medical research, and medical education - each domain dragging in its own stack of regulated data, legacy systems, and interconnected devices.
That's the threat model in a healthcare system: protected health information flowing between research labs, clinical workflows, and academic partnerships, all under HIPAA and a patchwork of state and federal mandates. The organization's commitment to a culture of collaboration and diversity extends into its security posture, where defending patient data means building trust across departments that operate with significant autonomy.
For security practitioners, UChicago Medicine presents the kind of environment where the work is concrete and the stakes are immediate - medical device networks, EHR integrations, research data pipelines, and the operational technology that keeps facilities running. The institution's scale and mission mean security isn't an abstract exercise; it's infrastructure that directly enables patient outcomes and research integrity.





