Tampa General Hospital

A research dossier on Connection's healthcare portfolio matched against TGH's live innovation roadmap — built into thirteen conversations for the CISO's office.

Account
Tampa General Hospital (TGH)
Target Contact
Dan Holland, Deputy CISO
Prepared By
Lorie Tomlinson, Connection
Date
Aug 27, 2026
01

What Connection Actually Sells Into Health Systems

Connection is a Premier Sponsor of CHIME (College of Healthcare Information Management Executives) and runs a dedicated healthcare practice. Seven lines matter for a system the size of TGH — six hospitals, 150+ sites, and an innovation roadmap that keeps adding new edge locations and, now, whole new hospitals.

Connection doesn't have a single flagship product the way Epic is a flagship EHR — the closest thing it has is Healthcare-in-a-Box, the only piece of the practice with its own proper name rather than a category label. The identity underneath that: Connection sells and supports the infrastructure and lifecycle layer a hospital's clinical systems run on top of — devices, data center, managed operations, and security — not the clinical systems themselves. Worth holding onto with Dan specifically: Connection is TGH's infrastructure partner, not an Epic consulting firm, and the seven lines below are what that distinction actually looks like in practice.

Clinical InfrastructureRefresh & Managed Services

  • Healthcare-in-a-Box — preconfigured, ready-to-deploy IT kits for opening or refreshing a clinical site, built to compress turn-up time.
  • Managed Service Desk — outsourced device/app support, incident management, and escalation tuned to clinical environments.
  • Healthcare IT staffing — contract technologists who already speak clinical workflow and regulatory language.
  • 24×7 NOC — proactive monitoring built around uptime for patient-care systems.

Cybersecurity & ComplianceGovernance-Ready Security

  • Compliance services spanning HIPAA, GDPR, and PCI DSS.
  • Security Landscape Optimization — a vulnerability-and-strategy assessment built to feed a risk register, not just produce a PDF.
  • 24×7 threat detection and response powered by Cisco XDR, purpose-built for healthcare's IoT-heavy attack surface.

Clinical MobilityEndpoints Clinicians Actually Carry

  • Integrated Apple–Cisco–PatientSafe–Jamf stack unifying secure device access with clinical communication.
  • Zebra healthcare line — 300+ SKUs: rugged mobile computers, RFID, scanners, and card/badge printers (e.g., the ZC10L).
  • OtterBox and UAG rugged cases across iPhone, iPad, Galaxy, and Surface — carried at the SKU level for fleet-wide standardization.

Physical SecurityCameras & Access

  • Full camera catalog from Axis (410+ SKUs), Motorola (337+ SKUs), and Verkada — including AI-analytics models (aggression detection, forced-entry alerts, license-plate/vehicle recognition).
  • Verkada access-control hardware (mullion readers, video intercoms) for unifying badge and camera events.

Data CenterModern Infrastructure & Consolidation

  • A dedicated Modern Infrastructure & Data Center practice covering hyperconverged infrastructure — Nutanix and VMware, including Cisco Compute HCI on Nutanix — plus cross-platform virtualization visibility (SolarWinds Virtualization Manager across vSphere, Hyper-V, and Nutanix AHV).
  • Disaster Recovery Design and DRaaS, plus Backup-as-a-Service — built for exactly the kind of newly-acquired-site consolidation TGH is mid-way through.
  • Colocation reach through partner Expedient for capacity that doesn't need to be built in-house.

PowerUptime Under Florida Weather

  • APC (Schneider Electric) — AI-ready data center power, from rack UPS to facility-scale.
  • Eaton — BladeUPS, PDU G4 with removable cabling, and Intelligent Power Manager software for hypervisor-integrated power monitoring; Tripp Lite by Eaton for edge/branch sites.
  • Runs seasonal storm-preparedness content — directly relevant to a Tampa Bay system's hurricane exposure.

LifecycleServer & Network Refresh

  • Lifecycle and refresh services across the Dell, HPE, and Lenovo server lines — asset disposition, staged rollout, firmware/compliance baselining.
  • Positioned to retire end-of-support hardware before it becomes an audit finding or a ransomware foothold.
02

What TGH Is Actually Building Right Now

TGH's leadership explicitly avoids long pilots — Chief Digital & Innovation Officer Scott Arnold's stated approach is to "test quickly and scale quickly." That posture is an opening: initiatives below are either already scaling past pilot or built to.

