West Tennessee Healthcare is a public, not-for-profit system spanning roughly 90 hospitals and medical centers across 9,000 square miles of West Tennessee, serving more than half a million people. Its anchor facility is a 642-bed hospital. The organization employs over 7,000 people and operates six Centers of Excellence - including high-volume cardiac, cancer, neuroscience, women's health, and emergency programs - plus the region's only Joint Commission-certified stroke center and only Level 3 NICU.
The cybersecurity threat model is defined by healthcare's attack surface: electronic health records, connected medical devices, and a sprawling network of clinical endpoints across dozens of facilities. The system is self-supporting - reinvesting all revenues into care, technology, and facilities rather than relying on local tax revenue - meaning security investments compete directly with clinical capital. That's a real-world constraint any security engineer should understand walking in.
No specific tooling or security stack details have been published. What's clear is the operational footprint: a regional healthcare system with the complexity of a large enterprise, a mission-critical uptime requirement, and regulatory obligations under HIPAA and Joint Commission standards. The team defending it is protecting clinical workflows that directly affect patient outcomes - not abstract data, but live care delivery at scale.






