Managed IT

Healthcare IT Case Studies Featuring Tapestry 360

Three healthcare organizations, three infrastructure decisions, three very different outcomes. From a Chicago FQHC's cloud migration to a $100M ransomware recovery, these case studies show what separates proactive IT planning from a costly scramble.

Blog Post

7 minute read

Aug 04, 2026

Healthcare organizations run on trust: patients trusting their providers, providers trusting their data, and everyone trusting that the systems behind the scenes will hold up when it matters most. That trust is built (or broken) by decisions made long before a patient ever walks through the door: how infrastructure is designed, how data moves between systems, and how prepared an organization is when something goes wrong.

The three case studies below show what that looks like in practice. One is a story about a community health center that got ahead of a security risk before it became a crisis. One is about two competing health systems that found a way to make their records talk to each other. And one is a hard look at what happens when preparation falls short.  

Together, they offer a useful cross-section of the technology decisions healthcare leaders, from the C-suite to the IT director's desk, are facing right now.

Read the full Tapestry 360 story to get a detailed look at their story and the role Impact played.

Tapestry 360

Tapestry 360 Health is a federally qualified health center (FQHC) operating 15 clinics across Chicago's North Side, serving more than 28,000 patients a year.  

Like most FQHCs, it doesn't have the luxury of a large internal IT department; a team of around four people, led by IT Director Scott Simpson, is responsible for the same things any healthcare organization needs: secure access to electronic medical records, protected patient data, and infrastructure reliable enough to support clinicians across multiple locations, all on a budget.

Working with managed IT provider Impact, Tapestry 360 Health strengthened its infrastructure and moved to a more secure, cloud-based environment to support reliable care across its clinics.  

The centerpiece of the project was a move from on-premises servers to a serverless setup, a shift Simpson has called the accomplishment he's most proud of in the partnership, since it delivered a more stable and secure environment for handling protected health information.  

The migration was planned around clinical realities, not just technical ones: when a proposed change wouldn't work for a specific provider's workflow, the plan adjusted rather than disrupting patient care.

The result is infrastructure that's more modern and secure without the operational disruption that often comes with a cloud migration. Just as important, the organization's leadership says it no longer has to spend energy thinking about IT risk, freeing up time and attention for patient care, budget planning, and the day-to-day realities of running an FQHC.  

Leadership also credits the partnership with helping them stay ahead of peer organizations on security and cloud maturity.

Atrium Health and Novant Health

Atrium Health (formerly Carolinas HealthCare System) and Novant Health are two major health systems serving the greater Charlotte, North Carolina region, and in most respects, direct competitors for the same patients.  

Atrium Health had already reached one of the highest levels of electronic medical record adoption in the country, but being advanced on your own EHR doesn't solve a much more common healthcare IT problem: getting two different organizations' systems to actually exchange patient data.  

Fragmented records between competing health systems mean slower care coordination, duplicated tests, and clinicians making decisions without a complete picture of a patient's history.

According to a case study published by HIMSS, Atrium Health and Novant Health reached an agreement to exchange patient health data directly between their EHR systems. The project required more than a technical integration; it meant aligning processes, roles, and change management across two organizations that had little precedent for this kind of direct collaboration.

The agreement helped move the healthcare industry closer to true data exchange and reduced the kind of information blocking that leaves clinicians working from incomplete records.  

It's a useful example of a broader shift happening across the industry: interoperability increasingly depends less on picking the "right" EHR vendor and more on the willingness of organizations to build direct data-sharing agreements with each other.

Ireland's Health Service Executive (HSE)

Ireland's Health Service Executive (HSE) is the country's national, publicly funded health system, encompassing dozens of hospitals nationwide. In March 2021, an HSE employee opened a malicious Microsoft Excel file attached to a phishing email.  

The file sat dormant for weeks. Then, in the early hours of May 14, 2021, the Conti ransomware group detonated its payload. Roughly 80% of the HSE's network was encrypted, according to the organization's own reporting, and hospitals across the country were forced back onto pen and paper. Appointments were cancelled, diagnostic services were disrupted, and patient data was ultimately stolen.

The HSE refused to pay the attackers' ransom demand of nearly $20 million. A week after the attack, the Conti group unexpectedly released a free decryption tool, but that gesture didn't undo the underlying damage.  

A subsequent independent review found the HSE's security posture going into the attack included unpatched systems, outdated antivirus software, and what one report called a "frail" IT infrastructure overall.

It took the HSE until September 21, 2021, more than four months after the attack began, to fully restore its servers and applications. Estimates of the total cost to rebuild systems and respond to the incident have ranged from roughly $83 million to more than $100 million, and the organization is still processing compensation claims from affected patients years later.  

It stands as one of the most extensively studied healthcare cyberattacks on record, largely because of how clearly it illustrates the gap between having some security measures in place and having an infrastructure genuinely built to withstand a serious attack.

What These Three Case Studies Have in Common

Read side by side, these three stories point to a few consistent truths about healthcare IT infrastructure:

  • Budget size doesn't determine outcome, preparation does. Tapestry 360 Health is a resource-constrained FQHC that got ahead of its risk. The HSE is a national health system with far greater resources that didn't. The difference wasn't money; it was whether infrastructure decisions were made proactively or reactively.
  • Interoperability and security are two sides of the same coin. Whether the goal is exchanging data between health systems or protecting it from attackers, the underlying challenge is the same: healthcare data has to move and be accessible to the right people, while staying locked down from everyone else.
  • The cost of inaction compounds. Tapestry 360 Health's migration was disruptive in the short term but avoided a much larger disruption later. The HSE's unpatched systems and outdated infrastructure turned a single phishing email into a four-month, nine-figure recovery. In healthcare IT, deferred maintenance isn't neutral; it's a liability that grows quietly until it doesn't.
  • Leadership buy-in matters as much as the technology. In both the Tapestry 360 Health and Atrium Health/Novant Health stories, success depended on non-technical stakeholders (clinicians, executives, competing organizations) understanding why the change mattered and getting on board with it.

Wrapping Up on IT in Healthcare Case Studies

The through-line across all three of these stories is that healthcare IT infrastructure is never just an IT problem. It's a patient safety problem, a budget problem, and a trust problem, all at once.  

Strong infrastructure doesn't happen by accident: it comes from proactive planning over reactive scrambling, from treating security and interoperability as connected rather than separate priorities, and from getting non-technical leadership genuinely invested in decisions too often dismissed as "just IT."  

The organizations that get this right protect more than their systems; they protect their ability to keep delivering care without interruption.

Read the full Tapestry 360 case study to learn firsthand what a partnership with Impact really entails.  

Andrew Mancini headshot

Andrew Mancini

Content Writer

Andrew Mancini is a Content Writer for Impact's in-house marketing team, where he plans content for the Impact insights hub, manages the publication schedule, drafts articles, Q&As, interview narratives, case studies, video scripts, and other content with SEO best practices. He is also the main contributor on a monthly cybersecurity news series, The Security Report, researching stories, writing the script, and delivering the report on camera.

Read More About Author

Tags

ITHealthcare

Share

Impact Insights

Sign up for The Edge newsletter to receive our latest insights, articles, and videos delivered straight to your inbox.

More From Impact

View all Insights