Live Pilot → ScalingWhole-Blood Drone Delivery

  • First-in-the-nation EMS-driven drone program delivering whole blood to trauma scenes, flying from two Hillsborough County fire stations across a 70-square-mile service area, average delivery under three minutes.
  • Built with Hillsborough County Fire Rescue, USF Health Morsani College of Medicine, the Florida Center for EMS, OneBlood, and Archer First Response Systems (ArcherFRS) for drone logistics.
  • Grew out of an earlier ArcherFRS partnership with Manatee County delivering emergency response equipment by drone — this is a program actively expanding its footprint, not a one-off demo.

Command CenterC3 / CareComm + Palantir + GE Healthcare

  • CEO John Couris frames it as a "NASA-inspired" command center — the CareComm hub, relaunched as the TGH Care Coordination Center (C3), runs 24/7 on GE Healthcare infrastructure and Palantir's AI platform.
  • Delivered roughly $40M in savings, eliminated ~20,000 excess patient-days, and cut average length of stay by half a day within its first two years.
  • Expanded AI-enabled coordination is credited with a 3% reduction in sepsis mortality — close to 600 lives.

Surgical InnovationRobotics & Simulation

  • Intuitive da Vinci 5 and the Symani microsurgery robotic system are both in active clinical use.
  • USF's CAMLS center installed GE HealthCare's Allia Moveo — first in Florida, third in the world — with a second unit slated to land at TGH itself in 2026 for clinical use.

Growth / M&ATGH North — Three-Hospital Integration

  • Completed a $294M acquisition of three Community Health Systems hospitals in December 2023 — Bravera Health Brooksville, Spring Hill, and Seven Rivers — renamed TGH Brooksville, TGH Spring Hill, and TGH Crystal River under a new "TGH North" division, plus a freestanding ED, two ambulatory surgery centers, and 10 clinics.
  • CIO Scott Arnold projected a 12-month Epic EHR rollout across TGH North — until that cutover lands, each site runs on infrastructure TGH didn't build.
  • TGH Crystal River sits in Citrus County — the same county TGH at Home expanded into in March 2026, suggesting overlapping regional build-out.
  • Purchased 53 acres north of the region in October 2025, reportedly eyeing a future hospital — the footprint keeps growing, not just consolidating.

Care at the EdgeTGH at Home

  • Hospital-at-home program running on a TytoCare-powered Virtual Health Kit — a cellular tablet plus vitals monitoring — since 2022, serving 2,500+ patients from the Davis Islands flagship.
  • Expanded geographically to Citrus County in March 2026 — every new county is a new set of field devices, connectivity, and identity to secure.
Case File — May 2023

The Snatch ransomware group operated inside TGH's network for roughly three weeks (May 18–30) before detection. TGH's monitoring stopped file encryption, but attackers still exfiltrated data on ~1.2 million patients (names, SSNs, medical record and account numbers, insurance details — the EMR itself was not reached). The breach lawsuit later settled for $6.8M. It's the incident CISO Jim Bowie now references publicly when he talks about cyber resilience and recovery rehearsal — and the direct reason Dan Holland's risk-quantification program exists.

03

Who's in the Room

Holland is the right first meeting — he's the working-level owner of vendor risk conversations — but real budget and technical execution eventually touch the names below too.

