A 548-bed teaching hospital serving the Washington, DC metro area from Arlington, Virginia, VHC Health has operated for over 75 years as a not-for-profit health system. It holds a Level II Trauma Center accreditation, a Magnet® designation for nursing, and has appeared in Newsweek's World's Best Hospitals ranking for four consecutive years. The Centers for Medicare and Medicaid Services gave it a 5-star rating. That's a lot of high-value data flowing through clinical and administrative systems every day.
For a cybersecurity team, the threat model is substantial: protected health information under HIPAA, operational technology controlling medical devices, and the attack surface inherent in a teaching hospital environment that integrates research, education, and acute care. The scope covers Northern Virginia and the broader DC metropolitan area, meaning the security posture has to account for both clinical workflows and the compliance demands of a major healthcare provider operating in proximity to one of the most targeted networks in the country.
This is a shop where the stakes are measured in patient safety and regulatory exposure, not just uptime. If you want to run security operations where a misconfigured access control or a missed detection window has consequences that don't fit neatly into a risk register, this is that environment.






