US Anesthesia Partners (USAP) operates at a scale where the attack surface isn't theoretical - it's a sprawling, distributed network. The organization delivers anesthesia care across more than 700 inpatient and outpatient facilities in 12 states, with over 5,000 clinicians and 4,500 clinical team members handling more than 2 million cases annually. That volume means every scheduling system, every patient record, every connection between a surgical center and a physician practice is a potential vector. The threat model here is healthcare-specific: protecting highly sensitive patient data across a decentralized operational footprint while maintaining the uptime and integrity of systems that directly support patient care.
The organization is physician-owned and clinician-led, independently governed by approximately 1,500 physician shareholders. This structure shapes how security decisions get made - clinical outcomes and patient trust are baked into the governance model, not bolted on as compliance requirements. USAP's clinical performance metrics are concrete: a 96%+ patient satisfaction rating, 100% of practices receiving positive performance scores in the CMS MIPS program, and a 45% lower 30-day readmission rate for select surgical procedures versus benchmarks. When your security posture directly supports those outcomes, the stakes are legible.
For a cybersecurity team, the operational domains span endpoint protection for thousands of clinicians, securing data flows between hundreds of healthcare facilities, identity and access management across a physician-led governance structure, and ensuring compliance in a heavily regulated environment. The geographic spread across states including Texas, Florida, Colorado, Ohio, and Washington D.C. means navigating varied state-level data protection requirements alongside federal healthcare regulations like HIPAA. The work is less about perimeter defense and more about securing a complex, distributed healthcare ecosystem where every connection matters.