NameRoleWhat they optimize forLinkedIn
John CourisPresident & CEOPublic-facing "first in the nation" innovation narrative; sets the ambition, not the spec sheet./in/jcouris
Scott ArnoldEVP, Chief Digital & Innovation OfficerOwns IT, cybersecurity, analytics, biomedical device integration, and innovation end-to-end since 2010. Ultimate budget holder for anything transformational. Publicly averse to slow pilots./in/scott-arnold
Brian HammondSVP, IT Operations & CTO25+ years in IT, at TGH since 2011. Owns infrastructure and systems-integration strategy — managed the security team through TGH's Epic upgrade and the Palantir work behind C3's staffing and PACU-hold-time gains. 2020 Tampa Bay Business Journal CIO of the Year. The likely co-signer on anything infrastructure or data-center shaped./in/brian-hammond
Jim BowieVP & CISORebuilt security for 18,000 users and 70,000 endpoints across 6 hospitals and 150+ sites. Talks to the C-suite in dollars, not CVEs. The gatekeeper on any AI rollout touching data permissions./in/james-b
Dan HollandDeputy CISOBuilt TGH's Cybersecurity Governance Council and its FAIR-based risk-quantification practice. Coast Guard Academy background; co-chairs the Tampa Bay FAIR Institute chapter. The working contact who takes the vendor meeting./in/danhollandarete
Ryan PoggenpohlDirector, Technology Integration & Clinical EngineeringRuns TGH's biomedical/clinical engineering department (three managers, four supervisors, ~30 technicians) — responsible for roughly 40,250 pieces of equipment across the main campus, the three TGH North hospitals, a behavioral hospital, a freestanding ED, and 150+ clinics. The named co-owner Topics 03 and 04 keep pointing to./in/ryan-poggenpohl
A note on accuracy: the brief you gave named "Dan Holland" as TGH's CISO. Public records (LinkedIn, the FAIR Institute, TGH's own newsroom) show Holland as Deputy CISO — the day-to-day contact and the person who literally built TGH's risk-quantification program — while Jim Bowie holds the VP/CISO title above him. The dialogues below target Holland as written; loop Bowie in once a deal has real budget behind it.

Connection: Who's on Our Side

Starting with the rep running the account, then who she'd loop in, and when.

The RepLorie Tomlinson — Twenty Years In

Lorie's path runs through three stops before Connection: Tech Data, where she started in channel sales; Insight, in business development; and six years at Hewlett Packard Enterprise — first as a Business Partner & Manager, then Enterprise Account Manager — before joining Connection on January 1, 2026.

That HPE stretch is the headline. Six years there ran through storage — arguably the single most competitive category in enterprise IT, with Dell, NetApp, Pure, Hitachi, and HPE's own Alletra/3PAR lines all fighting for the same rack space — which means Lorie isn't reciting a spec sheet on Topics 06, 10, 11, and 12, she's closed deals against every major name in that category. The same tenure built real depth in server and disaster recovery/backup, and in Aruba, HPE's networking division — network access control, wireless/wired backbone, and device segmentation carry that weight into Topics 03, 07, and 08.

TGH is effectively her first major healthcare engagement at Connection — she's arriving with the vendor-side depth already built, not building it on this account.

NameRoleBackgroundLinkedIn
Mickey BlandPresident, Enterprise Solutions GroupJoined Connection in Nov. 2022 after ~24 years at Insight Enterprises, most recently SVP & GM of Major Accounts and Global Sales. Reports directly to CEO Tim McGrath — the executive sponsor sitting above the healthcare practice./in/mickey-bland
Jennifer Johnson, CDH-LSr. Director, Healthcare Strategy & Business DevelopmentAt Connection since 2010, in the healthcare practice since 2015. CHIME Certified Digital Health Leader; NVIDIA AI Advisor and Dell AI Champion certified; named a CRN Women of the Channel in 2023 and 2024. The practice's lead strategist — bring her in for an executive-level healthcare conversation./in/jennifer-johnson-cdh-l
Kelly Kempf, CDH-PHealthcare Strategy ManagerAt Connection since 2013; previously at Express Scripts. Runs healthcare go-to-market strategy, vendor engagement, and internal healthcare sales training — the person who'd help scope and staff a multi-topic deal like this one./in/kelly-kempf-cdh-p
Bland, Johnson, and Kempf are sourced from Connection's own newsroom, community blog author pages, and public LinkedIn profiles — not guessed. Lorie's career history came from a mix of public records and direct confirmation of the parts public sources didn't agree on (her Connection start date, and the HPE/Aruba specifics). Confirm titles are still current before looping anyone in, since org charts move.
04

Thirteen Conversations With Dan Holland

Written as one continuous discovery call, broken into thirteen movements. Each opens with why it lands specifically at TGH, then a rehearsal script — not real quotes from either person, built from public information about the account.

LORIE —Dan, thanks for the time. Before we get into anything I'm selling — I read Jim's comments on the resilience panel about the '23 incident, and I saw what you and Lisa are building with the Tampa Bay FAIR chapter. I'd rather spend this call on where those two things point next than on a slide deck.
DAN —Fair enough. Most reps open with a product. Go ahead — where do you think they point?
01

Ransomware Resilience & Recovery Rehearsal

SecurityResilience

The Snatch actors sat inside TGH's network for three weeks before detection in 2023. Bowie now cites that dwell time on cyber-resilience panels as the case for disciplined rehearsal. That's a direct opening for managed detection that shortens dwell time, and for a tabletop exercise Holland can run without pulling his own team off other work.

LORIE —Your team caught the '23 activity before encryption ran, but the dwell window was almost three weeks. Is your current mean-time-to-detect somewhere you're comfortable with today, or is that still the gap you're closing?
DAN —Better than it was. The harder problem is coverage — we've got a lot of legacy systems that EDR just doesn't sit on well. That's where the exposure still lives.
LORIE —That's exactly the gap our 24x7 threat detection runs on Cisco XDR — it's built to pull telemetry from systems that can't run a traditional agent. Would it be useful to run a live tabletop against that scenario specifically, legacy-system compromise, before we talk tooling at all?
DAN —A tabletop I can justify without a purchase order. Send me a scope.
02

Scaling FAIR-Based Risk Quantification

StreamliningGovernance

Holland built TGH's FAIR practice himself — this is his program, not a vendor's. The honest opening isn't to sell him a new framework, it's to ask what's slowing down the one he already runs: usually stale asset and vulnerability data feeding the loss-exposure model by hand.

LORIE —I won't pitch you a risk framework — you've already built a better one than most vendors would show up with. What I'm curious about: what feeds the model today? Is your asset and vuln data current enough that the loss-exposure numbers hold up when Scott's team asks?
DAN —Honestly, it's patchier than I'd like. Some of it's still reconciled by hand across six hospitals.
LORIE —That's the piece our Security Landscape Optimization engagement is built for — it's not a report, it's a live feed of asset and vulnerability data structured to drop into a loss-exposure model instead of a spreadsheet. Worth a scoping call with whoever owns that reconciliation today?
03

Medical Device & IoMT Visibility

SecurityClinical

70,000 endpoints across six hospitals and 150+ sites is largely a biomedical-device problem, and biomedical integration sits in Scott Arnold's org, adjacent to Holland's. It's the natural next question after "legacy systems EDR can't reach."

LORIE —When you say legacy systems EDR doesn't sit on well — are we mostly talking infusion pumps, imaging, that class of device? And is that inventory something your team owns, or is it still Scott's biomedical group?
DAN —Split ownership, which is part of the problem. I see the network traffic, Ryan Poggenpohl's clinical engineering team owns the device relationship.
LORIE —That split is exactly where segmentation projects stall — nobody wants to touch a device neither team fully owns. We've run that reconciliation as a joint workstream with biomedical and security both in the room before. Would it help if I brought a device-visibility scope that names both teams up front?
04

Robotic Surgery & Surgical Simulation Infrastructure

ClinicalInfrastructure

Da Vinci 5 and the Symani microsurgery system are both live in TGH's ORs — network-connected robotic platforms that can't tolerate latency or downtime mid-procedure. Meanwhile, GE's Allia Moveo simulator — already running at USF's CAMLS as the first installation in Florida — has a second unit confirmed landing on TGH's own campus in 2026 for clinical use. That's a dated, near-term infrastructure trigger: a high-fidelity simulator throws off real compute and storage load the moment it's plugged in.

LORIE —Congratulations on the second Allia Moveo unit landing on your own campus this year — that's real validation from GE, not just a USF pilot anymore. Two things come out of that for me: where's the compute and storage going for all that recorded simulation data, and separately, for Da Vinci 5 and Symani in daily clinical use — what's your failover story if the OR network hiccups mid-case?
DAN —The simulation storage is honestly still being sized — we underestimated it the first time, at USF. The OR network redundancy is supposed to be solid, but that's Ryan Poggenpohl's lane more than mine. I couldn't tell you when it was last audited.
LORIE —That's worth a joint look, then, same pattern as the biomedical piece. A high-fidelity simulator generates recorded-session data fast, and it's not the kind of clinical archive anyone purges casually — we can size that properly. Pairing it with a redundancy and failover check on the OR network segment feeding Da Vinci 5 and Symani means neither system becomes the reason a case gets delayed.
DAN —Bring me a joint scope with Ryan named on it, same as the biomedical one. I'll take that one too.
05

AI Governance Ahead of the Next Copilot / Palantir Push

StreamliningAI Governance

Bowie has publicly described asking for two weeks to lock down permissions before Copilot went live, because it inherits whatever a user has already over-shared. As C3's Palantir footprint keeps expanding, that's a recurring need, not a one-time fix — and Connection can pre-package the audit instead of it eating two weeks of Holland's team every time.

LORIE —Jim's mentioned publicly that Copilot needed a two-week permissions lockdown before go-live, because it surfaces whatever's already over-shared. As Palantir's footprint inside C3 keeps growing, is that a one-time cleanup, or something you're going to have to re-run every time the platform expands?
DAN —Every time. It's manual right now, which is the problem — it doesn't scale with how fast Scott wants to move.
LORIE —That's a packaged assessment for us — a permissions and data-exposure audit ahead of any AI rollout, sized to run in days instead of weeks. It'd sit well ahead of whatever's next on the C3 roadmap rather than behind it.
06

C3 Command Center Infrastructure Backbone

AI InfrastructurePower

C3's numbers — $40M in savings, a real dent in sepsis mortality — are a production system making live decisions for six hospitals, not a pilot. As Palantir's data sources keep expanding under it (the same growth driving Topic 05's permissions problem), the network and compute underneath has to scale too, or it becomes the ceiling on the next win. And a room directing patient flow for the whole system 24/7 deserves the same badge and camera discipline as anywhere else sensitive.

LORIE —C3's numbers speak for themselves — $40M and a real dent in sepsis mortality isn't a pilot result, that's a production system making decisions in real time. As Palantir keeps pulling in more data sources across six hospitals, is the network and compute underneath scaling ahead of that growth, or is it playing catch-up?
DAN —Catch-up, if I'm honest. Nobody wants to tell Scott no when he wants another source connected, but the backbone conversation hasn't kept pace with the ambition.
LORIE —That's a specific, fundable piece of work on its own — a capacity and redundancy assessment on the network and compute feeding C3, sized against where Scott wants to take it next rather than where it sits today. And since that room is effectively directing patient flow for the whole system around the clock, it's worth asking who controls access to it, and how it's covered on camera.
DAN —It's badge-controlled. I couldn't tell you off the top of my head when the access list was last reviewed.
LORIE —That's a five-minute check for us to fold into the same proposal — no reason to make it two conversations.
07

AI-Powered Cameras & Workplace Violence Prevention

SafetyPhysical Security

TGH is a Level 1 trauma center — the acuity that makes the ED a magnet for workplace violence is the same acuity that makes it a flagship trauma program. AI camera analytics (aggression detection, forced-entry alerts) is a safety story that also happens to be a Connection catalog with 700+ camera SKUs already carried.

LORIE —Switching gears to physical safety for a second — how's the camera fleet at the flagship holding up? Ed workplace-violence incidents are up across the industry; is that on your radar as a security spend, or still sitting with facilities?
DAN —It's crept onto our side. Most of what we have is passive recording, nothing analytic.
LORIE —We carry Axis, Motorola, and Verkada, including models with aggression-detection and forced-entry alerting layered on top — no camera rip-and-replace required in a lot of cases, since the analytics can sit on existing IP cameras. Would a pilot in one ED be worth scoping before it's a system-wide ask?
08

Badge & Access Credentialing Across 150+ Sites

StreamliningAccess

Six hospitals, 150+ sites, and Citrus County just added another one in March — every new site means new badge issuance and new clinician logon friction. Tap-and-go badge SSO at clinical workstations is the single most direct answer to "streamlining processes" for the people actually doing the work.

LORIE —With Citrus County live, how's badge issuance handled for a new site like that — same central process, or does each site improvise until IT catches up?
DAN —It's centralized eventually, but the first few weeks at a new site are always messier than I'd like.
LORIE —We supply the Zebra badge printers and RFID credentials as part of a standard new-site kit, so day-one badging isn't improvised. And on the clinical side — are your nurses still typing passwords at every workstation, or already on tap-and-go?
DAN —Still typing, mostly. It's on the list.
LORIE —That's usually the fastest-loved change we make — clinicians notice it in week one. Happy to bring a reference from another health system that made that switch.
09

Securing the Whole-Blood Drone Network

InnovationEdge / OT

The whole-blood delivery program isn't TGH's first drone project — it's the second phase of an ArcherFRS partnership that started with Manatee County emergency-equipment deliveries, so it's already proven and actively scaling, not an experiment. That also makes it brand-new edge infrastructure outside the hospital's four walls: unattended dock stations, field tablets, a live dispatch link, and a cold chain for blood in flight — running over cellular, in a hurricane market. Nobody's pitched this yet because the program itself is only weeks old.

LORIE —The whole-blood program is genuinely first-in-the-nation stuff — and I noticed it grew out of the emergency-equipment drone work you'd already done with Manatee County and ArcherFRS. This isn't a science project, it's already on its second real use case. From a security seat, though: the dock stations at the fire houses, the field tablets Hillsborough crews are carrying, the dispatch link between ArcherFRS and your systems — whose risk register does all of that live on as it scales past two stations?
DAN —Good question. Honestly, it's still being worked out — ArcherFRS owns a lot of the flight infrastructure, we own the data that touches our network.
LORIE —That boundary's worth nailing down now, while it's two stations and not twenty. A few specific things I'd want eyes on: those dock stations sit unattended most of the day — any camera coverage against tampering or theft? Blood has to hold a cold chain in flight, so there's presumably a temperature sensor feed somewhere — is that logged and secured the same way any other clinical data would be? And the whole link runs over cellular — what's the fallback if a storm takes towers down at the exact moment trauma volume spikes?
DAN —We have answers to some of that. Not all of it, and not written down in one place.
LORIE —That's the deliverable, then, not a product pitch — just get it written down in one place before it's twenty stations instead of two. We do exactly this kind of edge-network, device, and physical-security mapping for field and EMS deployments. I'd rather help you get ahead of it than have it show up as a finding later.
DAN —Put that in writing and I'll read it before I read anything else you send this month.
10

Storm-Ready Power for Mission-Critical Systems

PowerResilience

A 24/7 AI command center, EHR, PACS, and now drone dock stations all need power that survives a Tampa Bay hurricane season. Connection literally publishes storm-season UPS content — this is home turf, not a stretch.

LORIE —With C3 running 24/7 and now drone dock stations depending on power at fire houses you don't control the facilities for — how confident are you in UPS runtime and battery health monitoring across all of that, especially heading into storm season?
DAN —The flagship's in good shape. The newer, smaller sites are the ones I lose sleep over.
LORIE —That's an APC-and-Eaton conversation more than a Connection conversation, honestly — we carry both, plus Eaton's Intelligent Power Manager, which gives you remote battery-health visibility at small sites without a truck roll. Worth a site-by-site power audit before hurricane season peaks?
11

Data Center Consolidation for the TGH North Integration

Data CenterGrowth

The three Community Health Systems hospitals TGH picked up in the $294M TGH North deal are mid-way through a 12-month Epic rollout — until that cutover finishes, each site is running on infrastructure TGH didn't build, on networks now joined to Holland's. It's also quietly a data center capacity decision: consolidate into TGH's core, stand up new capacity, or run hybrid in the meantime. With TGH also sitting on 53 fresh acres for a possible new hospital, this isn't a one-time cleanup — it's the shape of how TGH grows.

LORIE —Congrats on TGH North — Scott's running roughly a 12-month Epic rollout across the three Bravera/CHS hospitals, if I've got that right. Crystal River's actually in Citrus County, right where TGH at Home just expanded — is that the same regional push, or two separate initiatives that happen to overlap?
DAN —Related, not identical — different teams, same geography. Happens a lot when we grow this way.
LORIE —Good to know, because it means whatever network and infrastructure work is happening in that corridor is probably touching more than one initiative at once. Bigger question: until the Epic cutover finishes, is TGH North still largely running on whatever Community Health Systems had in place, sitting on your network in the meantime?
DAN —Largely, yes. Inherited until cutover — so for a while we've got environments we didn't build talking to systems we did.
LORIE —That's exactly the kind of window that turns into next year's incident report if it's not scoped now — three hospitals' worth of unknown patch levels and asset inventory joining your network before Epic even goes live. Separately, on the infrastructure side: is the plan to consolidate their data center footprint into your core once cutover's done, stand up new capacity, or run hybrid indefinitely?
DAN —Still being decided, and it's more Scott's infrastructure team's call than mine — but it lands on my risk register the moment their network's on ours, so I'm in the room either way.
LORIE —Then it's a joint scope again, same pattern as the biomedical and OR pieces — you, Scott's infrastructure lead, and us: an asset and vulnerability baseline on each TGH North site before full integration, paired with a consolidation plan so nothing sits half-migrated longer than it has to. We run exactly that combination — Security Landscape Optimization for the baseline, Modern Infrastructure and DRaaS design for wherever it lands, whether that's your core, colocation, or hybrid.
DAN —Bring me that scope with Scott's infrastructure lead named on it. Same as the others.
LORIE —Will do. One more thing while we're on growth — I saw TGH picked up 53 acres for a possible new hospital last year. If that goes ahead, that's a data center built from scratch, not a consolidation. Worth a placeholder now so we're at the table when that conversation starts, rather than after ground's broken.
DAN —Noted. Nothing's official yet, but I'll keep you in the loop if it moves.
12

Server & Network Refresh to Retire EOL Risk

StreamliningInfrastructure

Fast geographic growth plus six hospitals means aging, unsupported servers and switches are quietly accumulating somewhere in the estate — the kind of thing that turns into both a compliance finding and a ransomware foothold at once.

LORIE —Do you have a hard refresh cycle for servers and switches across all 150-plus sites, or does it vary site to site depending on when each one was stood up?
DAN —It varies more than it should. Some of the smaller sites are running gear well past support.
LORIE —That's precisely what Healthcare-in-a-Box was built for — standardized, preconfigured kits that make a refresh at a small site as fast as opening one. It turns "we'll get to it" into a repeatable rollout instead of a one-off project every time.
13

Durable Clinical & Field Mobility Fleet

MobilityStreamlining

TGH at Home's TytoCare tablets travel into patients' homes; EMS and drone-program field tablets travel to trauma scenes. Every device outside a controlled building needs a case that survives a drop, and a lifecycle program that doesn't leave a clinician holding a broken tablet mid-visit.

LORIE —Last thing — the TytoCare tablets going into patients' homes for TGH at Home, and now field tablets for the drone and EMS side: what's your device breakage and downtime rate on gear that leaves the building?
DAN —Higher than the in-building fleet, unsurprisingly. We eat some replacement cost every quarter.
LORIE —We standardize field and home-health fleets on OtterBox or UAG rugged cases at the SKU level, plus a repair-or-replace depot so a cracked screen doesn't take a device — or a home visit — out of service. With Citrus County adding volume, that's worth pricing out before the fleet gets bigger.
DAN —You clearly did the reading. Most of what you've named, I'm already worried about — I just haven't had bandwidth to chase all of it at once.
LORIE —Then let's not chase all of it at once. Pick the one with the least friction to start — I'd guess the tabletop, since it costs you a room and an afternoon, not a purchase order.
05

The Close

Leave with one committed next step, not thirteen open threads.

LORIE —Here's what I'll do: scope the legacy-systems tabletop and the Security Landscape Optimization assessment as one proposal, since they feed each other, and I'll draft the biomedical-device and OR/simulation visibility pieces as joint options for Scott's team to weigh in on later. Cameras, badges, the C3 capacity assessment, the drone-network mapping, storm power, server refresh, and the fleet work — I'll leave those as one-pagers you can pull off the shelf whenever budget opens up.
DAN —Send the tabletop scope first. If that goes well, bring Jim in for the risk-quantification piece — that one needs his sign-off on scope, not just mine.
LORIE —Done. I'll have it to you by end of week, and I'd like thirty minutes with you and Jim once he's had a chance to look at it.
  1. This week: Send Dan a one-page tabletop scope (legacy-system ransomware scenario) — low-friction, no PO required.
  2. On tabletop success: Propose the Security Landscape Optimization assessment, framed as feeding his existing FAIR model.
  3. Parallel track: Leave one-pagers on cameras, badge/access, the C3 capacity assessment, the drone-network security mapping, storm power, server refresh, and field mobility — sized for whenever budget cycles open.
  4. Joint-owner track: Scope the biomedical-device and OR/surgical-simulation work with Ryan Poggenpohl named on it, and the TGH North data center consolidation with Scott's infrastructure lead — nothing stalls on ambiguous ownership.
  5. Escalation: Bring Jim Bowie in once the tabletop or the risk-quant proposal has real scope attached — not before.
06

Sources

Dan Holland and Jim Bowie are real people with public professional profiles (LinkedIn, the FAIR Institute, TGH's newsroom, industry podcasts). Every line attributed to "Dan" or a summarized fact about TGH's people or programs below is built from those public sources. The dialogue itself is a rehearsal script for Lorie to practice with — not a transcript of anything either of them has actually said to Connection. Verify current titles and priorities directly before a real meeting.